Security News

Cybersecurity news aggregator

LOW News Dark Reading

Is Cyber Facing an Affordability Crisis?

  • What: Cybersecurity affordability crisis affecting small businesses
  • Impact: Small businesses face increased risk due to high breach costs
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERSECURITY OPERATIONS Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Is Cyber Facing an Affordability Crisis? As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security. Arielle Waldman,Features Writer,Dark Reading August 25, 2026 5 Min Read SOURCE: ALEXFIODOROV VIA GETTY IMAGES A chief information security officer—if the company can even afford one— is woken by an urgent phone call in the middle of the night. There's been a breach. Threat actors stole highly sensitive customer data, and now they're demanding a ransom. If the company doesn't pay, they will leak data on the Dark Web. That's when the clock, and the financial fallout, starts ticking. Whether it's a ransomware attack, business email compromise, or a third-party supply chain attack, organizations have unfortunately become increasingly accustomed to suffering data breaches. But they are caught between rising threats they can't ignore and burgeoning defense costs they can't sustain. The paradox is leading to a cybersecurity affordability crisis. For small-to-medium sized businesses (SMBs), which lack the deep pockets of large enterprises, one breach could shutter their doors permanently. The global average cost of a data breach reached a record $4.99 million in 2025, according to IBM's "2026 Cost of a Data Breach Report," that noted a 12% rise over the previous year. That equates to $1,100 per hour. Related:Money and Mindset: The Two Biggest Roadblocks to Cyber Policing Meanwhile, Gartner projects global cybersecurity spending costs for organizations – including network security, security services, and software security – will reach $239.8 billion this year, up from $193.4 billion in 2024. Artificial intelligence (AI) adoption is only adding to the challenge as organizations race to implement the latest models. Save the SMBs, Save the World Attackers target SMBs more often compared to large enterprises because they know they're the weak link, either due to budget constraints or because cybersecurity is not a priority. Although SMBs pose a systemic risk to the supply chain, the market doesn't reflect that. While vendors releasing new security tools may be doing it for the right reason, and truly want to manage risks and prevent attacks, their venture capital backers want them to find the more profitable big fishes, explains Bryson Byrd, cybersecurity advisor for Huntress. Subsequently, venture-backed vendors will develop a product for large enterprises that's more expensive or doesn't consider that smaller businesses lack a dedicated security team or around-the-clock security operations center, leaving them behind. That's a disservice to organizations of all sizes, Byrd tells Dark Reading. "When you have millions of small businesses that exist, what ends up happening is disproportionately we – as a country, we as a community, however we want to define it – are less secure," says Byrd. Related:Mission-Driven Security: Inside a Global Bank's Defense While cybersecurity is a budget issue, Byrd argues that it's also a prioritization and business resilience issue as much as anything else. Those are the problems that need to be solved, especially in the SMB space, he urges. Don't Bank on AI to Reduce Costs The issue is less that organizations have suddenly stopped spending money on cybersecurity and more that the economics are getting harder to sustain: Costs are rising faster than budgets while security headcounts remain the same, says Syed Ghayur, VP of solution engineering at ArmorCode. He believes the industry is seeing the early signs of a cyber affordability crisis. Security teams are being asked to process dramatically more risk without a comparable increase in people or budget, Ghayur adds. He notes the average enterprise already operates with 40 security scanners, and points to research from Palo Alto Networks and IBM that says broader security stacks include 83 tools from 29 vendors. Tool sprawl has created significant duplication as companies invest in dozens of scanners and security products that generate overlapping findings but are not specific to the business context, Ghayur says. AI adds another cost layer. Organizations rapidly adopted AI to supplement their security tools, but research shows costs were higher than anticipated, including spending on tokens and premium tiers. Using expensive AI to analyze every vulnerability finding indiscriminately may inflate costs and only add to alert fatigue. Related:Walmart Takes a 'Trusted Agent' Approach to Purple Teaming "Without prioritization and cost governance, spending can scale with the number of findings, rather than the amount of actual risk being reduced," says Ghayur. Additionally, AI can actually create more problems. One study by 1Password found large language model-generated patches did not resolve a vulnerability, added a new one, or did both 53.9% of the time on average. The number of reported vulnerabilities outpacing remediation capacity means throwing more people or more scanners at the problem becomes increasingly expensive without necessarily reducing more risk, Ghayur warns. "The risk is that organizations respond in one of two bad ways," he says. "They either spend indiscriminately trying to keep up, or they automate indiscriminately to reduce costs. The latter can be particularly dangerous in cybersecurity." Focus on Risk, Not Findings It's important to address this problem because it affects critical infrastructure organizations like healthcare and manufacturing; these operate with legacy equipment but are highly targeted by a range of threat actors, including nation-state hackers. Consulting company Signisys recommends that most enterprises should allocate eight percent to 12% of their total IT budget to cybersecurity, and organizations in healthcare, financial services, and government should target 10% to 15%. That can be a big ask for an organization operating with few resources. The answer is not to buy less security, but for organizations to get more measurable risk reduction from the security investments they already have, recommends Ghayur. That starts with shifting the unit of measurement from findings to risk, he says, adding that the same discipline needs to apply to AI investments. Ghayur believes the next phase of cybersecurity economics will look a lot like what the FinOps Foundation did for the cloud. Like today’s AI adoption, organizations moved to the cloud thinking it would save them money compared to on-premises servers, but costs climbed higher than expected. FinOps aimed to boost visibility, efficiency, and accountability by setting up a framework to establish policies and cost controls. "Security leaders will increasingly need to prove not only that they are reducing risk," he anticipates, “but that every dollar, every engineering hour, and increasingly every AI token is being spent on the exposures that matter most." About the Author Arielle Waldman Features Writer, Dark Reading Arielle spent the last decade working as a reporter, transitioning from human interest stories to covering all things cybersecurity related in 2020. Now, as a features writer for Dark Reading, she delves into the security problems enterprises face daily, providing context and actionable steps. She looks for stories that go past the initial news to understand where the industry is going. Her coverage areas include identity and access management, cyber risk and operations, industrial control systems, operational technology, and ransomware trends. She previously lived in Florida where she wrote for the Tampa Bay Times before returning to Boston where her cybersecurity career took off at TechTarget SearchSecurity. When she's not writing about cybersecurity, she pursues personal projects that include a mystery novel and poetry collection. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion More Webinars You May Also Like CYBERSECURITY OPERATIONS Hand CVE Over to the Private Sector by Brian Martin JAN 27, 2026 CYBERSECURITY OPERATIONS Shutdown Sparks 85% Increase in US Government Cyberattacks by Nate Nelson OCT 24, 2025 CYBERSECURITY OPERATIONS China Imposes One-Hour Reporting Rule for Major Cyber Incidents by Robert Lemos OCT 01, 2025 CYBERSECURITY OPERATIONS CISA, FBI, NSA Warn of Chinese 'Global Espionage System' by Alexander Culafi AUG 28, 2025 Edge Picks APPLICATION SECURITY AI Agents in Browsers Light on Cybersecurity, Bypass Controls CYBER RISK Browser Extensions Pose Heightened, but Manageable, Security Risks CYBERSECURITY OPERATIONS Video Convos: Agentic AI, Apple, EV Chargers; Cybersecurity Peril Abounds ENDPOINT SECURITY Extension Poisoning Campaign Highlights Gaps in Browser Security Latest Articles in The Edge PERIMETER New CUSTODY Framework Constrains AI Agents Inside the Network AUG 20, 2026 CYBERSECURITY OPERATIONS Money and Mindset: The Two Biggest Roadblocks to Cyber Policing AUG 20, 2026 CYBERATTAC

Share this article