
Next Year's Budget Should Buy Outcomes, Not Tools
A shopping list is not a security program. Here is how to write a budget that actually moves your risk.
Executive summary
- Most security budgets are written as a list of products. The products get bought, installed, and then quietly go unattended.
- Attackers do not care what you own. They care what you operate. And AI now works both sides: speeding their break-ins, and carrying your data into tools you never approved.
- Write next year's budget as a list of outcomes instead. Give each one a person's name and a number that proves it works.
A tool is not a result
Every security product is sold the same way. Here is a gap. Here is the thing that closes it. The first half is usually true. The money goes missing in the second half, where owning a tool and getting a result get treated as the same purchase.
The 2026 Verizon Data Breach Investigations Report found that exploiting an unpatched software flaw was the most common way attackers got in, at 31% of breaches, edging past stolen passwords for the first time in the report's nineteen-year run. Set that beside a second finding: of the vulnerabilities on the federal catalog of flaws known to be under active attack, only 26% were fully remediated during 2025, down from 38% the year before.
Read those together and the story tells itself. The flaws were known: published, catalogued, free to look up. Most already owned something capable of finding them. Three in four still did not get closed. That is not a product gap. It is an operating gap. A better scanner will not fix it. A person whose job is closing what it finds will.
The clock is also getting shorter. Verizon credits attackers' use of AI with compressing the gap between a flaw becoming public and being exploited from months down to hours. Whatever grace period you were relying on, assume it shrinks next year.
Write the budget as outcomes
Try this instead. Name the things that must be true a year from now, put a person against each, and decide up front what number proves it happened.
- Someone is watching when you are not. Semperis found 52% of the organizations it surveyed were hit on a holiday or weekend, while 78% cut security operations staffing by half or more in exactly those windows. Attackers read the same calendar you do. Proof: how long before a real person sees a real alert at 2 a.m. on a Sunday.
- Known holes close on a clock. Proof: the share of your critical flaws fixed inside 30 days, written down, every month.
- Your people have practiced, not just watched a video. The DBIR puts the human element in 62% of breaches. Proof: how many staff reported the last fake email you sent, not just how many avoided clicking.
- You can get the business running again. Proof: the date of your last test restore, and how long it actually took.
- You know what AI your people already use. The same report found 45% of employees now use AI regularly at work, up from 15% a year earlier, and two thirds of those doing so on company devices were signed in with personal accounts. Proof: a current written list of which AI tools are approved and what may be pasted into them.
Notice what is missing from that list: brand names. That conversation happens second, and it is shorter.
The Takeaway
Do not walk into budget season asking what to buy. Ask what should be true a year from now that is not true today, then fund the shortest path there. A line item with no owner and no number is not a control. It is a subscription.
How Simulint helps with the vCISO practice
This is what our virtual CISO practice was built for: senior security judgment without carrying a full-time executive. We help you decide what to fund and in what order, put an owner and a target on every line, and report progress in numbers your board and your insurer accept. If next year's budget is still a list of products, start there: https://lnkd.in/eE9HTaw8
