IMAGE CREDITS: COREWIRE / AI ILLUSTRATION

Security is the software budget nobody dares cut

91 percent of organizations plan to raise threat-intelligence spend in 2026 even as software budgets tighten, and July’s vulnerability wave shows why. An analysis of the unkillable line item.

Software budgets are under the tightest scrutiny in years, yet one line keeps growing. Industry research this year finds 91 percent of organizations planning to increase threat-intelligence spending in 2026, even as broader IT budgets compress, a pattern visible across enterprise security surveys and vendor earnings alike.

July has offered a live demonstration of why. In a single fortnight: an actively exploited CVSS 10.0 in Adobe ColdFusion, twin 9.2 pre-authentication flaws in BeyondTrust’s privileged-access products, an exploited Gitea container flaw and a router backdoor. The attack surface is not shrinking to match anyone’s budget cycle.

Why security spend defies gravity

Three forces make it the unkillable budget in the technology economy. Breach costs are asymmetric: one incident can erase a decade of savings from trimming the tools that would have caught it. Regulation keeps ratcheting: disclosure rules turned security failures into board-level securities events. And AI cuts both ways: it industrializes attacks faster than defenses, and every unsanctioned AI integration adds surface the security team never approved.

For advertisers of a certain kind, this is the strongest B2B demand signal in software; for buyers, it is a warning that security vendors know their line item survives every cut, and price accordingly. The margin discipline we apply to AI vendors applies here too.

What to watch

Watch Q3 earnings from the security platforms for confirmation of the spend shift, whether consolidation onto fewer platforms accelerates as buyers seek leverage, and whether cyber-insurance pricing starts crediting AI-specific controls, the surest sign the actuaries believe the new risk math. Capital is already answering: Keyfactor raised over $1 billion for machine identity days after Osney Capital closed a £60 million UK cybersecurity seed fund.

Get the Signal

AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.

Dr. Joseph Joshua

Dr. Joseph Joshua is the founder and editor of Corewire. A medical doctor by training, he brings the evidence-first discipline of clinical medicine to technology journalism: claims get checked against primary sources before they get published. He has produced technology and B2B content for companies across…

View Bio

Keep Reading