Skip to content

Pricing

Network security cost: what NGFW and NDR actually cost (2026)

Network security spend is dominated by two recurring lines — next-gen firewall subscriptions and network detection and response. For a mid-market org, budget roughly $50K–$200K a year.

Ask “what does network security cost” and you’ll get answers ranging from a few thousand dollars to well over a million — because the term bundles firewall hardware, firewall subscriptions, and network detection and response (NDR), each priced differently. For a mid-market organisation the recurring number that matters — NGFW security subscriptions plus an NDR subscription — typically lands around $50,000–$200,000 a year, with NDR the dominant and most variable part.

Here’s how that breaks down and what moves it.

The two recurring line items

Most network security spend is really two subscriptions layered on top of (mostly one-time) hardware:

ComponentWhat it isTypical annual cost (mid-market)
NGFW security subscriptionThreat prevention, IPS, URL filtering, sandboxing on each firewall~$8K–$45K across 2–4 appliances
NDR subscriptionDetects malicious activity moving across the network~$40K–$120K (single-module)
Combined recurring~$50K–$200K/yr

Hardware (the firewall appliances themselves) is usually capital expenditure and refreshed every few years, so it’s budgeted separately from these recurring subscriptions.

Why NDR is the bigger, more variable line

Next-gen firewall subscriptions scale fairly predictably — roughly 15–25% of hardware list price per appliance per year, multiplied by the number of firewalls and sites. NDR is where the cost really moves. Buyer data (e.g. Vendr) puts a typical Darktrace deal near the mid-five-figures, but multi-module deployments across 500–2,000 devices push into the low-to-mid six figures. Vectra and similar vendors price comparably.

So the same phrase — “network security” — can mean $50K for a lean FortiGate-plus-entry-NDR setup or $250K+ for multi-site next-gen firewalls with a full multi-module NDR platform.

What drives the number

  • Sites and appliances. Each firewall (and each HA pair) adds a per-appliance subscription. More locations, more cost.
  • Throughput / model tier. Bigger firewall models cost more to subscribe because the subscription tracks hardware list price.
  • NDR devices and modules. NDR pricing scales with monitored devices/IPs and the number of modules (detect vs detect + respond + cloud + email). This is the fastest-growing lever.
  • Term length. Multi-year commitments typically discount 20–35% off list.

Is NDR worth it for you?

Firewalls stop known-bad at the perimeter; NDR catches lateral movement and anomalies inside the network that a firewall never sees. For organisations with flat networks, sensitive data, or limited endpoint coverage, that visibility is worth the line item. For very small environments, endpoint detection (EDR/MDR) plus a solid firewall often covers more risk per dollar first.

Where it fits in the budget

Network security is one control among many. Overall security spend clusters near 11% of the IT budget (IANS/Artico), and network security is a meaningful but rarely dominant slice — staffing and detection tooling usually lead.

To size network security alongside endpoint, identity, cloud, SIEM and the rest for your specific footprint, run the free, ungated cybersecurity budget calculator.

References

Related

Put this into a number

Build a sourced, defensible budget from your own risk profile — free and ungated.

Open the calculator