How to Budget for Cybersecurity as a Small Business

A UK small business should allocate 5–15% of its overall IT budget to cybersecurity, or roughly £200–£1,500 per month depending on size and risk profile. The right approach is risk-based: invest proportionally to the value of what you are protecting.

Quick answer

A UK small business (10–50 staff) typically spends £400–£1,200 per month on cyber security — roughly £15–£25 per user per month for managed endpoint protection, email security, and monitoring. As a rule of thumb, allocate 5–15% of your total IT budget to security, weighted by the value of what you are protecting. AMVIA delivers all of it under one accountable, security-first provider.

Building a Practical Security Budget

A framework for allocating cybersecurity spend as a small business.

Start with Risk Assessment

Identify your most valuable data and systems. Your security budget should protect the assets whose loss would cause the most damage.

Prioritise by Impact

Fund the controls that reduce the most risk first: MFA, email security, endpoint protection, backups. These cover the majority of attack vectors.

Factor in Compliance

If your industry requires ISO 27001, or sector-specific compliance, budget for the controls and audit costs those frameworks demand.

Plan for Growth

Choose per-user pricing models that scale with your business. Avoid large upfront capital expenditure on security hardware that may become obsolete.

Security Budget by Business Size

Typical monthly cybersecurity spend for UK SMEs.

Feature
Micro (1–10)£100–£300/mo
Small (10–50)£300–£1,200/mo
Medium (50–250)£1,200–£5,000/mo
Endpoint protection
Email security
MFA
24/7 monitoringOptionalRecommended
Incident response retainerOptional
Vulnerability management
Compliance supportCE onlyCE/security certificationsecurity certification/ISO 27001

Budget ranges are indicative. Actual costs depend on industry, risk profile, and compliance requirements.

That is the short answer. The longer answer matters, because a cyber security budget set badly either wastes money on tools nobody watches or leaves the controls that actually stop attacks underfunded. This guide explains how to size your budget, where to spend first, and how to justify it to the people who sign it off. For a deeper breakdown of managed pricing, read our managed cybersecurity cost guide, and see the full managed cybersecurity pillar for the services these budgets buy.

How much should a small business spend on cyber security?

Most UK SMEs land between £200 and £1,500 per month (typical UK 2026 range), depending on headcount, sector, and risk profile. A 10-person firm with low-sensitivity data sits near the bottom; a 50-person professional-services business handling client money or health data sits near the top. The honest answer is risk-based: spend in proportion to what a breach would cost you.

That context is not abstract. According to the UK Government's Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a breach or attack in the past year (Cyber Security Breaches Survey 2025), and the average cost of the most disruptive breach was £3,550 (Cyber Security Breaches Survey 2025). Underspending is rarely a saving — it is deferred cost with interest.

A useful comparison: a single in-house security hire costs £40,000–£55,000 per year in salary alone (market rates as of 2026), before tooling, training, holiday cover, or out-of-hours response. Managed security spreads that capability across many clients, which is why per-user pricing usually wins for businesses under 250 staff.

Business sizeTypical monthly spend (UK, 2026)What it usually covers
Micro (1–10)£100–£300/moEndpoint protection, email security, MFA
Small (10–50)£300–£1,200/moThe above + 24/7 monitoring, vulnerability management
Medium (50–250)£1,200–£5,000/moThe above + incident response retainer, compliance support

Budget ranges are indicative. Actual cost depends on industry, risk profile, and compliance requirements.

How do you build a practical security budget?

Build it in four moves: assess risk, prioritise by impact, factor in compliance, and choose pricing that scales. Skip the assessment and you will buy tools that protect the wrong things. The goal is not "maximum security" — it is the most risk reduced per pound, in the order that reduces it fastest.

Start with a risk assessment. Identify the data and systems whose loss would hurt most — customer records, financial systems, intellectual property, the email accounts that authorise payments. Your budget protects those first. The NCSC's Small Business Guide is a free, practical starting point for working out where you are exposed.

Prioritise by impact. Fund the controls that close the most common attack routes before anything exotic: multi-factor authentication, email security, endpoint protection, and reliable backups. These cover the overwhelming majority of how SMEs actually get breached. Start with MFA across Microsoft 365 and managed email security — they stop the phishing and credential attacks that drive most incidents.

Factor in compliance. If you bid for enterprise or public-sector work, or operate in a regulated sector, budget for the certifications those contracts demand. Cyber Essentials Plus is the baseline most UK buyers now expect; some larger frameworks reference ISO 27001. AMVIA holds Cyber Essentials Plus, which means we run our own estate to the standard we help you meet.

Plan for growth. Choose per-user pricing that scales as you hire, and avoid large upfront capital spend on security hardware that dates quickly. Cloud-delivered controls flex with headcount and keep your budget predictable.

Where should the first £500 a month go?

If you only have a modest monthly budget, spend it on the controls with the highest stop rate per pound: MFA, managed email security, and managed endpoint detection. These three block the entry points behind most SME breaches and cost far less than recovering from one. Monitoring comes next, so a real human sees the alert that matters.

In practical order of priority:

  • Multi-factor authentication on every account — the single highest-leverage control, and effectively free with Microsoft 365.
  • Managed email securityemail security filtering using the Microsoft Defender and Barracuda stack to stop phishing and business email compromise.
  • Managed endpoint protectionendpoint security built on Microsoft Defender for Endpoint, so a compromised laptop is contained, not catastrophic.
  • 24/7 monitoringround-the-clock monitoring from AMVIA's in-house SOC, because attacks do not keep office hours.
  • Tested backups — the control that turns a ransomware crisis into an inconvenience.

Only once those are funded does it make sense to add vulnerability management, an incident-response retainer, and formal compliance work. Buying a SIEM before you have MFA is buying a smoke alarm for a house with the front door open.

How do you justify cyber security spend to the board?

Frame it as risk reduction, not a cost centre. Put the budget next to the exposure it removes: the cost of a disruptive breach, the regulatory fines a data loss would trigger, the cyber-insurance premium it lowers, and the contracts a certification enables. Boards fund quantified risk far more readily than they fund "security".

Two numbers do most of the work. First, the average most-disruptive breach costs £3,550 (Cyber Security Breaches Survey 2025) — and that rises sharply once data loss, downtime, and ICO involvement enter the picture. Second, only 14% of UK businesses review the cyber risks posed by their immediate suppliers (Cyber Security Breaches Survey 2025), which means demonstrable security is increasingly a competitive advantage in tenders, not just a defence.

Present three things and most boards say yes: the financial exposure the budget mitigates, the insurance and contract upside it creates, and the named provider accountable for delivering it.

Frequently Asked Questions

Get a Realistic Security Budget

We will assess your risk profile and recommend a cybersecurity budget that matches your actual needs — not a generic percentage.