"How much should we be spending on cybersecurity?" is one of the most common questions a Canadian small business owner asks — and one of the least consistently answered. Ask three IT providers and you'll often get three different numbers, usually pitched as a percentage of revenue or a percentage of IT budget, both of which are directionally useful but incomplete on their own. A ten-person consulting firm and a ten-person manufacturing shop with the same revenue face very different actual risk, and a percentage-of-revenue number treats them identically. A clearer, more actionable planning number for most small businesses is dollars per employee per month — it scales naturally with headcount, it's easy to compare against real benchmarks, and it maps directly onto the tools and services that make up an actual cybersecurity budget.
This guide walks through why per-employee spending is often the clearer number, real benchmark ranges by industry and company size, what that budget needs to actually cover, the real cost of underspending, a simple worksheet to calculate your own starting number, three realistic Canadian case studies, and how to phase spending if you can't fund everything in year one. If you're a business owner or an office manager trying to build a real number for next year's budget conversation rather than guessing, this is built to be the reference you work from.
Who wrote this guide
This guide was written and reviewed by IT Cares certified technicians based on scoping and managing cybersecurity budgets for Canadian SMBs across a range of industries and headcounts. The benchmark ranges below are framed as general industry-cited planning ranges, not a guaranteed quote — your actual number depends on your specific systems, data sensitivity, and existing tooling, and should be confirmed against a real assessment of your environment.
Why "Percentage of Budget" Isn't the Whole Answer
The two most commonly cited cybersecurity budgeting benchmarks are percentage of total IT budget and percentage of revenue. Both are genuinely useful as a sanity check, and both are incomplete as a standalone planning tool for a small business — here's why.
Percentage of IT budget is the more commonly cited figure: industry benchmarks generally suggest cybersecurity spend falling somewhere between roughly 7% and 20% of total IT budget, with the wide spread reflecting genuine differences across industry risk and regulatory obligation. The problem for a lot of small businesses is that this ratio assumes a reasonably sized, formally tracked IT budget to take a percentage of in the first place. A 12-person company that spends $1,800 CAD a month on IT total doesn't have enough of a base number for a percentage calculation to produce a workable, granular budget — 15% of $1,800 is a single line item, not a real cybersecurity program covering seven or eight distinct categories.
Percentage of revenue runs into a different problem: it treats two businesses with identical revenue as having identical risk, which frequently isn't true. A ten-person accounting firm generating $2M CAD in annual revenue handles meaningfully more sensitive data per employee than a ten-person e-commerce fulfillment operation generating the same revenue, yet a flat percentage-of-revenue rule would assign them the same budget. Revenue is a proxy for company size, but it's a weak proxy for actual data sensitivity and risk exposure, which is what should really be driving the number.
Per-employee spending solves both problems reasonably well for a small business. It scales with the number of people actually creating risk exposure (every employee is a potential phishing target, a device that needs protecting, an account that needs access control), it maps directly onto how most of the underlying tools and services are actually priced (endpoint protection, email security, and awareness training are almost universally licensed per seat), and it produces a number granular enough to actually plan against, even for a very small business with a modest total budget. It isn't a perfect measure either — a business with a small headcount but a large number of servers or a complex compliance footprint will still need to adjust upward — but for the majority of Canadian SMBs, per-employee is the clearest starting number to plan from, which is why the rest of this guide builds around it.
📊 IT Cares field note: The businesses that struggle most with cybersecurity budgeting aren't the ones spending too little in absolute terms — they're the ones with no consistent method for arriving at a number at all, so the figure ends up set by whatever the previous year happened to cost, or by whichever vendor made the most convincing pitch. A repeatable per-employee framework, even an imperfect one, beats an ad hoc number every time.
Want your real number, not an industry average?
IT Cares' managed IT services bundle the categories in this guide into one predictable monthly cost, sized to your actual headcount and risk profile.
Benchmark Ranges by Industry Vertical
Risk isn't distributed evenly across industries, and a reasonable cybersecurity budget shouldn't be either. The ranges below are framed as general industry-cited benchmarks for planning purposes, drawn from the kinds of risk factors each sector typically carries — actual spend should always be adjusted against your specific data sensitivity and compliance obligations rather than applied as a fixed rule.
- Professional services and legal: Typically toward the higher end of the benchmark range. Confidentiality obligations (client files, privileged communications, financial records) and the reputational cost of a breach in a trust-based profession both push spending up, even for relatively small firms.
- Healthcare and dental: Typically toward the higher end, driven by the sensitivity of personal health information and the provincial privacy obligations (including PIPEDA at the federal level and provincial health information legislation) tied to handling it, plus the operational disruption cost of a clinic being unable to access patient records.
- Retail and hospitality: Generally moderate, largely driven by PCI DSS obligations for any business storing, processing, or transmitting payment card data, with additional consideration for point-of-sale system security and customer data handling.
- Manufacturing: Historically lower than other sectors, but rising quickly as operational technology (OT) and industrial IoT devices — often older, harder to patch, and historically excluded from IT security programs — become an increasingly common attack target and increasingly connected to the broader corporate network.
- Nonprofits: Typically underfunded relative to actual risk. Many nonprofits handle donor payment information, beneficiary personal data, and grant-funded financial records — a risk profile closer to professional services than the minimal-budget assumption many nonprofits operate under.
Per-Employee CAD Budget Benchmarks by Industry & Size
The table below combines both dimensions — industry vertical and company size tier — into a single planning reference. These are general benchmark ranges for a reasonably complete cybersecurity stack (not a bare-minimum antivirus-only setup), expressed in CAD per employee per month.
| Industry Vertical | Small (10-25 employees) | Medium (25-100 employees) |
|---|---|---|
| Professional services / legal | $100–$180 CAD/employee/month | $70–$130 CAD/employee/month |
| Healthcare / dental | $110–$190 CAD/employee/month | $75–$140 CAD/employee/month |
| Retail / hospitality | $60–$110 CAD/employee/month | $45–$85 CAD/employee/month |
| Manufacturing | $50–$95 CAD/employee/month | $40–$75 CAD/employee/month |
| Nonprofit | $35–$75 CAD/employee/month | $30–$60 CAD/employee/month |
Two patterns are worth calling out explicitly. First, every row drops moving from the small-business column to the medium-business column — this is the economies-of-scale effect covered in the next section, and it holds fairly consistently across industries even though the absolute numbers differ. Second, the nonprofit row sits meaningfully below every other vertical despite often carrying donor and beneficiary data comparable in sensitivity to retail or professional services — this is precisely the underfunding-relative-to-risk pattern worth correcting for rather than treating as a valid target to aim for.
Why Per-Employee Cost Falls as Headcount Grows
The pattern in the table above — medium businesses spending less per employee than small businesses, despite spending considerably more in absolute dollars — surprises some business owners the first time they see it, but the underlying reason is straightforward economics rather than anything counterintuitive about risk.
Most of the tools that make up a cybersecurity stack — a managed detection and response contract, an email security platform, a security awareness training subscription, even the labour cost of a managed IT provider's monitoring team — carry either a fixed cost or a cost that grows much more slowly than headcount. A 15-person company and a 90-person company both need essentially the same categories of protection and, in many cases, the same underlying platforms, but the 90-person company spreads shared infrastructure, minimum contract fees, and negotiated volume pricing across six times the users. Per-seat licensing on most security tools also drops meaningfully at higher volume tiers — a pattern common across SaaS pricing generally, not unique to security tooling.
There's a practical implication worth planning around: a very small business (under 15 employees) often faces the least favourable per-employee economics of any size tier, precisely because it's too small to benefit from volume pricing but still needs the same baseline categories of protection as a larger company. This is one of the reasons a managed IT/security retainer — where a provider spreads its own fixed costs (monitoring infrastructure, threat intelligence feeds, senior staff time) across many client businesses — often produces a better per-employee outcome for a very small business than trying to assemble the same stack from individually licensed point tools.
A useful mental model
Think of the fixed-cost categories (monitoring platform, threat intelligence, senior security oversight) as a shared roof over the business, and the per-seat categories (endpoint licenses, training seats, email security per mailbox) as the furniture inside it. The roof costs roughly the same whether it covers 15 people or 90 — which is exactly why per-employee cost falls as more people move in underneath it.
What Your Budget Should Actually Cover
A cybersecurity budget isn't one line item — it's a small portfolio of categories, each addressing a different failure mode. Skipping any one of these tends to leave a specific, predictable gap that attackers are actively looking for, since most real-world SMB incidents trace back to a category that was either unfunded or underfunded rather than a fully-resourced control that simply failed anyway.
Endpoint Protection / EDR
Modern endpoint detection and response on every device, not legacy signature-only antivirus. Our EDR vs antivirus comparison covers the technical difference — for budgeting purposes, treat this as a non-negotiable per-seat cost rather than an optional upgrade.
Email Security
Anti-phishing and anti-malware filtering layered on top of whatever your email platform (Microsoft 365, Google Workspace) provides natively. Native platform filtering catches the obvious threats; a dedicated email security layer catches the more targeted, better-crafted attempts that make up the majority of real business email compromise incidents.
Backup & Disaster Recovery
Backups satisfying the 3-2-1 rule, with at least one immutable or air-gapped copy, and a budgeted line for periodic restore testing rather than assuming a "success" notification means the data is genuinely recoverable. Our full business backup guide covers what a real backup program requires.
Security Awareness Training
An ongoing training platform for staff, not a one-time onboarding video. Since a large share of real incidents start with a phishing click or a social engineering call, this is one of the highest-return-per-dollar categories in the entire budget, and one of the easiest to underfund because it doesn't feel as tangible as a piece of software.
Managed Detection & Response (or a Managed IT/Security Retainer)
Active monitoring and response capability, not just alerting. A tool that flags a compromised device at 2 a.m. is only useful if someone — internal staff or a managed provider — is actually positioned to act on it quickly; this category is what turns detection into an actual response.
Cyber Insurance Premium
A financial backstop for the residual risk that remains even with good controls in place. Increasingly, insurers require evidence of the categories above (MFA, EDR, tested backups) before issuing or renewing a policy at all, which means this line item and the others aren't really independent — underfunding the controls tends to raise the cost or availability of the insurance meant to cover what's left.
Incident Response Reserve / Retainer
Either a budgeted cash reserve or a pre-arranged retainer with an incident response provider, so that the first hours of an actual incident aren't spent scrambling to find help and negotiate pricing under pressure. This is the category most frequently skipped entirely by small businesses, and the one that most consistently determines whether an incident becomes a costly inconvenience or a genuinely business-threatening event.
Cybersecurity Budget Planning Checklist
Below is a condensed, actionable checklist covering every category above — save it, print it, or copy it into your own budgeting document as a starting framework for next year's planning cycle.
Cybersecurity Budget Planning Checklist
Prevention & Protection
☐ Endpoint protection / EDR budgeted for every device, including remote and personal devices used for work
☐ Email security layer budgeted on top of native Microsoft 365 / Google Workspace filtering
☐ Backup & disaster recovery budget includes periodic restore testing, not just storage cost
People & Process
☐ Security awareness training platform budgeted as an ongoing subscription, not a one-time cost
☐ MFA enforcement confirmed at no or low additional cost within existing platform licensing
Detection & Response
☐ Managed detection & response service or managed IT/security retainer budgeted with real response capability, not alerting only
☐ Incident response reserve or pre-arranged retainer budgeted as its own line item
Risk Transfer & One-Time Costs
☐ Cyber insurance premium budgeted, with underlying controls confirmed to meet insurer requirements
☐ Initial security audit budgeted as a one-time cost if none has been completed in the last 12-18 months
☐ Total budget calculated per employee per month and cross-checked against your industry benchmark tier
Budget & Pricing: Concrete CAD Ranges by Stack Tier
Beyond industry and size, it's useful to think in terms of stack tiers — how complete a cybersecurity program you're funding, independent of company size. The table below breaks out three tiers, plus a separate breakdown of one-time versus recurring costs.
| Stack Tier | What's Included | CAD per Employee / Month |
|---|---|---|
| Starter / Essential | Basic endpoint protection, native email filtering, backup with no restore testing, MFA on core systems | $35–$60 CAD |
| Mid-Tier | EDR, dedicated email security layer, backup with quarterly restore testing, security awareness training, basic managed monitoring | $70–$130 CAD |
| Comprehensive | Full EDR + MDR with active response, dedicated email security, immutable backup with tested restores, ongoing awareness training, incident response retainer, cyber insurance | $140–$220 CAD |
Alongside the recurring monthly figures above, it's important to budget one-time costs separately rather than folding them into the per-employee recurring number, since they land in a single fiscal period rather than spreading evenly:
- Initial security audit: Typically $1,500–$6,000 CAD for a small business, scaling up with company size and scope — see our full IT security audit checklist and cost guide for a detailed breakdown.
- Backup system setup: Typically $800–$3,500 CAD as a one-time implementation cost to properly configure 3-2-1 backup infrastructure, before ongoing storage and monitoring costs begin.
- Security awareness training platform setup: Often bundled into the subscription cost, but if a custom onboarding or phishing-simulation baseline is required, budget an additional $500–$1,500 CAD one-time.
- Initial EDR/MDR deployment and tuning: Typically $500–$2,000 CAD one-time for a small business, covering initial rollout, policy configuration, and tuning to reduce false positives.
Recurring costs — licensing, the managed security service or retainer, the training platform subscription, and the insurance premium — are the ongoing monthly or annual figures reflected in the stack-tier table above, and are the numbers that should actually drive the per-employee budgeting worksheet in the next section, with one-time costs tracked as a separate capital or setup line.
Want a real number for your business, not a range?
IT Cares' managed IT services bundle most of the recurring categories above into one predictable monthly cost sized to your real headcount and risk profile — no guessing at what "enterprise pricing" means for a 20-person business. Our cybersecurity services and security audit can also be scoped independently if you'd rather build the stack piece by piece.
The Cost of Underspending
Every budget conversation eventually gets compared against the alternative: what happens, financially, if a business simply doesn't fund these categories and something goes wrong. Industry-cited ranges for small business ransomware and breach incidents vary considerably by severity and how well-prepared the business was going in, but a consistent pattern holds across published incident data: total cost — factoring in downtime, incident response, potential data recovery or ransom costs, client notification obligations, and reputational impact — regularly runs into the tens of thousands of dollars even for a moderate incident, and considerably higher for a severe one involving extended downtime or regulatory exposure.
Downtime specifically deserves its own mention, since it's often the least-anticipated cost. A business unable to access its systems, invoice clients, or fulfill orders for even a handful of business days can lose revenue at a rate that, annualized, would fund several years of a reasonable cybersecurity program many times over. Industry-cited estimates for small business downtime commonly place the cost per day well above what a full month of comprehensive cybersecurity spending would cost at the per-employee ranges in this guide — a comparison worth making explicit in any budget conversation, since it reframes the spend from "a cost" to "materially cheaper insurance against a larger, more disruptive cost."
These are general industry-cited ranges, not a guarantee for any specific business — actual incident cost depends heavily on how quickly it's detected, how well backups actually restore, and whether an incident response plan exists and has been rehearsed. But the direction of the comparison holds consistently enough across published SMB incident data that it's a reasonable basis for a budget conversation: a planned, controlled cybersecurity spend is consistently cheaper than the unplanned, uncontrolled cost of the incident it's meant to reduce the likelihood and impact of.
The Budgeting Worksheet: Calculate Your Own Number
Rather than adopting an industry average wholesale, use this four-step framework to calculate a starting number specific to your business.
Pick a base per-employee rate from your size tier
Use the mid-tier stack figures from the pricing table above as a reasonable base: roughly $100 CAD/employee/month for a small business (10-25 employees), or roughly $70 CAD/employee/month for a medium business (25-100 employees), as your starting point before industry adjustment.
Apply an industry risk multiplier
Adjust the base rate using a simple multiplier: ×1.3 to ×1.6 for professional services, legal, or healthcare; ×1.0 (no adjustment) for retail, hospitality, or general office-based businesses; ×0.8 to ×0.9 for manufacturing without significant OT/IoT exposure; ×0.6 to ×0.8 for nonprofits with limited sensitive data (adjust upward toward ×1.0 if handling significant donor payment data).
Multiply by headcount to get your monthly figure
Base rate × industry multiplier × total headcount = your recurring monthly cybersecurity budget. For example: a 20-person Quebec consulting firm — $100 base × 1.4 multiplier × 20 employees = $2,800 CAD/month, or roughly $33,600 CAD annually for the recurring stack alone.
Add one-time and reserve costs as separate line items
Layer an initial security audit, backup setup, and an incident response reserve on top of the recurring figure from step 3, tracked as a separate capital or contingency line rather than folded into the monthly per-employee number — these don't scale with headcount the same way and shouldn't be averaged into it.
This worksheet produces a starting point, not a final quote
Treat the output of this worksheet as the number to bring into a real conversation with a provider, not a figure to commit to blind. Your actual environment — number of locations, existing tooling already in place, specific compliance obligations — will move the real number up or down from this baseline.
Real-World Examples: Three Canadian SMB Budget Stories
These three examples are composite, illustrative case studies based on the kinds of budgeting decisions and outcomes common across Canadian SMBs — not accounts of specific named clients. They're included because concrete numbers make the abstract budgeting math above easier to picture in practice.
Case study 1: Fontaine & Associates, Quebec City, QC — 18 employees
Fontaine & Associates, a business consulting and bookkeeping firm, had been spending roughly $28 CAD per employee per month on a bare-minimum stack — basic antivirus and native email filtering, no dedicated training platform, no MFA enforcement beyond email. A near-miss — a staff member nearly wired funds to a fraudulent account after a convincing business email compromise attempt, caught only because a second employee happened to double-check the request by phone — prompted a full budget review. The firm moved to a mid-tier stack at $95 CAD per employee per month, adding EDR, dedicated email security, MFA enforcement on all financial systems, and quarterly awareness training. Total monthly spend rose from roughly $504 CAD to $1,710 CAD (18 employees), an increase of about $1,206 CAD per month, or roughly $14,470 CAD annually. Leadership approved the increase within two weeks of the near-miss, citing the specific dollar amount that had nearly been lost as the deciding factor rather than any general risk argument.
Case study 2: Ridgeway Fabrication, Hamilton, ON — 54 employees
Ridgeway, a metal fabrication and light manufacturing company, took a deliberately phased approach over 18 months rather than a single large budget increase, given competing capital priorities on the shop floor. Phase one (months 1-3): MFA enforcement and a proper 3-2-1 backup system with restore testing, budgeted at $9,800 CAD one-time plus $1,890 CAD monthly ($35/employee). Phase two (months 4-9): EDR deployment across all 54 endpoints plus office and shop-floor network segmentation to isolate older OT equipment, adding $2,970 CAD monthly (bringing the total to $65/employee). Phase three (months 10-18): managed detection and response service and a formal incident response retainer, adding a further $1,350 CAD monthly (bringing the total to roughly $90/employee, in line with manufacturing benchmarks for a medium-sized business). By month 18, Ridgeway had moved from an essentially unmanaged security posture to a comprehensive-tier stack, spread across three fiscal quarters in a way finance leadership could approve incrementally rather than as one large ask.
Case study 3: Cascade Outfitters, Kamloops, BC — 22 employees
Cascade, a small outdoor gear retail chain with three storefronts, used a version of the worksheet framework above to move away from an ad hoc security budget that had simply carried forward unchanged for three years. Using a $70 CAD base rate for a small retail business and a ×1.0 industry multiplier (given moderate PCI DSS exposure across their point-of-sale systems), the calculation produced a target of roughly $1,540 CAD monthly for 22 employees — about 40% above what they'd actually been spending. Reallocating budget toward point-of-sale-specific EDR coverage and a proper email security layer (their previous biggest gap, discovered when the calculation forced a category-by-category review) caught and blocked a targeted phishing attempt against their finance manager within the first two months of the new stack being active — a save the retailer's IT provider directly attributed to the newly added email security layer that the old, lower budget hadn't funded.
What these three cases have in common
None of these businesses started from zero, and none jumped straight to a comprehensive-tier stack overnight. Each moved from an under-specified or stale budget to a deliberately calculated one — triggered by a near-miss, a phased capital plan, or simply running the numbers for the first time in years — and each produced a specific, defensible dollar figure rather than a vague sense that "we should probably spend more."
Phasing Spending: A Prioritization Order for Cash-Constrained SMBs
Not every business can fund a comprehensive-tier stack in a single budget cycle, and trying to do so all at once is often what causes a budget request to get rejected outright rather than partially approved. A phased approach, prioritized by impact per dollar, tends to get approved more easily and starts reducing real risk from week one rather than waiting for full funding.
Phase 1 — near-zero and low-cost, do this first
Enforce MFA everywhere it's available within existing platform licensing (often free or already included in your Microsoft 365 or Google Workspace subscription), confirm backups actually restore with a real test, and work through the Canadian Centre for Cyber Security's free baseline controls. This phase costs mostly time, not budget, and closes some of the highest-impact gaps identified across the case studies above.
Phase 2 — foundational paid tooling
Modern endpoint protection (EDR) and a dedicated email security layer. These two categories are most directly tied to how ransomware and business email compromise actually get into a business, making them the highest-priority paid additions once the free/low-cost phase one items are in place.
Phase 3 — people and detection capability
Security awareness training and a managed detection and response service or managed IT/security retainer. These add real detection and response capability and address the human factor that technical controls alone can't fully close.
Phase 4 — risk transfer and formal response readiness
Cyber insurance and a formal incident response retainer, added once the foundational categories are funded and verifiable — since insurers increasingly require evidence of exactly those foundational controls before offering favourable terms, completing this phase last (rather than first) often produces a better insurance outcome anyway.
This order isn't arbitrary — it follows the same logic as Ridgeway Fabrication's phased approach in the case studies above: fund the categories that close the most likely, highest-impact gaps first, and treat later phases as building on a foundation rather than trying to build everything simultaneously. A partial stack funded in the right order reduces more real risk, faster, than an equally-sized budget spread thin across every category at once from day one.
Canadian Government & Business Resources
Several free, credible Canadian resources are worth building into any budgeting process, particularly for stretching a limited budget toward the highest-impact protections first.
- Canadian Centre for Cyber Security (Cyber Centre): Publishes the free Baseline Cyber Security Controls for Small and Medium Organizations at cyber.gc.ca — a genuinely useful way to close phase-one gaps at near-zero cost before any paid budget is committed.
- Business Development Bank of Canada (BDC): Offers cybersecurity assessment tools and, in some cases, technology financing that can be applied toward security improvements as part of a broader financing relationship — worth exploring at bdc.ca if a phased budget still needs a financing bridge for larger one-time costs like an initial audit or backup system overhaul.
- Innovation, Science and Economic Development Canada (ISED): Publishes guidance connecting small businesses with available cybersecurity programs and oversees CyberSecure Canada certification, a recognized standard worth working toward as your budget matures — see ised-isde.canada.ca.
- Office of the Privacy Commissioner of Canada (OPC): Publishes guidance on PIPEDA obligations relevant to budgeting for data protection controls, particularly useful for healthcare, professional services, and any business handling significant personal information — see priv.gc.ca.
None of these resources replace a properly budgeted, ongoing cybersecurity program — they're free starting points and financing avenues, not a substitute for the recurring spend covered throughout this guide. Used alongside the worksheet and benchmark ranges above, they give a Canadian business a solid foundation for building a defensible, right-sized budget rather than either overspending on an unnecessarily large program or underfunding one that leaves real gaps.
Frequently Asked Questions
Ready to Turn This Into a Real Budget for Your Business?
IT Cares' managed IT services bundle the categories in this guide into one predictable monthly cost, sized to your real headcount and risk profile — no guessing at industry averages.
Comments (3)
Ran our numbers through the worksheet and it matched almost exactly what we ended up approving after our own near-miss last year. Wish we'd had this framework sooner instead of guessing.
The phased approach section is exactly what our finance team needed to see. Getting one big number approved was a non-starter, but breaking it into three phases actually worked.
Didn't realize how far below benchmark we were until I actually ran the per-employee math. Email security was our biggest gap too, same as the Cascade example.
Leave a Comment