Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Cybersecurity Spending Trends for 2022: What Organizations Planned to Fund

Organizations expected cybersecurity budgets to rise or remain level in 2022. Here is what drove spending, where it was allocated and how leaders could measure whether investments reduced business risk.
From TheFinanceBase Team7 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cybersecurity budgets were expected to rise or hold steady in 2022, but the important change was where organizations planned to put the money. Surveys pointed to greater emphasis on cloud security, identity, managed services, staffing, resilience and third-party risk—not simply more security products. Because the source forecasts were published in late 2021, these figures describe expectations for calendar 2022 rather than an audited total of what every organization ultimately spent.

How much cybersecurity spending was expected in 2022?

Three different measures are often quoted together, although they answer different questions.

Measure 2022 expectation What it represents
CSO Security Priorities Study 44% expected an increase; 54% expected level funding; 2% expected a decrease Security leaders’ expectations for their own budgets over the following 12 months
PwC 2022 Global Digital Trust Insights 69% expected cyber spending to rise; 26% expected an increase of at least 10% Global executive survey; the budget question had its own respondent base within the wider survey
Gartner forecast reported by CSO $172 billion worldwide, versus $155 billion in 2021 and $137 billion in 2020 Global information-security and risk-management market spending, not an average company budget

The CSO survey’s 44% increase figure was close to the prior year’s 41%, while the share expecting a decrease fell from 6% to 2%. PwC surveyed roughly 3,600 business, technology and security executives across more than 60 territories; its report identifies 1,638 technology and security executives for the budget-change question. The figures therefore should not be averaged into a single “global budget growth rate.” See the CSO analysis and PwC report.

What counted as cybersecurity spending?

Organizations and market analysts used different boundaries. A company budget might include software and hardware, security employees, consultants, managed monitoring, incident response, awareness training, compliance work, identity and access management, cloud and application security, governance and risk management, and security operations. Gartner’s “information security and risk management” market is broader than a typical security department cost center. Comparing a market forecast with an internal budget without defining the scope can produce a misleading conclusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why budgets were rising or staying protected

Threats with business consequences

Ransomware, financially motivated attacks and criminal marketplaces increased the potential cost of downtime, extortion, data loss and recovery. Interconnected systems and critical infrastructure made a security incident a continuity and reputation issue, not merely an IT problem. Executives also faced the possibility that a breach would become a public crisis affecting customers, investors and partners.

Remote work and cloud transformation

Hybrid work expanded the number of locations, devices and networks requiring protection. Cloud migration changed where identities, applications and data were managed. In the CSO survey, hybrid or remote work influenced 41% of respondents, while digital transformation and cloud migration influenced 38%.

Rules, customers and boards

Best practices and compliance, regulations or mandates were each cited by 49% of CSO respondents; those answers could overlap and do not establish causation. Boards and customers increasingly asked for evidence of security capability, while suppliers were assessed as part of broader business risk. The May 2021 U.S. executive order on cybersecurity was one influence, particularly for organizations serving the federal government or Department of Defense; it did not impose identical obligations on every company.

Recent incidents

A security incident in the respondent’s own organization influenced 35% of CSO respondents, and an incident at another organization influenced 25%. PwC also reported that more than half of executives expected an increase in reportable incidents in 2022. That was a pre-2022 expectation, not a verified count of incidents that occurred.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where organizations planned to put the money

The CSO survey reported this allocation of security spending. These are survey results, not recommended ratios or a universal industry budget.

Category Share of surveyed allocations
On-premises infrastructure and hardware 20%
Skilled security staff 19%
On-premises tools and software 16%
Cloud-based security solutions 10%
Consulting services 7%
Cloud-based security monitoring services 7%
Security awareness training 7%
Contracted evaluation services 6%
External incident-response services 5%

CSO’s report, which attributes the following figures to Gartner, estimated 2022 spending by broader market category as follows:

Gartner category Estimated 2022 spending
Security services Nearly $77 billion
Infrastructure protection $30 billion
Network security equipment $19 billion
Identity and access management $17 billion
Application security $6.6 billion
Integrated risk management $6.4 billion
Data security $4 billion
Security software $2.7 billion
Cloud security $1.4 billion

“Security services” can include consulting, managed services, support and other labor-intensive work, so its nearly $77 billion estimate is not directly comparable with a single software category. Gartner’s category definitions may also place some cloud-related activity elsewhere.

The strategic priorities behind the spending

Identity and a staged zero-trust program

As users, devices, applications and workloads operated from different locations, identity became a primary control point. Practical investments included multi-factor authentication, stronger authentication methods, role-based access, privileged-access management, behavior analytics and microsegmentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Zero trust is an architectural and policy approach, not a product or guarantee. A workable program requires asset visibility, identity governance, segmentation, monitoring and continual policy enforcement. Buying a “zero-trust” tool without those foundations can leave the core risk unchanged.

Cloud and application security

Cloud protection involved misconfiguration prevention and detection, cloud entitlement management, workload and container security, encryption, logging, application programming interface security, infrastructure-as-code scanning, secrets management and secure development practices. Shared-responsibility boundaries had to be explicit. Cloud platforms can provide scalable security capabilities, but they also increase the complexity of identities, data flows, configurations and third-party dependencies.

Services, staffing and automation

Security services were large because experienced defenders were scarce and many organizations could not operate a 24/7 security operations center alone. Managed security providers, threat hunting, incident-response retainers and specialist cloud or compliance consulting could add coverage without matching every capability with full-time hires.

The choice was not “people or technology.” Hiring and retaining defenders, upskilling IT and engineering teams, training the wider workforce, automating repetitive triage and using managed detection and response all had to fit one operating model. Automation fails when data quality, integrations, ownership or response playbooks are weak; adding analysts fails when fragmented tools create unmanageable alert volume.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Third-party and supply-chain risk

PwC found that 60% of respondents had less than a thorough understanding of breach risk through third parties, including 20% who had little or no understanding. The survey covered 3,602 executives in July and August 2021; see the PwC announcement.

Budget implications included a vendor inventory, critical-supplier classification, selective evidence-based assessments, contractual security and incident-notification terms, continuous monitoring for important providers, software-dependency visibility where relevant, access reviews, continuity testing and concentration-risk analysis. Questionnaires alone could not provide that assurance.

Incident response and resilience

Prevention did not remove the need to detect, contain and recover. Organizations funded external response retainers, tested playbooks, backup restoration, ransomware exercises, recovery objectives, crisis communications and continuity planning. A prevention-heavy budget that leaves restoration untested can still produce prolonged business disruption.

Why more spending did not automatically mean better security

  • More products can create duplicate telemetry, conflicting alerts, multiple consoles and unclear ownership.
  • A platform consolidation can simplify operations but create vendor lock-in or leave coverage gaps.
  • Licensing is only part of total cost; implementation, integration, staffing, training, data retention and renewals also matter.
  • Compliance establishes a required baseline, but an audit-ready control may not address the most consequential attack path.
  • Outsourcing provides coverage and expertise, but accountability remains internal. Contracts need service levels, data-handling rules, escalation authority, logging access, performance validation and an exit plan.
  • Cloud adoption does not remove identity, configuration, data-flow or supplier risk.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to prioritize a cybersecurity investment

Use a consistent business-risk score rather than selecting the most fashionable category. For each proposed investment, document:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Business criticality: Identify the revenue stream, customer service, regulated data or operational capability at stake.
  2. Threat and exposure: Name the credible attack path and the systems, identities or suppliers exposed to it.
  3. Control gap: Describe what is missing, ineffective or untested today.
  4. Effectiveness: State how the control should reduce likelihood, limit impact, improve detection or speed recovery.
  5. Coverage and integration: Check cloud, on-premises, remote, mobile and third-party environments, along with identity, endpoint, ticketing and response integrations.
  6. Operating burden: Assign configuration, monitoring, tuning, maintenance and escalation ownership.
  7. Total cost and exit risk: Include implementation, personnel, training, renewal and data-export or replacement requirements.
  8. Measurement: Set a baseline, target and review date before approving the spend.

Metrics that show whether the investment worked

Exposure and prevention

  • Percentage of critical assets inventoried.
  • Multi-factor authentication coverage for employees, contractors and privileged users.
  • Time to remediate critical vulnerabilities.
  • Internet-exposed assets with unacceptable risk.
  • Secure-configuration compliance and critical-vendor assessment coverage.

Detection and response

  • Mean time to detect, contain and recover.
  • Alert-to-incident conversion rate and high-severity alert backlog.
  • Coverage of endpoint, identity, cloud and network telemetry.
  • Percentage of incidents handled according to tested playbooks.

Resilience and business alignment

  • Recovery-point and recovery-time performance.
  • Backup restoration test results and ransomware tabletop completion.
  • Business-continuity exercise results.
  • Risk reduction per dollar, reduced material attack paths and control coverage for revenue-critical services.
  • Board-approved risk acceptance and residual-risk reporting.

These measures demonstrate preparedness, coverage and risk reduction; they cannot prove that a breach will never occur.

How to present the budget to a board or CFO

Frame the request around business services and scenarios rather than a product list. Show the current exposure, the control gap, the expected reduction in likelihood or impact, recovery objectives, alternatives considered, total cost over the planning period and the residual risk that would remain. Assign an owner and review date to every material outcome. This makes a flat budget defensible when it funds the highest-risk gaps, and it makes an increase defensible when existing controls cannot meet the organization’s resilience or regulatory obligations.

For readers evaluating vendors, examples of relevant categories include identity platforms such as Microsoft Entra ID, Okta Workforce Identity and Cisco Duo; endpoint and response platforms such as Microsoft Defender for Endpoint, CrowdStrike Falcon and SentinelOne Singularity; and managed services such as Arctic Wolf MDR, Secureworks Taegis and Red Canary MDR. These are examples, not endorsements. Current enterprise prices were not confirmed, and quote-based costs vary with users, endpoints, data volume, modules, geography, implementation and contract term.

The Bottom Line

2022’s outlook pointed to protected or growing cybersecurity budgets, but the durable lesson is allocation: combine identity, cloud controls, capable people, managed expertise, third-party oversight and tested recovery, then measure the reduction in business risk. A larger tool budget without ownership, integration and evidence of outcomes is not the same as better security.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.