How Much Does Email Security Cost for a Small Business?
A clear, direct answer to this question — written for UK business owners and IT decision-makers.
Direct Answer
Microsoft Defender for Office 365 Plan 1 costs £1.80 per user per month when purchased standalone, or is included in Microsoft 365 Business Premium. AMVIA's managed email security service — including configuration, ongoing management, DMARC setup, and phishing simulation — starts from £5 per user per month on top of your M365 licence.
Key Points
What you need to know.
The Short Answer
Phishing is the number one attack type — 85% of businesses that experienced a breach identified phishing as the cause (DSIT 2025).
For UK Businesses
Phishing was the most disruptive breach for 65% of businesses.
Cost Considerations
93% of cyber crimes against businesses were phishing-based.
Next Steps
35% of businesses that experienced breaches reported impersonation of the organisation or staff.
Quick Comparison
| Feature | Option A | Option B |
|---|
Frequently Asked Questions
Exchange Online Protection, included with all Microsoft 365 plans, provides basic anti-spam and anti-malware filtering. However, it lacks the advanced anti-phishing, safe attachments, and link detonation capabilities of Defender for Office 365. 85% of businesses that experienced a breach identified phishing as the attack vector (DSIT 2025), making the additional protection layers well worth the modest per-user cost.
DMARC is a free DNS-based standard that prevents attackers from spoofing your domain in phishing emails. Implementing it costs nothing for the DNS records themselves, though proper configuration and monitoring require expertise. BEC attacks increased 33% in 2025 (FBI IC3 Report), and DMARC is one of the most cost-effective defences against impersonation fraud targeting your clients and staff.
Yes. Even the best email filters cannot catch every threat, so training staff to recognise phishing is a critical second layer. The average cost of the most disruptive breach is £3,550 (DSIT 2025), and human error remains the trigger in most successful phishing attacks. Simulation platforms typically cost £1-£3 per user per month and measurably reduce click rates on malicious emails over time.
Related Questions
Email Security and Phishing Protection
Managed email security including DMARC, anti-phishing, and simulated phishing campaigns.
Microsoft 365 Security
Microsoft Defender for Office 365 configuration and ongoing management for UK businesses.
What Is Phishing?
How phishing attacks work and what email security controls can prevent them.
Cybersecurity Guide for UK SMEs
A complete guide to cybersecurity controls including email security priorities.
Protect your business → Get Cybersecurity Assessment