Cybersecurity spending rises as AI reshapes IT budgets and staffing
New research shows cybersecurity spending remains resilient as organizations shift IT budgets toward AI and rethink security staffing.
Key takeaways
- Security software spending is still growing, even as organizations redirect parts of IT budgets toward AI.
- Cybersecurity teams may see fewer cuts than other IT functions because AI is also increasing attacker speed and sophistication.
- AI may shift cybersecurity roles, but it is unlikely to eliminate the need for skilled security professionals.
A survey of 1,636 technology leaders conducted by the market research firm ETR, an arm of the Futurum Group, finds investments in security software increased 7.8% year-over-year at a time when many organizations are reallocating IT budgets to fund artificial intelligence (AI) initiatives.
However, the survey also finds that 18% of respondents have reallocated some portion of their security software budget to help pay for the cost of adopting AI, with just under a quarter (23%) expecting to also reduce cybersecurity headcount.
Those percentages are significantly less than in other sectors where, for example, 47% and 46% of respondents noted their organization has reduced spending on IT operations and monitoring tools and productivity and collaboration tools, respectively, to fund AI initiatives. The survey finds organizations are also looking to reduce headcount in IT support and helpdesk (60%), software and application development (58%), IT operations and infrastructure (53%), and IT administration and back office (51%).
How is AI changing IT staffing plans?
Overall, the survey finds nearly all organizations (96%) are leveraging AI to some degree, which is now having a significant impact on the IT labor market. More than a third (34%) are now limiting future headcount (34%), while 20% report their organization is strategically reducing headcount (20%) as they adopt AI.
The paradox is that even as cuts are made to staffing, investment in IT overall continues to increase, with respondents reporting a collective 3.8% increase year-over-year. Just under three quarters of respondents (72%) said their organization plans to continue increases in IT spending.
Given how AI might enable adversaries to launch cyberattacks at machine speed, it should not be all that surprising that any future staffing cuts will be much more limited among cybersecurity teams. However, it’s apparent that business and IT leaders do expect AI to reduce IT staffing. Whether that will actually happen, however, is unclear because in many cases IT staff are — thanks to AI — taking on more work, much of which was never previously done simply because there were not enough hours in the day.
What does this mean for SMBs and cybersecurity talent?
Of course, there are plenty of small-to-medium businesses (SMBs) that previously might not have been able to hire and retain the cybersecurity expertise needed. It wasn’t too long ago when many cybersecurity jobs postings went unfilled for months. Many of the cybersecurity professionals that are cut by one organization might discover there are still plenty of other organizations that still desperately need their expertise in an AI era where the fundamentals of cybersecurity are now being fundamentally altered.
At this juncture, no one can say with absolute certainty how AI will ultimately impact cybersecurity. While there is a natural tendency to want to justify the return on investment (ROI) by reducing headcount, the fact remains that adversaries are also going to be investing in AI to, in part, reduce headcount. The challenge is that they will use AI to simultaneously increase the volume and sophistication of the attacks being launched. That, in turn, will require hundreds of thousands of AI agents to thwart in real time. The issue then becomes determining who will ultimately be responsible for managing all those AI agents that, as already demonstrated, may not be behaving as intended at any given moment.
Relatório de Ameaças de E-mail de 2026
Saiba como a IA e o phishing como serviço estão a remodelar o panorama das ameaças de e-mail e como se proteger.
Subscreva o Blogue Barracuda.
Inscreva-se para receber destaques sobre ameaças, comentários do setor e muito mais.
O Relatório de Ameaças Globais XDR Gerido
Principais conclusões sobre as táticas que os atacantes utilizam para atacar as organizações e as vulnerabilidades de segurança que tentam explorar.