Businesses are increasing cybersecurity budgets, driven by rising financial losses from cyber incidents and evolving threat complexities. Kaspersky advises adopting advanced security solutions and managed services to safeguard against these risks effectively.
3 December 2024 – In response to escalating financial losses from cyber incidents, businesses worldwide are significantly increasing investments in cybersecurity, as revealed in Kaspersky’s latest IT Security Economics report. This annual study explores trends in IT security budgets, breaches, and challenges based on interviews with IT professionals across 27 countries in Europe, the Asia-Pacific, the Middle East, Turkey, Africa, and the Americas.
The report indicates that companies plan to raise IT security budgets by as much as 9%. For large enterprises, median cybersecurity spending is expected to reach $5.7 million, with total IT budgets averaging $41.8 million. Small and medium-sized businesses (SMBs) are allocating $0.2 million for cybersecurity from a median IT budget of $1.6 million.
Financial losses remain a significant driver of increased cybersecurity investment. Large enterprises reported an average of 12 cyber incidents in the past year, incurring $6.2 million in recovery costs—exceeding their median cybersecurity budget. Despite sophisticated defenses, the complexity of their IT environments makes them vulnerable to expensive breaches.
SMBs, facing even greater proportional impact, reported 16 incidents on average and spent $0.3 million on remediation—1.5 times their median IT security budget. Limited resources and weaker policies leave SMBs susceptible to issues such as public cloud misconfigurations, employee-related incidents, and inadequate permission controls.
“This data highlights a sustained growth trend in cybersecurity spending across all segments,” said Veniamin Levtsov, Vice President, Center of Corporate Business Expertise at Kaspersky. “Key factors include the increasing complexity of cyber threats, evolving regulatory requirements, and rising salary expectations for cybersecurity professionals.”
Kaspersky recommends adopting advanced solutions like its Next product line for comprehensive real-time protection, as well as managed services such as Kaspersky Managed Detection and Response (MDR) for companies lacking in-house expertise. These tools provide advanced investigation capabilities, automated response, and 24/7 protection to combat sophisticated cyber threats.