What cybersecurity actually costs a small business in Canada
What small businesses in Canada pay for security work, what changes the price, what to ask a provider, and what is worth doing before spending anything.
There is no single price for cybersecurity, and any provider who quotes one before understanding your setup is guessing. What small businesses actually buy falls into four categories, and they have very different price shapes:
- What your current tools already include. Multi-factor authentication, blocking legacy sign-in, and basic email protection are part of the Microsoft 365 licenses most businesses already pay for. This work costs staff time, not new licenses.
- A one-time assessment or review. A fixed scope, a fixed price, a written result. This is where most first engagements sit.
- Ongoing monitoring and maintenance. A monthly or annual arrangement to check logs, alerts, and configuration drift.
- Recovery. Help after an account or system has been taken over. Usually urgent, and usually priced differently from planned work.
The sections below use the prices we publish on our own services pages as one concrete example. They are not a market survey — other providers price per user, per device, or per year, and the total depends on what is actually covered. The useful part is the shape of the costs and the questions worth asking.
What a one-time assessment costs
A point-in-time review is the sensible first purchase for most small businesses, because it turns “how exposed are we?” into a written answer.
- An External Exposure Assessment looks at what a stranger can already see of your public systems. It is passive-only and needs no internal access. Ours is $400-$600.
- A Microsoft 365 Security Review & Hardening covers identity, email, sharing, admin roles, and recovery paths, with a staged plan for fixes. Ours is $750-$1,250.
- An Internal Security Review covers systems you choose and grant access to, with evidence for each finding. Ours is also $750-$1,250.
For any of these, the honest comparison is not the headline number — it is what the report contains and whether changes are included or quoted separately.
What ongoing security costs
Monitoring is usually the largest lifetime cost, because it repeats. Some providers charge per user per month; some sell an annual contract with a fixed scope. Ours, Monthly Security Care, is $200-$300 per month for a small Microsoft 365 tenant and covers sign-in and alert review, configuration drift, and outstanding actions — typically four to six hours of review per cycle.
Two questions matter more than the price here. First, what happens if you stop paying — do you lose access to logs, documentation, or tooling? Second, is the monitoring actually reviewing your environment, or is it an alert feed nobody has agreed to act on?
What recovery costs
Recovery is priced differently because the outcome is uncertain. Our Hacked Account Recovery is $99 for the assessment, plus $250 only if the account is recovered and you are back in control. Incident response for a business system is usually a separate, hourly engagement, and should be scoped before an incident, not during one.
What changes the price most
- Scale. Number of users, mailboxes, devices, domains, and sites in scope.
- Review versus change. Documenting a gap is faster than fixing it safely. A quote that includes changes should say how they are sequenced and verified.
- Licensing. Some controls require a higher Microsoft 365 tier. A good review flags the dependency instead of assuming you will upgrade.
- Who does the work. Owner-led or senior work is priced differently from work passed to junior staff. Ask who will actually be in your tenant.
- Documentation requirements. Cyber-insurance renewals, client security questionnaires, and compliance evidence all add reporting work.
- Urgency. Planned work is cheaper than emergency work. A short scoping call before anything is on fire is the cheapest hour in security.
Questions worth asking before you compare quotes
- What exactly is in scope, and what is explicitly excluded?
- What do I receive at the end — findings, fixed settings, both, or a handover document?
- Who performs the work, and are they the person on this call?
- What are the recurring costs after this engagement?
- What happens if I stop paying or switch providers — what do I keep?
- Do you resell any of the products you are recommending, and would you earn a commission on them?
- Have you done this for a business my size, in my industry, on my Microsoft 365 plan?
What is usually not worth paying for first
A penetration test before identity controls are fixed is the classic example: it tests defenses you already know are open. Certifications you do not yet need, long contracts you cannot leave, and fear-driven urgent purchases are the others. The Canadian Centre for Cyber Security’s top measures for small organizations are free and cover most of the ground most businesses need first.
A sensible spending order
- Turn on the protections your licenses already include: MFA, blocking legacy sign-in, basic email protection. Use our MFA guide or the Microsoft 365 audit checklist.
- Confirm recovery paths: who can restore mail, files, and access, and how long the window is.
- See what is publicly exposed. This is the cheapest way to find out what an attacker sees first.
- Have the tenant reviewed and hardened if no one is certain it matches how the business works today.
- Move to a regular cadence once the baseline is stable, not before.
If budget is the blocker, start with the British Columbia and Canada funding guide — some grants and training subsidies can offset part of a security project.
Sources