The 2027 benchmark numbers first: mid-market organisations spend 10–12% of their IT budget on security, roughly 1.0–1.2% of revenue, or $2,000–$2,500 (€1,850–€2,300) per employee per year. Budget growth slowed to a five-year low of 4.0% in 2025 — yet Gartner projects the market re-accelerating at 12.5% through 2027, driven by exactly the forces European teams feel most: NIS2, AI threats and insurance requirements. Benchmark against peers, but budget against risk; this guide gives you both sets of numbers.
Key takeaways
- The anchors: 10.9% of IT budget (down from 11.9% — because IT denominators grew, not because security shrank), 0.69% of revenue cross-industry, $2,700 per employee globally, $2,000–$2,500 at mid-market scale (IANS/Artico, Deloitte, 2025).
- NIS2 is a line item, not a footnote: the European Commission’s impact assessment projects a 22% baseline increase in ICT security spend for covered entities, spread over concrete items from board training to IR retainers.
- People eat the budget: internal staffing takes 37–39% of mid-market security spend, software 29–36%, managed services 15–20% — and Benelux wage indexation puts a +7% floor under the payroll line.
- The under-spending mirror: mid-market breaches cost $1–3 million, ransomware recovery averages $1.53 million before any ransom, and downtime runs ~$5,000 per minute.
- The 2027 lever is consolidation: 75% of organisations are reducing security vendors (versus 29% in 2020), and platformisation cuts licence spend 20–30% and infrastructure management overhead 30–40%.
What the benchmarks actually say
The IANS/Artico 2025 Security Budget Benchmark (587 CISOs, August 2025) recorded the slowdown: 4.0% average budget growth, half of the 8.0% seen in 2024 and the lowest in five years, with 54% of security leaders reporting flat or shrinking budgets. Security’s share of IT spend fell from 11.9% to 10.9% — a denominator effect, as cloud and generative-AI initiatives inflated total IT budgets faster than security grew. Meanwhile Gartner sizes the market at $213 billion for 2025, heading for $240 billion by end-2026 at 12.5% growth, with the same pace projected into 2027 on the back of compliance mandates and AI threat surfaces. Both things are true at once: individual budgets tightened, and the structural drivers are pushing them back up.
| Size band | % of IT budget | % of revenue | Per employee/year | Source |
|---|---|---|---|---|
| Small (1–99 employees) | 12–15% | 1.5–3.0% | $2,500–$2,800 | IANS/Artico small & mid-market report (June 2025) |
| Mid-market (100–999) | 10–12% | 1.0–1.2% | $2,000–$2,500 | IANS/Artico (n=587, Aug 2025); Gartner |
| Large enterprise (1,000+) | 8–10.9% | 0.5–0.7% | $1,500–$2,200 | IANS/Artico; Deloitte |
| Cross-industry average | 10.9% (2025) | 0.69% | $2,700 | IANS/Artico; Deloitte |
Sector matters as much as size: technology firms budget around $4,200 per employee, financial services $3,500, healthcare $2,100, manufacturing $1,600. And smaller firms pay more per head because licensing floors and MDR retainer minimums don’t scale down. Note for planners: the next IANS/Artico edition lands in late August–September 2026 — refresh these figures before the board sees them.
How Europe differs
US firms historically outspend European peers by 20–35% per employee on technology and security, but European budgets carry a heavier compliance load. Eurostat’s 2025 enterprise survey shows the maturity gap that load meets: 93% of EU enterprises use basic ICT security measures, yet only 35.5% maintain formal documented security policies — and 21.5% suffered incidents with disruption, data loss or financial harm. Hiscox’s 2025 readiness report adds the regional pressure: 59% of European SMEs were attacked in the past year (Germany worst at 67%), 14% of breached Belgian businesses were forced into layoffs by the financial damage, and 34% of Benelux leaders say a shortage of in-house security talent undermines their measures — which is precisely why mid-market budgets here lean harder on managed services and automated platforms.
Where the money goes
| Category | Mid-market share | What’s inside |
|---|---|---|
| Internal personnel | 37–39% | Security ops, architecture, compliance roles — plus Benelux wage indexation |
| Software licences & tools | 29–36% | Cloud security 34%, SIEM/XDR 31%, EDR 19% of the tooling slice |
| Managed services (MSSP/MDR/SOC) | 15–20% | 24/7 monitoring, IR retainers, threat hunting |
| Hardware & network security | 10–15% | Firewalls, edge appliances — the line consolidation shrinks first |
| Training & awareness | 3–5% | Phishing simulation, role-based training |
| Insurance, governance & audit | 3–5% | Premiums, NIS2 assessments, audits |
The five forces shaping 2027
- NIS2 compliance: the Commission’s impact assessment projects +22% baseline ICT security spend for covered entities. Concrete line items: registration (€2,000–€5,000), CyFun/ISO gap assessment and verification (€15,000–€45,000), mandatory board training under Article 20 (€5,000–€12,000/year), 24-hour-SLA incident-response retainers (€12,000–€35,000/year), supply-chain risk tooling (€8,000–€25,000/year).
- Consolidation: 75% of organisations are actively reducing vendors (29% in 2020); Dell’Oro expects single-vendor SASE to take 90% of that market by 2029.
- AI threat surface: IBM’s 2026 report counts 25% of malicious breaches as AI-enabled (+56% year-over-year) at $6.0 million average cost, and 20% of organisations breached via shadow AI — shifting 5–10% of tooling budgets toward prompt- and API-aware DLP.
- Insurance strictness: underwriters now require zero trust, EDR, immutable backups and universal MFA as policy conditions — the checklist detailed in cyber insurance requirements 2026, effectively dictating part of your tooling budget.
- Talent scarcity: Benelux indexation and competition put a +7% floor under security payroll, pushing teams toward automation and co-managed SOCs.
The cost of the alternative
The board will ask what happens without the budget. The anchors: global breach costs hit $4.44 million in 2025 and $4.99 million in 2026; the mid-market band runs $1–3 million per incident once forensics, notification, churn and GDPR exposure (up to €20 million or 4% of turnover) are counted. Ransomware is the dominant scenario — 88% of SMB breaches involve it — with median demands of $1.32 million and recovery costs averaging $1.53 million before any ransom. Downtime prices itself: ~$5,000 per minute at mid-market scale, the arithmetic behind the true cost of downtime. Against a €525,000 budget, a single prevented seven-figure incident is the whole ROI conversation.
A model 2027 budget: 250 employees, Benelux
Illustrative aggregation of the benchmarks above — a €45M-revenue organisation, €4.8M IT budget, targeting 11% of IT / ~€2,100 per employee = €525,000:
| Category | Amount | Share | Key line items |
|---|---|---|---|
| Internal personnel | €199,500 | 38% | Security ops engineer (1.0 FTE), compliance specialist (0.5 FTE), indexation allowance |
| Software & tools | €168,000 | 32% | Integrated SASE/ZTNA platform (250 seats), EDR/MDR, IAM/MFA, SIEM, vulnerability management |
| External managed services | €84,000 | 16% | Co-managed 24/7 SOC, NIS2-compliant IR retainer, annual pentest |
| NIS2 compliance & governance | €36,750 | 7% | CyFun gap assessment and verification, supply-chain scoring, board training |
| Training & culture | €21,000 | 4% | Phishing simulation, role-based admin/developer training |
| Cyber insurance | €15,750 | 3% | €2M-cover liability premium |
The consolidation lever, quantified
The largest controllable saving in that model sits in lines 2 and part of 4: replacing four to six point products — legacy VPN, edge firewalls, standalone web filter, CASB — with a unified SASE platform cuts aggregate licence spend 20–30%, drops administrative load from 1.5–2.0 FTE to roughly 0.5, and reduces infrastructure management overhead 30–40% by ending hardware refresh cycles and traffic hairpinning. IBM’s data adds the risk dividend: organisations with security automation and unified platforms cut breach costs by an average of $2.22 million. The mechanics are the same ones documented in the SASE pricing guide, the hidden-costs analysis and the DIY-versus-managed TCO comparison.
Presenting it to the board
Gartner reports 88% of boards now treat cyber as business risk, and the framing that works follows: outcome-driven metrics with protection-level choices (“maintaining a 30-day critical-patch window costs X; cutting exposure to 48 hours via automated ZTNA controls costs X+€40,000 — choose”), FAIR-style loss quantification (€350,000 expected annual loss from remote-access compromise × 80% reduction from a €50,000 control = defensible ROI), and CIS IG1 mapping as the legal-defensibility floor under NIS2 director liability. Percentage-of-IT alone is a trap — the denominator distortion above shows why — so pair it with per-employee figures and quantified risk. And remember benchmarks measure spending, not maturity: an integrated platform at $1,800 per employee can out-protect misconfigured point tools at $2,500.
Budget the outcome, not the tool count
Set the envelope with the benchmarks (10–12% of IT, ~€2,100 per employee at mid-market), add the NIS2 line items explicitly, anchor the request against $1–3 million incident maths, and fund the consolidation that pays for the rest. For EU mid-market teams, that consolidation line has a concrete shape: Jimber replaces the VPN, firewall, web-filter and access point products with one EU-sovereign flat-rate platform — a single predictable euro line in category 2 instead of five volatile ones, with the admin-hour savings landing in category 1. Book a demo before the budget round closes and put a real number where “network security stack” currently sits.
Frequently asked questions
What percentage of IT budget should we allocate to security in 2027?
Mid-market benchmark: 10–12%. European organisations under NIS2 should target the upper end (11.5–12%) to absorb mandatory governance, audit and reporting costs on top of technical controls.
What is the per-employee benchmark for a 250–500 person company?
$2,000–$2,500 (€1,850–€2,300) per employee per year, covering staff allocation, licences, managed services, training and insurance. Sector adjusts it: technology and finance sit higher, manufacturing lower.
How much does NIS2 add to the budget?
The European Commission’s impact assessment projects a 22% baseline increase for covered entities. Concrete items: registration fees, CyFun/ISO assessments (€15,000–€45,000), board training, 24-hour-SLA incident-response retainers and supply-chain risk tooling.
Why did budget growth slow, and will it recover?
Growth fell to 4.0% in 2025 on macroeconomic pressure — 54% of CISOs saw flat or shrinking budgets. Gartner projects re-acceleration at 12.5% annually through 2027, driven by NIS2 and DORA deadlines and AI-related security demands.
Is percentage-of-IT-budget a reliable metric?
Only partially. Big IT initiatives inflate the denominator, making security look under- or over-funded artificially — that mechanism explains most of the 11.9%→10.9% drop. Combine it with per-employee figures and quantified risk models such as FAIR.
What does a breach cost a mid-market organisation?
Between $1 million and $3 million on average, versus a $4.99 million global 2026 figure. Ransomware recovery adds $1.53 million on average excluding any payment, and downtime runs roughly $5,000 per minute.
How much does platform consolidation actually save?
Documented ranges: 20–30% lower aggregate licence spend, administrative load down from 1.5–2.0 FTE to about 0.5, and 30–40% lower infrastructure management overhead — plus an average $2.22 million breach-cost reduction for organisations with unified, automated platforms.
How do we present the budget to the board?
As risk choices, not tool lists: outcome-driven metrics with protection-level options, FAIR-quantified expected-loss reductions, and CIS-controls mapping as the due-diligence floor. Boards choose between defensible risk postures faster than they approve product names.