Cybersecurity rarely loses a council budget debate on merit. It loses because it never gets a clear line item, because the spend is framed as a technical cost rather than a service-continuity issue, and because no one has translated the risk into language councillors and ratepayers understand. The result is predictable: underfunded controls, ageing systems and a recovery bill that dwarfs what prevention would have cost.
This guide sets out a practical way to budget for cybersecurity in an Australian council, from sizing the spend to building a business case that survives the estimates process. It is written for finance managers, ICT coordinators and general managers, not just specialists.
Start with risk, not a benchmark
The most common budgeting mistake is starting with a number. Someone reads that organisations should spend a certain percentage of their ICT budget on security, applies it, and calls the job done. Benchmarks are useful for sanity-checking, but they cannot tell you what your council actually needs.
Instead, start with a documented risk assessment. Identify the systems that matter most: rates and revenue, payroll, planning and development applications, records management, and any operational technology such as water, waste or traffic systems. For each, ask what the impact would be if it were unavailable for a week, or if the data were leaked. That impact, expressed in dollars and in service terms, is what justifies the spend.
Once you understand the risk, a reference range becomes useful as a check. Many councils land somewhere between 8 and 15 per cent of total ICT spend on security once monitoring, licensing, staff time and uplift projects are counted. If your number is far below that, it usually means costs are hidden inside other lines rather than that you are efficient.
Separate recurrent costs from capital projects
Security spending falls into two very different buckets, and conflating them causes problems at budget time.
- Recurrent operating costs are the things you pay for every year: endpoint protection, email filtering, multi-factor authentication licences, backup storage, log monitoring, security awareness training, and any managed detection service or external advisory retainer. These should never be funded from one-off grants because they do not go away.
- Capital and project costs are one-off uplifts: replacing end-of-life firewalls, segmenting the network, deploying a new identity platform, or running a penetration test and remediation program. These are well suited to grant funding or a multi-year capital plan.
Splitting the two in your budget papers makes the recurrent commitment honest and stops a council from celebrating a grant-funded project while quietly defunding the operating costs that keep it working.
Fund the high-impact basics first
If the budget is tight, sequence matters. The controls that block the largest share of common attacks are also among the cheapest. Multi-factor authentication, disciplined patching of operating systems and applications, and regularly tested backups will stop or contain most opportunistic intrusions. These map directly to the Essential Eight, the Australian Signals Directorate’s baseline that most state government frameworks now expect councils to work towards.
Our plain-English Essential Eight guide walks through each control and what implementation actually involves. Use the maturity model in that framework to stage your spending: get every control to Maturity Level One before pouring money into advanced tooling. An expensive detection platform sitting on top of unpatched servers and shared admin passwords is wasted money.
Account for the costs people forget
Budgets blow out when hidden costs surface mid-year. Build these in from the start:
- Staff time. Patching, log review and access management are ongoing labour, not a one-off install.
- Cyber insurance. Premiums have risen sharply and insurers now demand evidence of controls before they will quote. Underfunding security can directly increase your premium or make cover unavailable.
- Incident response readiness. A retainer with an incident response provider, or at least a documented and tested plan, costs far less than scrambling for help mid-breach.
- Training and awareness. The cheapest control of all, and the one most often cut first.
- Third-party and supply-chain risk. Your vendors hold your data. Reviewing their security is part of the job, and our cyber due diligence approach covers how.
Map the spend to a multi-year plan
Cybersecurity uplift rarely fits inside a single budget year, and trying to cram it into one creates two problems: a spike that councillors resist, and an unrealistic delivery timeline that sets the program up to fail. A three-year view smooths both. Lay out the uplift projects across financial years, sequenced by risk, with the recurrent operating costs running underneath as a steady baseline that grows only as new systems come online.
A simple structure works well. Year one funds the high-impact basics and closes the most dangerous gaps: multi-factor authentication, patching discipline, backup isolation and the most urgent end-of-life replacements. Year two builds visibility and response: centralised logging, monitoring, an incident response retainer and staff capability. Year three matures the program: independent testing, network segmentation and advanced controls. This sequencing means each year’s spend builds on the last rather than scattering money across disconnected purchases, and it gives councillors a clear narrative of steady, deliberate progress.
Crucially, the multi-year plan should be revisited every budget cycle rather than locked in. A new threat, a failed audit or an insurer’s demand can reorder priorities, and the plan must be flexible enough to absorb that without abandoning the overall direction.
Build a business case councillors will back
The technical detail that convinces an ICT team will glaze over an elected council. Translate the request into service-continuity and ratepayer terms. A strong one-page case usually contains four things: the specific risk in plain language, the dollar and service impact if it eventuates, the proposed spend, and the residual risk that remains after spending it.
For example, rather than asking for funds to deploy a logging platform, explain that the council currently cannot tell whether an attacker has been inside its systems, that a ransomware event could halt rates and payroll for a week or more, and that the proposed spend would detect intrusions early and shorten any outage. Councillors can weigh service impact against cost; they cannot weigh acronyms.
It also helps to tie the request to obligations councils already accept. Many sit under state policies such as the NSW Cyber Security Policy, and demonstrating progress against a recognised framework reframes the spend as compliance rather than discretionary.
Anticipate the objections, too. The most common is “we’ve never been attacked, so why now?” The honest answer is that most councils have been probed and many have been breached without realising it, that absence of a known incident is not evidence of safety, and that the cost curve runs the wrong way: every dollar not spent on prevention tends to return as several dollars of recovery, insurance loading and reputational damage. A second objection is that security is “the IT department’s job and budget.” Reframe it as an enterprise risk that touches rates revenue, payroll, statutory record-keeping and resident services, none of which sit inside IT alone.
Watch for the budget traps councils fall into
A few patterns reliably undermine council cybersecurity budgets, and naming them helps avoid them:
- Funding tools but not the people to run them. A monitoring platform with no one assigned to review alerts is shelfware. Budget the labour alongside the licence.
- Treating training as optional. It is the lowest-cost, highest-return control, yet it is usually first on the chopping block. Protect it.
- Relying on grants for recurrent costs. When the grant ends, the capability collapses. Grants fund projects, not the lights staying on.
- Skipping the maturity baseline. Without knowing where you stand, spending becomes guesswork driven by whichever vendor called most recently.
- Ignoring decommissioning. Old systems left running because no one budgeted to retire them are a favourite attacker entry point.
Consider shared and outsourced models
Small councils rarely have the volume to justify a full-time security team, and the talent market makes hiring one difficult and expensive. Two models help. Neighbouring councils can pool resources through a shared-service arrangement, splitting the cost of monitoring or a security manager. Alternatively, a virtual CISO provides senior security leadership on a fractional basis, giving a council strategic direction, governance and incident oversight for a fraction of a full-time salary.
We cover the economics of this in detail in our guide on cybersecurity for Australian councils. For many smaller councils, a part-time expert plus a few well-chosen managed services delivers more real protection per dollar than an underqualified full-time hire.
Review the budget every year against actual risk
A cybersecurity budget is not set and forget. The threat landscape shifts, systems age, and last year’s uplift becomes this year’s baseline cost. Each budget cycle, revisit the risk assessment, check progress against your chosen framework, and adjust. Track spending against the separate security line so you can show councillors a clear story over time.
CISO Advisory Australia helps councils size their cybersecurity budget, build the business case and stage controls sensibly against the Essential Eight and state policy requirements. If you would like a plain-language review before your next estimates round, call 07 2112 8502 or get in touch through our contact page.
Frequently asked questions
How much should a council spend on cybersecurity?
There is no fixed percentage that fits every council. A common starting reference is 8 to 15 per cent of the total ICT budget, but the right figure depends on your risk profile, the data you hold and your current maturity. Base the number on a documented risk assessment, not a benchmark.
Should cybersecurity be a separate budget line?
Yes. Burying security inside general ICT makes it invisible and easy to cut. A distinct line item, ideally split between recurrent operating costs and one-off capital projects, gives councillors visibility and makes year-on-year tracking possible. It also strengthens any future grant or insurance application.
Can small councils access cybersecurity grants?
Sometimes. State governments and federal programs periodically offer co-funded uplift grants, and some peak bodies coordinate shared-service arrangements. Grants are usually one-off and project-based, so never rely on them for recurrent costs like monitoring, licensing or staff. Treat grant funding as a bonus, not a baseline.
What is the cheapest high-impact thing to fund first?
Multi-factor authentication, regular patching and tested backups. These three controls block the majority of common attacks and cost far less than incident recovery. They map directly to the Essential Eight and are the foundation any auditor or insurer will expect to see before anything more advanced.
How do I justify the spend to councillors?
Frame it in terms of service continuity and ratepayer impact, not technical jargon. Quantify what a week of downtime to rates, payroll or planning systems would cost, and compare that to the annual control spend. A short, plain-language risk briefing usually lands better than a controls checklist.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.