How to Budget for Cybersecurity as a Small Business
A UK small business should allocate 5–15% of its overall IT budget to cybersecurity, or roughly £200–£1,500 per month depending on size and risk profile. The right approach is risk-based: invest proportionally to the value of what you are protecting.
Quick answer
A UK small business (10–50 staff) typically spends £400–£1,200 per month on cyber security — roughly £15–£25 per user per month for managed endpoint protection, email security, and monitoring. As a rule of thumb, allocate 5–15% of your total IT budget to security, weighted by the value of what you are protecting. AMVIA delivers all of it under one accountable, security-first provider.
Building a Practical Security Budget
A framework for allocating cybersecurity spend as a small business.
Start with Risk Assessment
Identify your most valuable data and systems. Your security budget should protect the assets whose loss would cause the most damage.
Prioritise by Impact
Fund the controls that reduce the most risk first: MFA, email security, endpoint protection, backups. These cover the majority of attack vectors.
Factor in Compliance
If your industry requires ISO 27001, or sector-specific compliance, budget for the controls and audit costs those frameworks demand.
Plan for Growth
Choose per-user pricing models that scale with your business. Avoid large upfront capital expenditure on security hardware that may become obsolete.
Security Budget by Business Size
Typical monthly cybersecurity spend for UK SMEs.
| Feature | Micro (1–10)£100–£300/mo | Small (10–50)£300–£1,200/mo | Medium (50–250)£1,200–£5,000/mo |
|---|---|---|---|
| Endpoint protection | |||
| Email security | |||
| MFA | |||
| 24/7 monitoring | Optional | Recommended | |
| Incident response retainer | Optional | ||
| Vulnerability management | |||
| Compliance support | CE only | CE/security certification | security certification/ISO 27001 |
Budget ranges are indicative. Actual costs depend on industry, risk profile, and compliance requirements.
That is the short answer. The longer answer matters, because a cyber security budget set badly either wastes money on tools nobody watches or leaves the controls that actually stop attacks underfunded. This guide explains how to size your budget, where to spend first, and how to justify it to the people who sign it off. For a deeper breakdown of managed pricing, read our managed cybersecurity cost guide, and see the full managed cybersecurity pillar for the services these budgets buy.
How much should a small business spend on cyber security?
Most UK SMEs land between £200 and £1,500 per month (typical UK 2026 range), depending on headcount, sector, and risk profile. A 10-person firm with low-sensitivity data sits near the bottom; a 50-person professional-services business handling client money or health data sits near the top. The honest answer is risk-based: spend in proportion to what a breach would cost you.
That context is not abstract. According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a breach or attack in the past year (Cyber Security Breaches Survey 2025), and the average cost of the most disruptive breach was £3,550 (Cyber Security Breaches Survey 2025). Underspending is rarely a saving — it is deferred cost with interest.
A useful comparison: a single in-house security hire costs £40,000–£55,000 per year in salary alone (market rates as of 2026), before tooling, training, holiday cover, or out-of-hours response. Managed security spreads that capability across many clients, which is why per-user pricing usually wins for businesses under 250 staff.
| Business size | Typical monthly spend (UK, 2026) | What it usually covers |
|---|---|---|
| Micro (1–10) | £100–£300/mo | Endpoint protection, email security, MFA |
| Small (10–50) | £300–£1,200/mo | The above + 24/7 monitoring, vulnerability management |
| Medium (50–250) | £1,200–£5,000/mo | The above + incident response retainer, compliance support |
Budget ranges are indicative. Actual cost depends on industry, risk profile, and compliance requirements.
How do you build a practical security budget?
Build it in four moves: assess risk, prioritise by impact, factor in compliance, and choose pricing that scales. Skip the assessment and you will buy tools that protect the wrong things. The goal is not "maximum security" — it is the most risk reduced per pound, in the order that reduces it fastest.
Start with a risk assessment. Identify the data and systems whose loss would hurt most — customer records, financial systems, intellectual property, the email accounts that authorise payments. Your budget protects those first. The NCSC's Small Business Guide is a free, practical starting point for working out where you are exposed.
Prioritise by impact. Fund the controls that close the most common attack routes before anything exotic: multi-factor authentication, email security, endpoint protection, and reliable backups. These cover the overwhelming majority of how SMEs actually get breached. Start with MFA across Microsoft 365 and managed email security — they stop the phishing and credential attacks that drive most incidents.
Factor in compliance. If you bid for enterprise or public-sector work, or operate in a regulated sector, budget for the certifications those contracts demand. Cyber Essentials Plus is the baseline most UK buyers now expect; some larger frameworks reference ISO 27001. AMVIA holds Cyber Essentials Plus, which means we run our own estate to the standard we help you meet.
Plan for growth. Choose per-user pricing that scales as you hire, and avoid large upfront capital spend on security hardware that dates quickly. Cloud-delivered controls flex with headcount and keep your budget predictable.
Where should the first £500 a month go?
If you only have a modest monthly budget, spend it on the controls with the highest stop rate per pound: MFA, managed email security, and managed endpoint detection. These three block the entry points behind most SME breaches and cost far less than recovering from one. Monitoring comes next, so a real human sees the alert that matters.
In practical order of priority:
- Multi-factor authentication on every account — the single highest-leverage control, and effectively free with Microsoft 365.
- Managed email security — email security filtering using the Microsoft Defender and Barracuda stack to stop phishing and business email compromise.
- Managed endpoint protection — endpoint security built on Microsoft Defender for Endpoint, so a compromised laptop is contained, not catastrophic.
- 24/7 monitoring — round-the-clock monitoring from AMVIA's in-house SOC, because attacks do not keep office hours.
- Tested backups — the control that turns a ransomware crisis into an inconvenience.
Only once those are funded does it make sense to add vulnerability management, an incident-response retainer, and formal compliance work. Buying a SIEM before you have MFA is buying a smoke alarm for a house with the front door open.
How do you justify cyber security spend to the board?
Frame it as risk reduction, not a cost centre. Put the budget next to the exposure it removes: the cost of a disruptive breach, the regulatory fines a data loss would trigger, the cyber-insurance premium it lowers, and the contracts a certification enables. Boards fund quantified risk far more readily than they fund "security".
Two numbers do most of the work. First, the average most-disruptive breach costs £3,550 (Cyber Security Breaches Survey 2025) — and that rises sharply once data loss, downtime, and ICO involvement enter the picture. Second, only 14% of UK businesses review the cyber risks posed by their immediate suppliers (Cyber Security Breaches Survey 2025), which means demonstrable security is increasingly a competitive advantage in tenders, not just a defence.
Present three things and most boards say yes: the financial exposure the budget mitigates, the insurance and contract upside it creates, and the named provider accountable for delivering it.
Frequently Asked Questions
Industry guidance suggests 5–15% of total IT spend, though the right figure depends on your risk profile and the data you hold. Regulated firms and those handling sensitive client information should budget towards the higher end. With 43% of UK businesses hit by a breach or attack last year (Cyber Security Breaches Survey 2025), underspending is usually a false economy.
For a managed bundle of endpoint protection, email security, and monitoring, UK SMEs typically pay £15–£25 per user per month. Per-user pricing scales cleanly as you hire and avoids large upfront hardware costs. Exact pricing depends on the controls included and your compliance requirements — our managed cybersecurity cost guide breaks it down.
For most businesses under 250 staff, yes. A single in-house security analyst costs £40,000–£55,000 per year in salary alone, plus tooling, training, and holiday and out-of-hours cover. Managed security spreads a 24/7 team and enterprise tooling across many clients, so you get round-the-clock coverage for a fraction of one full-time salary.
Cyber security spend is an allowable business expense for corporation tax. Some local enterprise partnerships and industry bodies run funded cyber-readiness programmes for SMEs, and the NCSC publishes free guidance and tools. Achieving Cyber Essentials is low-cost and can be a contractual requirement for public-sector work.
Fund MFA, managed email security, managed endpoint protection, and tested backups before anything else. These four close the entry points behind most SME breaches and cost far less than recovering from one incident. Add 24/7 monitoring next so alerts reach a human, then layer on vulnerability management and compliance support as budget allows.
Review it at least annually, and whenever you change headcount, win a contract with new security obligations, or adopt new systems. Threats and business risk both move, so a budget set once and forgotten drifts out of line with your actual exposure within a year.
Get a Realistic Security Budget
We will assess your risk profile and recommend a cybersecurity budget that matches your actual needs — not a generic percentage.
Protect your business → Get Cybersecurity Assessment