Budgets down, risk up

3 hours ago
2 min read
NIS2 was supposed to be fully in force across the EU by October 2024. Almost two years later, several member states are still finishing their national transposition, and 2026 is shaping up to be the year enforcement finally catches up with the law.
This makes it an odd time for so many organisations to be quietly pulling back on cybersecurity spend. It looks like an easy short-term saving, but it rarely is: budgets are shrinking just as attack surfaces grow, threats get more sophisticated, and regulators pay closer attention.

For boards, a breach or a compliance failure costs far more than whatever was saved on the budget line once you add remediation, fines and reputational damage, and under NIS2 that risk now lands on management personally, not only on the security team.
For security practitioners, the cuts rarely land where they should. Training, patch cycles and monitoring are usually first to go, and the risk that creates builds quietly in the background, unnoticed until it isn't.
For SMEs and suppliers, being too small to matter is no longer a safe assumption. NIS2 obligations are flowing down supply chains, and larger customers are increasingly asking for proof of a solid cyber posture before they'll keep doing business with you, so underinvesting here risks the contract, not just a fine.
None of this means spending more or less, it means spending deliberately. NIS2 is built around proportionality: your measures should match your risk, size and criticality, not a fixed number in a budget, and a scaled-back but genuinely risk-based posture can already meet that bar rather than just excuse falling short of it. In practice, that means:
Letting a real risk assessment decide what gets cut, not last year's budget line
Treating a documented, risk-based posture as something you can defend to a CFO, not a wish list
Building maturity in phases, hygiene first, then monitoring, then resilience
Keeping the cost of one incident or one lost contract visible next to whatever you think you're saving, because it usually outweighs it
If budget forces a trade-off anyway, write down why. The gap between "we ignored it" and "we made a documented, risk-based call" is enormous, and it's usually what regulators weigh most heavily when they calculate a penalty. A line in a risk register beats a memory of good intentions, and finding a gap yourself before a regulator does shapes how leniently that penalty lands, even though it doesn't make the underlying gap disappear. That protection also assumes the basics are covered, incidents get reported and audits get cooperated with, skip those and no amount of documentation will save you.
The distance between shrinking budgets and rising risk won't close on its own. It closes when spend gets smarter and every trade-off gets written down.
---------------------------------------------------------------------------------------------------------------



Comments