
What IT security costs an SME depends less on your size than on your mess. In our experience, two companies with 120 employees, same industry, comparable systems, can be a factor of two apart in their annual security spend. Not because one is better protected. Because one knows what it runs, and the other has to find out piece by piece.
The question itself is fair, and it comes up in the first ten minutes of almost every initial call. It is the standard answer that is of little use. Usually it goes: this or that percentage of the IT budget.
Why the percentage answers a good question badly
Benchmarks along the lines of "security should be X percent of the IT budget" sound like orientation. In practice they are of little use to an SME.
Figures like these almost always come from organisations with their own security function. A corporation with twelve people on the security team has a different cost structure than a Swiss manufacturer where the IT lead carries the topic on the side. The average across both worlds describes neither.
On top of that comes an arithmetic problem that is easy to miss. A percentage is a share of a number that was never examined itself. If your IT budget is too high because legacy systems keep running that nobody switches off, then eight percent of it is too much as well. If it is too low, eight percent is too little. You carry an error forward instead of finding it.
What hurts most in the budget discussion, though, is a different point: a percentage says nothing about whether the money buys protection. Two companies can spend the same amount. At one of them the overlapping coverage is paid for and was never configured, at the other less is running, but what runs is looked after. The invoice looks the same. The outcome does not.
That is why the question of IT security costs in an SME only gets you somewhere once you break it into blocks.
The four blocks that make up your IT security costs
The item everyone names first is licences and tools. Usually it is also the dullest, because a substantial part of it has long been paid for in Swiss SMEs. Anyone licensed for Microsoft 365 at a higher tier carries protective features in the subscription that were never switched on in the tenant. That money is already flowing out. The question is not whether you spend it, but whether you get anything for it.
The second block is operations, meaning the hours in which somebody looks, judges alerts, catches up on patches, cleans up permissions and decides when it matters. It is the largest block in almost every SME and visible in almost no budget, because it disappears into staff costs that are labelled differently. If you want to know what IT security actually costs you, work this one out first. How to organise those operations without a team of your own is described in running IT security without your own security team.
Then comes evidence: audits, certifications, customer questionnaires, insurance forms, documentation. Rarely large, but with one unpleasant property. It is driven from outside. A single enterprise customer who writes an ISO certificate into a tender can double it overnight. How this item breaks down in practice is covered in what ISO 27001 costs.
That leaves one-off projects. A stocktake, a migration, closing a gap you no longer want to ignore. These costs stand out because they arrive as a proposal, and they are the only block where you know in advance exactly what you pay. Our security assessment with implementation, for instance, costs CHF 9,800 at a fixed price, including an action plan and a stop list. We publish the price so you do not have to ask for it.
Put these four blocks side by side once and the picture is usually the same. Licences get overestimated, operations underestimated, evidence forgotten, and the debate is held over the one block that already sits on the table as a number.
The cost driver is mess, not the threat level
Now to the actual point, and it is unspectacular.
An SME's security costs follow the unclear inventory that keeps running, and barely follow the number of attacks out there. Devices nobody knows who looks after. An account still open since somebody left. Three products doing the same job, because each was sold in a different year by a different vendor. An alert that pops up every morning with nobody assigned to it.
Each of these pieces costs money, but almost never as a line on an invoice. It costs hours. And hours are more expensive than licences, because they fall on the person who has too few of them to begin with.
An example from a manufacturer we worked with, anonymised, but typical in its pattern. Three products ran on the endpoints that did essentially the same job. One had come along with a server project years earlier, one had been set by the previous service provider, one was included in the Microsoft subscription anyway. All three produced alerts. None was fully configured, because nobody felt responsible, and two of them slowed down production in certain situations. The most expensive part of this situation appeared on no invoice: it was the time the IT lead spent every month reconciling alerts against each other instead of working one of them through to the end.
That is also why cleaning up is cheaper than adding on in most SMEs. Once you know your inventory, you can merge tools, cancel duplication and put the freed-up time into operations. We described this in more detail in consolidating security tools and in right-sizing IT security instead of adding to it. In our experience the effect repeats reliably: protection goes up, effort goes down, and nobody had to buy anything new for it.
Honestly, this does not hold without limit. There are points where something is simply missing and money is the right answer. But you only find those points once the rest is sorted. Before that, you are buying blind.
The items where saving gets expensive
So that no wrong impression forms: this is not about pushing the security budget down as a matter of principle. It is about moving it to where it works. A few items are the worst saving candidates we know of.
Backup belongs on that list, more precisely the check of whether it can actually be restored. A backup that was never tested is an assumption with a maintenance contract. The same goes for identity, meaning multifactor sign-in and a clean process for joiners and leavers. That is the area with the best ratio of effort to effect, and in many subscriptions it is already paid for.
And then there is ownership, the least conspicuous item of them all. A task with no name next to it does not get cheaper. It just gets done later, usually on a day when that is inconvenient. Everything else can be up for discussion. These items we do not put up for discussion in our mandates, because cleaning up afterwards regularly costs more than keeping them in place beforehand.
Three questions that give you your own number
You do not need a market study for a solid number. You need three answers, and you can gather them in one or two days.
What are you already paying without booking it as security?
Go through the licence tiers, the contract with the IT service provider, the backup solution, the insurance premium. With most SMEs we work with, there is already an amount here that surprises people. It is rarely high. It had just never been added up.
Who does the work, and in what time?
Not in headcount, but in hours per month. Ask the person who actually does it, not the one who is accountable for it. The two answers are almost always apart, and the more honest one comes from below.
What will you have to prove next year?
A customer, an insurer, a supervisory body, a tender. If you can name something concrete here, you have a date and therefore a number. If not, the evidence block can stay small for now.
That is all it takes for a first order of magnitude. What comes after is prioritisation, and that is a different exercise.
The number to start with
If you take one thing from this piece: add up what you already pay today before you ask what you should additionally spend. That single number shifts the conversation more than any benchmark, because it comes from your own operation rather than from an average.
In most SMEs it leads to one of two realisations. Either you pay more than you thought and get less for it than you assumed. Or you pay less than you feared, and the distance to solid protection is shorter than expected. Both are a good starting position. Only uncertainty is not.
One question stays open here, and we have no general answer for it. At what point is it worth an SME outsourcing security operations for good rather than compressing them further in house? The threshold sits surprisingly far apart from company to company, and we have yet to find a criterion that predicts it reliably. Company size certainly does not.
If you want a second opinion on this calculation, get in touch. A first conversation is informal and costs you half an hour.
Frequently asked questions
What percentage of the IT budget should go to IT security?
There is no reliable percentage for an SME. Benchmarks like these mostly come from organisations with their own security function, and they express a share of an IT budget that was never examined itself. It is more useful to break your own costs into licences, operations, evidence and one-off projects.
Which cost block is the largest for IT security in an SME?
In almost every SME it is operations, meaning the hours spent judging alerts, patching, cleaning up permissions and deciding when it matters. This block appears in very few budgets because it disappears into staff costs labelled differently. Anyone who wants to know their security costs works it out first.
How can an SME reduce IT security costs without losing protection?
Clarify the inventory first, then merge tools and cancel duplication. In our experience cleaning up is cheaper than adding on, because the real costs fall in hours rather than in licences. Backup restore tests, multifactor sign-in and clear ownership remain the worst saving candidates.




