
How much does cybersecurity cost for a small business? Published market guides put managed security at $50 to $200 per user per month, per Harbour Technology Consulting's 2025 MSSP pricing guide, while Corsica Technologies' 2026 breakdown puts combined IT-plus-security plans at $125 to $200 per user. Where you land depends on headcount, industry, compliance, and what you already own.
For most small businesses, cybersecurity cost is not a one-time purchase; it is a monthly subscription that bundles tools and the people watching them, priced per user or per device. Understanding what sits inside that number is the difference between a fair quote and an expensive mystery.
How much does cybersecurity cost per user?
Because vendors rarely publish prices, the honest answer is a set of ranges from sources willing to name numbers:
- Managed security services: $50 to $200 per user per month, or $25 to $150 per device, per Harbour Technology Consulting's 2025 MSSP pricing guide.
- IT and security combined: $125 to $200 per user per month is what the average MSP charges, per Corsica Technologies' pricing guide (updated August 2026). The same guide says most businesses spend $5,000 to $20,000 per month in total; the top of that range reflects environments far bigger than a 10-person office.
- 24/7 managed detection and response (MDR): $10 to $30 per asset per month, per MDR provider UnderDefense's 2025 pricing page.
- Emergency incident response without a contract: $200 to $500 per hour, per the same 2025 Harbour Technology guide, which is the rate you pay when you skipped the other rows.
Security pricing sits on top of, or bundled into, standard managed IT rates. For the IT side of the equation, see our breakdown of managed IT services cost per user in 2026.
What drives the cost up or down?
- Headcount and devices. Per-user pricing scales linearly, and every laptop, server, and phone that touches company data widens the bill.
- Compliance obligations. HIPAA, CMMC, FTC Safeguards, and cyber insurance questionnaires all add required controls, evidence gathering, and reporting, which push you toward the top of the ranges.
- Industry risk. Healthcare, finance, and law firms hold data attackers pay a premium for, and their quotes reflect it.
- Your existing stack. Microsoft 365 Business Premium licenses already include identity and endpoint security features a good provider will configure rather than replace, trimming tooling costs.
- Coverage hours. Business-hours monitoring is cheaper than a 24/7 SOC, but attackers famously prefer Friday night.
- Current condition. Environments with no MFA, flat networks, and unpatched servers need remediation projects before steady-state pricing applies.
Which security layers should you pay for first?
If the full stack is out of reach this quarter, buy in this order: identity, endpoints, monitoring, then leadership. The table below shows the layers with published market rates where a named source exists.
| Security layer | What it buys you | Published market rate |
|---|---|---|
| MFA and identity hardening | Blocks most account-takeover attempts; the prerequisite for everything else | No separate tool cost in most Microsoft 365 plans; the expense is configuration labor, usually bundled |
| Endpoint detection and response (EDR) | Software that detects and isolates malware behavior on each machine | Microsoft Defender for Business lists at $3.00 per user/month, billed annually (Microsoft, 2026) |
| Managed detection and response (MDR) | Humans watching those endpoint alerts around the clock | $10-$30 per asset/month (UnderDefense, 2025) |
| Full managed security bundle | Monitoring, response, vulnerability management, compliance reporting | $50-$200 per user/month (Harbour Technology Consulting, 2025) |
| IT + security in one plan | Help desk and infrastructure plus the security stack, one accountable vendor | $125-$200 per user/month (Corsica Technologies, 2026) |
| vCISO / security leadership | Strategy, policies, audit and insurance readiness without a full-time hire | $3,000-$10,000+ per month retainer (Corsica Technologies, 2026) |
Backups and security awareness training belong on the list too; they are usually folded into per-user bundles rather than priced on their own, so ask any provider to itemize them.
What does a breach cost if you skip all this?
The comparison that matters is not this quote versus that quote; it is any quote versus an incident. IBM's 2026 Cost of a Data Breach report puts the global average breach at $4.99 million, a record high and a 12% jump in a year, with the United States average at $11.5 million. Those figures skew toward large companies, but the small-business numbers bite in their own way: ransomware appeared in 88% of breaches at small and mid-sized organizations, and the median ransom payment was $115,000, per Verizon's 2025 Data Breach Investigations Report.
Run the arithmetic against the table above. Twenty users at the very top of Harbour's managed-security range ($200 per user) is $48,000 a year, still well under half that median ransom before counting downtime, forensics, notification, and insurance consequences. The same Verizon report notes 64% of victims now refuse to pay, up from 50% two years earlier, but refusing is only realistic when tested backups and a response plan already exist.
How does bundled managed security pricing work?
Most small businesses buy security as part of a managed services bundle: one per-user monthly price covering the help desk, patching, backups, and the security stack (EDR, email filtering, MFA enforcement, monitoring, reporting). Bundles are usually the economical route, but only if you can see inside them. Ask for the itemized list of security layers, who provides the 24/7 monitoring, and what happens to licenses and log data if you leave.
Contract structure matters as much as the number. Multi-year lock-ins are common in this market; month-to-month pricing keeps the provider accountable every billing cycle. The NetSys Group publishes how its managed IT pricing is structured and keeps agreements month-to-month. And if you want evidence about your actual exposure before spending anything, its free on-site penetration test shows what an attacker would find first.
Frequently asked questions
How much should a 10-person business budget for cybersecurity?
Applying Harbour Technology Consulting's 2025 published range of $50 to $200 per user per month, a 10-person firm lands roughly between $500 and $2,000 monthly for managed security, sitting toward the top if it is regulated or handles payments. Get quotes itemized by layer so you can compare like with like.
Is cyber insurance a substitute for cybersecurity spending?
No. Insurance transfers part of the financial loss after an incident; it prevents nothing. Carriers now routinely require MFA, EDR, and tested backups before binding coverage, and claims can be reduced or denied when controls stated on the application were not actually in place. Treat the policy as the last layer, not the first.
What is the cheapest meaningful place to start?
Enforce MFA on email, banking, and remote access, which costs mostly effort. Then add endpoint detection: Microsoft Defender for Business lists at $3.00 per user per month billed annually, per Microsoft's 2026 pricing. Then verify you have backups that someone has actually restored from. Those three steps blunt the most common small-business attack paths.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



