Security budget benchmarks for Canada
Security typically runs 5 to 15 per cent of IT spend, and IT typically runs 3 to 8 per cent of revenue, which puts security somewhere between 0.2 and 1.2 per cent of revenue for most companies. Those ratios are sanity checks, not targets, and using one as a target rewards you for having a bloated IT budget.
The three ratios worth knowing are these. Security spend as a share of IT spend commonly lands at 5 to 15 per cent, with regulated financial institutions at the top and companies with no regulatory driver at the bottom. Security spend per employee lands at roughly $1,200 to $4,500 CAD a year at mid-market scale. Security as a share of revenue lands between 0.2 and 1.2 per cent. All three are wide.
What these numbers are, and are not
There is no authoritative Canadian security budget survey at mid-market scale. The ranges here are assembled from published international ratios that are widely reported, from Canadian salary and tooling costs priced out directly, and from what the components on this site cost when you add them up. Use them as a check on a number you built bottom-up, not as a way of producing that number. A budget defended with "the benchmark says 10 per cent" will lose to a CFO who asks what happens if it is 7.
What Canadian companies spend by size
| Company size | Typical total | Per employee | What it covers |
|---|---|---|---|
| Under 50 | $40,000 to $120,000 | $1,000 to $2,800 | Platform tooling, a certification if a customer demands it, and outside leadership if anything is forcing it |
| 50 to 150 | $120,000 to $350,000 | $1,400 to $3,200 | Tooling, one internal engineer or a vCISO retainer, annual testing, one certification cycle |
| 150 to 500 | $350,000 to $1,100,000 | $1,600 to $3,600 | A small internal function, leadership either fractional or hired, two frameworks, managed detection |
| 500 to 1,500 | $1,100,000 to $3,000,000 | $1,800 to $4,500 | A real function with sub-teams, continuous testing, and audit obligations that no longer fit around other jobs |
Sector changes the answer more than size does
| Sector | Share of IT spend | What drives it |
|---|---|---|
| Federally regulated financial institutions | 12 to 20% | OSFI expectations, examinations and resilience testing. See OSFI regulated institutions |
| Health and health technology | 8 to 15% | PHIPA and provincial equivalents, plus hospital procurement diligence |
| B2B software selling to enterprise | 7 to 14% | Customer security reviews and certification maintenance, not regulation |
| Professional services | 5 to 10% | Client confidentiality obligations and occasional client audits |
| Manufacturing and logistics | 4 to 9% | Operational technology and ransomware exposure, often underfunded |
| Retail and consumer | 4 to 8% | Payment card obligations concentrated in a narrow scope |
Spend follows whoever is asking. Companies do not spend on security in proportion to their risk. They spend in proportion to how often someone who can withhold money or a contract asks them to prove something. That is why the manufacturing row carries the largest gap between exposure and spending.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Build it bottom-up, then check it against the ratio
A budget assembled from named line items survives a CFO conversation. A budget derived from a percentage does not, because the first question is which line you would cut and the percentage cannot answer it.
| Line | Low | High | Cuttable? |
|---|---|---|---|
| Security leadership: vCISO retainer, 20 hours a month | $72,000 | $120,000 | Hours, not the role |
| One internal security engineer, loaded | $140,000 | $210,000 | No |
| Core tooling: endpoint, identity, logging, scanning | $61,000 | $210,000 | Scope down, do not remove |
| Managed detection and response | $40,000 | $110,000 | Yes, if you accept the gap explicitly |
| Compliance platform | $8,000 | $30,000 | Only outside an audit cycle |
| Penetration testing, annual | $8,000 | $25,000 | No if a customer reads the report |
| SOC 2 Type 2 audit fee | $25,000 | $55,000 | No once committed to customers |
| Awareness training and phishing simulation | $3,000 | $12,000 | No, and it is the cheapest line here |
| Tabletop exercise and incident readiness | $8,000 | $20,000 | Every other year at a push |
| Contingency, 10 per cent | $37,000 | $79,000 | The line that gets cut and then gets spent anyway |
| Total per year | $402,000 | $871,000 | Roughly 8 to 14% of a typical IT budget at this size |
Security budgets are consistently underspent on planned items and overspent on unplanned ones: an incident, a customer demanding a framework you had not planned for, a vendor breach that consumes three weeks. Ten per cent is not padding. It is the recognition that this budget has a demand side you do not control.
Defending the budget
- Lead with what forced it. A customer requirement, an audit date, a regulator or an incident. A budget presented as general prudence competes with every other general priority and loses to the ones with dates.
- Show the deal friction number. Days added to the sales cycle by security reviews, and deals delayed or lost. This is the one figure that moves a CFO, and it is on security metrics and KPIs.
- Present three tiers, not one number. What you would do at 70 per cent of the ask, at 100, and at 130, with what each buys and what each leaves accepted. The 70 per cent column is what makes the request credible.
- Name what gets accepted if it is cut, and put it on the risk register with the executive who accepted it. This is not a threat. It is how the decision gets recorded rather than reopened every quarter.
- Separate one-time from recurring. A first certification is a project cost that falls by roughly half in year two. Presenting the first year as the run rate makes the program look twice as expensive as it is, and the correction next year will not be believed.
Where the money goes wrong
- Tooling bought reactively, one questionnaire at a time. The difference between a well-scoped and a reactively assembled toolset at 250 people is well over $100,000 CAD a year, which is roughly the cost of the leadership that would have prevented it. That comparison is on the cost of an in-house security team.
- Overlapping tools nobody retired. Two logging products and three scanners is common by the third year, because each arrived to answer a specific question and none was ever removed.
- Buying a platform before there is anyone to run it. A compliance platform with no owner produces dashboards and no evidence.
- Post-incident spending. The month after an incident is when budgets are approved without argument, which is precisely when the spending is worst. Wait for root cause.
- Under 25 people spending like a regulated institution. If nothing external is forcing the question, the honest budget at that size is platform tooling, backups you have tested, MFA everywhere and nothing else. Check with the qualification tool before adding a retainer to it.
The under 50 band covers a wide range, and the bottom of it needs its own arithmetic. A line by line budget at 20 people builds the same number from the bottom up, and the version with no budget at all lists what to do when the answer this year is zero.
Get the leadership line priced
The largest single variable in a mid-market security budget is what you pay for leadership. Tell us the scope and we will get comparable Canadian quotes.
Get matchedCommon questions
What percentage of IT spend should go to security?
Commonly 5 to 15 per cent, with federally regulated financial institutions at 12 to 20 and companies with no regulatory or customer driver at the bottom of the range. Treat it as a check on a number you built from line items rather than as a way to produce that number, because the ratio rewards a bloated IT budget and penalises an efficient one.
How much should a 200 person Canadian company spend on security?
Roughly $400,000 to $870,000 CAD a year for a B2B software company with large customers and a SOC 2 obligation, which is about 8 to 14 per cent of a typical IT budget at that size. Around half of it is people. A company at the same headcount with no certification obligation and no regulator can reasonably run at half that.
Is security spend per employee a better benchmark?
It is more stable than the share of IT spend, because it does not depend on how your finance team classifies IT costs. At Canadian mid-market scale it runs about $1,200 to $4,500 CAD per employee per year. It breaks for companies with unusual shapes, such as a small engineering team running very large infrastructure, where the exposure follows the systems rather than the payroll.
How much does the first year cost compared with later years?
The first year typically runs 40 to 70 per cent higher, because it carries the initial assessment, the first policy set, a first certification audit and the tooling purchases all at once. Show one-time and recurring separately in the budget request, otherwise year two looks like a cut you have to justify and year three looks like an increase you have to defend.
What should we cut first if the budget is reduced?
Managed detection hours, the frequency of testing beyond what customers require, and the scope of log retention, in that order, with each cut written onto the risk register and accepted by a named executive. What should not be cut is anything you have contractually committed to a customer, anything an auditor will ask for evidence of, and awareness training, which is the cheapest line in the budget and one of the few that changes behaviour.