Skip to content

Typical costs

What this stuff actually costs.

Indicative UK pricing as of 2026. Ranges, not promises. Always get a current quote — SaaS prices move, and discounts apply for annual commits, charities, education, and bundles.

Productivity & identity

Line itemTypical costNotes
Microsoft 365 Business Standard~£14 / user / monthProductivity suite without security extras.
Microsoft 365 Business Premium~£19 / user / monthRecommended. Adds EDR, MDM, conditional access.
Google Workspace Business Standard~£12 / user / monthProductivity suite.
Google Workspace Business Plus~£18 / user / monthIncludes Vault for retention.
Password manager (Bitwarden Teams)~£3 / user / monthBusiness tier.
Password manager (1Password Business)~£6 / user / monthMore polished UX.
FIDO security keys (YubiKey)~£45 each, one-offFor admins and directors.

Backup & recovery

Line itemTypical costNotes
M365 backup (Veeam / Acronis)~£4–£8 / user / monthEssential. Microsoft doesn't back up your M365 data.
Server / endpoint backup~£15–£40 / device / monthDepends on volume.
Off-site / immutable storage~£0.02–£0.05 / GB / monthRansomware-aware target.

Security tooling

Line itemTypical costNotes
EDR (often bundled in M365 Premium)£0 if bundled, else ~£5 / device / monthDon't pay twice.
Phishing simulation training~£1–£3 / user / monthKnowBe4, Proofpoint, Hoxhunt.
Email security (advanced anti-phish)~£2–£5 / user / monthDefender for Office P2, Mimecast, Proofpoint.
Cloud SIEM (small SME)~£100–£400 / monthOften included in MSP package.

Certifications & assurance

Line itemTypical costNotes
Cyber Essentials (self-assessed)~£300–£700, one-off + annual renewalAchievable in weeks.
Cyber Essentials Plus~£1,500–£3,500, annualExternal technical check.
ISO 27001 (SME)~£10k–£40k year 1Heavier-weight.
Penetration test (web, SME)~£3k–£10k per testUseful annually for customer portals.

Insurance & response

Line itemTypical costNotes
Cyber insurance (£1m turnover)~£500–£2,500 / yearDepends on industry and security posture.
Cyber insurance (£5m+ turnover)~£2,500–£15,000 / yearWider range.
Incident response retainer (standalone)~£5k–£15k / yearOften bundled with insurance.

People & advice

Line itemTypical costNotes
Managed Service Provider (general)~£30–£60 / user / monthLower end = helpdesk; higher = security work.
Fractional / virtual CISO~£1k–£5k / monthA few hours a week.
Independent annual review~£2k–£8k, one-offOutside view, no MSP allegiance.