How much should a small business spend on cybersecurity?

There is no correct percentage. The figures that circulate — roughly a tenth of the IT budget, or somewhere under a couple of percent of revenue — are descriptions of what companies currently do, not prescriptions of what any particular company should do, and they include the firms that were breached. A defensible number is built from the other direction, in three pieces: a floor of obligations you do not get to decline, a ceiling set by your expected annual loss, and between them a short list of controls ranked by how much loss each dollar removes. For the worked example below, a 47-person accounting firm, that method produces roughly $27,750 a year — a figure the firm can defend line by line, which the benchmark could never have given it.

Why the percentage benchmarks are the wrong starting point

Benchmarks are seductive because they answer instantly, and they mislead for two structural reasons.

The first is circularity. An industry average is the average of everyone’s guesses, including the guesses of the organisations that later discovered they were wrong. It carries no information about whether that level of spending was adequate; it only reports what was spent. Anchoring on it is a way of adopting the median firm’s risk appetite without ever examining your own.

The second is that the denominator is the wrong quantity. Expressing security as a share of the IT budget ties it to the size of your technology estate, when what actually drives breach cost is the sensitivity and volume of the data you hold. A 40-person dental practice and a 40-person landscaping company can run near-identical IT: the same laptops, the same cloud suite, the same broadly similar spend. One of them holds health records and the other holds a customer list. Their exposure differs by a large multiple, and a percentage rule is blind to the difference — a point the underlying cost model makes precise in how data breach cost is calculated.

Public-sector guidance aimed at small firms, such as the NIST Small Business Cybersecurity Corner and the resources published by CISA, is notably reluctant to name a number for exactly this reason. It describes practices, not budgets, and leaves the sizing to the business — which is correct, and unhelpful if you are the one holding the spreadsheet.

The ceiling: what risk reduction can rationally be worth

Prevention cannot rationally cost more than the loss it prevents. That gives a hard upper bound, and the bound is your annual loss expectancy: the cost of one breach multiplied by how often you expect one. It is a ceiling on the risk-reduction portion of the budget specifically, and it is usually a much smaller number than people expect — which is itself informative, because it explains why small firms so often find that the security stack they were sold does not survive an honest return calculation.

Our 47-person accounting firm holds about 9,400 client records containing financial data. Its modeled single-breach cost is roughly $268,000, and the indicative annual breach probability for professional services is about 0.25. Its ALE is therefore 0.25 × $268,000 = $67,000 a year. That figure — not a percentage of anything — is the most that pure risk reduction is worth to this firm in a year, and in practice the sensible spend is well below it, because each control only removes a fraction of the loss.

The floor: spending that is not a return calculation

Before ranking anything by return, subtract the part of the budget that was never optional. If the firm takes card payments it inherits card-scheme requirements whose cost is a condition of processing, not an investment decision — and the consequences of falling short are contractual, as set out under PCI non-compliance cost. If it holds regulated categories of data it carries safeguard obligations; which regime attaches to which data is summarised, informationally, in which penalties apply to an SMB. Customer contracts increasingly carry security clauses of their own, and insurers attach conditions to cover.

None of this is legal advice, and the specific obligations of any given business need qualified counsel. The budgeting point is narrower and safe to state: obligations are priced, not justified. They belong in the total before the ROI exercise starts, and a control that appears on both lists — required and return-positive — is simply a control you were going to buy twice over.

Building the number bottom-up

The firm already spends about $23,500 a year on security embedded in its existing tooling and obligations. Four additions are on the table, priced on a fully loaded annual basis:

Candidate controls: annual cost against expected loss avoided
ControlAnnual costLoss avoidedNetROI
Multi-factor authentication$1,900$3,350+$1,45076%
Security-awareness training$2,350$2,680+$33014%
Tested incident-response plan$6,800$4,690−$2,110−31%
Endpoint detection and response$8,460$4,020−$4,440−52%

The loss-avoided column is the firm’s $67,000 ALE multiplied by each control’s indicative risk-reduction factor from the cost-mitigation factors dataset. Two results deserve attention, and the second is the one that usually gets suppressed.

First, the bundle does not pay for itself. Buying all four costs $19,510 a year and, because the reduction factors multiply rather than add, avoids only about $13,583 — a net loss of roughly $5,900 on expected-value grounds. The diminishing return is not a rounding artefact; it is the structure of the arithmetic, explained in the ROI of security controls. Adding controls to a shrinking residual loss gets less valuable every time.

Second, only part of the list clears the bar. Multi-factor authentication is comfortably positive, awareness training is marginally so, and at this ALE neither the incident-response retainer nor the endpoint platform pays back on expected value alone. Bought together, MFA and training cost $4,250 and avoid about $5,896 — a net gain of roughly $1,646, an ROI near 39%.

Floor (obligations, already committed): $23,500
Return-positive additions: $4,250
Defensible annual security budget: $27,750

That is not the end of the discussion about the incident-response plan and the endpoint tooling — it is the beginning of an honest one. Both may still be bought, for reasons the expected-value model does not price: a client contract that demands them, an insurer that requires them, or a judgement that the firm cannot absorb the tail. What the arithmetic has done is move them out of the “obviously worth it” column and into the column where somebody has to state the actual reason. That is the whole value of building the number bottom-up.

Where the tail goes

Expected annual loss deliberately averages across years in which nothing happens and the one year in which everything does. For a firm of this size the bad year is not a line item, it is an existential event, and no amount of expected-value optimisation addresses it. That is the specific job of insurance: it does not lower the average loss, it caps the worst case and converts an unpredictable exposure into a predictable premium. Weigh the premium against the retained risk — deductible plus anything above the policy limit — with the cyber insurance calculator, and treat that line separately from the ROI ranking, because it is answering a different question. Whether to quantify the underlying risks at all, and how, is the subject of quantitative versus qualitative cyber risk.

Now, and only now, check the benchmark

With a number in hand the comparison finally becomes useful. The firm’s total security spend of $27,750 sits against an IT budget of about $148,000 — around 18.7%, noticeably above the commonly cited band — and against revenue of roughly $8.4 million, about 0.33%, which is unremarkable. The two ratios disagree, and the disagreement is the point: the firm is data-heavy relative to its technology estate, so a share-of-IT rule overstates how aggressive it is being while a share-of-revenue rule looks placid. Neither ratio decided anything. They served as a check that nothing was wildly off, which is all a benchmark can honestly do.

Run the same three steps on your own figures: obligations first, an expected breach cost and probability to set the ceiling, then controls ranked by return until the next one stops paying. Small-business guidance from bodies such as the US Small Business Administration and the mitigation analysis published with the IBM Cost of a Data Breach report are useful inputs to that process, but the output belongs to your business, not to an average. A budget you can defend line by line survives the meeting; a percentage never does.

Frequently asked questions

What percentage of revenue should a small business spend on cybersecurity?

There is no correct percentage, and the commonly cited bands describe what firms do rather than what they should do. A useful way to read them is as a smell test after the fact: build the number from your own obligations and expected loss, then check where it lands. If it falls far outside the usual fraction of a percent to a couple of percent of revenue, you should be able to explain why — an unusual data holding, a contractual requirement, a recent incident.

Is there a minimum security budget for a small company?

Effectively yes, but it is set by obligations rather than by risk arithmetic. If you accept card payments, hold regulated data, or have signed customer contracts with security clauses, the cost of meeting those commitments is a floor you cannot optimise away. Below that floor the question is not whether the spending pays off but whether you can operate at all.

Should cybersecurity come out of the IT budget?

Accounting for it inside IT is convenient and slightly misleading, because it ties the size of the security budget to the size of the technology estate rather than to the sensitivity of the data. Two firms with identical IT spend can carry wildly different exposure. Wherever the line sits in the ledger, size it against expected loss and obligations, not against a share of another number.

Does cyber insurance replace security spending?

No — it addresses a different part of the problem. Controls reduce the expected loss; a policy caps the worst case and converts a volatile exposure into a predictable premium. Insurers also increasingly require specific controls as a condition of cover, which means the two line items interact rather than substitute. Weigh the premium against retained risk with the cyber insurance calculator.

How often should the number be revisited?

Annually as a matter of routine, and immediately whenever a driver of it moves: a jump in the volume or sensitivity of records held, a new regulated data type, an acquisition, a major contract with security obligations, or a near miss. The budget is a function of exposure, and exposure changes faster than most firms revisit the figure.

Disclaimer. BreachCostLab provides cost and risk estimates for informational purposes only, based on published industry benchmarks (e.g. IBM/Ponemon Cost of a Data Breach, Verizon DBIR) and publicly available statutory figures as of the verification date shown (Jun 25, 2026). These figures are estimates for planning, not a prediction of the cost of any specific incident, and are not legal, financial, insurance, or compliance advice. Actual breach costs vary widely; for regulatory obligations consult qualified counsel. Always verify current figures with the cited sources.