Budget and scope
What does cybersecurity cost for an SMB? The honest answer
Why no serious provider can publish a single price, which variables actually determine scope, and how a proposal gets built here.
Key points
- Scope depends on headcount, sites, sector, and above all on what already exists.
- A single published price would be wrong for most of the organizations reading it.
- We build no proposal before establishing the facts: otherwise we would be pricing a guess.
- Budget is discussed in the first conversation, plainly, without you having to push for it.
Why we do not publish a price
Because a published price would be accurate for a handful of organizations and misleading for everyone else. Two thirty-person businesses can require five times the work depending on their number of sites, their sector, their obligations and the state of what they already have. Publishing an average would mean misleading almost everyone.
There is a second reason, less openly discussed in this trade. A headline price mainly serves to secure the meeting; it is then revised upward once the real scope surfaces. The technique works commercially and destroys trust at precisely the moment it becomes necessary.
We take the opposite position, and it costs us something: some visitors leave this page without a figure. We accept that, because a security provider who opens with a comfortable approximation starts the relationship badly.
None of which makes the question taboo. It is addressed, with orders of magnitude, in the first conversation: after understanding what we are talking about, not before.
Which variables actually determine scope?
Four, and only one is obvious. Headcount and number of sites give the volume. Sector and regulatory obligations set the level of rigour required. What already exists (in place, licensed, or paid for but never switched on)moves the work more than the other three combined.
- Headcount and sites. They determine how many endpoints, accounts and links are in play. It is the most visible variable and, paradoxically, not the most decisive.
- Sector and obligations. An organization handling health information, bidding on public contracts, or serving a demanding enterprise customer does not have to produce the same level of evidence as a retail business.
- What already exists. This is the dominant variable. Many organizations already hold, inside current licences, security capabilities they have never enabled. That finding changes the nature of the work entirely: configure rather than acquire.
- The service level expected. A one-off engagement, periodic support, or continuous monitoring do not draw on the same resources, and that choice is yours.
How does a proposal actually get built?
It always starts from the findings, never from a catalogue. We establish your real exposure and your obligations, we agree together on what is in scope and what is out, and only then do we describe the corresponding work. Pricing comes last, once those three points are settled.
What you receive sets out the deliverables, what stays on your side, the assumptions made, and what would change them. That last part matters as much as the rest: a proposal whose assumptions are unwritten is a proposal that will be revised without anyone being able to say why.
We also state what we will not do. Some requests belong to another trade (legal, insurance, application development)and saying so immediately avoids selling support that disappoints.
Finally, a proposal is not a disguised lock-in. Exit terms appear explicitly, because a security relationship held together only by a contract protects nobody.
When do we talk about money?
In the first conversation, as soon as the context is clear. We give orders of magnitude verbally, explaining what would move them, rather than deferring the question to a written proposal. You need to be able to judge early whether the subject is fundable this year.
Deferring the budget question is common practice and expensive for both sides. It burns weeks of discussion to arrive at a gap that would have been visible in the first fifteen minutes.
If the order of magnitude does not match what you can commit, two routes exist and we offer them plainly: narrow the scope to what removes the most risk for the least effort, or spread the work across several financial years. Neither is a failure.
Sometimes the honest answer is that we are not the right firm for you. We say so.
Frequently asked questions
Yes, and we are glad to, once we know what we are talking about: headcount, number of sites, sector, obligations, and what already exists. Five minutes of context is enough for an order of magnitude to mean something. Offering one beforehand, without those elements, would put forward a figure reality would contradict, which serves nobody.
No, and it commits you to nothing. It covers a conversation and a written summary of your principal exposure, which stays yours even if the discussion ends there. We consider this the only way to establish an honest scope: pricing without having looked would mean billing for a hypothesis.
That is often the better approach. Treating first what removes the most risk for the least effort produces a visible result quickly and lets you decide the next step on facts rather than intentions. Scope is revisited on an agreed date, in either direction.
We resell no licences. Where tools are required, you buy them directly from the vendor or your usual reseller, and we help you size what is genuinely useful. The separation is deliberate: it guarantees that our recommendations do not depend on our margin.
The initial phase (mapping, prioritization, implementation)is a distinct effort from ongoing support, and it is identified as such in the proposal. We do not bury it in a smoothed monthly figure: you need to be able to tell a one-off investment apart from a recurring cost.
Sources
- Commission d'accès à l'information du Québec · applicable obligations, which form part of the scope variables
- Canadian Centre for Cyber Security · baseline controls recommended to Canadian organizations
Is your infrastructure ready for the next threat?
An initial assessment, free and without commitment, to evaluate your security posture.