enterprisesecuritymag

Over Two-Thirds Of IT Security Decision-Makers Report An Increase in Cybersecurity Budgets for 2024

Enterprise Security Magazine | Wednesday, February 28, 2024

Infosecurity Europe opens registration for 2024 with cyber investment a significant talking point as organisations address security spend

• 69% of surveyed IT decision-makers cite that they have seen, or will see, their cybersecurity budgets increase between 10-100% in 2024.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

• Almost one in five (19%) of those surveyed are seeing, or are expecting to see budgets increase between 30-49% over the coming year.

• Whilst 15% of IT decision-makers highlight that their security budgets had decreased, or will, in 2024.

• Cloud security and incident response will see the highest injection, followed by MSSP outsourcing and antivirus, education and training, managed detection and patching.

Infosecurity Europe, ExCeL London,: Infosecurity Europe 4-6 June 2024, the most influential information security event running at ExCeL London, has today announced findings from research into the cybersecurity budgets of organisations, with 69% of surveyed IT decision-makers citing that they have seen, or will see, their cybersecurity budgets increase between 10-100% in 2024[1].

Almost one in five (19%) of those surveyed are seeing or are expecting to see budgets increase between 30-49% over the coming year.

“We continue to see pragmatic budgetary spend on cyber security under mounting macroeconomic pressures. The fast-changing threat landscape and tightening regulatory pressures have in the main seen security budgets benefiting from much-needed increases which is positively received”, said Mun Valiji, CISO, Trainline, Infosecurity Europe’s Advisory Council member.

For those who plan to increase cybersecurity budget in 2024, cloud security and incident response will see the biggest injection, with 47% noting that between 1-20% of the additional investment will be spent in those areas. Additionally:

• 46% said 1-20% of their spend will go towards MSSP outsourcing and antivirus.

• 45% of respondents said the same amount of spend will go on identity security management.

• A further 44% are willing to invest between 1-20% of their budget on education and training.

• 43% of respondents are willing to invest the same amount of their budget on managed detection and patching.

• Whilst 41% consider investing the same budget in AI enabled cyber tools and consolidation.

Email security and threat exposure management seemed to be at the bottom of the priority list with only 40% saying they would invest between 1-20% of their additional budget in these areas. This could be down to the budget injection in MSSP’s and the potential to outsource these issues.

“One major consideration for cyber security spending in 2024, is the forecast, and in some cases significant increase in licences and associated support costs compared to 2023, either through direct price increases or the more insidious practice of licensed product scope manipulation. Add this to the continued rise in cyber professionals’ salaries, which makes outsourcing to an MSSP a more viable proposition for many businesses. SaaS in particular is seeing notable price increases, with many businesses ‘locked-in’ and with little choice but to bite the bullet,” explains Ian Hill, CISO, UPP Corporation, and Infosecurity Europe’s Advisory Council member.

The increase in cyber security budgets for many reflects the escalating concerns regarding online threats and data breaches and the need to fortify defences against cyberattacks. Against this backdrop, Infosecurity Europe 2024 will host a panel focusing on maximising budgets amidst turbulent times. It will offer a vital platform for CISOs and cybersecurity professionals to glean insights on topics such as articulating the costs of cyber tools and communicating a business case to secure more for their budget. Attendees can also explore new strategies aimed at optimising their security expenditure including conducting an audit of existing systems, securing more value from what’s in place already, and investing in people rather than new systems.

Nicole Mills, Exhibition Director at Infosecurity Group, added: “Cybersecurity is all[1]encompassing and no business, organisation or individual is devoid of risk. The industry continues to grow, threats evolve and so too do the innovative products developed to protect against them. The conference provides a springboard for industry leaders, experts and vendors to join heads and join forces, to collaborate and share experiences and knowledge. Peers come together to debate and discuss critical topics, to find solutions to problems and put solid cybersecurity strategies in place. This year, Infosecurity Europe 2024 will continue to forge a future of innovation, collaboration, and resilience.”

The research also highlighted that for some, the tables had turned, with 15%[2] of IT decision-makers highlighting that their security budgets had decreased, or will, in 2024. A minor 4% had seen, or expect to see, no change in their budget for 2024.

The research comes as visitor registration for Infosecurity Europe 2024 has opened with the findings being indicative of some of the themes and discussions lined up for this year’s conference which will run from Tuesday 4 th to Thursday 6 th June 2024 at ExCeL London. Cybersecurity professionals and members of the infosec community are invited to sign up and secure their place to hear more about the pressing issues topping the agenda at this year’s event.

The event will provide opportunities to hear from, and network with, the people who make up our community, exchange ideas, build resilience and be able to work together to protect our shared future. Below are some of the sessions and opportunities that visitors will be able to take advantage of at the 2024 event:

• Hear from speakers at the sharp end of the industry who are tackling major information security challenges every day. Look out for the upcoming keynote announcement!

• Join a networking programme open to CISOs and heads of information security with a programme of ‘off-the-record’roundtables informing security strategies, and the opportunity to discover the latest technology and solutions in their field.

• Take inspiration from a presentation series that addresses the strategic business challenges impacting information security and showcases the latest information and cybersecurity insight, knowledge, and expertise.

• Gain new perspectives and strategies to apply within the organisation to enhance cyber-resilience and strengthen security posture as well as fresh ideas on how to tackle strategic and technical cybersecurity challenges.

• Join ‘how to’ sessions that deal with how to overcome specific challenges.

• Get to grips with the latest products and technological innovations from exhibitors as they are put in the spotlight, guiding organisation’s security investment and ensuring ROI.

• Benefit from in-depth, practical sessions offering advice on how to strengthen information security posture. Security workshop expert speakers will provide attendees with learning-orientated sessions to improve their skills while networking with peers.

• Participate in immersive, hands-on learning experiences as well as learning from the experts, with activities for varying levels of experience.

• Hear experts address future industry developments and how to be prepared to seize these opportunities. Discussions will cover everything from channel, diversity, and access to the industry, through to professional development. More details will be shared as speakers are announced.

• Join fellow women in cybersecurity at a popular networking event with high demands for attendance and hear from senior female leaders in cybersecurity.

• Infosecurity is committed to supporting cutting-edge companies that are embarking upon growth by providing a launchpad to hear from them. This is exclusively for companies that are three years in maturity.

More in News

DNS has become harder to police as application traffic moves between corporate networks and cloud environments. Security teams may inspect internet-bound requests while retaining limited visibility into internal DNS activity, leaving lateral traffic harder to trace. That gap matters when malicious domains, DNS tunneling or compromised endpoints use ordinary name resolution as a path around controls. Executives evaluating DNS traffic security should look beyond external filtering and ask how much of the actual query path the security layer can see. Visibility begins with knowing which device generated a query and where that request traveled. Internet-only inspection can miss traffic that remains inside the enterprise, particularly in distributed networks where applications depend on internal DNS records. Useful protection needs coverage at the point where queries originate, supported by searchable logging that gives security teams enough context to investigate suspicious behavior. DNS data should also feed existing security tools rather than create another isolated console. Integration with SIEM platforms and established security controls can shorten the path from detection to investigation. Hybrid infrastructure creates a separate purchasing problem. Enterprises rarely operate on a clean network built around one architecture. Legacy DNS services may remain in place while workloads spread across data centers and public clouds. Replacing that infrastructure can introduce migration risk and delay security improvements. A practical DNS security platform should be able to sit over existing environments, centralize policy and extend control without forcing an immediate rebuild. API access also matters because repetitive DNS administration becomes costly when changes across large networks still depend on manual intervention. “Access Quality layers centralized DNS control over existing infrastructure without forcing buyers into a wholesale replacement.” Availability deserves equal scrutiny, as DNS protection cannot become another point of failure. Traffic surges and denial-of-service attacks can disrupt access even when the application infrastructure remains healthy. Buyers should examine how DNS security handles sudden demand, distributed environments and malicious traffic while preserving response availability. Policy enforcement also needs to remain consistent as applications move between locations. A security model that works only in one cloud or inside the corporate network leaves the enterprise managing different rules across the same service path. Regional deployment adds another layer of complexity. Large organizations may need local technical support, training for internal teams and deployment choices that reflect existing network designs. The quality of implementation matters here as much as the underlying technology. Centralized control has limited value if internal teams cannot maintain policies or investigate events once the initial project ends. Access Quality fits this buying logic through BlueCat-based DDI and DNS security deployments that combine DNS control with DHCP, IP address management and native protection. BlueCat DNS Edge can inspect internal and external DNS activity while forwarding logs into SIEM environments and working alongside Cisco Umbrella. It layers centralized DNS control over existing infrastructure without forcing buyers into a wholesale replacement. Its use of BlueCat Micetro DDI and Integrity DDI also supports hybrid and multi-cloud management, while RESTful API integration helps reduce manual administration. For enterprises that need broader DNS visibility without rebuilding the network underneath it, that combination merits close consideration. ...Read more
Identity theft has shifted from isolated financial fraud to a broad digital risk affecting employees, families and institutions. Criminal networks now deploy AI-driven impersonation, automated payment scams and large-scale data harvesting to exploit individuals at speed. For executives responsible for selecting identity and privacy protection providers, the issue extends beyond offering a benefit. It involves safeguarding workforce well-being, reducing reputational exposure and reinforcing institutional trust. Boards increasingly expect leadership teams to demonstrate that identity protection programs are structured, measurable and aligned with broader risk management priorities. The most credible providers demonstrate depth across the full lifecycle of identity risk. Protection must begin before a loss occurs, through continuous monitoring across credit activity, transactions, dark web sources and emerging scam channels such as email, text and device notifications. Effective programs extend beyond detection alerts. They guide individuals in interpreting threats, provide real-time assistance and assume responsibility for restoring identity when fraud occurs. Dedicated case management, clear ownership of recovery and coverage for eligible scam losses signal whether a provider can meaningfully reduce harm rather than simply notify users. Clear communication during incidents also strengthens confidence among employees and customers who expect immediate clarity rather than fragmented support. Prevention requires education delivered before the moment of vulnerability. Fraud often succeeds by creating urgency and fear, prompting individuals to act without verification. Ongoing awareness initiatives, timely alerts and targeted guidance help shift behavior in advance. Tools that allow individuals to manage their digital footprint and request removal of exposed data from broker sources further reduce repeat targeting. Organizations also benefit from vendors that address disproportionate fraud exposure among seniors, families and vulnerable populations through focused knowledge centers and accessible resources. Prevention becomes more credible when it is continuous rather than episodic and when individuals receive practical next steps instead of abstract warnings. Enterprise adoption depends on simplicity and adaptability. Employers and financial institutions face constraints around implementation, adoption and integration within existing platforms. Providers that streamline onboarding, offer configurable plans and embed protection directly into digital environments support higher engagement and clearer reporting. Large enterprises require evidence of scale, sustained innovation and the ability to anticipate shifts in identity itself as biometric authentication and device-based credentials become more prevalent. Vendors must demonstrate that their roadmap keeps pace with changes in how identity is defined and exploited. Allstate Identity Protection aligns closely with these expectations. Built on its nearly two decades experience in the identity protection market and supported by a longstanding national brand associated with protection, it positions trust at the center of its approach. Its model spans education, detection, prevention and restoration, combining credit, transaction and scam monitoring with proactive device-level scam detection and personal data removal capabilities. The company assigns certified specialists to oversee each restoration case, ensuring continuity of support until resolution. It also provides eligible scam loss reimbursement beyond what many financial institutions offer and partners with established cybersecurity and family digital safety providers to strengthen its platform. Serving a significant share of Fortune 500 clients while remaining accessible as an employer benefit, it demonstrates both scale and adaptability. For organizations aiming to embed comprehensive identity and privacy protection within employee and customer ecosystems, it represents a disciplined and forward-looking choice. ...Read more
In an increasingly interconnected world, businesses face a growing number of cybersecurity threats that continue to evolve in complexity and scale. Traditional network defense systems, while effective to a certain extent, often struggle to keep pace with the sophisticated tactics employed by cybercriminals. In response to this, AI-powered firewall solutions are gaining traction as a cutting-edge method to enhance cybersecurity efforts. These intelligent systems leverage machine learning and artificial intelligence to detect, analyze, and mitigate threats in real-time. By automating threat detection and response, AI firewalls offer businesses a more dynamic, proactive approach to security, addressing some of the limitations inherent in traditional security frameworks. The Power of AI in Firewall Technology AI-driven firewalls set themselves apart from traditional ones by processing incoming network traffic through data analysis, predictive modeling, and advanced algorithms for decision-making. Traditional firewalls apply a set of rule-based patterns to detect malicious activity, often becoming unprotected against new, unknown threats. AI firewalls, in contrast, continuously learn from historical data and establish correlations between user behaviors and network traffic patterns that can be used to identify suspicious, anomalous activities, which could either be deviations from the norm. It gives AI firewalls the ability to detect zero-day attacks, previously unknown vulnerabilities, and emerging threats that otherwise might have escaped scrutiny. AI firewalls are enabled with real-time decision-making capabilities to counterattack potential threats immediately. Firewalls, based on the nature of the attack detected-whether it is a DDoS (Distributed Denial of Service) attack, a malware injection, or an unauthorized access attempt- attempt to adjust their set of precautions dynamically. These properties serve to make AI firewalls correct and fast in their decision-making, which leads to a minimization of incidences of false positives and negatives. Another key consideration in favor of AI firewalls is scalability. As an organization grows and the network becomes more complex, these firewalls can change and scale in response to the increased traffic, new endpoints, and added security roles. Meanwhile, the traditional firewall has a drawback of requiring manual updates to rules and configurations, which can become tedious and time-consuming as the actual network expands. The AI firewalls, on the other hand, are continually refining the rules and strategies through their own initiatives to ensure security is guaranteed as the organization matures. The Efficiency and Reduced Costs of Operations Aside from these advanced means of threat detection, operational efficiency is also where AI firewalls stand out. Traditional security measures require intensive human involvement to configure, monitor, and manage. Security teams need to update firewall rules regularly and check for potential incidents and possible unreported vulnerabilities, which exhaust human resources. AI firewalls reduce such work to a minimum because most are automated, therefore freeing up cybersecurity professionals to partake in high-level strategic work. Conversely, AI firewalls greatly minimize operational costs through less manual intervention. They can automatically perform routine tasks, including filtering traffic and ranking threats, thereby cutting down on labor costs and human fallibility. Businesses mitigate some of the effects of security compromises by applying automated responses to some attacks; otherwise, the repercussions would result in costly downtimes, reputational degradation, and legal accountability. AI firewalls greatly facilitate operational efficiency through the rapid identification and elimination of threats. This proactive approach to cybersecurity affords companies excellent network uptime and stability and, hence, productivity protection from operational interruptions. In the finance or healthcare industries, where data safeguarding is paramount, a proactive defensive mechanism guarantees compliance with regulations and protection for clients' sensitive information. Integrating AI Firewalls within Existing Security Infrastructure Integration of AI firewall solutions into the existing structure of an organization’s security infrastructure poses several challenges in terms of due diligence and feasibility. Such concern requires an extra look at how these AI systems will work in concert alongside traditional firewalls, intrusion detection systems, and other extant measures. Ideally, AI firewalls will complement already existing solutions by improving their capabilities instead of completely replacing them. One of the significant issues surrounding the implementation of AI firewalls is the assurance of seamless communication between different security components. A good integration will allow the business to reap the full benefits of AI firewalls' learning capabilities without interrupting other established protocols. Most organizations adopt partial implementations of the AI firewall, essentially starting from the network's most critical parts and then expanding outwards. For the successful deployment of AI firewalls, there must be a significant investment in further training of cybersecurity practitioners and experts. These will require the acquisition of skills in interpreting data provided by the AI, effective handling of alerts, and optimization of algorithm performance. This way, the company will be in a position to enjoy the full range of benefits afforded by such an advanced system. In the long run, with the advancement of AI technology, AI firewalls will be a linchpin in comprehensive strategies for safeguarding against cyber threats by proactively predicting threats, managing networks dynamically, and cutting overall costs. As a result, companies adopting an AI firewall into their security infrastructure will build a more resilient and responsive countermeasure for the protection of data and assets in an arduous digital arena. ...Read more
Cybersecurity leaders no longer evaluate multifactor authentication as a narrow login control. It now sits at the center of trust because the network perimeter has been replaced by cloud applications, remote access, mobile users and third-party services. Attackers have adapted. Rather than defeating infrastructure directly, they target the human identity layer through phishing, fake websites, credential reuse, session interception and social engineering. AI has sharpened deception, weakening legacy assumptions about passwords, one-time codes and user vigilance. Traditional MFA can reduce some exposure, but it often preserves the weakness it is meant to protect. A password remains in the path, a user still has to recognize a fraudulent prompt, a code may still be entered into a hostile session and the burden of correctness often sits with the individual. For executives, this is not just a security design problem. It becomes a cost, productivity and confidence problem. Help desks carry reset volume, employees navigate repeated prompts, customers abandon frustrating processes and fraud teams absorb losses when authentication stops at login but fails to control sensitive actions after access is granted. The stronger path removes static credentials from daily use rather than hiding them behind more steps. It should make trust mutual, so the service proves itself to the user before the user approves the session. It should also extend beyond login, because access to payroll, funds transfer, privileged systems or sensitive records requires authorization tied to the verified person, not just an earlier sign-in. Biometric confirmation, device trust, cryptographic validation and context-aware checks matter most when they reduce the chance that a stolen credential, copied website or compromised session can become real damage. Adoption depends just as much on usability. Security teams have spent years asking users to remember, rotate, reset and protect secrets while interpreting security cues under pressure. That model does not scale across banking customers, public-sector users, field employees, shared workstations, legacy applications and VPN access. The right approach should simplify the act of proving identity, accommodate users with different levels of digital confidence and integrate across environments that cannot all be rebuilt. Simplicity is not softness. It is the discipline of reducing unnecessary steps while preserving proof, control and auditability. Executives should also look for coverage that matches enterprise reality. A solution that works only for new cloud applications can leave exposed systems behind. One that requires broad redesign can slow adoption. One that replaces a single password burden with multiple disconnected authentication paths can dilute governance. The benchmark is a consistent identity experience across cloud, desktop, VPN, legacy, shared and constrained environments, backed by implementation support that lets security leaders test, train and expand without disrupting users. PasswordFree© emerges as the premier choice for organizations that want MFA to move from layered passwords toward true password elimination. Its differentiator is full duplex authentication, in which the service validates itself to the user before the user confirms identity through a matched image, short code and biometric approval. That design addresses phishing, imposter websites and one-way code entry. Its website scope reinforces the fit through passwordless authentication, Windows Hello extension and coverage across cloud, desktop, VPN, legacy, shared and airgapped systems. For buyers prioritizing trust, broad reach and user simplicity, PasswordFree© offers the clearest path forward. ...Read more