
When business slows down, cybersecurity budgets often come under pressure.
Revenue falls. Hiring freezes appear. Projects are delayed. Technology spending gets reviewed line by line. Security teams are then asked to do more with fewer people, fewer tools and less time.
That creates a dangerous situation.
Cybercriminals do not go into recession when businesses do. In fact, financial pressure can make a company more attractive to attackers. A distracted finance team, an understaffed IT department and postponed security upgrades can open doors that were previously harder to reach.
The result is a simple business problem: cutting cybersecurity costs during a recession can create much larger costs later.
Why Recessions Can Weaken Cybersecurity
Cybersecurity is often treated as an operating expense rather than a direct revenue generator. When executives are searching for savings, security projects can therefore face uncomfortable questions.
- Does that new security platform really need to be purchased now?
- Can security staff be reduced?
- Can an upgrade wait until next year?
- Can an existing system be stretched a little further?
Some of these decisions may be reasonable. The trouble starts when cost reduction becomes indiscriminate.
ENISA’s 2025 research shows that organisations are already taking cost-cutting measures affecting cybersecurity staffing. Across surveyed EU organisations, 16% reported hiring freezes for cybersecurity roles, while 13% reduced cybersecurity recruitment budgets and 11% reported layoffs affecting cybersecurity positions.
A smaller security team does not simply mean fewer people in meetings. It can mean slower patching, weaker monitoring, delayed incident response and less time for security testing.
During an economic downturn, those gaps can quietly widen.
Cybercriminals Still See Opportunity
A recession does not make cyber threats disappear. It can change the conditions in which attacks succeed.
Employees may be under greater financial or professional pressure. Temporary workers may replace experienced staff. Contractors may receive broader access to systems. IT teams may postpone maintenance. Security professionals may leave organisations facing budget restrictions.
Each change adds another potential weakness.
Ransomware remains a particularly serious concern. Verizon’s 2026 Data Breach Investigations Report says ransomware was involved in 48% of analysed breaches, while software vulnerabilities had become the leading initial access route, accounting for 31% of breaches.
That matters during a downturn because vulnerability management is rarely a one-off task. Systems need to be monitored, patched and tested continuously.
A delayed security update can look harmless on a spreadsheet.
An exploited vulnerability looks very different at 2 a.m. when business systems are unavailable.
Security Staff Cuts Can Create Hidden Risk
Cybersecurity depends heavily on people.
Security software can detect suspicious activity, but someone still needs to investigate alerts, review logs, manage access controls, test backups and respond when something goes wrong.
Reducing headcount can therefore create a workload problem before it creates an obvious security problem.
ENISA’s 2025 NIS Investments research found that 71% of surveyed organisations viewed difficulties hiring cybersecurity professionals as a factor increasing their exposure to cyberattacks. The same research points to overstretched teams and limited training as contributors to turnover.
This creates a nasty cycle.
Fewer employees produce heavier workloads. Heavy workloads increase burnout. Experienced staff leave. Remaining employees inherit even more responsibility.
Eventually, routine security work starts slipping through the cracks.
Small Businesses Face an Even Tougher Problem
Large enterprises may be able to absorb a temporary reduction in security spending. Smaller companies have less room for manoeuvre.
Many small businesses operate without dedicated security staff. IT responsibilities may sit with one person or a small external provider. A serious incident can therefore overwhelm normal operations very quickly.
ENISA notes that SMEs commonly face challenges involving ransomware, phishing, stolen devices and CEO fraud. Its research has also found that many surveyed SMEs considered a serious cybersecurity incident capable of causing severe business consequences within a short period.
For a small business, the question is not simply whether customer data could be stolen.
- Could payroll continue?
- Could orders be processed?
- Could customer records be accessed?
- Could suppliers still be paid?
- Could the company operate for a week without its core systems?
Those questions turn cybersecurity from an IT issue into a business continuity issue.
Cutting the Wrong Security Costs Can Backfire
Not every cybersecurity expense deserves protection from budget reviews.
Some tools overlap. Some subscriptions may deliver little value. Some projects may be poorly aligned with actual business risks.
Cost control can be useful when it is based on risk rather than guesswork.
The priority should be protecting the systems and information that would cause the greatest damage if compromised.
During a recession, organisations should generally protect funding for:
- Security patching and vulnerability management
- Multi-factor authentication
- Endpoint and email protection
- Backup and recovery systems
- Identity and access management
- Security monitoring
- Incident response planning
- Employee security awareness
- Critical software and infrastructure updates
The goal is not to spend endlessly. It is to avoid false economies.
Cybersecurity Budgets Need Better Priorities, Not Blind Growth
More spending does not automatically produce better security.
A company can purchase expensive security products while leaving basic weaknesses unresolved. McKinsey has previously highlighted that higher cybersecurity spending alone does not guarantee stronger security outcomes; organisations also need to direct resources toward the risks that matter most.
That principle becomes especially useful during a recession.
Security leaders should identify the company’s most important assets, map the major threats against them and remove obvious weaknesses first.
For example, improving identity controls may be more useful than buying another dashboard. Reliable offline backups may matter more than adding another detection product. Closing exposed vulnerabilities may deliver more protection than funding a large security transformation project.
The best defence is not always the biggest one. It is the one aimed at the right problems.
Recession Planning Should Include Cyber Risk
Financial planning and cybersecurity planning should not operate in separate rooms.
A recession plan should account for what happens if a critical supplier is attacked, a cloud service becomes unavailable, an employee account is compromised or ransomware locks important systems.
Security teams should also test what happens after staff reductions.
- Who responds to an incident if the security manager is unavailable?
- Who has administrative access?
- Who contacts customers?
- Who speaks with legal advisers and regulators?
- Where are the backups?
- How quickly can systems be restored?
These questions are uncomfortable, but discovering the answers during an attack is far worse.
Cyber Defence Is Not a Good Place for Blind Cuts
A recession forces difficult business decisions. Cybersecurity spending cannot be immune from financial scrutiny, but treating security as an easy place to make across-the-board cuts can create a much bigger liability.
The threat does not pause because budgets are tight.
Attackers continue looking for exposed systems, weak passwords, unpatched software and overworked employees. Meanwhile, regulatory expectations and supply-chain risks continue to put pressure on businesses.
The smarter approach is selective spending.
Remove waste. Consolidate overlapping tools. Automate repetitive work where sensible. Prioritise critical systems. Keep essential security staff. Maintain tested backups and incident response plans.
In a downturn, resilience matters more, not less.
A business may survive slower sales for a quarter. Recovering from a major breach, prolonged ransomware incident or serious data loss is a different proposition entirely.
Also Read:
