Cybersecurity

We Fought for Cybersecurity Dollars. AI Got Them Without a Fight.

8 min read

After 22 years in IT leadership, I've witnessed numerous budget cycles where organizations chase the latest innovation. Throughout 2025, I've observed a concerning trend that mirrors past mistakes but with potentially greater consequences and a troubling irony at its heart.

After 22 years in IT leadership, I've witnessed numerous budget cycles where organizations chase the latest innovation. Throughout 2025, I've observed a concerning trend that mirrors past mistakes but with potentially greater consequences and a troubling irony at its heart.

For years, security leaders fought tooth and nail for every cybersecurity dollar. Research from recent years showed that 37% of CISOs reported flat or declining budgets, with budget approval rates dropping to just 35% of requested amounts. We had to quantify risks, demonstrate ROI, and often wait for a breach to justify essential security investments.

Yet throughout 2025, AI budgets have flowed freely. Organizations investing $10 million or more in AI nearly doubled this year, with 92% of technology leaders increasing AI spending. No breach required. No extensive ROI calculations. Just promise and potential.

The Psychology Behind the Double Standard

What drives this paradox? Fear sells cybersecurity, but hope sells AI. When presenting security budgets, we highlight what could go wrong. With AI, executives envision competitive advantage and transformation. One executive admitted they approved AI spending because "we can't afford to be left behind," despite having no clear implementation strategy.

This year revealed another uncomfortable truth: AI spending grew despite 51% of organizations being unable to confidently evaluate AI ROI. Compare this to cybersecurity, where we measure everything from mean time to detect to cost per incident prevented

The Real Numbers Behind 2025's Spending Spree

The average monthly AI spend jumped from $62,964 in 2024 to $85,521 in 2025, marking a 36% increase. Where did this money come from? Often, directly from security and infrastructure budgets.

While cybersecurity budgets grew by 15% to $212 billion globally, this growth was uneven. Healthcare, retail, and professional services saw flat or reduced security budgets, affecting the very industries handling our most sensitive data.

The Hidden Infrastructure Crisis

Here's what budget committees missed: research found many organizations failed to invest in necessary infrastructure for AI, jeopardizing the technology's potential impact. We bought Ferraris but skimped on roads.

73% of organizations invested in AI-specific security tools, essentially paying twice: once for AI capabilities and again to secure them. Had we maintained robust security programs, much of this redundant spending could have been avoided.

What Happened When Reality Hit

By mid-2025, the cracks began showing. AI data privacy concerns shot up to 69% from 43% earlier in the year. 30% of AI pilot projects were abandoned before deployment. Each failed project represented not just wasted money, but missed opportunities to strengthen foundational capabilities.

42% of organizations with AI in production hadn't seen ROI, yet spending continued to accelerate. In cybersecurity, such metrics would trigger immediate budget reviews and strategy pivots.

The Vendor Gold Rush

2025 saw vendors expertly exploit this spending disparity. AI companies promised revolutionary capabilities with vague timelines. Meanwhile, security vendors, accustomed to proving value, watched their carefully crafted ROI models lose to AI's sparkle.

Microsoft, Google Cloud, and OpenAI emerged as top budget consumers, with organizations often purchasing overlapping capabilities from multiple vendors. The "fear of missing out" drove duplicate investments that would never pass security's stringent vendor consolidation reviews.

The Compliance Wildcard

Ironically, many AI projects received funding by claiming compliance benefits, the same justification security teams have used for years. The difference? AI compliance requirements remain largely undefined, while security compliance grows ever more stringent.

Regulatory concerns around AI grew from 42% to 55% during 2025, yet this didn't slow spending. When GDPR emerged, security budgets faced scrutiny despite clear requirements. AI spending accelerated despite regulatory uncertainty.

The Skills Gap Nobody Discussed

High salary expectations and lack of internal expertise were cited as greatest challenges in AI hiring. Organizations threw money at AI talent acquisition while maintaining hiring freezes for security roles.

CISOs reported that while they could secure budget for tools, they lacked staff to utilize them fully. This same constraint now plagues AI initiatives, but with higher price tags and less mature talent pools.

International Perspectives: Not Just Our Problem

This phenomenon wasn't uniquely American. European markets showed similar patterns, with some sectors allocating over 15% of IT budgets to AI while keeping security under 10%.

The Middle East and North Africa saw 14% growth in security spending, but even this couldn't match AI's explosive budget increases. Global organizations created a dangerous precedent: innovation over protection, universally.

The Board Dynamics That Enabled This

While 88% of boards view cybersecurity as a business risk, AI captured imaginations differently. Board members, influenced by media coverage and peer pressure, pushed for AI initiatives without demanding the same rigor they'd apply to security investments.

Forward-thinking CISOs started adding "decommissioning" as a formal budget line, recognizing that simplification creates more value than addition. AI teams, flush with cash, showed no such discipline.

Unexpected Consequences

The budget imbalance created surprising ripple effects:

  1. Talent Migration : Security professionals moved to AI roles, not for passion but for pay. We lost decades of security expertise to AI teams still figuring out their mission.
  2. Technical Debt Acceleration : Organizations focusing on AI let foundational systems deteriorate. Legacy systems, already security risks, received even less attention.
  3. Vendor Lock-in : Rushed AI purchases created dependencies we're only now understanding. Unlike security tools with established standards, AI platforms lock data and workflows in proprietary formats.
  4. Shadow AI : Just as we battled shadow IT, ungoverned AI experiments proliferated. 15% of companies admitted to having no formal cost-tracking system for AI spending.

The Insurance Wake-Up Call

Cyber insurance providers, who've long influenced security budgets through premium adjustments, began reassessing AI-related risks. Organizations celebrating reduced premiums from security investments faced increases due to ungoverned AI deployments. A costly irony.

Cultural Implications

The budget disparity sent clear organizational messages. Security teams, despite protecting crown jewels, felt undervalued. AI teams, swimming in resources, faced immense pressure to deliver miracles. Neither environment fostered sustainable success.

Security team morale suffered from lean budgets, leading to attrition and knowledge loss. Meanwhile, AI teams burned through resources without establishing the operational discipline security teams developed through constraint.

What Smart Organizations Did Differently

A minority took a different path. They required AI initiatives to meet security's ROI standards, funded AI and security as integrated programs, applied security's governance frameworks to AI from day one, and invested in foundation before innovation.

These organizations report higher AI success rates and lower security incidents. Proof that discipline drives outcomes.

Preparing for the Reckoning

As we plan for 2026, several factors will force change:

  1. Regulatory Reality : With predictions that 17% of cyberattacks will involve AI by 2027, regulations will demand integrated AI-security strategies.
  2. Breach Accountability : The first major AI-related breach will trigger the same budget scrutiny security faced. Organizations will wish they'd invested in protection earlier.
  3. ROI Pressure : As boards demand returns on 2025's investments, AI budgets will face the rigor security budgets always have.
  4. Talent Reality : The AI talent shortage will force organizations to value and retain security professionals who understand risk management.

Actionable Recommendations for 2026

  1. Unified Budget Planning : Stop treating AI and security as competing priorities. Create integrated technology investment portfolios.
  2. Risk-Based Allocation : Apply security's risk quantification methods to all technology investments. Financial cyber risk quantification tools can evaluate any technology investment.
  3. Governance First : Before funding new capabilities, ensure governance frameworks exist. Security learned this through painful breaches. AI shouldn't repeat history.
  4. Metrics That Matter : Leading CISOs redefined ROI as "security yield": risk reduction per dollar spent. Apply similar thinking to AI investments.
  5. Sustainable Staffing : Balance tool and talent investments. Tools without skilled operators deliver no value, true for security and AI alike.

The Wisdom We Ignored

Reflecting on 2025, the signs were clear. Security veterans warned that sustainable success comes from thoughtful planning, not reactive spending. We had roadmaps from cybersecurity's maturation journey. We chose to ignore them.

The most expensive lesson? Technology budgets might reach 32% of revenue by 2028 if current trends continue. This isn't sustainable. Organizations must choose: continue the AI spending spree or build integrated, secure, valuable technology capabilities.

Looking Forward

As November 2025 draws to a close, we stand at an inflection point. The budget decisions made now will determine whether 2026 continues 2025's unsustainable patterns or marks a return to disciplined technology investment.

The cybersecurity profession's budget battles, though frustrating, created antifragile programs that improve with stress. AI programs, built on easy money, remain fragile. The first major crisis will reveal which approach builds lasting value.

History will judge whether we learned from cybersecurity's hard-won lessons or repeated every mistake with a new technology. The choice, and the budgets, are ours to shape.

The ultimate irony? The discipline cybersecurity developed through budget constraints became its greatest strength. Perhaps it's time AI learned the same lesson before market forces teach it for us.