Back to Blog
Security Services17 min read

Cybersecurity Services: What They Cost, Who Sells Them, and What to Buy First

A

Founder and Principal Security Consultant - CISSP, CEH, CHFI, Mandiant

Cybersecurity Services: What They Cost, Who Sells Them, and What to Buy First

Buyer’s Guide · September 2026

Cybersecurity Services, Decoded

Four delivery models, six kinds of seller, and prices that vary by a factor of twenty under one heading. Here is what each service actually is, what it costs, and the order to buy in.

12

services priced

6

provider types compared

200+

assessments behind it

"Cybersecurity services" is one of the least useful phrases in business software, because it covers four completely different commercial relationships sold by six different kinds of company at prices that vary by a factor of twenty. A managed detection contract, a two-week penetration test, a fractional security leader and a team of contractors are all sold under that heading, and buying the wrong one is the single most common way security budget is wasted.

This guide sorts the category out. What the services are, what each costs, who sells them, what to buy first, and what to buy last. It is written by a firm that sells some of these services and not others, so where we are the wrong answer, that is said.

📌

Executive Summary

The short version

  • There are four delivery models: project work, managed services, retained advisory and staff augmentation.
  • There are six kinds of provider, and they are not interchangeable.
  • Most companies should buy in this order: free configuration work, one assessment, the fixes, then everything else.
  • Tooling should be last, and only against a gap an assessment actually named.
🧭

Delivery Models

The four delivery models

Before comparing providers, know which of these you are buying. The model determines who carries the risk, how you are billed, and whether the relationship ever ends.

The four delivery models for cybersecurity services: project, managed, retained advisory and staffing
The same service name can be sold under any of these four models. Ask which one is in the proposal.

The distinction that costs people most money is between project work and managed services. A penetration test is project work: it ends, and you own a report. Managed detection is a subscription: it does not end, and if you stop paying you lose the capability entirely. Both are legitimate. Confusing them at budget time is not.

💰

Price Bands

The services themselves, and what each costs

Indicative market ranges for a single-entity company of roughly 20 to 300 staff, buying from a competent independent or mid-size specialist. Large-brand consultancies typically run two to four times higher for the same scope, and enterprise scale moves everything.

ServiceModel What it answersIndicative cost
Security auditProjectWhat is exposed, ranked$5,000 to $25,000
Penetration testProjectCan this be broken into$4,000 to $30,000
Vulnerability managementManagedAre known holes closing over time$500 to $4,000/mo
Managed detection (MDR)ManagedWill anyone notice at 3am$15 to $60/endpoint/mo
Risk assessmentProjectWhich risks actually matter$6,000 to $20,000
Compliance readinessProjectWill we pass the audit$12,000 to $70,000
Virtual CISORetainedWho is accountable$3,000 to $15,000/mo
Incident responseProject or retainerWhat do we do right now$15,000 upward
Cloud security reviewProjectIs our tenant configured safely$4,000 to $20,000
Awareness trainingManagedWill staff click the thing$2,000 to $15,000/yr
Third-party riskProject or managedAre our suppliers a liability$8,000 to $40,000
Security architectureProjectWill this design hold up$10,000 to $50,000

These are indicative ranges gathered from the mid-market, not quotes. Anyone who gives you a firm number before asking what you run is guessing, and the guess will be padded.

📋

Service Catalogue

The services in detail

Security audit

The broadest assessment, covering identity, endpoints, cloud configuration, network, backup, policy and process. The output should name systems and fixes, not produce a maturity score. Buy it when nobody can answer how an attacker would get in, and buy it before anything else.

Expect two to four weeks, read access to your cloud tenant, and a few hours of interviews. A firm that needs neither is not looking hard. Ask whether retesting is included before you sign.

Penetration testing

A time-boxed attempt to break into a defined target, producing proof and attack paths rather than a list of theoretical weaknesses. Valuable when you have already done the basics, because a test against an environment without multi-factor authentication just confirms the obvious at consultant rates.

Scope precisely: one web application is a different engagement from an external network range, which is different again from an internal test including Active Directory. Ask whether the testing is manual or predominantly scanner output, because the price difference is largely the difference in human hours.

Vulnerability management

A programme rather than an event. Scanning is the easy part; the value is in triage, ownership and proof that the count goes down over time. Sold as a managed subscription, often bundled with tooling.

The failure mode is a monthly report nobody actions. Before buying, decide who internally receives the list and has authority to patch. Without that person, you are buying a recurring reminder of a problem.

Managed detection and response

Continuous monitoring with humans who act. Priced per endpoint or per user. The genuine case for buying is that 24-hour coverage requires a rota you cannot staff below a certain size.

Ask what "response" means contractually. Some providers alert you and stop; others isolate a host. The difference matters at 3am, and it is frequently ambiguous in the proposal. Ask for the mean time to respond, in writing, and what happens if they miss it.

Risk assessment

Risks identified, scored against your appetite and mapped to a framework. Distinct from an audit: an audit finds technical exposure, a risk assessment translates it into business consequence and priority. Often required by insurers and by frameworks like ISO 27001.

Compliance readiness

Getting you to the point of passing an external audit: SOC 2, ISO 27001, HIPAA, PCI DSS, DORA, NIS 2. Mostly evidence assembly and control gap-closing, driven by a date in someone else's contract.

Two rules save the most money. Sequence backwards from the deadline. And reuse evidence across frameworks, because SOC 2 and ISO 27001 overlap heavily, as do DORA and NIS 2 on incident reporting and third-party risk. Note that consultancies prepare you and accredited bodies certify you. Any firm implying it does both should be asked to explain precisely how.

Virtual CISO

A named accountable security leader on a part-time retainer. Makes sense roughly between 50 and 500 staff, where a full-time hire is disproportionate but having nobody accountable is exactly what customer questionnaires and insurers ask about.

Check you are buying decisions rather than a ticket queue. The deliverables should include board reporting, customer and insurer answers, and a roadmap that survives staff turnover.

Incident response

Containment, forensics, and handling the regulatory clocks. Buy the retainer before you need the response. The gap between calling a firm you have a contract with and cold-calling three firms on a Friday evening is measured in days, and days are what the cost is made of.

Most of the expensive part is decisions, not technology: who is in charge, whether to notify customers, what the insurer requires, whether backups work. An afternoon spent deciding those in advance is the highest-return hour in security.

Cloud security review

Your AWS, Azure, GCP or Microsoft 365 tenant assessed against a benchmark. Worth buying separately when the cloud is where the business actually runs, because a general audit will sample it rather than exhaust it. Microsoft 365 in particular ships with a large number of protective settings switched off.

Security awareness training

Role-specific training plus phishing simulation. Cheap, and one of the few services with a directly measurable output: click rate over time. Insist on role-specific content. Generic annual training that everyone clicks through changes very little.

Third-party and supplier risk

Assessing the companies you depend on. Increasingly demanded by regulators and by your own customers, who now ask what you do about your suppliers. The difference between a real programme and theatre is whether anything happens when a supplier scores badly.

Security architecture

Designing something so it does not need rebuilding in eighteen months. Bought at inflection points: a cloud migration, a new product, a merger, entry into a regulated market. The cheapest security work available, because it prevents rather than remediates, and the hardest to justify because nothing visibly breaks when you do it.

📈

Market Shift

What changed recently, and what it means for buyers

Three shifts are worth knowing about when you compare providers.

Insurers became de facto regulators. Cyber insurance applications now ask specific control questions, and the answers change both price and whether cover is offered. For many mid-size companies the insurer, not a regulator, is the entity effectively setting the security baseline.

Customer questionnaires moved down-market. Security reviews that used to apply only to enterprise vendors now reach companies of twenty people. This is the single most common trigger for first-time buyers, and it is why evidence assembly has become a service in its own right.

Regulation multiplied. DORA, NIS 2 and the Gulf and Asian regulator catalogues have pushed compliance readiness from a SaaS concern to a general one. The practical effect is that more buyers now arrive with a date rather than a worry, which changes what they should buy.

🌍

Geography

Regional variations worth knowing

Gulf and Asian regulators publish prescriptive control catalogues, and supervisors assess against the catalogue rather than a generic framework. An existing ISO 27001 programme typically covers half to two thirds of the work; the remainder is local, and it is exactly the part that gets examined: data residency, named officers, in-country reporting lines, specific evidence formats.

If one of these applies to you, the provider you pick should be able to name the document and its current version without looking it up: SAMA CSF and NCA ECC in Saudi Arabia, NESA, ADHICS and Dubai ISR in the UAE, Qatar NIA, MAS TRM in Singapore, HKMA C-RAF in Hong Kong, and DORA with threat-led penetration testing across the EU.

🏢

Provider Types

Who sells cybersecurity services, and what they are actually good at

Six kinds of company sell under this heading. Each is the right answer for someone.

Table of cybersecurity service provider types and what each actually sells
The mismatch between what a buyer needs and the provider type they approach is the root of most disappointment in this market.

Managed security service providers and MDR

These firms watch your environment continuously and respond when something fires. That is a genuinely hard capability to build in-house, because it requires people awake at 3am, and it is the clearest case for buying rather than building.

What they do not do is tell you whether your architecture is sound, whether your cloud tenant is configured properly, or whether you will pass an audit. An MDR contract on a badly configured environment produces a great many alerts about problems you could have designed out.

Buy MDR when you have something worth monitoring and nobody to monitor it. Do not buy it as your first security purchase.

CrowdStrike homepage
CrowdStrike. Endpoint-led detection and response, widely deployed and correspondingly well understood by insurers and auditors.
Arctic Wolf homepage
Arctic Wolf. Mid-market focused managed detection, often the first monitoring purchase a growing company makes.
Rapid7 homepage
Rapid7. Vulnerability management and detection, sold both as product and as managed service.

Large consultancies

Deloitte, PwC, KPMG, EY, Accenture. You are buying assurance that carries weight with boards, regulators and acquirers, plus the ability to field large teams across many countries. In the right situation that is worth a premium.

The trade is cost and staffing. Partners sell, managers scope, and much of the delivery lands with consultants early in their careers. For a company under a few hundred staff, this is usually the wrong shape.

Accenture cybersecurity services homepage
Accenture. The large firm most oriented toward building and running rather than advising alone.
Deloitte cyber homepage
Deloitte. Board and regulator credibility. Their site blocks automated capture, so this is a placeholder card.

Security specialist firms

Optiv, NCC Group, Kroll. Security is the entire business, so technical depth generally exceeds the large consultancies at similar or lower cost, and most carry genuine incident response capability.

Kroll cyber risk homepage
Kroll. Strongest where an incident may end in a dispute, an insurance claim or a regulatory filing.
NCC Group homepage
NCC Group. Deep technical assurance heritage, particularly in testing and product security.

Technical boutiques

Narrow catalogues, deep expertise. The right call when the work is genuinely hard rather than merely large: complex application testing, cloud-native architecture, assessments that must withstand scrutiny.

Bishop Fox homepage
Bishop Fox. Offensive security specialists, for when you need proof rather than a checklist.
Coalfire homepage
Coalfire. Compliance-weighted specialist, strong on FedRAMP, PCI and formal attestation.

Independent practices

One senior practitioner doing the work personally. Nothing is lost between the person who scoped the engagement and the person who delivers it, and pricing sits well below the large firms because there is no bench to carry. The limit is capacity: an independent cannot field ten people next Monday.

Atlant Security is in this group, so weigh the following accordingly. Alexander Sverdlov runs every engagement personally: former Microsoft Security Consulting team, CISSP, 200+ assessments across 14 countries since 2013, including banks, payment institutions, government bodies and critical infrastructure. Scope and price agreed in writing first; for assessments you read the report before an invoice is issued; no reseller agreements with any vendor. When the calendar is full the answer is a date, not a junior.

Atlant Security consultancy homepage
Atlant Security. Founder-led, fixed scope, no vendor commissions.

Product vendors

Palo Alto, Fortinet, Check Point, Microsoft and the rest sell software, usually with services attached to help you deploy it. That is the correct purchase when a tool genuinely is the answer, and the wrong one when it is being used to substitute for a decision nobody wants to make.

Palo Alto Networks homepage
Palo Alto Networks. Platform vendor. Their services exist largely to help you get value from the platform.
Fortinet homepage
Fortinet. Strong in network security hardware, common in mid-market and distributed estates.
🔢

Buying Order

What to buy first, and what to buy last

The sequence matters more than the individual choices. This is roughly the order that produces the most risk reduction per unit of spend.

The order to buy cybersecurity services for best return on spend
Tooling is last on purpose. Buying a product before an assessment means buying against a guess.

The first row is free and is where most small companies should start. Multi-factor authentication on every account, admin rights cut to a named few, a backup you have actually restored from, and control of what is reachable from the internet will close more real risk than most products you could buy. None of it requires a supplier.

What cybersecurity services to buy first depending on company size
Company size is a rough guide, not a rule. A regulated twenty-person firm buys like a much larger one.
🏭

By Industry

Cybersecurity services by industry

Industry changes which services are mandatory rather than optional, and that changes the order.

SectorUsually forced to buyBy whom
B2B SaaSSOC 2 or ISO 27001 readiness, pen testingEnterprise customers in procurement
Fintech and paymentsFramework programme, resilience testingThe regulator, then customers
HealthcareHIPAA work, risk assessment, BAAsRegulation and partner contracts
EcommercePCI DSS, application testingCard schemes and acquirers
Manufacturing and OTOT assessment, segmentation, IR planningInsurers and large customers
Professional servicesEmail security, awareness, backupInsurers, and invoice fraud losses
Public sector suppliersThe named scheme in the tenderThe tender itself
🔍

Vendor Selection

Nine questions that separate good providers from expensive ones

  • Who does the work, by name, and what happens if they are unavailable?
  • Is this project work or a subscription? If the latter, what happens when it stops?
  • What standard are you assessing against? A firm that cannot name one is improvising.
  • Is retesting included? Excluding it makes the headline cheaper and the total higher.
  • Do you hold reseller or partner agreements? A yes is not disqualifying. Not answering is.
  • Can I see a redacted deliverable? Good firms have one ready.
  • What is explicitly out of scope? The answer shows how carefully they scoped.
  • Who attends the debrief? If engineers are not invited, the fixes will not land.
  • What do you do if you find something critical on day two? You want a phone call, not a paragraph on page 40.
🚩

Buyer Beware

Six ways this goes wrong

  • Buying tooling first. A product bought before an assessment is bought against a guess, and it becomes the thing you defend rather than the thing you use.
  • Buying a pen test when you needed an audit. Testing an environment with no multi-factor authentication confirms what you already knew, expensively.
  • Treating the report as the outcome. The outcome is what changed six months later. Resource the follow-through before you commission the work.
  • Running overlapping frameworks separately. SOC 2 and ISO 27001 share most of their control work. Buying them as two programmes pays twice.
  • Confusing monitoring with security. Detection tells you something happened. It does not stop a misconfiguration existing.
  • Signing an annual contract before any work is delivered. Reasonable firms will start with something bounded.

The Honest Answer

Do you need cybersecurity services at all?

Sometimes the honest answer is not yet. A fifteen-person company with no regulated data, no enterprise customers asking questions and no incident history is usually better served by doing the free work properly than by commissioning anything. Multi-factor authentication everywhere, two admins, a tested restore, nothing unnecessary exposed to the internet, and a written note of who to call.

The trigger that changes this is external: a customer questionnaire, an insurance renewal, a contract naming a framework, a regulator with a date, or something that has already happened. When one of those arrives, buy. Until then, most spend is premature.

📅

Buying Process

Running the buying process without wasting three months

Most buyers approach this badly, not through incompetence but because they have never bought it before. A process that works takes about three weeks and costs nothing.

Week one: write down the trigger and the constraint

One paragraph. What happened, who is asking, what the deadline is, and roughly what you can spend. That paragraph is your scope brief, and it will save you more money than any negotiation. Providers quote wildly different numbers largely because they are quoting different assumptions, and a written brief removes most of that variance before it starts.

Include what you run: how many legal entities, which cloud, whether you host anything yourself, whether you build software, how many staff, and whether any regulated data is involved. Those six facts determine most of the price.

Week two: talk to three providers of different shapes

Deliberately pick one large firm, one specialist and one independent. You are not only collecting quotes, you are calibrating. The large firm will tell you what a thorough programme looks like. The independent will tell you what the minimum viable version is. The truth is usually between them, and you cannot locate it by talking to three firms of the same shape.

On each call, ask the nine questions listed earlier. Note which provider asks you the most questions back. That correlates with delivery quality more reliably than anything in the pitch deck.

Week three: compare like for like, then decide

Send all three the same written scope and ask them to price it including retesting. Ask each to name the person delivering. Quotes that appeared to differ by a factor of five usually land within a much narrower band once assumptions are fixed, and the remaining spread is genuine: brand, bench and risk appetite on fixed pricing.

Then decide on fit rather than price alone. The cheapest quote from a firm that will staff it with someone learning on your environment is not cheap. The most expensive quote from a firm whose name you need on the report may be exactly right.

📝

Contract Terms

What a fair contract looks like

  • Scope with explicit exclusions. Inclusions are easy to write. Exclusions are where honesty shows.
  • A fixed price, or a clearly capped rate. Open-ended day rates move all delivery risk to you.
  • Named deliverables and a named deliverer. Both should appear in the document.
  • Retesting stated either way. Included or excluded, but never unmentioned.
  • An escalation clause. What happens if something critical is found on day two.
  • Data handling terms. What they see, where it is stored, how long they keep it, what is destroyed at the end.
  • Sane notice periods. For anything ongoing, thirty days is normal and twelve-month lock-ins before delivery are not.
📊

Measurement

How to tell, six months later, whether it was worth it

The report is not the outcome. These are.

  • Somebody internal can name the top five risks without opening a document.
  • The findings that mattered are closed, and the rest have an owner and a date.
  • The next customer questionnaire took an afternoon, because the evidence already existed.
  • Your engineers can explain why a control exists, not merely that an auditor asked for it.
  • You know who to call at 6pm on a Friday, and they already hold your environment documentation.
  • Your insurance renewal was easier than the last one.

If none of that is true, the money bought a document rather than a change. The fault is usually shared: a provider who did not push hard enough, and a buyer who did not resource the follow-through. Fix the second and the first matters much less.

FAQ

Cybersecurity services: frequently asked questions

What are cybersecurity services?

Cybersecurity services are the work companies buy from external providers to assess, improve, monitor or defend their security. They fall into four delivery models: project work such as audits and penetration tests, managed services such as monitoring and detection, retained advisory such as a virtual CISO, and staff augmentation. The same service name can be sold under any of those models, which is why comparing providers is harder than it should be.

How much do cybersecurity services cost?

For a single-entity company of 20 to 300 staff: a security audit runs $5,000 to $25,000, a penetration test $4,000 to $30,000, compliance readiness $12,000 to $70,000, and a virtual CISO $3,000 to $15,000 per month. Managed detection is usually priced per endpoint, commonly $15 to $60 per endpoint per month. Large-brand consultancies run two to four times higher for equivalent project scopes.

What is the difference between cybersecurity services and managed security services?

Managed security services are one subset: someone runs something for you continuously, typically monitoring and detection, billed as a subscription. Cybersecurity services is the broader category and also includes project work that ends with a deliverable you own, retained advisory, and staffing. The practical difference is that project work leaves you with an asset, while a managed service leaves you with a capability that stops when you stop paying.

Which cybersecurity service should a small business buy first?

Usually none, until the free work is done: multi-factor authentication on every account, admin rights reduced to two named people, a backup you have actually restored from, and control of what is reachable from the internet. After that, the first purchase should be one independent assessment, so that everything you buy afterwards is aimed at something real rather than at a guess.

Do cybersecurity services include software?

Sometimes, and that is worth checking carefully. Some providers bundle licences into a service price, which can be good value or can be a way to carry reseller margin. Ask whether the fee includes software, what it would cost separately, and whether the provider earns anything from the vendor. None of that makes bundling wrong, but you should be able to see the components.

How do I compare quotes from different providers?

Make every provider price the same written scope, insist that retesting is either included or priced separately by all of them, and ask each to name the individual who will deliver the work. Quotes that looked five times apart usually converge once those three things are fixed, because most of the spread was differing assumptions rather than differing quality.

Are cybersecurity services worth it for a company under 50 people?

When there is a trigger, yes. A customer questionnaire, an insurance renewal, a contract naming a framework, or an incident all justify spend, and the cost of getting them wrong exceeds the cost of help. Without a trigger, a small company gets more risk reduction from configuration work it can do itself than from anything it can buy.

What is the difference between an MSSP and a cybersecurity consultant?

An MSSP runs a capability for you on an ongoing basis, usually monitoring and response. A consultant assesses, advises or builds, then leaves you owning the result. They are complements, not substitutes. An MSSP watching your alerts cannot tell you whether your architecture is sound, and a consultant's report does not watch your alerts at 3am.

How long do cybersecurity services take to show results?

Configuration fixes show up immediately, and they are where most early risk reduction comes from. An assessment takes two to four weeks to produce findings. Compliance readiness runs two to five months. Managed detection produces value from the first month, but only proves itself during an incident. If nothing has changed six months after a project, the money bought a document.

Can one provider do everything?

Large firms will say yes, and for very large organisations that can be true. Below a few hundred staff it is usually better to separate assurance from operations: one party assessing and advising, another running monitoring. A provider who assesses their own managed service is marking their own homework, and even with the best intentions that is a difficult position to hold.

What should be in a cybersecurity services contract?

A written scope with explicit exclusions, a fixed price or a clearly capped rate, named deliverables, who delivers them, whether retesting is included, what happens if something critical is found mid-engagement, data handling terms, and notice periods for anything ongoing. If a provider resists putting exclusions in writing, that is the clearest early signal available to you.

Where should cybersecurity services sit in the budget?

Most companies under 300 staff should expect security to be a small but non-zero line rather than a project spike, weighted toward one assessment and the fixes it names, with ongoing spend added only when there is something worth running continuously. Spikes usually mean the spend is being driven by an external deadline rather than by a plan, which is normal but more expensive.

🚀

Next Step

Where to start

Pick the line that sounds like your situation:

Or book a thirty-minute scoping call. You will leave knowing the three things most likely to be exposed in your environment, and whether you need to buy anything at all.

Start Here

Not sure which of these you actually need?

A 30-minute call is usually enough to name the one service that matters first for your situation, and to rule out the three you have been quoted for but do not need yet.

Book a 30-minute scoping call →

Last Updated: September 2026 · Author: , Founder and Principal Security Consultant

Pricing ranges reflect observed market rates in 2026 and vary by scope, geography and provider. They are indicative, not quotes.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. CISSP, CEH, CHFI and Mandiant certified. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.

Connect on LinkedIn