I’ve sat across the table from two very different founders in the same month.
One had just signed a contract for an enterprise-grade security platform — the kind built for companies with a dedicated IT department and a seven-figure security budget. She was proud of it. She should’ve been; it looked impressive on paper. But three months in, she quietly admitted she wasn’t using a quarter of what she was paying for, and she still didn’t feel any safer. She just felt broke.
The other founder had nothing. No email filtering, no employee training, nothing beyond “we use a strong password, most places.” His logic wasn’t reckless — it seemed like enough to him. We’re too small. Nobody’s coming for us. He wasn’t lazy about it. He genuinely didn’t know what he didn’t know.

Neither of them was wrong to worry about cybersecurity. They were both wrong about the math.
That’s the trap almost every small business owner falls into: either you spend like you’re a target of nation-state actors, or you spend like you’re invisible. Both are guesses. Neither is a strategy. And if you know anything about me, I run on strategy.
Here’s the strategy: small business cybersecurity spending should be based on what an attack would actually cost you if it happened — not on fear, and not on hope.
The math nobody teaches you
Let’s talk about the attack we see most often with small businesses: phishing. It’s the front door for almost everything else, including ransomware — a phishing email gets an employee to click, and what follows is often a ransomware demand holding your files, your client data, or your ability to operate at all, hostage.
So let’s say — using industry figures, not any one client’s numbers — that a small business hit by a ransomware attack that started with a phishing email is looking at something in the range of $50,000–$250,000 to recover: forensic investigation, downtime, notifying clients, possibly a ransom, and the slow work of rebuilding trust.
Now let’s say a vendor is quoting you $40,000 a year for a security stack that’s built to stop threats far bigger than phishing — threats you’re statistically unlikely to face at your size.
We don’t just look at the cost of the recovery as a straight cost. We also have to look at the likelihood it is to happen in any given year. Let’s say that the likelihood of you getting hit with ransomware is 10%. This is to make our math easy and we are going to use the number $100,000 for the fix. The cost of attack is calculated at $10,000.
When we compare the $10,000 to the $40,000 a year security stack, that’s not protection. That’s overpaying for peace of mind you don’t actually have, because the stack you bought isn’t even aimed at your real risk.
Flip it: if your entire defense against phishing is “I hope my team doesn’t click the wrong thing,” and you have zero investment in training or filtering, you’re not saving money. You’re financing your own recovery costs later, at a markup, under duress, on the worst week of your year.
The framework: spend to the size of the risk

Smart small business cybersecurity spending doesn’t start with “how much security can I buy?” It starts with “what would this specific attack cost me, and what’s the smallest, smartest investment that meaningfully lowers that number?”
For most small businesses facing phishing and ransomware, that often looks less like a six-figure platform and more like: employee training that actually changes behavior, email filtering that catches what humans miss, and a response plan so that if something does get through, it costs you hours instead of weeks.
That’s the whole idea behind call me before you’re hacked, not after. Not because you need the biggest system on the market — but because you deserve a real answer to “what am I actually protecting against, and what does that protection need to cost?”
Small businesses aren’t small versions of enterprises. So why would your security spending follow an enterprise script?
In Part 2, we’ll get into exactly what that means: why the standard security playbook doesn’t fit small business reality, and how to figure out what your business actually needs — no guessing, no overpaying, no exposure you can’t afford.
Not sure what your number is?
That’s exactly what the Security Self-Assessment is for — and it’s free. Before you spend another dollar on prevention, let’s find out what you’re actually protecting — and what it’s really worth protecting it.







Leave a Reply