Home » Top stories » Cybersecurity Funding Gap Widens as AI Spend Soars
News Desk -

Share

New WEF research quantifies the cybersecurity funding gap. For enterprise buyers and investors, the numbers point to an emerging market opportunity.

By TECHx Media Staff – [August 4, 2026]

The cybersecurity funding gap is now measurable, and the scale is striking. According to a new analysis from the World Economic Forum’s Global Future Council on Cybersecurity, corporate AI investment hit roughly $580 billion in 2025. By contrast, cybersecurity philanthropy came in at an estimated $100–200 million in the same year. That is not a rounding error. It is closer to a statistical footnote.

In other words, cyber resilience funding amounts to a few hundredths of one percent of what flowed into AI. As a result, the infrastructure securing AI systems is drastically underfunded compared with the technology it protects.

The WEF council includes representatives from KnowBe4, UC Berkeley’s Center for Long-Term Cybersecurity, NYU Abu Dhabi, the Cyber Threat Alliance, and the Observer Research Foundation. The council frames this shortfall as a governance failure. Specifically, it proposes a “sustainable cybersecurity finance mechanism,” or SCFM, to direct more stable capital toward under-resourced regions and civil-sector defenders.

That framing makes sense coming from a policy body. However, for the enterprise technology sector, a different reading emerges. Rather than simply calling for more funding, the data suggests the world has not yet priced cybersecurity as an asset class. Consequently, that mispricing creates room for new market entrants.

The Mispricing Problem, Not Just the Funding Problem

Beyond the funding numbers, the WEF report highlights a classification issue. Most OECD and development-finance frameworks still classify cybersecurity as a “military/defence” cost rather than “civil resilience” infrastructure. Because of this, the council argues, the classification actively blocks capital. Pension funds, impact investors, and development finance institutions therefore avoid the sector, regardless of expected returns.

Fleur Heyns, CEO of Proof of Impact, addressed this dynamic directly in the WEF piece. According to Heyns, capital flows toward problems that demonstrate economic inevitability and material impact. Cyber resilience, she notes, must make that case in economic terms in order to attract funding.

In market terms, this represents a classification arbitrage that is hiding in plain sight. Typically, when a category of infrastructure spend is systematically excluded from major capital pools, the mispricing does not last. This exclusion often stems from a labeling quirk rather than poor risk-adjusted returns.

Cyber insurance underwent a similar shift roughly a decade ago. During that period, risk-modeling firms and reinsurers eventually developed the actuarial tools needed to price ransomware exposure, much like they would price a hurricane. Likewise, the WEF’s proposed “avoided-loss modelling” and “standardized resilience accounting” pillars call for the same shift at the infrastructure-funding level. This step is a prerequisite for unlocking institutional capital, not simply a side effect.

Where the Cybersecurity Funding Gap Is Actually Opening Up

Meanwhile, the regional data in the WEF report tells a sharper story. Government cyber grant programs are now moving hundreds of millions of dollars a year. These include the U.S. State and Local Cybersecurity Grants Program, the UK’s Integrated Security Fund, and the EU’s Digital Europe Programme. Despite this growth, almost none of this funding reaches emerging economies or least-developed countries.

This gap persists even though these markets face disproportionate exposure to AI-enabled cybercrime. At the same time, their capacity to respond remains limited.

Brazil stands out as an exception. Rather than waiting for a multilateral fund to close the gap, the country is actively building around it. Its Institutional Security Office, working alongside the Inter-American Development Bank and the National Bank for Economic and Social Development, has developed a subsidized-credit model for SME cyber resilience. This model combines financing with technical support, maturity assessments, and post-incident recovery. In addition, a youth-training arm called Hackers do Bem supports the effort.

This structure resembles a fintech-meets-cybersecurity model more than a traditional grant program. As a result, MSSPs, cyber-insurance startups, and embedded-finance vendors watching Latin America should study this model now, rather than after it scales.

The Takeaway for Enterprise Tech

The WEF council’s proposal targets philanthropic and multilateral funders. Still, the underlying diagnosis applies more broadly. Cyber resilience remains undercapitalized primarily because it is misclassified and unmeasured, not because the underlying risk is small.

Enterprise vendors, MSSPs, and investors can act on this thesis well before any global finance mechanism is built. Ultimately, whoever builds the credible “avoided-loss” and resilience-accounting models the WEF is calling for will not only support public-interest goals. They will also hand institutional capital the pricing tool it says it is missing, positioning themselves as the infrastructure layer the rest of the market prices off of. As the cybersecurity funding gap becomes harder to ignore, this window for early movers may not stay open for long.

Source: World Economic Forum, Global Future Council on Cybersecurity, “Why a sustainable finance mechanism for cybersecurity is key to securing the global economy,” August 3, 2026.