Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Tools

Cyber Security Budget Calculator: What Should You Spend?

By the Assured Cyber Protection team · Updated 2026 · Reviewed

Most small firms have no cyber security budget, they have a pile of invoices nobody adds up. This calculator builds the figure from the bottom: your people, your devices and your servers, priced line by line. The useful surprise is usually where the money goes. The line that outweighs every software subscription is usually the staff time nobody has ever costed.

Build your annual cyber security budget

Prices shown are indicative UK figures for a small or mid-sized business. Where you already have a quote, type it in further down.

Your business
Includes part-timers and regular contractors.
Every device that touches business data. Count servers in the next box, not this one.
Enter 0 if you are fully on hosted apps.
Used only to show the budget as a share of turnover.
Ongoing tools and services
Figures from your own quotes (annual, enter 0 if none)
No quote yet? Size one with the cyber insurance cost calculator.
Work yours out with the Cyber Essentials cost calculator.
Scope one with the pen test cost calculator. Spread a two-yearly test over the years.
Internal time
Access reviews, patch chasing, supplier questionnaires, insurer forms.
Salary plus on-costs, or your IT provider's hourly rate.

Two things tend to fall out of this. First, the four lines insurers ask about, multi-factor authentication, endpoint protection, tested backups and patching, are subscriptions rather than projects, and the MFA line is usually already inside licences you pay for. Second, internal time is real money: eight hours a month at £35 is £3,360 a year, which on the default figures above is more than any single software line.

What the budget does not buy you

A budget is not a plan. Spending goes wrong in the same two ways every time: paying for a tool nobody watches, and paying for cover the controls will not support. Monitoring you never read is the classic example of the first. A policy bought before you can answer the proposal form honestly is the second, and it is the one that turns into a declined claim.

Before you sign anything, run the cyber insurance readiness checker to see which controls the underwriter will look for, and put a number on what an outage actually costs you with the downtime cost calculator. If the downtime figure dwarfs the budget above, you have your business case.

Where to start if the total looks too big

Order matters more than total spend. Multi-factor authentication is usually included in licences you already hold, so it costs setup time rather than money. A tested backup with an offline or immutable copy is the control that decides whether ransomware is a bad week or the end of the business, and it is worth funding before anything with the word "detection" in it. Patching comes next, since it closes the route most attacks actually use. Monitoring, sandboxing and simulated phishing are worth having, but they are refinements on top of a base that works.

If you need the spend to earn its keep twice, aim it at Cyber Essentials. The same controls that satisfy the certificate are the ones insurers reward and larger customers ask about in procurement, so one piece of work answers three questions.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.