Tools
Cyber Security Budget Calculator: What Should You Spend?
Most small firms have no cyber security budget, they have a pile of invoices nobody adds up. This calculator builds the figure from the bottom: your people, your devices and your servers, priced line by line. The useful surprise is usually where the money goes. The line that outweighs every software subscription is usually the staff time nobody has ever costed.
Build your annual cyber security budget
Prices shown are indicative UK figures for a small or mid-sized business. Where you already have a quote, type it in further down.
Check the figures: you need at least one member of staff, and no negative numbers.
Two things tend to fall out of this. First, the four lines insurers ask about, multi-factor authentication, endpoint protection, tested backups and patching, are subscriptions rather than projects, and the MFA line is usually already inside licences you pay for. Second, internal time is real money: eight hours a month at £35 is £3,360 a year, which on the default figures above is more than any single software line.
What the budget does not buy you
A budget is not a plan. Spending goes wrong in the same two ways every time: paying for a tool nobody watches, and paying for cover the controls will not support. Monitoring you never read is the classic example of the first. A policy bought before you can answer the proposal form honestly is the second, and it is the one that turns into a declined claim.
Before you sign anything, run the cyber insurance readiness checker to see which controls the underwriter will look for, and put a number on what an outage actually costs you with the downtime cost calculator. If the downtime figure dwarfs the budget above, you have your business case.
Where to start if the total looks too big
Order matters more than total spend. Multi-factor authentication is usually included in licences you already hold, so it costs setup time rather than money. A tested backup with an offline or immutable copy is the control that decides whether ransomware is a bad week or the end of the business, and it is worth funding before anything with the word "detection" in it. Patching comes next, since it closes the route most attacks actually use. Monitoring, sandboxing and simulated phishing are worth having, but they are refinements on top of a base that works.
If you need the spend to earn its keep twice, aim it at Cyber Essentials. The same controls that satisfy the certificate are the ones insurers reward and larger customers ask about in procurement, so one piece of work answers three questions.