All insights

How much do cyber security services cost in Australia?

4 min readBy Brendon Whiting, Founder · 29 June 2026

In Australia, managed cyber security for a small business is usually bundled with IT support and priced per user, per month. Our published plans run $79 to $199 per user per month with a minimum of five users, and the tier is set by Essential Eight maturity level. Standalone services such as penetration tests are quoted per engagement, on top.

If you have tried to research this number, you have met the contradiction: one source says $100 to $500 a month, another says $50 to $100 per device, a third quotes hourly rates in US dollars. None of them is necessarily wrong. They are pricing different units, different scopes and different countries, which makes the comparison meaningless until you force everything into one shape: total dollars per month, for your headcount, with the included controls listed. The unit trick works in both directions, so do the conversion yourself rather than letting either salesperson do it for you.

Here is our shape, in the open. Sentinel is $79 per user per month and configures the Essential Eight foundations that Microsoft 365 licensing already contains; it is honest groundwork, not full Maturity Level 1. Fortress at $139 delivers the complete Essential Eight Maturity Level 1, the sensible floor for a business with anything worth stealing. Knox at $179 reaches Maturity Level 2, and Titan at $199 reaches Level 3. The security is bundled with the IT support because, at this scale, separating them creates gaps rather than savings. The five-user minimum also makes the entry point a knowable number: five users on Fortress is $695 a month, complete Maturity Level 1 included, and you can scale that to your own headcount in your head.

What pushes any quote up is mostly structure, not appetite: servers on site rather than cloud, multiple locations, contractual obligations such as DISP for defence suppliers, formal reporting, and after-hours requirements. What sits outside a monthly fee at most providers is also consistent: hardware, one-off projects, penetration tests, and incident response for businesses that were not clients when the incident started, which is the most expensive way to meet a security provider. None of these drivers is padding; each is real work with a real cause, and an honest provider can tell you exactly which ones apply to you and what removing them would change.

Be careful at the cheap end, and not for the reason salespeople say. When a quote sits well below the going rate, most buyers rightly suspect something has been left out. With security that instinct is usually correct, and better still it is checkable: the omission is almost always a control, and the Essential Eight gives you the neutral list to find which one. Ask the cheaper provider to mark their inclusions against the eight controls, and the difference stops being a mystery. That request is also the polite way out of a sales meeting: ask for the marked-up list, thank them, and compare at your own desk.

The same test defends you at the expensive end. A large quote wrapped in an enterprise brand is not automatically deeper protection; ask which maturity level it actually delivers, and what the extra buys beyond Maturity Level 2 that your business specifically needs. A ten-person firm with no defence contracts rarely needs Level 3, and a provider who cannot explain the gap between their price and their controls is charging for the logo. The logo test works on proposals too: count the pages about them against the pages about your controls.

The honest summary: for most Australian small businesses the real decision is between roughly our Fortress and Knox shape, whoever provides it, and the money questions worth asking are unit, inclusions and exclusions, not brand. Prevention is a known, budgetable number that appears on a monthly invoice; an incident is an unknowable one that arrives with a deadline. Most of what you are buying is the difference between those two kinds of number.

If you want to know what you would be paying to fix before anyone prices anything, our Essential Eight Cyber Security Scorecard is free and puts your gaps in writing, or call us on 1800 456 567.

Anchor against real published numbers.

Four plans, four prices, and the Essential Eight maturity level each one delivers, all published so you can convert any competing quote into the same shape.

Frequently asked questions

Both units are defensible; the danger is comparing one against the other. A per-device price looks cheaper for a team where everyone has a laptop and a phone, then grows with every gadget. Per-user pricing follows people, which is usually how small businesses actually grow. Convert any quote to a total monthly figure for your real headcount and device count before comparing.

It is cheaper and it buys a different thing: a snapshot of where you stand, not protection. An audit or assessment tells you which controls are missing; someone still has to implement and run them, which is the monthly service. The sensible order is a baseline first, then ongoing protection sized to what it found.

Generally the opposite: insurers increasingly require specific controls, multi-factor authentication and tested backups among them, before they will write or renew a policy, and claims can fail when stated controls were not actually in place. Treat insurance as the backstop behind your controls, not a substitute for them.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.