How much do cyber security services cost in Australia?
In Australia, managed cyber security for a small business is usually bundled with IT support and priced per user, per month. Our published plans run $139 to $219 per user per month with a minimum of five users, and the tier is set by Essential Eight maturity level. Standalone services such as penetration tests are quoted per engagement, on top.
If you have tried to research this number, you have met the contradiction: one source says $100 to $500 a month, another says $50 to $100 per device, a third quotes hourly rates in US dollars. None of them is necessarily wrong. They are pricing different units, different scopes and different countries, which makes the comparison meaningless until you force everything into one shape: total dollars per month, for your headcount, with the included controls listed. The unit trick works in both directions, so do the conversion yourself rather than letting either salesperson do it for you.
Here is our shape, in the open. Fortress at $139 per user per month delivers the complete Essential Eight Maturity Level 1, the sensible floor for a business with anything worth stealing. Knox at $179 reaches Maturity Level 2, and Titan at $219 reaches Level 3. The security is bundled with the IT support because, at this scale, separating them creates gaps rather than savings. The five-user minimum also makes the entry point a knowable number: five users on Fortress is $695 a month, complete Maturity Level 1 included, and you can scale that to your own headcount in your head.
What pushes any quote up is mostly structure, not appetite: servers on site rather than cloud, multiple locations, contractual obligations such as DISP for defence suppliers, formal reporting, and after-hours requirements. What sits outside a monthly fee at most providers is also consistent: hardware, one-off projects, penetration tests, and incident response for businesses that were not clients when the incident started, which is the most expensive way to meet a security provider. None of these drivers is padding; each is real work with a real cause, and an honest provider can tell you exactly which ones apply to you and what removing them would change.
Be careful at the cheap end, and not for the reason salespeople say. When a quote sits well below the going rate, most buyers rightly suspect something has been left out. With security that instinct is usually correct, and better still it is checkable: the omission is almost always a control, and the Essential Eight gives you the neutral list to find which one. Ask the cheaper provider to mark their inclusions against the eight controls, and the difference stops being a mystery. That request is also the polite way out of a sales meeting: ask for the marked-up list, thank them, and compare at your own desk.
The same test defends you at the expensive end. A large quote wrapped in an enterprise brand is not automatically deeper protection; ask which maturity level it actually delivers, and what the extra buys beyond Maturity Level 2 that your business specifically needs. A ten-person firm with no defence contracts rarely needs Level 3, and a provider who cannot explain the gap between their price and their controls is charging for the logo. The logo test works on proposals too: count the pages about them against the pages about your controls.
The honest summary: for most Australian small businesses the real decision is between roughly our Fortress and Knox shape, whoever provides it, and the money questions worth asking are unit, inclusions and exclusions, not brand. Prevention is a known, budgetable number that appears on a monthly invoice; an incident is an unknowable one that arrives with a deadline. Most of what you are buying is the difference between those two kinds of number.
If you want to know what you would be paying to fix before anyone prices anything, our Essential Eight Cyber Security Scorecard is free and puts your gaps in writing, or call us on 1800 456 567.
One last comparison point worth insisting on: ask every provider what is excluded, not just what is included. The gap between two quotes is almost always sitting in the exclusions rather than in the feature list.
Anchor against real published numbers.
Three plans, three prices, and the Essential Eight maturity level each one delivers, all published so you can convert any competing quote into the same shape.
Other questions we are asked about this, answered the same way.
- 4 min
What is the difference between managed IT support and managed cyber security?
Managed IT keeps systems working; managed security keeps intruders out. Buying one and assuming it includes the other is how gaps happen.
Read the article - 2 min
What is the 80/20 rule in cyber security?
A minority of controls prevents the majority of incidents. Australia's version of the vital few has a name: the Essential Eight.
Read the article - 4 min
What are cyber security services, and which ones does a small business actually need?
Pen testing, SOC, MDR, incident response: the full menu decoded, and the short list a small business actually needs.
Read the article
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business