Every owner asks the question eventually, usually after a client questionnaire, an insurance renewal, or a story about a competitor who got hit. The two answers they normally get are equally useless: a percentage borrowed from an enterprise survey, or a proposal that includes everything at once with no explanation of what would happen if half of it waited.
There is a better way to decide, and it starts by admitting that no honest benchmark exists for a twenty person business. The useful question is not what percentage of your cybersecurity budget is normal, but what you must have, what you should buy next, and what can wait until it earns its place.
Why the Benchmark Percentage Does Not Transfer
The figures that circulate, the ones saying businesses spend some share of the IT budget on security, come from surveys of organizations with security teams, compliance departments, and thousands of employees. Their spending reflects staff salaries and enterprise tooling that a small office will never buy.
There is a deeper problem: percentage thinking measures the wrong variable. Two ten person businesses can have wildly different exposure: a design studio holding nothing but its own files sits in a different position from a medical billing office holding thousands of patient records under a federal rule. Risk follows the data and the obligations, not the headcount, and the budget should follow the risk.
Start From Obligations, Not Products
Before pricing anything, write down four things. What sensitive data does the business actually hold, which rules apply to it, what do your clients and contracts require, and what did your insurance application commit you to.
Those four answers set the floor, and the floor is not negotiable in the way the rest of the list is. A practice that promised its insurer it enforces multi-factor authentication does not get to treat that as a future project, and a firm whose clients send security questionnaires has commitments to meet whether or not they are in a plan. Sorting which obligations apply is exactly what a structured approach to choosing a cybersecurity framework gives you, and it beats guessing from a vendor's feature list.

The Order to Buy In
Given a limited budget, sequence matters more than total. This order reflects what actually prevents and contains incidents in small businesses, rather than what is easiest to sell.
- Identity first: multi-factor authentication on every account that touches business data, and everyday work done without administrator rights.
- Backups you have restored, kept where an attacker with your credentials cannot reach or delete them.
- Patching and lifecycle: nothing running past its support date, and updates that finish installing.
- Email filtering and staff training, because that is still where most incidents begin.
- Monitored endpoint protection, meaning detection that reaches a human who can act, not an icon in a system tray.
- Logging and a response commitment, so somebody sees an event out of hours and knows what to do about it.
- Everything else: penetration testing, advanced analytics, data loss prevention, and the rest, once the six above are genuinely in place.
The order is deliberate. Items one through three prevent the majority of small business incidents and cost little beyond the discipline to do them, while items five and six are where real money starts and where they belong once the free wins are taken. Businesses that buy from the bottom of this list first end up with impressive tools protecting an environment where a former employee's account still works.
Check What You Are Already Paying For
The most common waste in small business security is not overspending; it is buying a product to do something the existing subscription already does. Business tier license plans include email filtering, device management, encryption controls, and conditional access, and a large share of small offices pay for those capabilities twice because nobody audited what was included.
Before approving anything new, ask which of the requirements it meets are already covered by tools you own but have not configured. Configuration effort is usually cheaper than a new subscription, and the answer belongs in the same conversation as the rest of your IT consulting planning rather than in a purchase decision made in isolation.
Three Costs That Never Make the Budget
Line items are the easy part. Three costs sit outside the quote and derail small business plans every year.
The first is people's time, because every control has an operating cost: someone reviews alerts, runs the restore test, checks the access list, and answers the questionnaire. A tool nobody operates is worse than no tool, since it produces the feeling of protection without the fact of it.
The second is renewal creep, where each subscription rises modestly and the total quietly outgrows what anyone approved. The third is the incident cost you carry yourself, meaning the insurance deductible, the lost days, and the work of notification, which is the number that makes the rest of the budget look small and which our guide to cyber insurance covers from the coverage side.
Subscriptions Versus Purchases
Security spending has largely become monthly rather than capital, which is easier to start and harder to stop. That structural shift has its own logic, and the trade offs of moving technology spending from purchases to predictable monthly costs are covered in our article on shifting from CapEx to OpEx.
The practical implication for a security budget is a rule worth adopting: every new subscription gets a review date. Anything not reviewed within a year becomes a candidate for removal rather than an automatic renewal, which is the only reliable defense against a stack that grew by accident.
Two Numbers That Belong in the Conversation
If percentages are unhelpful, two other figures are worth calculating before any purchase. Both are specific to your business rather than borrowed from someone else's report.
The first is what a day of downtime costs you: staff time that cannot be used, revenue that does not arrive, appointments or filings that move, and the work of catching up afterward. Most owners have never worked it out, and the figure usually surprises them enough to reorder the priorities on its own.
The Second Number Is the Deductible
The other figure sits in your insurance policy: what you pay before coverage responds, plus whatever the policy excludes. That is the amount your business self funds in an incident, and it is the honest benchmark against which a monthly security cost should be judged.
Put those two numbers on the same page as the proposal. A monthly figure that looked expensive next to a subscription list looks different next to the cost of the event it prevents, and unlike a survey percentage, both numbers are defensible because they came from your own business.
What "Enough" Looks Like
Since no percentage answers the question, use capability tests instead. A small business has a defensible security position when it can answer yes to a short list, honestly, with evidence.
- Could we restore the systems we depend on, and when did we last prove it?
- Would we know if something serious happened at two in the morning, and who would act?
- Can we answer a client questionnaire without inventing anything?
- Does every account require more than a password, including the ones no one remembers?
- Do we know what we hold, where it lives, and who can reach it?
Five yeses with evidence behind them is a stronger position than a large budget spent on the wrong sequence. Staff training belongs in that picture too, since the people using the systems decide how often the technology gets tested, which is why security awareness training keeps earning its modest line item.
Where the Money Gets Wasted
Four patterns account for most wasted security spending in small businesses, and none of them involves buying a bad product. They involve buying a reasonable product at the wrong moment or without the capacity to run it.
The first is buying detection before recovery, meaning a business that pays monthly for advanced monitoring while its backup has never been restored. The second is buying tools no one operates, since a console with three hundred unread alerts is a subscription rather than a control, and the operating cost is the real price of every security product.
The Compliance Purchase That Satisfies No One
The third pattern is buying to answer a questionnaire rather than to reduce risk. It shows up as a product purchased the week before an audit, configured minimally, and never revisited, which produces a yes on the form and nothing in reality.
The fourth is the long commitment made early. Multi year contracts signed for a discount lock a small business into decisions made before it understood its own environment, and the sensible pattern is short terms while the program is young and longer ones only for tools that have proved themselves in your specific business.
Put It on One Page
The document that gets a budget approved is short. For each item, name the obligation or risk it addresses, the monthly cost, what happens if it waits another year, who operates it, and the date it will be reviewed.
Five columns, one page, and the conversation stops being about products. It also creates the record that a client questionnaire, an insurer, or an auditor will eventually ask for, which means the planning document doubles as evidence rather than sitting in a drawer.
Presenting It to Whoever Signs
Budget conversations fail when they are presented as product lists. An owner asked to approve an endpoint detection subscription has no way to judge it, while the same owner asked whether the business should be able to detect and stop an attack in progress at midnight is being asked a question they can answer.
Frame each item as the risk it addresses, what happens without it, and what it costs per month, then let the decision be made with real information. That translation from technical requirement into business decision is the core of what a virtual CIO does, and it is the difference between a budget that gets approved and one that gets deferred every quarter.
Plan on a Rhythm, Not in a Panic
The worst time to decide a cybersecurity budget is immediately after a scare or during an insurance renewal, because both produce buying rather than planning. Set a yearly review with a short list of what changed: new obligations, new systems, new staff, and what the last twelve months revealed.
Businesses in the region can run that review with a provider offering IT support in Westlake Village, including an honest account of which requirements your current subscriptions already cover. The output should be a sequenced plan, not a quote.
Companies across the city can plan it through managed IT services in Los Angeles, starting at the obligations inventory and ending with the order of purchase. Spending deliberately costs the same as spending in a panic and buys considerably more.
Frequently Asked Questions
Being handed a security proposal with no way to judge which parts are urgent is a common place to be stuck, and GlobeVM will map your obligations, show what your current licensing already covers, and put the rest in a sequence your cybersecurity budget can support.
Comments
0 Comments
