top of page

How much should Cyber Security cost?

Updated: Jul 1

This content is intended for Small to Medium Enterprises as Large Enterprise and OT operations have complexities that may not be sufficiently considered in the free Risk Assessment questionnaire or its report. Celtech do offer individual Risk Assessment for larger clients but at a negotiated price.


The answer is impossible because the question is wrong, its like asking how long is a piece of string. While the fun answer for the length of a piece of sting is "half as long as twice its length" the correct answer is it depends on what you are going to use it for.


The same applies to how much should I spend on Cyber Security. For example, f you were being paid $100,000 pa to guard a diamond worth $5,000,000:


10% of turnover is not a good formula-> $10,000 on alarms, cameras, and electronic locks may not be enough.


10% of the value of what you are protecting the same -> $500,000 would take you decades to pay back if you had business costs like wages and tax.


This is where a Risk Assessment steps in. Risk Assessments are not an exacting science, they are just a way of estimating in a smarter way. Risk Assessments help you clarify the questions you will have approximate, or actual answers to, and some where values are scientifically known.


Lets go back to our piece of string, If I am wanting to tie a piece of string around a parcel,

I would first get the parcel's measurements, if I didn't have the parcel yet I could get it from the Internet or the supplier, or make an educated guess.

I would then decide the style of tying, just once around the short side, a crossover, or multiple pieces tied separately. (now I am thinking about methods)

Then I would find the length of string I need for a knot, another call to the Internet will provide this, but which knot and why? Do I want to be able to untie it?


In Cyber Security there are many considerations that you need to consider and many you can ignore. For example, a hardware store probably does need to worry about the Russian Government trying to infiltrate their network, but a rare earth exploration company might. Even if you keep no private information about your clients, you have information required for you to operate. If you lost all of your tax, customer, supplier, billing, ordering, and warranty info, how badly would it impact your operations?


In line with our not-for-profit model Celtech have invested in CRAFT an in-depth cyber risk self assessment tool that is FREE to use. You fill in the answers as accurately as you can, and the report will advise you of the threats most likely to impact you. If you have, or can get, the know-how to respond to the report's recommendations, you are all done. If you appreciate that we offered this to you for free and you need some support, our not-for-profit models provides a variety of compelling reasons to consider choosing us to guide, support, or perform your uplift with you.


As part of Celtech's partnership philosophy and advice, we recommend our clients rerun CRAFT yearly. Celtech's continuous improvement plan means we update our tools to reflect changes in the cyber threat Landscape and as your business changes, your vulnerabilities and risks may benefit from reassessment too, and it is free to reuse.





Recent Posts

See All
Data loss; not always intentional

Cyber Security's has a strong focus on Confidentiality currently because it is newsworthy, but the loss of Integrity and Availability of your data, intentional or not, should be noteworthy. We are se

 
 
 
Consultancy vs Partnership

Learn how partnering with Celtech can benefit you long-term for less than the standard consultancy model.

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

© 2026 Celtech

bottom of page