IMAGE CREDITS: COREWIRE / AI ILLUSTRATION

Security is the software budget nobody dares cut

91 percent of organizations plan to raise threat-intelligence spend in 2026 even as software budgets tighten, and July’s vulnerability wave shows why. An analysis of the unkillable line item.

Software budgets are under the tightest scrutiny in years, yet one line keeps growing. Industry research this year finds 91 percent of organizations planning to increase threat-intelligence spending in 2026, even as broader IT budgets compress, a pattern visible across enterprise security surveys and vendor earnings alike.

July has offered a live demonstration of why. In a single fortnight: an actively exploited CVSS 10.0 in Adobe ColdFusion, twin 9.2 pre-authentication flaws in BeyondTrust’s privileged-access products, an exploited Gitea container flaw and a router backdoor. The attack surface is not shrinking to match anyone’s budget cycle.

Why security spend defies gravity

Three forces make it the unkillable budget in the technology economy. Breach costs are asymmetric: one incident can erase a decade of savings from trimming the tools that would have caught it. Regulation keeps ratcheting: disclosure rules turned security failures into board-level securities events. And AI cuts both ways: it industrializes attacks faster than defenses, and every unsanctioned AI integration adds surface the security team never approved.

For advertisers of a certain kind, this is the strongest B2B demand signal in software; for buyers, it is a warning that security vendors know their line item survives every cut, and price accordingly. The margin discipline we apply to AI vendors applies here too.

What the unkillable budget does not buy

A budget that survives every cut carries its own risk: complacency dressed as prudence. Rising spend is not the same as rising protection, and vendors who know their line item is safe have little incentive to make their pricing legible. The security estates that actually reduce risk tend to be consolidating, retiring overlapping tools whose combined alerts no human team can triage, rather than adding another dashboard each renewal cycle. Spend that grows while tool sprawl grows faster is buying noise, not coverage.

The sharper question for a CFO is not whether to cut security, it is whether the current spend is aimed at this year’s attack surface or last year’s. The fastest-growing exposure, machine and agent identity, barely existed as a category two budget cycles ago, which is why capital is flooding toward it through raises like Keyfactor’s and the emergence of the ungoverned surface in shadow AI. The same margin discipline we apply in the AI software scoreboard belongs here: an unkillable budget deserves more scrutiny than a discretionary one, not less, precisely because nobody is watching it for waste.

What to watch

Watch Q3 earnings from the security platforms for confirmation of the spend shift, whether consolidation onto fewer platforms accelerates as buyers seek leverage, and whether cyber-insurance pricing starts crediting AI-specific controls, the surest sign the actuaries believe the new risk math. Capital is already answering: Keyfactor raised over $1 billion for machine identity days after Osney Capital closed a £60 million UK cybersecurity seed fund.

Get the Signal

AI and business tech news, verified by a physician who reads the filings. One email a week, no noise.

Dr. Joseph Joshua

Dr. Joseph Joshua is the founder and editor of Corewire. A medical doctor by training, he brings the evidence-first discipline of clinical medicine to technology journalism: claims get checked against primary sources before they get published. He has produced technology and B2B content for companies across…

View Bio

Keep Reading