error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

Loading

The page is loading.

Please wait...


      The challenge isn’t funding. It’s how cyber investment decisions get made.

      Cybersecurity has entered a new phase. Budgets are flattening while cyber risk accelerates. Yet most cyber budgeting still relies on rolling forward last year’s spend, adjusting at the margins, and defending what’s already in place. It feels safe, but it locks organisations into historic decisions that no longer reflect today’s risks.

      The result is familiar. Crowded dashboards, long lists of “critical” issues, and budget conversations that centre on tools and headcount – rather than outcomes and trade-offs.

      This publication argues that the model needs a reset. Not another framework, but a more deliberate way of deciding where investment actually reduces risk. That means moving from static budgeting to a risk-led investment approach, grounded in measurable outcomes.

      This is where cyber risk quantification (CRQ) becomes essential – translating cyber risk into financial terms and enabling clearer, more defensible decisions.

      In collaboration with TAG Infosphere, this report explores how organisations can rethink cyber budgeting –challenging legacy assumptions, adopting risk-based models, and using CRQ to make cyber risk actionable.

      The question for leaders is no longer how much you spend, it’s how effectively you allocate it against the risks that matter most.

      Martin Tyley

      Partner, Global Lead Cyber Risk Insights

      KPMG in the UK


      Del Heppenstall

      Partner, UK Cyber Lead

      KPMG in the UK




      Download

      Reinventing cyber budgeting

      Cybersecurity has entered a new phase, where rising risk is colliding with flat budgets. This report explores how organisations can move beyond legacy budgeting and adopt a risk-led investment approach. By using cyber risk quantification (CRQ) to translate cyber threats into financial terms, leaders can make clearer, more defensible decisions, prioritise spend, and focus investment on the risks that matter most.






      TAG Infosphere

      Reinventing Cyber Budgeting is a joint publication by KPMG and TAG, written for CISOs, risk leaders and executives who are being asked to do more – with less – and need a better way to explain, justify and defend cyber investment decisions.


      Contact us

      Martin Tyley

      Partner, Global Lead Cyber Risk Insights

      KPMG in the UK

      Del Heppenstall

      Partner, UK Cyber Lead

      KPMG in the UK

      Dr. Jayne Goble

      Partner - Sector Specialist

      KPMG in the UK

      Rajvir Cheema

      Partner, Digital Healthcare Advisory

      KPMG in the UK


      Our regulatory insights

      Cybersecurity is not changing because of a new tool or framework.

      The latest Global Cybersecurity Outlook from the World Economic Forum (WEF) highlights three forces reshaping cyber risk in 2026

      Many organisations say they want to be “cyber resilient”, but the term is often vague.

      Something went wrong

      Oops!! Something went wrong, please try again



      MTD

      Get in touch


      Discover why organisations across the UK trust KPMG to make the difference and how we can help you to do the same.