The mid-2026 CISO survey shows that AI continues to drive cybersecurity demand, with budget growth flowing first to software, identity security, and SecOps.
AI summary card
The mid-2026 CISO survey shows that AI continues to drive cybersecurity demand, with budget growth flowing first to software, identity security, and SecOps.
Bernstein’s survey of 100 U.S. CISOs shows cybersecurity spending is expected to grow about 7% year over year in 2026, and 43% of respondents believe cybersecurity budgets will grow faster than overall IT budgets.
- Cybersecurity spending accounts for about 8% of 2026 IT budgets, with most respondent companies in the 3%-11% range.
- 62% of CISOs raised their full-year cybersecurity spending expectations, implying stronger demand may emerge in 2H26.
- Software/SaaS is the clearest budget winner, with 70% of respondents expecting spending growth over the next 12 months.
- Identity, cloud security, and endpoint security are the biggest beneficiaries within software spending, while SecOps improves at the margin due to GenAI-driven automation demand.
- CrowdStrike and Palo Alto remain perceived as cybersecurity vendor leaders by CISOs, while AWS and Microsoft have seen improved assessments of their security capabilities.
Report interpretation
Overview
This report is based on Bernstein’s semiannual CISO survey conducted in June 2026, with a sample of 100 U.S. respondents. The survey concludes that cybersecurity budgets remain resilient in 2026 and are clearly outpacing overall IT budgets, while rising risks related to GenAI and AI agents have increased the urgency for enterprises to upgrade security capabilities. Incremental budget allocation is skewed toward software, SaaS, identity security, cloud security, endpoint security, and SecOps, while growth is relatively limited in hardware, SSE, SIEM, Email Security, Secure Browser, and other mature areas or categories less directly tied to the AI narrative.
Core views
The core views are: first, cybersecurity budgets are expected to grow about 7% year over year in 2026, with 43% of CISOs believing cybersecurity budgets will grow faster than IT budgets, versus only 20% who believe IT budgets will grow faster. Second, AI is not crowding out cybersecurity budgets, but instead creating new security demand, especially in AI-enhanced attack defense, security operations automation, incident response, and AI agent governance. Third, software/SaaS remains the strongest investment area, with identity, cloud security, and endpoint security benefiting the most, while SecOps demand rises at the margin. Fourth, in the vendor landscape, CrowdStrike and Palo Alto continue to be viewed by CISOs as leaders, while the reputations of AWS and Microsoft security products have improved. Fifth, the trends toward platformization and vendor consolidation are clear, but the replacement of physical firewalls and cybersecurity appliances is still more a future expectation than a current reality.
Analysis framework
The report uses survey research and cross-sectional comparison, contrasting mid-2026 CISO feedback with the late-2025 survey results to analyze budget growth, share of IT budgets, industry differences, software/hardware spending by segment, changes in vendor perception, and the impact of GenAI on cybersecurity investment priorities.
Methodology notes
Sample of 100 U.S. CISOs
The report is based on feedback collected from 100 U.S. CISOs in June 2026 to assess cybersecurity budgets, spending mix, and vendor perceptions.
Cyber spend as % of IT
The intensity of enterprise security investment is measured by cybersecurity spending as a share of IT budgets; the report shows the 2026 average is about 8%.
Cybersecurity spending structure
The report compares expected spending changes over the next 12 months across software/SaaS, hardware, internal personnel costs, and outsourced/managed services to determine where incremental budgets are flowing.
CISO perceptions of the quality of vendors’ cybersecurity products
The report compares how CISOs rate product quality for vendors including CrowdStrike, Palo Alto, AWS, Microsoft, GCP, Oracle, SentinelOne, and CyberArk.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- CrowdStrike (CRWD.US)An endpoint security, XDR, and platformized cybersecurity vendor; listed in the report table as a covered name.
- Strengths
- Perceived by CISOs, alongside Palo Alto, as one of the most recognized cybersecurity leaders; endpoint security is still viewed as a critical foundational capability, and desktop-side AI agent security may support modernization demand.
- Weaknesses
- The survey shows planned incremental spending on endpoint security over the next year has declined from prior highs, with mature customers focusing more on renewals, consolidation, and platform optimization.
- Comparison
- Vendor reputation is meaningfully ahead of most cybersecurity peers, placing it in the top tier with Palo Alto, while AWS and Microsoft follow but still trail.
- Risks
- If endpoint security deployments among existing customers are already mature, incremental expansion may be weaker than vendor performance narratives suggest; CRWD is rated Market-Perform in the ratings table.
- Palo Alto Networks (PANW)A leading platformized cybersecurity company, highlighted in the report’s vendor perception discussion.
- Strengths
- CISOs rank its product quality in the top tier, and vendor consolidation and platformization trends support its multi-product portfolio.
- Weaknesses
- Migration from some hardware and traditional cybersecurity categories to software/virtualization still requires time, and physical cybersecurity appliance replacement is not yet a widespread current reality.
- Comparison
- Along with CrowdStrike, it sits in the top tier of CISO perception, above most pure-play software security vendors and hyperscaler security suites.
- Risks
- Platformization may improve pricing power, but it could also raise customer concerns about vendor concentration and acquisition integration friction.
- Zscaler (ZS)An SSE and zero-trust cloud security vendor discussed in the report’s investment implications.
- Strengths
- SSE remains a strategic direction in enterprise cloud-first and zero-trust architectures.
- Weaknesses
- In this survey, SSE is the weakest-growth cybersecurity software category, with fewer than 20% of respondents expecting spending growth.
- Comparison
- Compared with identity, cloud security, endpoint, and SecOps, SSE has a clearly lower near-term budget priority.
- Risks
- Maturing deployments among existing customers, feature convergence, and consolidation orientation may suppress incremental expansion; the AI security narrative has not yet clearly translated into CISO budget priority.
- Okta (OKTA)An identity security vendor affected by trends in AI agents and non-human identity governance.
- Strengths
- Identity security is one of the strongest software investment areas in the survey, and no CISOs expect spending in this category to decline.
- Weaknesses
- CISOs are only moderately convinced that GenAI will further increase identity security spending, possibly because identity is already an established high-priority area.
- Comparison
- Compared with endpoint and SSE, identity security benefits from both structural growth and new AI agent use cases.
- Risks
- If enterprises believe their existing identity architecture is sufficient to support human-in-the-loop AI workflows, near-term incremental spending may fall short of market narratives.
- SentinelOne (S)An endpoint security vendor discussed in the report in comparison with CrowdStrike.
- Strengths
- Endpoint security remains a mission-critical security domain, and AI agent endpoint protection may create modernization demand.
- Weaknesses
- Within the coverage discussed in the report, SentinelOne received the lowest CISO scores.
- Comparison
- Compared with CrowdStrike, it is at a clear disadvantage in brand and perceived product quality.
- Risks
- Slowing endpoint security spending growth, customer platform consolidation, and the brand advantage of category leaders may pressure its relative performance.
- AWS / Microsoft SecuritySecurity product suites from hyperscale cloud vendors.
- Strengths
- CISOs have improved their assessments of AWS and Microsoft security capabilities, placing them in the second tier behind CrowdStrike and Palo Alto.
- Weaknesses
- There remains a perception gap versus top-tier pure-play cybersecurity vendors.
- Comparison
- AWS improved meaningfully versus the late-2025 survey, while Microsoft similarly benefits from cloud security and platformization trends.
- Risks
- Improving hyperscaler security capabilities may intensify competitive pressure on independent cybersecurity software vendors.
Key data
- Survey sample100 U.S. CISOsSample for the semiannual survey conducted in June 2026.
- Cybersecurity spending as a share of IT budgetAbout 8%Average expectation for 2026, with most respondents in the 3%-11% range.
- 2026 cybersecurity budget growthAbout 7%Cybersecurity spending is expected to continue growing versus 2025.
- Cybersecurity budget growing faster than IT budget43%43% of CISOs expect cybersecurity budget growth to outpace overall IT budget growth; 20% expect IT budget growth to be faster.
- Raised full-year spending expectations62%62% of surveyed CISOs raised their full-year 2026 cybersecurity spending expectations, implying 2H demand may be stronger.
- Software/SaaS growth expectation over the next 12 months70%70% of respondents expect cybersecurity software/SaaS spending to grow, and almost none expect contraction.
- Cybersecurity appliance spending growth expectation58%Within hardware segments, cybersecurity appliances such as firewalls benefit the most.
- CRWD rating and target priceMarket-Perform; target price USD 103.00; current price USD 198.49The report states that this survey does not affect target prices or investment ratings.
Impact & implications
From an investment perspective, cybersecurity remains one of the few areas within IT budgets that is gaining share, while AI-related demand is reinforcing enterprise spending on security automation, identity governance, endpoint modernization, and cloud security. For listed companies, leaders with platform capabilities, strong brand reputation, and AI security narratives are more likely to capture incremental budgets; however, areas such as SSE, SIEM, Email Security, and Secure Browser need to prove their direct relevance to GenAI security demand, or they may face slower growth and a weakening valuation narrative.
Risks
- The survey sample includes 100 U.S. CISOs, and some industries such as Media, Communications, and Utilities have small sample sizes, so industry conclusions should be interpreted cautiously.
- GenAI-related security spending faces concerns around model hallucinations, accuracy, and false positives, which may lead customers to prefer mature vendors over startups.
- Mature categories such as endpoint security, SSE, and SIEM may face pressure from completed deployments, feature convergence, or declining budget priority.
- While vendor platformization and consolidation benefit leaders, they may also make customers more sensitive to vendor concentration, migration costs, and acquisition integration risks.
- Macro uncertainty may still affect total IT budgets, even though cybersecurity’s relative budget priority is rising.
What to watch
- Whether cybersecurity budgets in 2H26 deliver on the trend of being stronger than 1H26.
- Whether GenAI and AI agents continue to drive actual order growth in SecOps, identity security, endpoint security, and cloud security.
- Whether SSE, SIEM, Email Security, and Secure Browser vendors can convert the AI security narrative into budget priority.
- Whether the leading vendor perception of CrowdStrike and Palo Alto continues to translate into financial performance and platform expansion.
- Whether improving reputations of AWS and Microsoft security products create stronger competitive pressure on independent cybersecurity vendors.
- The pace of migration in cybersecurity hardware toward softwareization and virtualization, and whether physical firewall replacement shifts from expectation to reality.