HireACISO

Security budget benchmarks for Canada

Security typically runs 5 to 15 per cent of IT spend, and IT typically runs 3 to 8 per cent of revenue, which puts security somewhere between 0.2 and 1.2 per cent of revenue for most companies. Those ratios are sanity checks, not targets, and using one as a target rewards you for having a bloated IT budget.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

The three ratios worth knowing are these. Security spend as a share of IT spend commonly lands at 5 to 15 per cent, with regulated financial institutions at the top and companies with no regulatory driver at the bottom. Security spend per employee lands at roughly $1,200 to $4,500 CAD a year at mid-market scale. Security as a share of revenue lands between 0.2 and 1.2 per cent. All three are wide.

What these numbers are, and are not

There is no authoritative Canadian security budget survey at mid-market scale. The ranges here are assembled from published international ratios that are widely reported, from Canadian salary and tooling costs priced out directly, and from what the components on this site cost when you add them up. Use them as a check on a number you built bottom-up, not as a way of producing that number. A budget defended with "the benchmark says 10 per cent" will lose to a CFO who asks what happens if it is 7.

What Canadian companies spend by size

Total annual security spend by company size, Canadian mid-market, CAD
Company sizeTypical totalPer employeeWhat it covers
Under 50 $40,000 to $120,000 $1,000 to $2,800 Platform tooling, a certification if a customer demands it, and outside leadership if anything is forcing it
50 to 150 $120,000 to $350,000 $1,400 to $3,200 Tooling, one internal engineer or a vCISO retainer, annual testing, one certification cycle
150 to 500 $350,000 to $1,100,000 $1,600 to $3,600 A small internal function, leadership either fractional or hired, two frameworks, managed detection
500 to 1,500 $1,100,000 to $3,000,000 $1,800 to $4,500 A real function with sub-teams, continuous testing, and audit obligations that no longer fit around other jobs
Security spend per employee by company size Midpoint spend per employee rises modestly with size, from about $1,900 CAD under 50 staff to about $3,150 at 500 to 1,500 staff, while total spend rises far faster. $1,900 $2,300 $2,600 $3,150 under 50 50-150 150-500 500-1500 Company headcount CAD/head
Midpoints of the per-employee column above. The line is much flatter than the total, which is why per-employee is the more stable check of the two.

Sector changes the answer more than size does

Security as a share of IT spend by Canadian sector
SectorShare of IT spendWhat drives it
Federally regulated financial institutions12 to 20%OSFI expectations, examinations and resilience testing. See OSFI regulated institutions
Health and health technology8 to 15%PHIPA and provincial equivalents, plus hospital procurement diligence
B2B software selling to enterprise7 to 14%Customer security reviews and certification maintenance, not regulation
Professional services5 to 10%Client confidentiality obligations and occasional client audits
Manufacturing and logistics4 to 9%Operational technology and ransomware exposure, often underfunded
Retail and consumer4 to 8%Payment card obligations concentrated in a narrow scope

Spend follows whoever is asking. Companies do not spend on security in proportion to their risk. They spend in proportion to how often someone who can withhold money or a contract asks them to prove something. That is why the manufacturing row carries the largest gap between exposure and spending.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Build it bottom-up, then check it against the ratio

A budget assembled from named line items survives a CFO conversation. A budget derived from a percentage does not, because the first question is which line you would cut and the percentage cannot answer it.

Bottom-up security budget, 200 person Canadian B2B software company, CAD per year
LineLowHighCuttable?
Security leadership: vCISO retainer, 20 hours a month$72,000$120,000Hours, not the role
One internal security engineer, loaded$140,000$210,000No
Core tooling: endpoint, identity, logging, scanning$61,000$210,000Scope down, do not remove
Managed detection and response$40,000$110,000Yes, if you accept the gap explicitly
Compliance platform$8,000$30,000Only outside an audit cycle
Penetration testing, annual$8,000$25,000No if a customer reads the report
SOC 2 Type 2 audit fee$25,000$55,000No once committed to customers
Awareness training and phishing simulation$3,000$12,000No, and it is the cheapest line here
Tabletop exercise and incident readiness$8,000$20,000Every other year at a push
Contingency, 10 per cent$37,000$79,000The line that gets cut and then gets spent anyway
Total per year$402,000$871,000Roughly 8 to 14% of a typical IT budget at this size

Security budgets are consistently underspent on planned items and overspent on unplanned ones: an incident, a customer demanding a framework you had not planned for, a vendor breach that consumes three weeks. Ten per cent is not padding. It is the recognition that this budget has a demand side you do not control.

Defending the budget

  1. Lead with what forced it. A customer requirement, an audit date, a regulator or an incident. A budget presented as general prudence competes with every other general priority and loses to the ones with dates.
  2. Show the deal friction number. Days added to the sales cycle by security reviews, and deals delayed or lost. This is the one figure that moves a CFO, and it is on security metrics and KPIs.
  3. Present three tiers, not one number. What you would do at 70 per cent of the ask, at 100, and at 130, with what each buys and what each leaves accepted. The 70 per cent column is what makes the request credible.
  4. Name what gets accepted if it is cut, and put it on the risk register with the executive who accepted it. This is not a threat. It is how the decision gets recorded rather than reopened every quarter.
  5. Separate one-time from recurring. A first certification is a project cost that falls by roughly half in year two. Presenting the first year as the run rate makes the program look twice as expensive as it is, and the correction next year will not be believed.

Where the money goes wrong

  • Tooling bought reactively, one questionnaire at a time. The difference between a well-scoped and a reactively assembled toolset at 250 people is well over $100,000 CAD a year, which is roughly the cost of the leadership that would have prevented it. That comparison is on the cost of an in-house security team.
  • Overlapping tools nobody retired. Two logging products and three scanners is common by the third year, because each arrived to answer a specific question and none was ever removed.
  • Buying a platform before there is anyone to run it. A compliance platform with no owner produces dashboards and no evidence.
  • Post-incident spending. The month after an incident is when budgets are approved without argument, which is precisely when the spending is worst. Wait for root cause.
  • Under 25 people spending like a regulated institution. If nothing external is forcing the question, the honest budget at that size is platform tooling, backups you have tested, MFA everywhere and nothing else. Check with the qualification tool before adding a retainer to it.

The under 50 band covers a wide range, and the bottom of it needs its own arithmetic. A line by line budget at 20 people builds the same number from the bottom up, and the version with no budget at all lists what to do when the answer this year is zero.

Get the leadership line priced

The largest single variable in a mid-market security budget is what you pay for leadership. Tell us the scope and we will get comparable Canadian quotes.

Get matched

Common questions

What percentage of IT spend should go to security?

Commonly 5 to 15 per cent, with federally regulated financial institutions at 12 to 20 and companies with no regulatory or customer driver at the bottom of the range. Treat it as a check on a number you built from line items rather than as a way to produce that number, because the ratio rewards a bloated IT budget and penalises an efficient one.

How much should a 200 person Canadian company spend on security?

Roughly $400,000 to $870,000 CAD a year for a B2B software company with large customers and a SOC 2 obligation, which is about 8 to 14 per cent of a typical IT budget at that size. Around half of it is people. A company at the same headcount with no certification obligation and no regulator can reasonably run at half that.

Is security spend per employee a better benchmark?

It is more stable than the share of IT spend, because it does not depend on how your finance team classifies IT costs. At Canadian mid-market scale it runs about $1,200 to $4,500 CAD per employee per year. It breaks for companies with unusual shapes, such as a small engineering team running very large infrastructure, where the exposure follows the systems rather than the payroll.

How much does the first year cost compared with later years?

The first year typically runs 40 to 70 per cent higher, because it carries the initial assessment, the first policy set, a first certification audit and the tooling purchases all at once. Show one-time and recurring separately in the budget request, otherwise year two looks like a cut you have to justify and year three looks like an increase you have to defend.

What should we cut first if the budget is reduced?

Managed detection hours, the frequency of testing beyond what customers require, and the scope of log retention, in that order, with each cut written onto the risk register and accepted by a named executive. What should not be cut is anything you have contractually committed to a customer, anything an auditor will ask for evidence of, and awareness training, which is the cheapest line in the budget and one of the few that changes behaviour.