“How much should we be spending on cybersecurity?” is the wrong first question, but it’s still worth a real answer before getting to the right one.
The Benchmark Numbers
A defensible starting range for small and mid-sized businesses is roughly 7-12% of total IT budget, with some guidance widening that to 4-15% depending on risk profile. Higher-risk industries — finance and healthcare in particular, given regulatory exposure — often land toward the higher end. Measured against total revenue instead, organizations spend an average of roughly 0.69% today, up from about 0.50% five years ago. Small businesses often land above that average as a share of revenue, simply because foundational tools like endpoint protection and email security cost roughly the same whether a business has 10 employees or 100.
The trend line matters too: around 63% of small businesses increased their cybersecurity budget year-over-year in a recent industry survey, reflecting rising awareness even as many businesses’ actual spending still lags what their real risk would justify.
The Better Question: What’s Actually Included?
Benchmarks are a useful sanity check, but the more practical question for a small business is what a given dollar figure actually buys. A well-structured flat-rate managed IT and cybersecurity agreement typically bundles 24/7 monitoring, EDR/MDR endpoint protection, email security, MFA management, patch management, monitored and tested backups, help desk support, and baseline incident response — all under one predictable fee. What typically falls outside that flat rate: larger one-time projects like a full network redesign, a compliance audit for a new regulatory requirement, digital forensics after a serious incident, or specialized penetration testing. A transparent provider defines that boundary upfront, not after an invoice surprises you.
The Gut-Check for Underspending
Skip the percentage math for a moment and ask three direct questions: Is MFA enforced everywhere, with no exceptions? Have your backups actually been tested with a real restore, not just scheduled? Do you know specifically who would lead an incident response tomorrow morning if something went wrong tonight? If any answer is no or “I’m not sure,” spending is very likely below what your actual risk justifies, regardless of what a benchmark percentage says on paper.
Why Risk Profile Matters More Than Headcount
Budget should scale with risk, not just employee count. A five-person healthcare practice handling patient data or a five-person title company handling wire transfers carries meaningfully more risk, and often more regulatory exposure, than a five-person business with no sensitive data at all. A flat per-employee assumption misses this entirely.
Build vs. Buy
For nearly every small business, outsourcing security is dramatically more cost-effective than building it in-house. A single qualified security-focused hire commands a salary most small businesses can’t justify for one role, and one person can’t provide 24/7 coverage, redundancy during vacation or turnover, or the breadth of expertise a managed provider spreads across many clients.
How CelereTech Helps
CelereTech starts with a free assessment of your actual environment and risk profile, not a generic percentage-of-revenue formula, then proposes a flat-rate plan covering the baseline controls your business genuinely needs — a specific, defensible number instead of an industry benchmark to guess from.
Get a free cybersecurity assessment and find out where your business actually stands.