{"id":26241,"date":"2026-09-23T09:24:27","date_gmt":"2026-09-23T17:24:27","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/23\/ai-changes-cyber-spending-but-wheres-the-line-item-for-tokens\/"},"modified":"2026-09-23T09:24:27","modified_gmt":"2026-09-23T17:24:27","slug":"ai-changes-cyber-spending-but-wheres-the-line-item-for-tokens","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2026\/09\/23\/ai-changes-cyber-spending-but-wheres-the-line-item-for-tokens\/","title":{"rendered":"AI changes cyber spending \u2014\u00a0but where\u2019s the line-item for tokens?"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>AI is increasing both the volume and speed of cyberthreats, pushing organizations to invest more in AI-powered security capabilities to keep pace. Yet overall cybersecurity budgets are barely growing, suggesting that much of the increased spending on AI is coming at the expense of traditional security tools.<\/p>\n<p>A <a href=\"https:\/\/www.ians.com\/blog\/is-your-security-budget-ready-for-ai \" rel=\"noopener noreferrer\" target=\"_blank\">recent survey by IANS and Artico<\/a> shows that AI investments in cybersecurity have become a priority for 69% of organizations, with 24% giving AI its own security budget line. Others are folding their AI spending into broader security, IT, data, and innovation budgets.<\/p>\n<p>AI is accounting now for about 3% of the average security budget, and the survey found that organizations are directing much of that portion toward AI-enabled security tools and software. . AI investment is flowing into security operations automation and AI capabilities embedded in existing workflows. Some related spending is being funded outside security budgets through IT, data, or innovation functions, the report notes.<\/p>\n<p>The spending momentum appears likely to continue, with many organizations that increased AI security investments by more than 10% this year expecting another double-digit increase in the next budget cycle.<\/p>\n<p>The survey also suggests that significant changes are coming to the security workforce as AI adoption accelerates. With 91% saying so, CISOs are nearly unanimous in expecting AI to boost the productivity of their existing teams over the next year, while 81% anticipate a need for new cybersecurity roles and skills. Rather than eliminating security jobs, the technology is expected to shift the composition and focus of security teams as organizations automate more routine work and demand greater expertise with AI.<\/p>\n<p>Here\u2019s what you need to know about how AI security investments are playing out as they become a priority for most organizations. While overall spending is not the concern of the day, spending on AI compute cycles is on the radar for many.<\/p>\n<p><strong>[ See webinar: <\/strong><a href=\"https:\/\/www.reversinglabs.com\/webinar\/autonomy-not-autopilot-agentic-soc-watch-now\"><strong>Autonomy, Not Autopilot \u2014 Get Real About Agentic SOCs<\/strong><\/a><strong> ]<\/strong><\/p>\n<h2 id=\"shadow-ai-shifts-line-items-in-cyber-spending\">Shadow AI shifts line-items in cyber spending<\/h2>\n<p>Dave Gerry, CEO of Bugcrowd, said much of the current AI spending trend involves a reshuffling of existing security priorities rather than a significant expansion of overall budgets. \u201cIt\u2019s mostly reallocation. Very few CISOs are walking into a board meeting and getting a bigger number.\u201d<\/p>\n<p>Rather, they are moving money out of areas such as penetration testing and point-in-time testing and putting it into capabilities such as continuous validation. They\u2019re also adding budget for monitoring what employees are doing with AI tools.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cShadow AI is the new shadow IT. The total stays flat, the line items look nothing like last year\u2019s.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/davegerry\">Dave Gerry<\/a><\/p>\n<p>The greatest increases in AI spending, Gerry said, are for application security (AppSec) and offensive validation, as organizations grapple with a growing gap between the vulnerabilities they can discover and those they can fix.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cDiscovery isn\u2019t the constraint anymore. Teams can find far more than they can fix, so money is moving toward triage and prioritization, the work that turns findings into decisions.\u201d<\/em><br \/><em>\u2014<\/em>Dave Gerry<\/p>\n<p>Identity is another line item that could see a substantial increase in spending as organizations rush to address the access-control issues that contribute to many AI agent failures, he said.<\/p>\n<h2 id=\"agentic-ai-an-evolving-investment-area\">Agentic AI: An evolving investment area<\/h2>\n<p>Agentic AI is emerging as a growing area of investment as organizations move quickly to deploy autonomous agents across business and security workflows, including increasingly agentic SOC operations. Nonetheless, not many organizations appear to be establishing dedicated budget lines for these investments. Instead, much of the spending is being carved out of existing SOC tooling and automation budgets, potentially at the expense of other priorities, security experts say.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cVery few teams have a dedicated agentic AI line item. It\u2019s mostly being carved out of existing SOC tooling and automation budgets, which means something else got quietly deprioritized to pay for it.\u201d<\/em><br \/><em>\u2014<\/em>Dave Gerry<\/p>\n<p>Other organizations are spreading agentic AI investments across dedicated AI security programs, traditional security budgets, and broader enterprise AI initiatives. Security experts expect that over time many of these capabilities will become embedded in areas such as identity and access management, insider risk, data security, and security operations. That is partly because securing AI agents cuts across multiple parts of the organization, said Diana Kelley, CISO at Noma Security.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThe business unit or a dedicated AI team may build the agents, engineering or DevOps teams may deploy them, IT may operate the underlying infrastructure, and the CISO may be expected to manage the security risk. The funding model should reflect that shared responsibility instead of forcing the entire cost into an existing SOC or automation budget.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/dianakelleysecuritycurve\">Diana Kelley<\/a><\/p>\n<h2 id=\"how-ai-reshapes-what-organizations-need-to-secure\">How AI reshapes what organizations need to secure<\/h2>\n<p>Kelley sees AI spending as falling into two broad categories:<\/p>\n<ul class=\"list-bullet\">\n<li class=\"\" value=\"1\"><strong>Improving traditional security functions<\/strong>, including AppSec testing, vulnerability discovery and remediation, and security operations analysis<\/li>\n<li class=\"\" value=\"2\"><strong>Securing AI systems themselves<\/strong>, including identifying sanctioned and unsanctioned AI use, testing models and applications, monitoring agents at runtime, and controlling the data, tools, identities, and actions available to them<\/li>\n<\/ul>\n<p>Agent identity and authorization are likely to become particularly important as AI agents gain access to enterprise systems, Kelley said. The risk is not simply that an AI model produces an incorrect or harmful response; it\u2019s that the software surrounding it can turn that output into an action using legitimate corporate access.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cAI introduces additional systems, artifacts, data flows, identities, and automated actions that companies must secure. That creates net-new spending. At the same time, CISOs are under pressure to fund some of those requirements by consolidating vendors, automating existing work, and reallocating money from established security categories.\u201d<\/em><br \/><em>\u2014<\/em>Diana Kelley<\/p>\n<p>In <a href=\"https:\/\/cpl.thalesgroup.com\/data-threat-report\"><span style=\"text-decoration:underline\">a recent Thales survey<\/span><\/a> of more than 3,100 security and IT professionals in 20 countries, 30% of responding organizations said they have a dedicated budget for securing their AI use, and 53% said they fund AI security through the existing security budget.\u00a0<\/p>\n<p>In the same survey, 70% of respondents cited rapid change in the AI ecosystem as one of their biggest sources of risk.<\/p>\n<p>AI is not just creating a new security budget line; it is reshaping the entire cybersecurity budget, said Aviv Nahum, co-founder and CEO of Above Security. Organizations still have to protect the same endpoints, identities, applications, cloud environments, and data they always have needed to protect. But now they also have to secure models, agents, and AI-driven workflows, while defending against attackers who are using AI to move faster.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThe biggest new area of spend will be around visibility and control over AI itself. Companies need to know which AI tools and agents are operating in the environment, what data they can access, which identities and credentials they are using, and whether their behavior makes sense. That is a fundamentally different problem from simply buying another threat-detection product.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/avivon\">Aviv Nahum<\/a><\/p>\n<p>It\u2019s not just large organizations that are increasing AI spending. A<a href=\"https:\/\/www.globenewswire.com\/news-release\/2026\/07\/13\/3326217\/0\/en\/pax8-research-finds-small-businesses-all-in-on-ai-with-2-in-3-projecting-stronger-competitive-composure.html\" rel=\"noopener noreferrer\" target=\"_blank\"> <span style=\"text-decoration:underline\">Q2 2026 SMB AI Pulse Report<\/span><\/a> from Pax8 found that 61% of small and midsize businesses are using AI forcompetitive advantage. Though 29% of SMBs remain stuck in the experimentation stage and have not moved toward full deployment, the percentage that are still undecided on the use of AI dropped from 9% to a mere 1.5% in a single quarter.\u00a0<\/p>\n<h2 id=\"is-ai-cyber-spending-a-no-brainer\">Is AI cyber spending a no-brainer?<\/h2>\n<p>Above Security\u2019s Nahum said he perceives the business case for AI spending as straightforward. \u201cAI is increasing both the number of things organizations need to protect and the speed at which risk can materialize,\u201d he said. Security leaders should not pitch AI security as another compliance project. Rather they should tie the investments to enabling the company to deploy AI more aggressively without losing visibility or control.<\/p>\n<p>What\u2019s unlikely to work is trying to get more budget just with\u00a0 frightening stories about new AI attacks, Kelley said. Instead, make it about the need to secure AI as organizations put it into production. \u201cThe strongest business case is not \u2018Spend more because AI is dangerous,\u2019\u201d she said. \u201cIt is, \u2018If the company wants to get the full value from its AI investment, security is part of the cost of putting AI into production without putting the company or its customers at unnecessary risk.\u2019\u201d<\/p>\n<p>The reality is twofold: AI has significantly boosted attacker capabilities, and it has significantly boosted defensive capabilities. The result is an arms race in which improvements on one side drive greater investment on the other, said John Strand, owner of Black Hills Information Security.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cA lot of CTOs and CIOs were sold on the idea that AI was going to cut costs. It may do that in some areas, but cybersecurity isn\u2019t one of the easy ones. When offense and defense are both getting better at the same time, you don\u2019t necessarily get lower costs. You get escalation.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/john-strand-a1b4b62\">John Strand<\/a><\/p>\n<h2 id=\"the-hidden-line-item-ai-tokens-in-the-soc\">The hidden line-item: AI tokens in the SOC<\/h2>\n<p>Strand\u2019s \u201cescalation, not savings\u201d framing understates one cost most organizations have not yet put on a spreadsheet: the token spend behind every decision an agent makes. An underinformed agent does not fail quietly. It reasons longer, calls more tools, and loops back to a human analyst before it reaches a verdict, and each of those steps runs up a compute bill that scales with the volume of alerts, not with the value of the outcome. Gerry\u2019s point about triage outpacing remediation applies just as directly to compute: The faster agents generate findings, the faster that spend compounds if the findings are not resolved efficiently.<\/p>\n<p>That is the premise behind efforts such as the<a href=\"https:\/\/www.reversinglabs.com\/blog\/how-to-build-effective-agentic-socs\"> <span style=\"text-decoration:underline\">Agentic SOC Alliance<\/span><\/a>, launched this year by ExtraHop with more than a dozen partners, including ReversingLabs, CrowdStrike, and LangChain, to build a shared context layer of threat, identity, and file intelligence that AI-SOC agents can draw on directly rather than re-deriving through costly chains of reasoning. <\/p>\n<p>Binary-level reputation and threat-actor data, RL&#8217;s contribution to that layer, is meant to let an agent turn a flagged file into a confirmed verdict in a single pass instead of escalating noise back to a human queue or burning tokens working the problem from scratch, narrowing both the discovery-to-decision gap Gerry described and the compute cost that comes with it.<\/p>\n<p>Kelley\u2019s shared-responsibility model and Nahum\u2019s call for visibility into what agents can access point to the same conclusion from a different angle: the organizations getting the most from AI security spending aren\u2019t the ones buying the most agents, but the ones building the infrastructure \u2014 identity, context, and verified data \u2014 that lets those agents reach the right answer without paying a premium to reason their way there. As budgets stay flat and reallocation continues, that infrastructure \u2014 more than any single tool \u2014 is where cost containment for the agentic SOC is likely to come from.<\/p>\n<p><a href=\"https:\/\/www.linkedin.com\/in\/kanaiyavasani\/\"><span style=\"text-decoration:underline\"><em>Kanaiya Vasani<\/em><\/span><\/a><em>, chief product officer and chief marketing officer at ExtraHop,<\/em> <em>shares best practices in this Q&amp;A:<\/em><a href=\"https:\/\/www.reversinglabs.com\/blog\/how-to-build-effective-agentic-socs\"> <span style=\"text-decoration:underline\"><em>How to build effective agentic SOCs<\/em><\/span><\/a>.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>AI is increasing both the volume and speed of cyberthreats, pushing organizations to invest more in AI-powered security capabilities to keep pace. Yet overall cybersecurity budgets are barely growing, suggesting that much of the increased spending on AI is coming at the expense of traditional security tools.Arecent survey by IANS and Articoshows that AI investments in cybersecurity have become a priority for 69% of organizations, with 24% giving AI its own security budget line. Others are foldin<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26241","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26241","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26241"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26241\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26241"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26241"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26241"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}