Security is the easiest thing in this market to sell badly, because the buyer cannot evaluate the product and the consequence of being wrong is invisible until it is catastrophic. Almost every proposal mixes three different purchases into one number: software that runs on your machines, monitoring that somebody is supposed to watch, and advice about what to do. They have different prices, different value and different failure modes, and separating them is most of the work of buying well.
The three things a security quote contains
Tools, watching and advice. Tools are software: endpoint protection, filtering, mail security, backup. Watching is people looking at what the tools produce, which is the expensive part and the part most often implied rather than staffed. Advice is somebody telling you what your risks are and what to do about them, usually sold as an assessment or a retainer. A quote that does not separate the three cannot be compared with another one, so ask for it as three lines before anything else.
What is probably already in your IT contract
More than most security proposals admit. A standard managed contract usually includes endpoint protection and its management, patching, mail filtering, backup and its testing, and administrative access control. Those are the controls that prevent the majority of ordinary incidents. Before buying a security package, ask your existing provider in writing which of the proposed lines it already performs, because paying twice for endpoint protection is a common and avoidable outcome.
Assessments: useful once, worthless annually
A risk assessment is worth buying when you do not know what you have or what would hurt: it should produce an inventory, a list of the ways in, and a prioritised set of things to fix with costs against them. It is worth much less as an annual ritual that produces the same document with a new date. Ask what the deliverable is, whether the findings come with remediation costs, and whether the firm doing the assessment also sells the remediation, because that is a conflict worth pricing in.
What this record can and cannot tell you
Of the 29 IT support providers read on 10 September 2026, seven publish a per-seat figure for the base managed contract and none publishes a separate figure for its security line. So this record can tell you what the underlying IT contract costs and cannot tell you what security adds, because the market does not publish it. Ask for it as a line, in writing, from every provider, and treat a refusal to separate it as information rather than as an inconvenience.
Questions people ask about cyber security services
What should be in a cyber security quote?
Three separated lines: the tools, the people watching them and their hours, and the advisory work. A single blended number cannot be compared with anything.
Is security included in managed IT?
Endpoint protection, patching, mail filtering and backup usually are. Monitoring with people behind it and advisory work usually are not.
Is a security assessment worth buying?
Once, if it produces an inventory, the ways in, and a prioritised fix list with costs. Much less as an annual document with a new date on it.
Do providers publish security prices?
None of the 29 read for this record publishes a separate security figure, though seven publish one for the base managed contract.