Written by: Jakub Pietroszek, Partnership Manager, Digital Colliers
Okta closed the week up more than 20% and CrowdStrike up more than 15%, both on earnings that pointed at the same thing: AI is driving attack volume, and buyers are paying for the defense. That is a public price signal. If you run security or finance at a mid-market bank, it is also a warning. The market repriced cyber risk in a single earnings cycle. Your budget process runs once a year.
What the earnings actually said
Both vendors called out AI-generated phishing, credential stuffing, and identity attacks as growth drivers. Not because the attacks are novel, but because the unit economics of running them collapsed. An attacker with a decent model can generate thousands of tailored lures for the cost of a coffee. That means volume goes up, quality goes up, and the marginal cost of hitting your call center or your commercial banking portal trends toward zero.
The security vendors are pricing that reality in. Their customers are paying it. If your renewal is nine months out and priced against last year's threat model, you are already behind on the math.
The pass-through nobody put in the budget
Here is the chain the market just repriced:
- AI drops the cost of attack generation.
- Attack volume and personalization go up.
- Identity and endpoint vendors see demand spike.
- Vendors raise prices, tighten SKUs, and push AI add-ons.
- Your renewal quote lands 20 to 40% higher than you modeled.
At the same time, the defensive side is not keeping up on patching. Only about 3 to 5% of publicly disclosed vulnerabilities get patched within 30 days across the industry. So the exposed surface grows, the vendors charge more to defend it, and the internal remediation clock does not move. That gap is the cost of inaction, and it compounds every quarter you do not reprice.
Why annual budgeting breaks in this environment
Mid-market banks tend to lock cyber spend in a Q4 planning cycle, freeze it in January, and revisit in the next Q4. That worked when threat economics moved on multi-year cycles. It does not work now.
A few things break at once:
- Vendor pricing moves faster than your PO cycle. You negotiate against a stale baseline.
- New regulatory load lands mid-year. DORA has been in force across the EU since 17 January 2025, and it pulled ICT third-party risk, incident reporting, and resilience testing into scope for in-scope financial entities. That is not a line item you defer.
- Incident cost is asymmetric. A single GDPR-relevant breach can run up to €20M or 4% of global turnover. No annual budget line survives that.
- Internal close cycles hide the drift. If your finance team is closing in 8 to 10 days on spreadsheets, you are not seeing cyber run-rate changes until the quarter is already over.
A quarterly cyber-cost data model
The operators I see handling this well are not buying more tools. They are rebuilding the data model that feeds the budget. The shape looks something like this:
- A live vendor cost table. Every security SKU, unit price, renewal date, and AI add-on tier. Refreshed monthly, not annually.
- A threat-volume feed. Blocked auth attempts, phishing click rates, EDR detections. Trended weekly. This is the signal that tells you the attacker side is repricing.
- A patch-latency metric. Mean time to patch on internet-facing assets. Compared against the industry 3 to 5% within 30 days baseline so you know if you are ahead or behind.
- A regulatory clock. DORA obligations, incident reporting windows, third-party attestations. Tied to specific owners with specific dates.
- A quarterly reforecast. One page. Actual vendor spend, projected renewal deltas, exposure change, and a recommended budget move.
None of this is exotic. Most of the data already exists inside your SIEM, your procurement system, and your GRC tool. The work is joining it and putting it in front of the CFO on a 90-day cadence instead of a 365-day one.
The market told you this week that cyber is a quarterly variable. Treat it like one, or pay the pass-through with no offsetting move on your side.

