Getty Images/iStockphoto

Tip

AI budgeting: Estimating tokens for enterprise cybersecurity

AI tools are transforming cybersecurity, but token-based pricing can be a budgeting nightmare. Learn how CISOs can estimate costs, optimize usage and build realistic AI budgets.

As security tools like SIEM, SOAR, vulnerability scanning tools and agentic response systems become embedded with AI and LLMs, CISOs face a new and somewhat unfamiliar challenge: budgeting for highly variable, token-based costs.

Traditionally, security spending has been largely predictable -- buy a software tool or appliance, purchase a license or subscription, and hire qualified teams to run them. Token consumption, on the other hand, scales with the security tools' needs. Above-average data volume, alert spikes and incident complexity can significantly affect the number of tokens used on any given day.

This unpredictability puts CISOs in a difficult position. They want to harness the power of AI to improve triage, conduct deeper investigations and strengthen defenses, but they must also keep a close eye on governance. For many, AI budgeting remains a guessing game. There are, however, some core concepts, estimation techniques, optimization strategies and governance practices CISOs can use to manage AI token costs more effectively.

Tokens and AI cost models

Many security tools using AI rely on the concept of tokens. A token's data value roughly equates to four characters in the English language. Models consume and track both input and output tokens. Prompts and automations use input tokens, while the generated output or actions generate output tokens. It's important to note that output tokens generated by AI often cost three to five times more than input tokens.

Most security AI features sold today rely on pay-per-token methods through cloud APIs, but some cost models are subscription-based with overage charges or committed spend agreements. Regardless of the token method used, security use cases -- including alert triage, incident investigation, vulnerability analysis and security-focused agentic workflows -- can create token usage spikes, making it essential to truly understand token demand for budgeting purposes.

Managing AI token use

Estimating token use, modeling costs and putting the right guardrails in place are practical steps to eliminate budget risk for any security team.

Estimating token usage

Many AI security companies offer built-in tools to measure typical prompts, alerts and logs, helping customers forecast how many input and output tokens specific workflows will consume. Security vendors also commonly offer prospective customers pilot programs that enable them to run security-focused AI in a portion of their environments and to predict token consumption.

Modeling costs

With an estimate of token usage in hand, the next step is to convert token counts into dollars. Taking estimated averages, including baseline and peak usage, CISOs can get a realistic estimate under normal conditions. Including a buffer in modeling costs can prevent inadvertent depletion of token budgets at the end of the fiscal year. Moving forward, teams should conduct modeling cost estimates at least once or twice a year, using actual consumption data to further refine estimates.

Optimizations and guardrails

Implementing AI in security tools for the first time rarely includes optimization plans or guardrails to protect against unforeseen spikes in token use. Once a tool is in place, however, CISOs should establish processes to reduce token overconsumption. For example:

  • Ensure prompts are short and well-structured.
  • Categorize tasks and route them to lower-cost models.
  • Enable AI route caching for repeated processes.
  • Create guardrails around maximum output lengths.
  • Standardize high-volume use cases to eliminate repetitive use of AI.
  • Set per-user, per-team and per-workflow usage quotas.
  • Monitor and track cost-per-alert and cost-per-incident data.

By combining realistic estimates, cost modeling and ongoing optimizations with guardrails, CISOs can appropriately budget for AI use and limit the risk of unexpected overruns.

Best practices for building an AI budget

Once estimates and controls are in place, the focus shifts to building a realistic budget. Follow these four practices:

  1. Involve the finance team early in the budgeting process so it understands the variability and usage-based behavior of AI token costs.
  2. Build a budget by calculating both baseline and peak scenarios.
  3. Review and refine budget numbers regularly.
  4. Tie the budget to measurable security outcomes and KPIs to prove value and ROI.

Following these steps helps convert usage data into a meaningful and defensible budgeting plan.

Practical tools for token visibility

In addition to the token estimation tools provided by AI and LLM providers, larger enterprises can deploy one or more AI gateways. These are software-based tools that sit between the security platform and LLM. All AI traffic is routed through the gateways, helping security teams to enforce model routing, enable caching and quotas, and maintain a centralized set of logs. For easy auditing and chargebacks, CISOs can also deploy observability platforms to attribute token spend to specific security tools, workloads or teams.

For many in the security world, AI is quickly becoming table stakes within the enterprise security stack. The organizations that get the most value from it will be those that treat token management as an ongoing operational discipline rather than an afterthought. The goal is to use AI to its fullest potential while proving clear value for every dollar spent.

Andrew Froehlich is founder of InfraMomentum, an enterprise IT research and analyst firm, and president of West Gate Networks, an IT consulting company. He has been involved in enterprise IT for more than 20 years.

Next Steps

Future of security holds bigger budgets, new threats

Data spending: Up and to the right

Dig Deeper on CISO Strategy & Planning