How CISOs Actually Budget: Why Your Deal Timing Matters More Than Your Demo
Security budgets are set months before most vendors pitch, and they follow problems, not products. Here is how CISOs actually budget, and how to land on the line item before the cycle closes.
Most vendors think they lose deals in the demo. They lose them in the budget cycle, months earlier, in a planning conversation they were never in the room for.
I have spent 14 years on the buyer side of security. I have built the budget, defended it to a CFO, and watched good products get a polite "not this year" that had nothing to do with the product. The pattern is almost always the same. The money was already committed to a set of named problems before the vendor ever showed up. The demo was real. The interest was real. The line item was not.
If you sell to CISOs, understanding how they budget is worth more than any messaging refresh you will do this quarter.
How do CISOs actually budget?
CISOs budget by mapping money to named problems, not to products. Each year a fixed pool gets allocated to risks the board and the CFO already agree matter, usually months before most vendors pitch. If your product is not tied to a funded problem before that cycle closes, no demo moves the money until the next one opens.
This is the single idea that reframes everything about how you sell. The CISO is not shopping. The CISO is allocating. Those are different jobs. A shopper compares products and picks the best one. An allocator starts with a fixed number and a list of problems that outrank the money available, then decides which problems get funded and which wait. Your product is not competing against other products in that moment. It is competing against other problems.
Nikoloz Kokhreidze
Where does the security budget come from?
Security budget is not free money that appears because threats exist. It is carved out of the IT budget and, increasingly, out of the risk and enterprise line items too. The share has been climbing for years. According to IANS Research data for 2026, security now consumes roughly 12 to 13 percent of the IT budget, up from about 8.6 percent in 2020. At the macro level, Gartner put worldwide information security spending at 213 billion dollars in 2025 and expects double-digit growth again into 2026.
Those numbers look like a rising tide that should lift every vendor. They are not. The budget grows, but it grows against a threat surface, a compliance calendar, and a headcount bill that all grow faster. People remain the single largest line in most security budgets, ahead of any tool. So when a CISO sits down to plan, the discretionary room for new products is a thin slice on top of a large stack of commitments that renew automatically: salaries, the platforms already deployed, the audits already scheduled.
That thin slice is what you are actually selling into. And it is spoken for early.
When does the CISO budget cycle actually happen?
For most companies on a calendar fiscal year, the real allocation decisions happen in the autumn of the prior year: roughly September through November. By December the number is mostly set. By January it is being executed. A vendor who starts a conversation in February is, in budget terms, talking about next year, even if nobody says so out loud.
The Mandos Brief
Analysis like this, every Monday. Ten minutes.
This is why timing beats the demo. A brilliant demo in Q2 lands on a CISO who has no uncommitted money left for a new category. The same demo in August, while planning is still open, lands on someone who is actively deciding which problems make the cut. Same product, same pitch, completely different outcome, because one arrived while the money was liquid and the other arrived after it froze.
There is a second cycle worth knowing. Many teams hold a small contingency or "unplanned but urgent" reserve. That is the budget an incident, a failed audit, or a board question unlocks mid-year. You do not win that money with a demo either. You win it by already being the name the CISO remembers when the problem suddenly becomes urgent.
Why did the CISO love my demo but not buy?
Because a demo answers "is this a good product," and budgeting answers "is this problem funded this year." Those are different questions decided by different people at different times. The security architect on your demo can love your product and still have no authority to move money to it. The CISO holds the veto but not always the pen. Procurement and the budget owner sit between enthusiasm and a signature.
When a vendor tells me the deal "went dark after a great demo," I almost always find the same thing: the product was never mapped to a problem that already had money attached. It was interesting, not funded. Interesting gets a follow-up call. Funded gets a purchase order.
The table below is how I think about the two states a vendor can be in when the cycle closes.
Mapped to a funded problem
Interesting but unbudgeted
How the CISO sees you
Part of solving a risk we already agreed to fund
A better way to do something we have not prioritized
Who champions it
The owner of that risk line item
Whoever liked the demo, with no budget authority
What closes the deal
Proof you solve the funded problem better
Nothing, until the problem gets funded
Typical outcome
Enters procurement this cycle
"Let's revisit next year"
How much competition is really on the CISO's desk?
More than most founders imagine, and it is growing every month. According to Mandos platform data (August 2026), 263 cybersecurity funding rounds have already closed so far in 2026, from a two billion dollar debt raise at the top down to seed rounds. Cloud Security alone accounts for 81 tracked companies that have raised a combined 8.4 billion dollars. Zoom out to the whole market and there are more than 9,000 products in the CybersecTools directory. Every one of those vendors wants a line item, and the CISO's budget did not grow 9,000 ways.
Mandos platform data, August 2026
The practical consequence is legibility. When a CISO scans a category with dozens of funded, well-marketed options, the ones that survive the cut are not always the best built. They are the ones whose value maps cleanly to a problem the CISO already has money against. A product that makes the buyer do the translation work, figuring out which of their funded risks you actually reduce, loses to a weaker product that did the translation for them. That translation is a positioning problem, not an engineering one, and it is exactly what a positioning audit is built to fix. You can browse the underlying funding and category movements yourself on the Mandos market data.
How can a vendor get into next year's security budget?
You get in by being mapped to a funded problem before the planning cycle starts, and by making that mapping impossible to miss. That is a positioning and timing exercise, and it runs on the buyer's calendar, not yours.
Here is the 90-day plan I would run if I were selling into the autumn budget cycle.
Name the budget line, not the feature. Write down the exact problem your buyer already funds that you reduce. Not "we use AI to detect anomalies" but "we cut the cost of the identity audit you already pay for." If you cannot name the funded problem, that is the first thing to fix.
Get the language right for the person signing. The buyer does not read your site the way you wrote it. Map your message to the risk owner's vocabulary, not your engineering team's. The seven-dimension method I use in the framework behind my services checks whether each part of your story ties back to a budget line a CISO recognizes.
Arrive while the money is liquid. Time your outbound and your case studies to land in the planning window, roughly September to November for calendar-year buyers. A reference from a peer in that window is worth ten cold demos in February.
Know which funded problems your rivals already own. If three funded competitors already sit on the line item you want, you need a different problem or a sharper wedge. A competitive benchmark shows which problems your category rivals have already claimed in the buyer's mind.
Give the champion something to defend the number with. Your internal champion has to justify the spend to a budget owner who was not on your demo. Hand them a one-page problem-and-cost story they can forward without you in the room.
None of this requires a bigger marketing budget. It requires selling on the buyer's terms. If you want a second set of eyes on whether your positioning actually maps to a funded problem, that is the core of what I do in a Mandos engagement, and you can always start with a conversation at cal.com/nikolozk/30min.
Frequently asked questions
How do CISOs decide their cybersecurity budget?
They start with a fixed pool carved out of IT and risk budgets, then allocate it to named problems the board and CFO already agree matter. Salaries and existing platforms consume most of it. New products compete for a thin discretionary slice, and they win that slice by being tied to a funded risk, not by having the best feature list.
When is the cybersecurity budget cycle?
For calendar-year companies, allocation decisions are mostly made from September to November of the prior year, locked by December, and executed from January. Many teams also hold a small mid-year contingency reserve that incidents, failed audits, or board questions can unlock outside the main cycle.
Why did a CISO love my demo but not buy?
A demo answers whether your product is good. Budgeting answers whether the problem it solves is funded this year. If your product was never mapped to a problem that already had money attached, it stays "interesting" rather than becoming "funded," and interesting does not generate a purchase order.
How much do companies spend on cybersecurity?
Gartner put worldwide information security spending at about 213 billion dollars in 2025, with double-digit growth expected into 2026. As a share of IT, IANS Research data for 2026 shows security at roughly 12 to 13 percent of the IT budget, up from 8.6 percent in 2020. The pool is growing, but so are the commitments already claiming it.
How do I get my product into next year's security budget?
Map your product to a problem the buyer already funds, phrase it in the risk owner's language, and arrive during the autumn planning window while the money is still liquid. Give your internal champion a one-page problem-and-cost story they can defend without you present.
The Platform
Track the market this article is describing.
Every cybersecurity vendor, product, funding round and market move — 3,279 companies and 8,525 products, 450+ data points each, updated daily.