Practical cyber security guidance

How much does cyber security cost for a small business in the UK?

There is no sensible single price for cyber security because the cost depends on your users, devices, Microsoft 365 setup, existing IT, compliance needs and how much monitoring you want. A useful budget starts with the risks you need to control rather than a shopping list of security products.

Frequently asked questions

6 practical answers.

### What determines the cost of cyber security for a small business?

The main factors are the number of users and devices, the systems being protected, the quality of the existing setup, whether you need 24/7 monitoring, backup requirements, compliance or customer requirements, and how much remediation is needed before managed protection can begin.

### Should a small business buy cyber security tools separately?

Usually it is better to design a joined-up control set. Email security, identity protection, endpoint detection, backup, firewalling and staff training overlap. Buying them independently can create gaps, duplicated alerts and unclear ownership.

### What should we pay for first?

Prioritise identity protection and MFA, supported and securely configured devices, effective email protection, reliable backup and recovery, endpoint protection, and a clear incident process. The exact order should follow the risks in your environment.

### Is the cheapest cyber security package good enough?

Price alone is a poor measure. Ask who monitors alerts, who responds when something happens, whether restores are tested, what is excluded, how administrator accounts are protected and what reporting you receive.

### Can we improve security without replacing our IT provider?

Yes. 39Security can work alongside an existing IT provider and take ownership of defined security controls while the existing provider continues day-to-day IT support.

### How do we get a realistic budget?

Start with an assessment of users, devices, Microsoft 365, email, backup, endpoints, firewalling and current policies. That makes it possible to separate urgent remediation from ongoing managed protection.

Related guidance

Keep improving the control set.