What Cyber Security Actually Costs, and a Worked Budget

Itwerx is a managed IT and cybersecurity provider serving businesses across Seattle, Bellevue and Snohomish County, founded in 2005. This is a worked security budget with real line items rather than a range, and the prices in it are left at what they were when it was assembled.

This budget was first put together as two posts in April 2022, and the per-unit pricing below is 2022 pricing. The one figure that needed correcting is the industry-wide cost of cybercrime cited to justify the spend: the original post used a single-source dollar total that turned out to trace to no published methodology. Below it is replaced with a federal figure that was actually current for a post written that month, and the closing statistic about business survival, which has since been formally retracted by the body it was attributed to, is replaced with a more recent and better-sourced measure of what a breach actually costs a small business.

What drives the number

The news treats every company as a target, but the more useful question is what the companies who stay out of the news are actually spending. Cyber security is layered products and services, maintained, updated and reconfigured against an attacker landscape that never holds still. What it costs depends on the size and complexity of the organization, the type of data involved, the products and services already deployed, and how much testing and auditing sits behind them.

Products

  • Firewalls: $500 to $5,000 or more per location, plus a recurring annual subscription. A typical initial cost is around $1,500 per site.
  • Endpoint security: $10 to $30 per system per month.
  • Email filtering: around $5 per seat, sometimes bundled with other services.
  • Multi-factor authentication: hardware keys run $25 to $50 each; software key generators run $0 to $10 per seat per month, often with additional management features.

Services

  • Vulnerability assessments: $1,000 to $2,000 per server, or $5,000 to $10,000 per site, with follow-up assessments costing much less barring major changes.
  • Web application assessments: the internet-facing presence is effectively one more “site,” often the largest and most complex of all. A functional web presence with customer portals or EDI/ERP integration typically needs at least a week of work, and complex systems can take months.
  • Architectural assessment: usually a one-time, high-level sanity check of the overall approach, often bundled with the first vulnerability assessment. A reasonable estimate adds roughly one more site’s worth of cost.
  • Program development: for a company with no formal cyber security plan, the first step is scoping what is actually needed before assessments are planned. Typically less than a week of work, fixed-rate or hourly.
  • Threat monitoring: almost always outsourced, given the staffing and data volume required. Endpoint products often include a baseline; a fuller picture that pulls in other sources, like web hosting logs, costs more.

A worked example: 250 people, five sites

Take a company with 250 employees across five locations: 20 servers at headquarters and three servers at each of four similar satellite offices, a simple brochure website, and no prior formal assessment.

One-time assessment costs: program development $2,000, architectural assessment $2,000, vulnerability assessments $10,000 for headquarters plus $5,000 for the web presence plus roughly $1,000 for each of three of the four similar satellite sites (the fourth discounted for similarity). Total: about $22,000.

One-time remediation, once the assessment turns up outdated firewall architecture and missing modern endpoint protection: firewalls at $5,000 for headquarters plus $500 at each of four satellites, and an endpoint protection rollout across roughly 282 systems (250 users, 20 headquarters servers, 12 satellite servers) at about $30 per system. Total: around $15,000.

Recurring annual costs: firewall subscriptions across five sites at roughly $500 each, endpoint protection across the same 282 systems at about $15 per month, email filtering and MFA at roughly $7 per seat per month across 250 seats, and an annual re-assessment at $5,000. Total: a minimum of roughly $80,000 a year.

Why that number is not the expensive option

In 2021, the year this budget’s cost factors were current, the FBI’s Internet Crime Complaint Center recorded losses exceeding $6.9 billion from 847,376 complaints, a US-only figure and one that counts only what was reported. That is the scale of the problem an $80,000 annual program is defending against, not a marketing estimate.

What matters more for a company this size is what a breach actually costs afterward. The Identity Theft Resource Center’s 2024 Consumer & Business Impact Report found that the share of small businesses reporting losses over $500,000 from a breach had doubled in a single year. Set against that, a recurring budget in the tens of thousands looks like the cheap option, because the alternative is not a fixed, insurable cost – it is an open-ended one.

Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.