2024 Cybersecurity Budget: Where SMB Money Goes
Security spending keeps climbing. Recent industry estimates put global cybersecurity spending well over US$200 billion a year, and it grows every cycle. Yet a majority of organisations still report at least one security incident in the past year, average breach costs keep setting records, and ransomware keeps landing despite all that investment.
Something isn’t adding up. For small and medium businesses, the uncomfortable truth is that the problem usually isn’t the size of the budget — it’s where the money goes. A surprising share of security spend buys no actual security at all.
Where security budgets leak
Three patterns account for most of the waste we see when organisations walk us through their current spend.
Shelfware: tools you pay for but barely use
Organisations buy security platforms, get through a partial rollout, and then use a fraction of what they licensed. Industry estimates commonly suggest that 30–40% of purchased security-tool capability goes unused. If you’re paying $100K for a platform and exercising $60K worth of it, that’s $40K a year evaporating — per tool.
The causes are predictable: nobody owned the implementation past go-live, the team that bought it left, or the tool demanded more tuning time than anyone budgeted for. The licence renews anyway.
Redundant tools: three products, one job
Stacks accumulate. A vulnerability scanner arrives with a compliance project, a second one comes bundled with an MSP contract, a third gets bought because an auditor mentioned it. Nobody ever rationalises the overlap, so you end up paying two or three times for the same coverage. One properly implemented scanner with full asset coverage beats three half-deployed ones — at a third of the cost.
Vendor-driven buying: solving the vendor’s problem, not yours
Some meaningful share of security purchases are driven by vendor marketing rather than an identified gap — the conference-booth buy, the “everyone in our industry uses X” buy, the renewal that auto-renews because questioning it takes effort. The tell: if you can’t name the specific risk a tool addresses and how you’d measure whether it’s working, it was probably sold to you rather than chosen by you.
Add these together and a meaningful fraction — often a third to half — of a typical security-tool budget isn’t improving anyone’s security posture. That’s the budget you get to reclaim.
What an SMB actually needs
Strip away the brand names and a complete security program for a small or mid-sized company comes down to a short list of capabilities:
- Visibility: centralised logging with detection rules and someone watching the output (SIEM/XDR)
- Vulnerability management: continuous scanning of your external and internal surface, with prioritised remediation
- Identity: single sign-on and multi-factor authentication in front of everything that matters
- Endpoint response: the ability to investigate a machine when something goes wrong (DFIR)
- People: phishing awareness training, because most incidents still start with an inbox
Every one of those capabilities has a mature open-source implementation — Wazuh, OpenVAS, Keycloak, Velociraptor — that competes head-on with commercial products costing ten to fifty times more. The catch is that open source trades licence fees for operational effort, which is exactly what a managed service absorbs.
An illustrative budget for a 50-person company
Illustrative budget — the figures below are representative, not a price list. Real pricing depends on your environment, asset count, and compliance requirements. Request a quote for numbers that apply to you.
Here’s what a complete managed open-source stack can look like for a 50-person company:
| Component | Capability | Representative annual cost |
|---|---|---|
| Managed Wazuh | SIEM/XDR — log collection, 3,000+ detection rules, continuous monitoring with senior on-call escalation | ~$5,500 |
| Managed Velociraptor | Endpoint forensics and incident response | ~$2,200 |
| Managed OpenVAS | Continuous vulnerability scanning | ~$1,200 |
| Managed Keycloak | SSO and MFA for a team this size | ~$600 |
| Phishing awareness training | Simulated campaigns plus training | ~$300 |
| Total | Complete core stack | ~$9,800 |
Compare that with the commercial equivalents — a commercial SIEM alone is commonly quoted in the high five to six figures annually at typical mid-market log volumes — and the arithmetic is straightforward. Counting only the licence fees it displaces, a managed open-source stack typically pays for itself within the first year. Identity is the sharpest example — Okta bills per user every year while managed Keycloak stays flat; the full Okta-pricing math is here.
No further claims needed. We’re not going to show you a fabricated ROI percentage, because honest maths doesn’t need one.
How much of your IT budget should go to security?
Common industry guidance puts security at roughly 10–15% of total IT spend for organisations that handle sensitive data or face compliance requirements, with some advisories suggesting less for low-risk businesses and more for regulated ones. Treat any percentage as a sanity check, not a target — these figures vary widely by source and sector.
The better question is coverage-based: do you have the five capabilities above, is each one actually operating (not shelfware), and is someone accountable for the output? An SMB with all five running well on a modest budget is in better shape than one spending triple on a stack nobody finished deploying.
Map the stack to the services
If you want to see what each component looks like as a managed service:
- Managed security overview — the full stack, how the pieces fit together, and what “managed” actually includes
- Managed Wazuh — the SIEM/XDR layer; if you’re currently on a commercial SIEM, read why you’re probably paying 5x too much for SIEM first
- Managed OpenVAS — continuous vulnerability scanning
- Managed Keycloak — SSO and MFA without per-user pricing
And before you spend anything: run the free external security audit to find your gaps first. It’s a zero-touch passive scan of your public-facing surface — knowing where you’re actually exposed is the cheapest budget-allocation tool there is.
FAQ
What percentage of IT budget should go to cybersecurity?
Common industry guidance lands around 10–15% of IT spend for organisations with meaningful data or compliance exposure, but published figures vary widely by source, sector, and risk profile. Use the percentage as a rough sanity check; prioritise covering the core capabilities (visibility, vulnerability management, identity, endpoint response, training) over hitting a number.
How much should a 50–100 person company spend on security?
It depends on your environment, but with a managed open-source stack, complete core coverage for a company that size typically lands in the low five figures annually — far below the commercial-stack equivalent. The illustrative budget above shows representative figures for a 50-person company; request a quote for real numbers matched to your environment.
Is open-source security really cheaper once you add management?
Usually yes, by a wide margin — but be honest about why. Open-source tools eliminate licence fees, not operational effort. If you run them yourself, you pay in engineering time instead. A managed service puts the operational cost back on the bill, and the total still typically comes in well below commercial licensing alone, because you’re paying for expertise once rather than for per-seat or per-gigabyte licences forever.
What security tools can an SMB safely cut?
Start with the overlap: if two tools scan for the same vulnerabilities or collect the same logs, keep the better-deployed one. Then audit shelfware — any tool nobody has logged into in 90 days is a candidate. What you should not cut: log visibility, MFA, vulnerability scanning, and backups. Those are the capabilities that determine whether an incident is an inconvenience or a catastrophe.
Get an honest read on your budget
If you’d like a second opinion on where your security spend is going, we’ll give you one without a sales pitch: start with the free external audit to see your real exposure, then contact us or email sales@thinsky.com for a budget review — what you’re paying for, what’s overlapping, and what a managed open-source stack would cost in your environment.