Ask how much the iGaming industry spends on cybersecurity and you will not find a clean answer. No regulator, consultancy or trade body publishes a single figure that captures what operators, suppliers and affiliates collectively put into digital defence. What exists instead is a scattering of fraud statistics, general enterprise benchmarks and operator-level anecdotes, all pointing in the same direction without ever adding up to a total.
That gap matters for anyone trying to budget sensibly. Here is what the available data actually shows, and how to turn it into a working estimate rather than a guess.
Why there is no single industry figure
iGaming cybersecurity spending tends to sit buried inside broader IT, compliance and fraud-prevention budgets rather than being reported as its own line item. Operators rarely break out “security” spend separately in financial disclosures, and even where they do, definitions vary wildly between fraud losses, prevention tooling, compliance staffing and incident response.
The result is that most published figures describe either the threat (fraud rates, attack volumes) or the general enterprise security market (global totals across every sector), with nothing that isolates gambling and betting specifically.
The fraud pressure behind the budget conversation
The threat side of the picture is much clearer than the spending side. Industry survey data shows that 82.9 percent of operators experienced more fraud over the previous year, with a notable share of attacks clustering between four and eight in the morning, a window when compliance teams are typically less active. That timing pattern alone is pushing operators towards round-the-clock automated monitoring rather than office-hours fraud teams.
The attack surface has also grown sharply. Web-application attacks against the gaming sector rose by close to 94 percent between the first quarter of 2023 and the first quarter of 2024, a jump that reflects how many new entry points a modern operator now carries: payment gateways, affiliate integrations, game studio aggregation and third-party content feeds all add potential weak links.
Despite this, plenty of operators still treat cybersecurity as a line item to be minimised rather than a strategic budget category, an attitude that industry commentary suggests is becoming harder to justify as attack volumes climb.
What general enterprise benchmarks suggest
In the absence of iGaming-specific numbers, the closest useful proxy comes from enterprise security spending as a whole. Global end-user spending on information security is projected to reach 240 billion US dollars in 2026, up from 213 billion in 2025, a 12.5 percent year-on-year increase and a sharp acceleration from the roughly 4 percent growth seen the year before.
Within that spend, typical enterprise guidance calls for security to consume between 8 and 12 percent of total IT budget, rising to between 10 and 15 percent for organisations in high-threat sectors such as healthcare and financial services. iGaming is not one of the named benchmark categories, but the parallels are hard to ignore: real-money transactions, sensitive personal data, heavy regulatory reporting and a genuinely global, always-on attack surface.
That similarity is a reasonable basis for analysis, though it remains an inference rather than a confirmed figure. One plausible reading is that well-run iGaming operators sit somewhere in that 10 to 15 percent band of IT spend, given how closely their risk profile mirrors regulated financial services. A more cautious reader might place smaller or less mature operators lower, closer to the 8 percent baseline, particularly where compliance and fraud teams are still combined with general IT functions rather than run as a dedicated security function.
Longer-term market signals
Zooming out further, some forecasters expect global cybersecurity products and services spending to exceed 520 billion US dollars annually by 2026, on a trajectory toward 1 trillion dollars by 2031. Whether or not those exact totals land precisely on target, the direction is consistent across every source: spending is compounding, not levelling off, and gambling platforms are explicitly named among the digital systems driving that growth alongside IoT devices, industrial control systems and connected vehicles.
On the defensive side, artificial intelligence is increasingly framed as a double-edged tool in iGaming specifically. The same AI capability that powers real-time fraud detection and behavioural anomaly scoring is also expected to enable more convincing deepfake-driven identity fraud and automated intrusion attempts, which suggests security budgets may need to grow simply to keep pace with AI-enabled attackers rather than to get ahead of them.
Building a working estimate for your own budget
Given the lack of a definitive published number, the most useful approach for an operator or supplier is to build a working estimate rather than search for a benchmark that does not exist. A reasonable starting method looks like this:
- Take your total annual IT and technology budget as the base figure.
- Apply the 10 to 15 percent high-threat-sector range as a starting allocation for security specifically, adjusting downward if your fraud and compliance functions are less mature.
- Layer in the typical enterprise split of roughly 40 percent software and platforms, 30 percent personnel, 15 percent hardware and 15 percent outsourced services, then adjust for how much of your fraud monitoring is already outsourced to a payments or KYC provider.
- Revisit the allocation at least annually, given how quickly attack volumes and regulatory requirements are moving in this sector.
This will not produce a figure you can quote as an industry average, because no such average currently exists in reliable form. What it does produce is a defensible, board-ready number grounded in the closest comparable benchmarks available, framed honestly as an estimate rather than a fact.
The board-level framing that tends to work
How the conversation is framed internally appears to matter as much as the number itself. Security leaders who present spending in risk-reduction terms, rather than as a pure IT cost, tend to see budgets approved more readily and more generously. For an iGaming operator, that might mean tying a security budget request directly to fraud loss trends, licence conditions in key markets, or the cost and reputational fallout of a single serious breach, rather than presenting it as a generic technology line item.
Given how often gambling platforms are cited by name in the wider cybersecurity market’s threat models, alongside sectors like financial services and healthcare, that framing is increasingly hard for a board to dismiss.
The bottom line
There is no reliable single figure for iGaming cybersecurity spending, and any source claiming otherwise should be treated with caution. What exists instead is a strong, consistent set of proxies: rising fraud rates, a near-doubling of attack volumes in under two years, and enterprise security benchmarks that place high-threat sectors at 10 to 15 percent of IT budget. Combined thoughtfully, and reviewed regularly against your own fraud data, those proxies give operators a workable, defensible number even where the industry itself has not produced one.
For more coverage on how operators are responding to these pressures, including our recent report on the Kratos phishing kit takedown, keep exploring the cybersecurity section of the site. If you found this useful, sign up to our newsletter for the latest news, offers and announcements from across the iGaming industry.





