The global cost of a data breach hit a record $4.99 million in 2025 — up 12% year-over-year and equivalent to roughly $1,100 per hour — according to IBM's 2026 Cost of a Data Breach Report. At the same time, Gartner projects global cybersecurity spending will reach $239.8 billion in 2026, up from $193.4 billion in 2024. The numbers are staggering, but the more troubling trend may be how unevenly these costs land.
The Gap Is Widening
Security budgets are growing, but breach costs and operational complexity are growing faster. The average enterprise now runs 40 security scanners, while broader enterprise environments average 83 tools from 29 vendors — creating massive duplication, overlapping findings, and alert fatigue that erodes the value of each individual investment.
As Syed Ghayur, VP of Solution Engineering at ArmorCode, put it: security teams are being asked to process dramatically more risk without comparable increases in people or budget. Headcounts are essentially flat.
Who Gets Hit Hardest
For large enterprises, the financial sting is severe but survivable. For small and medium-sized businesses (SMBs), the math is existential. A single breach at the $4.99M average could permanently shut down a small operation — yet SMBs typically lack the security staff, tooling maturity, or cyber insurance coverage that larger organizations rely on.
This creates a tiered threat landscape: well-resourced organizations absorb breaches as a cost of doing business, while under-resourced organizations face potential closure from the same incident type.
What This Looks Like in Practice
Several dynamics are converging to make the affordability problem worse:
- Tool sprawl: Enterprises purchasing more point solutions add licensing costs and operational overhead without proportional security gains
- Alert fatigue: Overlapping scanners generate redundant findings, requiring human hours to triage findings that tools should be filtering out
- Skills shortage: Security hiring remains competitive, and salaries have risen — adding to operational budgets even when headcount stays flat
- Insurance pressure: Cyber insurers are tightening requirements, raising premiums, and excluding more incident types, shifting more residual risk back to organizations
Is "Affordability Crisis" the Right Frame?
The piece from Dark Reading frames this as the early signs of a cyber affordability crisis — a moment where the economics of defense are becoming unsustainable for a growing segment of organizations.
Whether it reaches true crisis levels may depend on how quickly the industry consolidates its tooling landscape, how effectively AI-assisted security operations can offset headcount gaps, and whether regulatory pressure pushes organizations toward more standardized (and cost-efficient) baseline controls.
For now, the numbers suggest that the current trajectory — more spend, more complexity, more breach cost — is not self-correcting on its own.
What Security Teams Can Do
- Audit tool sprawl: Identify overlapping vendors and consolidate where coverage is genuinely redundant
- Prioritize platform approaches: Fewer integrated platforms over many point solutions reduce operational overhead
- Risk-tier your environment: Not every asset warrants the same protection level — focus expensive controls where breach impact is highest
- Invest in detection speed: IBM's data consistently shows faster detection correlates with lower breach costs — dwell time reduction is one of the highest-ROI investments available
The affordability challenge is real, but it is also, in large part, a problem of complexity and prioritization as much as raw dollar spend.
Source: Is Cyber Facing an Affordability Crisis? — Dark Reading