Cost breakdown chart for cyber security services for UK small businesses

How Much Does Cyber Security Cost for a UK Small Business? (2026 Guide)

Table of Contents

Quick answer: Most UK small businesses spend between roughly £100 and £600 a month on cyber security once Cyber Essentials certification, managed endpoint protection, email security and staff training are added together, with the exact figure driven by headcount, the sensitivity of the data you hold and whether you need independently tested (Cyber Essentials Plus) assurance. Certification itself starts at £320 +VAT. The full breakdown below shows what each layer costs and what pushes the price up or down.

If you have started asking suppliers, insurers or a bigger client what your cyber security actually looks like, you have probably also started wondering what it should cost. This guide is for UK small business owners and office managers who need a realistic, itemised answer rather than a single headline figure, because cyber security is not one product with one price. It is a set of layers, and you can build those layers up gradually as your risk and budget allow.

In this guide: what determines your cost, a cost breakdown by service with real UK pricing where it exists, an illustrative example for a small business, what a breach can cost if you skip this, and the questions worth asking any provider before you sign anything.

From £320 +VATCyber Essentials certification, priced by organisation size (NCSC)
43%of UK businesses identified a breach or attack in the last 12 months (2025/26)
£0–£4,000range of perceived cost for most disruptive breaches, 25th–95th percentile
Freecyber liability insurance included with Cyber Essentials for orgs under £20m turnover

What Actually Determines Your Cyber Security Cost

There is no single price because cyber security covers several distinct jobs: certifying that basic controls are in place, actively monitoring for problems, training staff, testing your defences, and having a plan for when something goes wrong anyway. A business that only needs the first of those pays far less than one that needs all five.

What Pushes the Cost Up

  • Higher headcount and more devices to protect
  • Handling sensitive customer, financial or health data
  • A client, insurer or tender requiring Cyber Essentials Plus rather than Cyber Essentials
  • Older or unsupported hardware and software that needs extra work to secure
  • A remote or hybrid workforce using multiple networks and personal devices
  • A requirement for 24/7 monitoring rather than business-hours cover

What Keeps the Cost Down

  • A smaller, standardised device fleet
  • An existing Microsoft 365 setup with security features already switched on
  • Bundling security into a managed IT support contract rather than buying each piece separately
  • Good patching and update habits already in place
  • Fewer third-party systems and integrations to secure

Cyber Security Cost Breakdown by Service

The table below sets out each layer separately. Where a figure comes from an official source, we say so. Where it is a typical UK market range rather than a fixed price, we say that too, because your actual quote will depend on the factors above.

Service Typical UK Cost What It Covers
Cyber Essentials certification From £320 +VAT, tiered by organisation size (NCSC/IASME assessment fee) Self-assessed certification against five technical controls: firewalls, secure configuration, security update management, user access control and malware protection
Cyber Essentials Plus Priced individually by network size and complexity, quoted by a licensed Certification Body The same five controls, verified through independent technical testing rather than self-assessment
Managed endpoint protection & monitoring (estimate) Roughly £5–£15 per device, per month Antivirus, threat detection and ongoing monitoring across laptops, desktops and servers
Email security & anti-phishing filtering (estimate) Roughly £2–£6 per mailbox, per month Filtering malicious attachments and links before they reach staff inboxes
Staff security awareness training (estimate) Roughly £500–£2,000 a year for a small team, or ongoing simulated phishing from a few pounds per user, per month Training staff to recognise phishing, social engineering and password risks, usually the cheapest way to reduce incidents
External penetration testing (estimate) Roughly £1,500–£6,000 per test, depending on scope An independent tester actively attempting to find and exploit weaknesses in your systems
Cyber insurance (estimate) Roughly £500–£3,000+ a year, depending on cover and turnover Financial protection and incident response support if a breach happens. Note that Cyber Essentials-certified businesses under £20m turnover get a baseline policy included free (NCSC)
Incident response retainer (estimate) Roughly £1,000–£5,000 a year Guaranteed priority access to specialist help if you suspect a live compromise, rather than starting from scratch under pressure

These estimate ranges reflect typical UK market pricing rather than a single provider’s rate card. Get a tailored quote based on your actual headcount and setup before budgeting against them.

An Illustrative Example: A 15-Person UK Business

This is a worked illustration, not a real customer result. Take a 15-person UK professional services business that already uses Microsoft 365 and has never been certified before. A realistic first-year budget might look like this: Cyber Essentials certification around £350–£450 +VAT, managed endpoint protection and monitoring around £75–£225 a month, email security around £30–£90 a month, and staff awareness training folded into onboarding at a few hundred pounds a year. That puts a realistic first-year total somewhere in the £2,500–£5,500 range, with the ongoing annual run rate typically lower once certification is renewed rather than started from scratch and no one-off testing is scheduled that year.

What It Costs to Skip This

The Cyber Security Breaches Survey 2025/2026, the UK government’s official annual survey of business cyber security, found that 43% of UK businesses identified a cyber security breach or attack in the previous 12 months. Most of those incidents were not catastrophic: the median perceived cost of a business’s most disruptive breach was £0, and the middle 50% of businesses reported a cost of £0 to £200. But that average hides the tail end. At the 95th percentile, the cost of the most disruptive breach reached £4,000, and the survey also recorded a rising share of businesses reporting real revenue loss or reputational damage from breaches year on year.

In our experience, the businesses that get hit hardest are usually the ones with no monitoring in place to catch a problem early, not the ones spending the most on prevention. The point of the spending above is not to guarantee nothing ever goes wrong. It is to reduce how often it happens and how much damage it does when it does.

What This Guide Doesn’t Cover

This is a pricing guide, not a security assessment. Cyber Essentials certification is not the same as a penetration test, and passing it does not mean your business is immune to every type of attack, it confirms that five baseline technical controls are in place. Cyber insurance is not a substitute for having the controls above; most insurers now ask about your security posture before they will quote, and some require Cyber Essentials as a condition of cover. If you are not sure which of these services your business actually needs first, a cyber security risk assessment is normally the right starting point rather than buying every layer at once.

Questions to Ask a Provider Before You Buy

Use these to compare quotes properly rather than on headline price alone.

  • Is monitoring genuinely 24/7, or business hours only with alerts reviewed the next morning?
  • Is annual Cyber Essentials renewal included in the contract, or billed separately each year?
  • What is the guaranteed response time if you report a suspected compromise?
  • Is the provider an accredited Cyber Essentials Certification Body or working with one, rather than just advising informally?
  • Does the price change automatically as your headcount grows, and by how much?
  • What exactly is excluded from the package, for example penetration testing, incident response or out-of-hours cover?

Frequently Asked Questions

Is Cyber Essentials a legal requirement for UK businesses?

No, not generally. The NCSC describes Cyber Essentials as the government-recommended minimum standard, not a universal legal obligation for private businesses. That said, some public sector contracts, supply chains and insurers now require it before they will work with you, so check what your clients and industry actually expect.

What’s the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment: you answer a question set and a board member signs it off before an assessor marks it. Cyber Essentials Plus covers the same five technical controls but adds independent, hands-on technical testing, which is why it costs more and is priced individually rather than at a fixed starting rate. See our full guide to what Cyber Essentials involves for more detail on the certification process itself.

Can I reduce cyber security costs by bundling it with IT support?

Often, yes. We recommend businesses that already have a managed IT support contract ask their provider what security coverage is already included before buying separate tools, since monitoring and patching frequently overlap with what a managed IT contract already covers.

Do very small businesses (under 10 staff) need to spend this much?

Not necessarily. A very small business with modern cloud software and no sensitive data to protect might reasonably start with Cyber Essentials certification and staff awareness training alone, then add monitoring and testing as the business and its risk grow.

How much does a cyber attack actually cost if it goes wrong?

According to the government’s Cyber Security Breaches Survey 2025/2026, most businesses that experience a breach report a low direct cost, with a median of £0 and most falling between £0 and £200. A smaller proportion face far higher costs, up to £4,000 at the 95th percentile for their most disruptive breach, before accounting for lost time, reputational damage or a bigger incident such as ransomware.

Want a Cost Figure Specific to Your Business?

These ranges are a starting point. Talk to our cyber security team for a free, no-obligation quote based on your actual headcount, systems and risk.

Get a Free Cyber Security Quote

Cyber security spending works best built up in layers rather than bought all at once. Start with certification and staff training, add monitoring once you know what you are protecting, and bring in testing and an incident response plan as your business and its risk grow. If you want help working out which layer to prioritise first, our cyber security services team can talk you through it alongside your existing IT support costs so the two budgets make sense together.

Table of Contents