4 MIN READ
Most security budgets in 2026 still get allocated by historical precedent, by what got funded last year and the year before that, with a small adjustment for headcount and a smaller adjustment for inflation. The result sits as a budget that does not match the actual risk. The threats move. The regulation moves. The business moves. The budget stays where it was three CIOs ago.
The CISO who wants to change the allocation is the CISO who has to walk into a board meeting with a different shape of argument. Not “we need more.” More of what, against what, by when. The framework that makes the argument land is the one this post is going to walk through. The four reasons the historical budget keeps winning, and the five step process for putting an actual risk based allocation in front of the people who sign the cheque.
Why the historical budget keeps winning
The easy case to defend is the case that looks like last year’s case. The CISO who wants to reallocate the budget has to fight the gravitational pull of whatever got funded the year before, because the CFO has institutional memory and the audit committee has a copy of last year’s approved plan. The match to precedent is the single most common reason a security budget lands the way it does.
Second, the political cost. Moving money from one line to another means someone in the company loses a project or a headcount they had been promised, and the risk function amounts to the only org that can credibly make that call. The risk function is also usually too small to win the fight on its own.
Third, the lack of a defensible alternative. Without a written threat assessment and a control mapping, the CISO cannot point to a specific number and say “this is the right number.” The number has to come from somewhere, and the somewhere has to be a document the audit committee will accept on the first read.
Fourth, the time it takes. The CFO wants the budget in three weeks. A proper threat assessment takes three months. The CFO usually wins, and the historical budget stays where it was three CIOs ago.
The five step process for an actual risk based allocation
Start with the threat assessment. The CISO sits with the threat intelligence function, the business stakeholders, and the regulators who have direct visibility into the company’s vertical, and writes down the threats the company actually faces in 2026. Not the threats the framework says to track, the threats the company has seen in the last twelve months, the threats the regulator has put on the examination list, the threats the business has flagged as existential in the last risk committee meeting. The output is a one page document with the five to ten threats that matter, ranked by likelihood and impact.
Control mapping comes second. For each of those five to ten threats, the CISO writes down the controls the company already has in place and the controls the company needs. The gap is the budget ask. Threat assessment and control mapping together are the piece most security orgs skip, which is why most security budgets read like a shopping list rather than a strategic document.
Risk scoring comes third. Take each gap, score it on a defensible scale (likelihood, impact, recovery cost, regulatory exposure), and rank the gaps against each other. The budget allocation step sits fourth, and the CFO actually sees this one. The CISO presents the top ranked gaps, the cost to close each one, and the cost of not closing each one. The fifth step, the executive review, amounts to the moment the document lands on the CFO, the CIO, and the audit committee chair’s desk for a real read. The CISO who has done the first four steps walks out of that meeting with the budget reallocated.
The bottom line
Threat assessment, control mapping, risk scoring, budget allocation, executive review. The security budget that runs on actual risk in 2026 starts with the CISO doing the homework, not the CFO writing a bigger cheque.

Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



