Forecast. A projection, not an observation. It carries the assumptions of whoever produced it and has not happened yet.
Put the two numbers next to each other and something has to give. The market is forecast to grow at roughly three times the rate of the average buyer's budget.
There are only a few ways both hold. Spend concentrates into fewer, larger buyers, which matches the Wiz finding that the biggest spenders are also the least satisfied. Or buyers reallocate rather than add, retiring tools to fund platforms, which is the consolidation thesis every platform vendor is currently selling. Or the growth is coming from organizations that had no security budget line at all a year ago, which is what AI-native companies and newly regulated sectors look like.
For a security leader, the read is straightforward. Vendor pricing assumptions for 2026 are built on a 12% growth market. Your budget is not. Every renewal conversation this year is happening across that gap, and the vendor's uplift expectation is anchored to a number that does not describe your organization.
What this does not mean
This does not mean vendors are overcharging or that the forecast is wrong. Gartner measures worldwide vendor revenue including currency effects and new-market expansion; IANS measures the budgets of 587 mostly North American organizations that already employ a CISO. A gap between those two series is expected. What is not expected is a gap of eight points, and that is the part worth taking into a renewal.
Take this to your board
The security market is forecast to grow about 12.5 percent while buyer budgets grow about four percent, per Gartner's information security forecast read against the IANS and Artico budget benchmark, so prices rise faster than the budget absorbing them.
Say the peer figure and your own in the same breath. A number without a comparison invites the board to supply one from memory.
Sources
Every external figure on this page, with its origin, sample, and the date it was last checked by hand.
Gartner forecast worldwide end-user information security spending of $213 billion in 2025, rising 12.5% to approximately $240 billion in 2026. IANS Research and Artico Search separately found average CISO security budget growth of 4% year over year across 587 respondents.
Gartner's 3Q25 update subsequently revised 2026 to approximately $244 billion at 11.6% constant-currency growth, so the headline growth rate is a range of roughly 11.6% to 12.5% depending on which vintage is cited. Gartner measures vendor-side revenue; IANS measures buyer-side budgets. The two are not the same denominator, which is the point of the comparison rather than a flaw in it.
Common questions
How fast is the cybersecurity market growing in 2026?
Gartner forecast worldwide end-user information security spending at $213 billion for 2025, rising about 12.5% to $240 billion in 2026, with a later 3Q25 revision putting 2026 nearer $244 billion at 11.6% constant-currency growth. Both figures measure vendor-side revenue rather than individual organizations' budgets.
Why is my security budget growing slower than the market?
Because the two figures measure different things. Gartner tracks worldwide vendor revenue, which includes new buyers, currency effects, and geographic expansion. IANS tracks existing CISO budgets and found 4% average growth. A market can grow at 12% while established buyers grow at 4% if spend is concentrating into fewer, larger accounts.
What should a buyer do with the gap between market and budget growth?
Take it into renewal conversations. Vendor pricing expectations for 2026 are anchored to a market forecast to grow above 11%, while IANS puts average buyer budget growth at 4%. Naming that gap explicitly reframes an uplift request as the vendor asking one customer to fund growth that is coming from somewhere else.