IT Strategy

Cybersecurity has been CIOs' top budget line for three years. That's the tell.

When the same category tops the list three years running, it has stopped being a priority and become a standing tax. What CIOs do with the rest of the budget is the more interesting question.

Cybersecurity has topped CIO budget priorities for a third consecutive year. That is not a sign of urgency. It is a sign of a bill that never gets paid off.

A permanent line, not a project

Nearly half of CIOs plan to increase technology spending this year, and 47% will put fresh money into cybersecurity specifically. Three straight years at the top of the list means security has quietly moved from "initiative" to "overhead" — closer to payroll than to a project with an end date. That reclassification matters, because overhead gets budgeted differently than initiatives do. It should be sized to risk, not negotiated annually as if it might shrink.

Most CIOs are still negotiating it annually as if it might shrink.

The money is chasing the wrong horizon

67% of CIOs are investing in AI and machine learning, 52% in data and analytics, and 47% in security — a spending mix that reads as an organization hedging every direction at once rather than committing to one. Operationalizing AI and firming up the data foundation both made the top-three list alongside cybersecurity this year. That is not obviously wrong, but it is worth noticing that two of the three priorities are aspirational and one is defensive. Defensive spending protects what you have. Aspirational spending is a bet on what you might become. Funding both at similar levels usually means neither gets funded properly.

What proportional actually means

The standing belief worth restating here is that governance, including security governance, should be proportional to risk. In practice this means the security budget should track the size of the attack surface — which is growing every time a new AI agent gets a credential, a new SaaS platform gets connected, a new vendor gets a foothold in the stack. If the security line has been flat while the surface has expanded, "top priority" is a label, not a fact.

The test for whether your security spending is proportional rather than ceremonial: can you point to the specific systems, accounts, and vendors driving this year's increase, or is the number simply last year's plus inflation? If it is the latter, you are funding a habit, not a risk model.

Treat cybersecurity's permanent place at the top of the list as the baseline it has become, and spend the rest of the budget as if the baseline is already covered — because if you keep re-litigating it every cycle, it never will be.

What this reacts to

The daily brief

CIOReview, in your inbox before standup

The headlines technology leaders are reading, synthesized and source-linked. One email each morning. No filler.