THREAT BRIEFING · 14.09.2026 DEENFRES

Strategy & Governance

Checklist: Planning Your 2025 Security Budget

By Tobias Massow · January 20, 2025 · 4 min read

Budget season is here. This checklist helps CISOs and IT directors plan their 2025 security budget in a structured way – from inventory to compliance requirements to prioritization.

TL;DR

Budget season is here. This checklist helps CISOs and IT directors plan their 2025 security budget in a structured way – from inventory to compliance requirements to prioritization. Including benchmarks for typical cost items.

Phase 1: Inventory (Weeks 1-2)

Capture current expenses:

Evaluate usage:

Phase 2: Define Requirements (Weeks 3-4)

Regulatory obligations for 2025:

Technical gaps:

Phase 3: Prioritization (Weeks 5-6)

Assign each planned investment to one of three categories:

  1. Must-Have: Compliance requirements, critical gaps, expiring contracts
  2. Should-Have: Efficiency gains, automation, consolidation
  3. Nice-to-Have: Emerging technologies, innovation projects

Benchmarks for 2025

Key Facts

6-14% of the IT budget is the industry average for security (Gartner 2024)

NIS2, DORA, and the AI Act create new mandatory expenses in 2025

Tool consolidation saves an average of 15-25% with the same coverage

Managed Detection and Response is growing as an alternative to an in-house SOC

A security budget without a business case loses support from the executive board

Fact: 95 percent of all cybersecurity incidents are due to human error, according to IBM.

Fact: The average cost of a data breach in 2025 was $4.88 million, according to IBM.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

How do I argue for the security budget with the executive board?

With three arguments: compliance requirements (NIS2 threatens personal liability), damage prevention (average ransomware costs in DACH: €1.2 million, according to Sophos), and insurability (cyber insurers are increasingly demanding minimum standards).

Should I invest in my own SOC or MDR?

For companies with fewer than 1,000 employees, MDR is almost always more cost-effective. An in-house SOC requires at least 5-7 analysts for 24/7 operation – personnel costs of €500,000+ annually.

Further Reading

NIS2 Directive: What Companies Need to Know

Cyber Insurance 2026

Zero Trust: The 7 Most Common Mistakes

Does every company need a CISO?

Not every company needs a full-time CISO, but every company needs clear accountability for IT security at the executive level. SMBs can rely on an external CISO (Virtual CISO). With NIS2, management responsibility will be legally anchored.

Related Articles

More from the MBF Media Network

MyBusinessFutureBusiness Future: Trends for decision-makersDigital ChiefsC-Level perspectives on IT security

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH