Cyber Security and IT Support Pricing
We will not publish a number that turns out to be wrong for your business. We will publish exactly how we price, what drives cost up or down, and what you get for it.
How much does cyber security cost for a small business?
It depends on scope, but the model matters more than the number. Cipher Knights prices assessment and project work as a fixed price agreed in writing before starting, and managed IT support as a fixed monthly fee per user. You should never receive an open-ended day-rate invoice from us.
What drives the price
For assessment and testing work, cost is driven by scope: how many internet-facing systems, how many internal devices, how many users, how many web applications, and how complex each of those is. A ten-person office with one office network and a Microsoft 365 tenant is a fundamentally different exercise from a manufacturer with three sites and a production network.
For managed IT support, cost is driven by supported user count, the number and type of devices and servers, and whether on-site visits are included. Because it is charged per user per month, it scales predictably as you grow rather than spiking when you have a difficult month.
- Number of users and devices in scope
- Number of internet-facing systems and web applications
- Number of sites, and whether on-site attendance is needed
- Cloud platforms in use and their complexity
- Whether you want us to implement fixes or only to report them
What is always included
Every engagement includes the scoping call, the report, a walkthrough call to explain it, and — for assessment and testing work — a free retest of remediated findings within sixty days. We regard the retest as part of the job rather than an upsell, because an assessment nobody acts on has achieved nothing.
Where third-party costs apply, such as IASME certification fees for Cyber Essentials or certification body fees for ISO 27001, we state them separately and do not mark them up.
A sensible starting budget
If you are starting from nothing, the sequence that delivers the most risk reduction per pound is consistent: a vulnerability assessment to find out where you stand, then remediation of the critical findings, then Cyber Essentials to evidence the baseline, then a support arrangement that keeps it from drifting back.
Penetration testing comes after that, not before. Paying for a creative attacker to break into a network with unpatched internet-facing services is spending money to learn something you could have been told for less.
- 1. Vulnerability assessment — establish the baseline
- 2. Remediation of critical and high findings
- 3. Cyber Essentials — evidence the baseline to customers and insurers
- 4. Managed support or scheduled reassessment to prevent drift
- 5. Penetration testing once the foundations are genuinely in place
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
Pricing — your questions answered
Why do you not publish fixed prices on the website?
Is the initial consultation really free?
Do you charge a day rate?
Are retests charged separately?
What payment terms do you offer?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about pricing?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.