How much does a security assessment cost? Honest numbers for SMEs

The question almost always comes first

"How much does a security assessment actually cost us?"

Usually, it comes at the end of a conversation, a bit hesitantly, as if the answer might be embarrassingly high. And to be honest, we understand. You've probably already seen a few offers that differ by a factor of five, seemingly for the same thing. One wants three days, the other three weeks. You rightly wonder if you are being ripped off.

So let's set the record straight. We are talking here about the real security assessment costs for a Swiss SME, what they consist of, and how you can recognize whether an offer is fair or just expensive. No sales pitch, but what we would tell you over the kitchen table.

Why there is no price list

A security assessment is not a standard service like an oil change. It is an investigation, and the depth of the investigation determines the price.

Imagine two companies. One has twenty employees, everything runs on Microsoft 365, no proprietary server in the basement, no proprietary software. The other has one hundred and fifty people, three locations, a self-developed application, and a manufacturing operation with machines connected to the network. Both ask for a security assessment. Both get completely different numbers, and that is exactly how it should be.

The price follows the attack surface, not just the company size. The more systems and custom development involved, the more time someone needs to review it seriously. And time is almost the only cost driver in an assessment, because the work happens in the mind and in the systems, not in the supply room.

That is why no reputable provider will give you a number over the phone without asking a few questions first. Anyone who quotes you a fixed price without looking at your environment is selling you a package, not an assessment. That doesn't have to be a bad thing, but you should know that the number then comes from a price list rather than from your actual risk.

The rough range

Still, you want a ballpark figure. Fair enough. Here is what we see in practice, always as a rough orientation, never as an official quote.

A compact assessment for a small, tidy SME that runs essentially on a cloud platform often falls within the range of just a few daily rates. You get a structured inventory, the biggest gaps identified, and a prioritized list of what to address first. This goes surprisingly far when the environment is manageable.

If it gets larger, with multiple systems, custom infrastructure, regulatory requirements like the revised Data Protection Act, or demands from enterprise customers, you quickly find yourself in the mid-five-figure range. For that, you also get more: technical checks, interviews with the people who operate the systems, and a look at processes, not just technology.

And then there are the quotes that are significantly higher. Sometimes with good reason, when there is really a lot to check. Often, however, because the assessment is intended as a foot in the door for a larger project. That is precisely where it is worth asking questions, and we will get to that in a moment.

If you want to compare the assessment figures with the ongoing costs of a security function, we have calculated this in the article on the costs of a CISO in Switzerland.

What really drives the price

Three things make the difference between a cheap and an expensive assessment, and none of them is the provider's name.

Scope is the first. Are you only checking the technical configuration, or also how security is handled within the company? A pure technology check is faster and cheaper. However, it often overlooks precisely the things that hurt in an emergency—such as nobody knowing who makes decisions in a crisis.

Depth is the second. There is a big difference between "we look at whether the important protective measures are in place" and "we actively try to break into your systems". The second is closer to a penetration test, takes longer, and costs more. Which variant you need depends on where you stand. We have written down the difference between an assessment and a penetration test separately, because many SMEs buy the wrong thing first.

The third is the report preparation. A report that only a technician can understand is cheaper to create than one that your executive management can actually use. And yet, you want the second one. An assessment that ends up in a drawer because nobody reads it is the most expensive one you can buy, regardless of the price.

The most expensive mistake: the assessment as a shopping list

For many providers, the security assessment is not a goal, but a sales channel. At the end, there is a report with red-flagged gaps and, what a coincidence, exactly the products and services that the same provider happens to sell. The assessment becomes a shopping list. The more red in the report, the larger the follow-up business.

We deliberately sit on the other side. In our experience, many SMEs spend too much on security, not too little, and the problem is rarely a missing tool. It is three overlapping tools for the same task, licenses that nobody uses, and measures that only exist because someone bought them at some point.

A good assessment finds exactly that. It shows you where protection is lacking and where you are paying twice. It is just as ready to say "you can turn this off" as "you urgently need this". We have seen environments where the assessment ended up freeing up more budget than it tied down, because it became clear what was security theater and what was real protection. If you are interested in this idea, the same principle lies behind our post on why fewer tools often mean more protection.

So the honest measure of an assessment is not how many gaps it finds. It is whether you have a clearer understanding afterward of what is worth your money and what is not.

A practical example

A production company from Central Switzerland, with around eighty employees, came to us with a quote in the high five-figure range. The provider had proposed a large, technical assessment, including a series of new tools that would have been sold directly at the end. On paper, it looked thorough.

We first invested a few days just to understand where the real risk lay. The result was inconvenient for the original quote: the vast majority of the proposed audit targeted systems that played almost no role in operations. The real risk was elsewhere. It lay in the access permissions of external service providers, which no one was keeping track of, and in a backup that had been silently failing to run for months.

In the end, the appropriate assessment was smaller and much sharper than what was on the table. It cost less and delivered more because it tested the two things that would have paralyzed operations in a real emergency. That is exactly what dimensioning is about. Not checking as much as possible, but checking the right things. And that is almost always less than the initial proposal suggests.

How to recognize a fair offer

You don't have to be a security expert to distinguish a good offer from a questionable one. A few questions are enough.

Ask what specifically is being checked and what is not. A reputable provider defines the scope clearly instead of throwing around the word "comprehensive". Comprehensive is a word, not a scope.

Ask what you will have in your hand at the end. A prioritized report with concrete next steps? Or just a list of tools? Ask to see an anonymized example before you agree.

Ask how independent the recommendations are. Does the provider sell the solutions they recommend to you? This doesn't have to be a dealbreaker, but you should know it and read the report accordingly.

And ask about experience with companies of your size. An assessment approach designed for a large corporation fits an SME about as well as a suit three sizes too big. It costs more and fits worse.

If you like, you can find our view on pragmatic security work on our Cybersecurity page. The common thread is the same everywhere: properly dimensioned instead of maximally sold.

Before you sign the next offer

If you only take away one thing from this text, let it be this: the cost of the security assessment is not the real question. The real question is whether the assessment fits your actual risk and whether it enables you to make better decisions afterward than before.

A cheap assessment that tests the wrong things is expensive. A more expensive one that shows you what you can safely leave out often pays for itself in the very first year.

Take the next proposal on your desk and ask the four questions above. If the answers remain vague, you know enough.

And if you want a second, independent opinion before you sign: a brief initial consultation costs you nothing but half an hour, and sometimes exactly that half-hour saves a whole lot.