A chief information security officer—if the company can even afford one— is woken by an urgent phone call in the middle of the night. There’s been a breach. Threat actors stole highly sensitive customer data, and now they’re demanding a ransom. If the company doesn’t pay, they will leak data on the Dark Web. That’s when the clock, and the financial fallout, starts ticking.
Whether it’s a ransomware attack, business email compromise, or a third-party supply chain attack, organizations have unfortunately become increasingly accustomed to suffering data breaches. But they are caught between rising threats they can’t ignore and burgeoning defense costs they can’t sustain.
The paradox is leading to a cybersecurity affordability crisis. For small-to-medium sized businesses (SMBs), which lack the deep pockets of large enterprises, one breach could shutter their doors permanently.
The global average cost of a data breach reached a record $4.99 million in 2025, according to IBM’s “2026 Cost of a Data Breach Report,” that noted a 12% rise over the previous year. That equates to $1,100 per hour.
Meanwhile, Gartner projects global cybersecurity spending costs for organizations – including network security, security services, and software security – will reach $239.8 billion this year, up from $193.4 billion in 2024. Artificial intelligence (AI) adoption is only adding to the challenge as organizations race to implement the latest models.
Save the SMBs, Save the World
Attackers target SMBs more often compared to large enterprises because they know they’re the weak link, either due to budget constraints or because cybersecurity is not a priority. Although SMBs pose a systemic risk to the supply chain, the market doesn’t reflect that.
While vendors releasing new security tools may be doing it for the right reason, and truly want to manage risks and prevent attacks, their venture capital backers want them to find the more profitable big fishes, explains Bryson Byrd, cybersecurity advisor for Huntress.
Subsequently, venture-backed vendors will develop a product for large enterprises that’s more expensive or doesn’t consider that smaller businesses lack a dedicated security team or around-the-clock security operations center, leaving them behind. That’s a disservice to organizations of all sizes, Byrd tells Dark Reading.
“When you have millions of small businesses that exist, what ends up happening is disproportionately we – as a country, we as a community, however we want to define it – are less secure,” says Byrd.
While cybersecurity is a budget issue, Byrd argues that it’s also a prioritization and business resilience issue as much as anything else. Those are the problems that need to be solved, especially in the SMB space, he urges.
Don’t Bank on AI to Reduce Costs
The issue is less that organizations have suddenly stopped spending money on cybersecurity and more that the economics are getting harder to sustain: Costs are rising faster than budgets while security headcounts remain the same, says Syed Ghayur, VP of solution engineering at ArmorCode. He believes the industry is seeing the early signs of a cyber affordability crisis.
Security teams are being asked to process dramatically more risk without a comparable increase in people or budget, Ghayur adds. He notes the average enterprise already operates with 40 security scanners, and points to research from Palo Alto Networks and IBM that says broader security stacks include 83 tools from 29 vendors.
Tool sprawl has created significant duplication as companies invest in dozens of scanners and security products that generate overlapping findings but are not specific to the business context, Ghayur says.
AI adds another cost layer. Organizations rapidly adopted AI to supplement their security tools, but research shows costs were higher than anticipated, including spending on tokens and premium tiers. Using expensive AI to analyze every vulnerability finding indiscriminately may inflate costs and only add to alert fatigue.
“Without prioritization and cost governance, spending can scale with the number of findings, rather than the amount of actual risk being reduced,” says Ghayur.
Additionally, AI can actually create more problems. One study by 1Password found large language model-generated patches did not resolve a vulnerability, added a new one, or did both 53.9% of the time on average.
The number of reported vulnerabilities outpacing remediation capacity means throwing more people or more scanners at the problem becomes increasingly expensive without necessarily reducing more risk, Ghayur warns.
“The risk is that organizations respond in one of two bad ways,” he says. “They either spend indiscriminately trying to keep up, or they automate indiscriminately to reduce costs. The latter can be particularly dangerous in cybersecurity.”
Focus on Risk, Not Findings
It’s important to address this problem because it affects critical infrastructure organizations like healthcare and manufacturing; these operate with legacy equipment but are highly targeted by a range of threat actors, including nation-state hackers. Consulting company Signisys recommends that most enterprises should allocate eight percent to 12% of their total IT budget to cybersecurity, and organizations in healthcare, financial services, and government should target 10% to 15%.
That can be a big ask for an organization operating with few resources. The answer is not to buy less security, but for organizations to get more measurable risk reduction from the security investments they already have, recommends Ghayur. That starts with shifting the unit of measurement from findings to risk, he says, adding that the same discipline needs to apply to AI investments.
Ghayur believes the next phase of cybersecurity economics will look a lot like what the FinOps Foundation did for the cloud. Like today’s AI adoption, organizations moved to the cloud thinking it would save them money compared to on-premises servers, but costs climbed higher than expected. FinOps aimed to boost visibility, efficiency, and accountability by setting up a framework to establish policies and cost controls.
“Security leaders will increasingly need to prove not only that they are reducing risk,” he anticipates, “but that every dollar, every engineering hour, and increasingly every AI token is being spent on the exposures that matter most.”

Comments are closed