
Quick Answer
For most small businesses, a cyber security review from Systems Secure costs between £760 and £1,520 + VAT.
Our consultancy rate is £760 + VAT per day, and most reviews take between one and two days depending on the size and complexity of the business.
A smaller, straightforward business may only need one day. A business with more users, multiple sites, servers, remote access or a more complex setup may need two days or more.
We will agree the scope and expected cost with you before any work starts.
A small business owner once said to me, “I know we probably need to look at security, but I have no idea what something like that should cost.”
That is a fair question.
Cyber security can feel like one of those areas where pricing is not always clear. Companies talk about audits, assessments, penetration testing, Cyber Essentials, vulnerability scanning and managed security, while the business owner is left asking one simple question:
“How much is this actually going to cost me?”
The answer depends on the size and complexity of the business, but for most small companies, a practical cyber security review does not need to become a huge or expensive project.
At Systems Secure, most small business reviews take between one and two days, which gives us a fairly simple starting point for pricing.
The biggest factor is simply how much there is to review.
A small business with a handful of users, Microsoft 365, a few laptops, basic backups and one main office will usually take less time than a business with multiple sites, servers, remote workers, older systems or more complex access arrangements.
The scope of the review also matters.
Depending on the business, we may look at areas such as:
Email security
Microsoft 365 settings
User accounts
Multi-factor authentication
Administrator access
Backups
Device updates
Antivirus and endpoint protection
Firewall and remote access
Common security risks
Cyber Essentials readiness
For most small businesses, these checks can be covered within one or two days.
A full penetration test, detailed compliance audit or larger technical assessment is a different type of project and would be priced separately.
For a typical small business, a practical cyber security review will usually take between one and two days.
Systems Secure charges £760 + VAT per day for consultancy work.
That means a typical small business review will usually cost:
£760 + VAT for a one-day review
£1,520 + VAT for a two-day review
A smaller, straightforward business may only need one day. A business with more users, multiple sites, servers or a more complex setup may need longer.
We will agree the expected scope and cost before any work starts, so you know what you are likely to spend from the outset.
A basic checklist can be useful, but it only tells you so much.
It may ask whether multi-factor authentication is turned on. A proper review looks at how it is configured and whether there are gaps that could still leave accounts exposed.
It may ask whether you have backups. A proper review looks at whether those backups are protected, working and actually recoverable.
It may ask whether old users have been removed. A proper review looks at who still has access, who has administrator rights, and whether any accounts are creating unnecessary risk.
That extra detail is important.
Most small businesses do not have one huge security problem. More often, they have a number of smaller gaps that have built up over time. Individually they may not look serious, but together they can create a much bigger risk.
Not exactly.
Cyber Essentials is a recognised UK certification scheme that focuses on a set of important basic security controls, including firewalls, secure configuration, access control, malware protection and keeping systems up to date.
A cyber security review is broader.
Rather than working towards a specific certification, the aim is to understand where your business stands today, what your main risks are, and what should be fixed first.
For some businesses, a security review can also be a useful step before Cyber Essentials. It can help identify obvious gaps and give you a clearer idea of what needs to be addressed before you apply.
The aim of a security review is to give you a clearer understanding of where your business stands.
Depending on the scope of the review, we will explain the main findings in plain English and highlight any areas that need attention.
That may include:
Things that are already in good shape
Areas that could be improved
Issues that should be dealt with sooner
Lower-priority items that can wait
Practical next steps
The goal is not to produce a huge technical report. It is to give you useful information that helps you understand the risks and decide what to do next.
For many small businesses, yes.
If your business relies on email, stores customer information, sends invoices, uses Microsoft 365, has staff accounts or depends on computers to operate, then a security review can be a sensible way to identify weaknesses before they become bigger problems.
Think of it like servicing a vehicle.
You are not paying someone because the car has already broken down. You are paying someone to check the brakes, tyres, oil and warning signs so that potential problems can be spotted early.
A security review works in a similar way.
It gives you a clearer picture of your current security position, highlights areas that may need attention and helps you decide what should be improved first.
For many small businesses, spending a relatively small amount to understand their current risks is a sensible investment compared with discovering those weaknesses during a cyber incident.

Innovation
Fresh, creative solutions.


Excellence

Systems Secure® Limited·Registered in England and Wales, company no. 07295869 6 The Meadow, Copthorne, West Sussex RH10 3RG·07702 896 910·[email protected]
How to check you’re dealing with usServing Crawley, East Grinstead, Brighton and businesses across Sussex · UK-wide remote support
Copyright 2026. Systems Secure. All Rights Reserved.