Skip to content

How-to

How much should an SMB spend on security?

A practical, range-based way for small and mid-sized businesses to size a security budget without copying enterprise spreadsheets.

“How much should we spend on security?” is the most common question small and mid-sized businesses ask — and the honest answer is a range, not a number. The useful version of the question is “how do we size a budget that fits our risk, our revenue, and our team?”

Start from your IT budget, not from fear

The most durable anchor is your existing IT spend. IANS benchmarking puts security at roughly 11% of the IT budget for a typical organization. That’s a starting reference point, not a target carved in stone — a regulated fintech will land higher, a low-risk local services firm lower.

A second sanity check is per-employee spend. Across industries, security costs land near ~$2,300 per employee per year, though very small organizations typically come in well under that because fixed tooling spreads across fewer people and they lean on bundled or outsourced services.

Use both as guardrails:

  • The % of IT lens keeps security proportional to how technology-dependent you already are.
  • The per-employee lens catches the case where your IT budget is unusually small for your headcount.

If the two methods disagree wildly, that’s a signal worth investigating, not an error to average away.

Don’t budget to hire — budget to cover the function

The single biggest budgeting mistake SMBs make is assuming they need to hire a security team. A loaded security FTE runs roughly $162K per year (BLS-based, fully loaded), which is more than many small businesses spend on their entire security program. For most SMBs, hiring a full analyst is the wrong first move.

The alternative is outsourcing the operational work. Managed detection and response (MDR) is the common path: instead of staffing 24/7 monitoring, you pay per endpoint. Pricing ranges widely — roughly $3 to $45 per endpoint per month, with ~$6 typical for a mid-tier service. For a 75-person company, that’s a real but bounded cost, and it buys you eyes on your environment outside business hours without a six-figure salary.

Rule of thumb for SMBs: buy the function (detection, response, monitoring) as a service before you buy the headcount to run it yourself. You can always insource later as you grow.

Budget compliance separately and explicitly

Compliance costs are lumpy and tend to ambush SMBs that forget to plan for them. They’re driven by which frameworks your customers and regulators require, and each one is a distinct, recurring line item:

FrameworkTypical cost (per cycle)
SOC 2~$40K
HIPAA~$15K
PCI~$20K
All three~$75K combined

These figures cover the audit and readiness work and vary with scope, auditor, and how much remediation you need first. If a customer contract hinges on SOC 2, that ~$40K isn’t optional spend — it’s revenue-enabling, and it belongs in the budget conversation early.

A worked starting point

Suppose a 50-person company with a $400K annual IT budget and a customer pushing for SOC 2. A first-pass security budget might look like:

  • Controls baseline (EDR, identity/MFA, email security, backups): the bulk of the program
  • MDR at ~$6/endpoint/mo across ~60 endpoints: roughly $4–5K/year
  • SOC 2 readiness and audit: ~$40K (a one-time spike, then lighter renewals)
  • Cyber insurance: a smaller line, sized to tail risk

Applying the 11%-of-IT anchor lands the ongoing program near ~$44K/year, with the SOC 2 push sitting on top as a project cost. The exact split depends entirely on your gaps — the point is that each piece is sized from a defensible reference, not from a vendor’s quota or a competitor’s headline number.

What to avoid

  • Copying an enterprise budget. Their per-employee economics and threat model don’t transfer down.
  • Treating compliance as a surprise. Forecast it by framework, on its own line.
  • Hiring before you’ve outsourced. A six-figure FTE is rarely the cheapest way to get monitoring.
  • Chasing false precision. Plan in ranges and revisit quarterly as you grow.

The right number for your business depends on your revenue, risk, and which frameworks you’re chasing — but you can get to a defensible range quickly. Start with the cybersecurity budget calculator to turn these anchors into your own figures.

References

Related

Put this into a number

Build a sourced, defensible budget from your own risk profile — free and ungated.

Open the calculator