HireACISO

Cost of an in-house security team

A minimum credible in-house security function in Canada costs about $250,000 to $400,000 CAD a year at 100 people, and about $700,000 to $1.2 million at 500. Most of that is payroll, and most of the surprise is the tooling underneath it.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Standing up an internal security function in Canada costs roughly $250,000 to $400,000 CAD a year at 100 staff, $450,000 to $750,000 at 250, and $700,000 to $1.2 million at 500. Those figures are people plus the tooling and testing a function needs to be more than a job title. Audit fees for a certification sit on top, and are covered on fractional CISO cost.

Work this out before hiring anyone. The first hire is the cheapest part and the least useful in isolation. One security person with no tooling, no budget and no executive cover produces a list of things that are wrong and no authority to fix any of them. The number below is what it costs to avoid that outcome.

What does an internal security function cost by company size?

Annual cost of an in-house security function in Canada, CAD, by headcount
Company size Team shape People, loaded Tooling and testing Total per year
50 to 100 One security engineer, leadership bought in $155,000 to $215,000 $60,000 to $150,000 $215,000 to $365,000
100 to 250 Head of security plus one engineer $330,000 to $480,000 $95,000 to $220,000 $425,000 to $700,000
250 to 500 CISO, two engineers, one GRC analyst $620,000 to $880,000 $140,000 to $320,000 $760,000 to $1,200,000
500 to 1,500 CISO, five to eight across engineering, GRC and operations $1,150,000 to $1,900,000 $250,000 to $600,000 $1,400,000 to $2,500,000
Annual in-house security cost by company size Midpoint annual cost rises from about $290,000 CAD at 50 to 100 staff, to $560,000 at 100 to 250, to $980,000 at 250 to 500, and about $1,950,000 at 500 to 1,500. $290k $560k $980k $1.95M 50-100 100-250 250-500 500-1500 Company headcount CAD/yr
Midpoints of the total column above. Cost per employee falls as headcount rises, which is the whole reason the small end buys leadership rather than building it.

The people line, worked properly

Loaded cost is base plus bonus plus statutory employer cost plus benefits, which in Canada adds roughly 20 to 30 per cent to base at these salary levels. Recruiting is on top and is not annual, but at the turnover this field runs it recurs more often than a budget assumes.

Canadian security roles, base and loaded annual cost, CAD
RoleBaseLoadedWhat they actually do
CISO or head of security$190,000 to $290,000$240,000 to $380,000Owns the program, the budget and the board conversation
Security engineer$110,000 to $165,000$140,000 to $210,000Identity, logging, endpoint, cloud configuration, the actual fixing
GRC or compliance analyst$80,000 to $120,000$100,000 to $155,000Evidence, questionnaires, policy upkeep, audit coordination
Security analyst, detection$85,000 to $130,000$108,000 to $166,000Alert triage. Three of them do not make a 24 hour rota
Application security engineer$130,000 to $185,000$165,000 to $235,000Only worth hiring if you ship your own software

The rota arithmetic that kills the build case

Round the clock monitoring with your own staff needs a minimum of five to six analysts once you account for coverage, holidays, illness and attrition. At $108,000 to $166,000 loaded each, that is $540,000 to $1,000,000 CAD a year before tooling. A managed detection service covering the same hours for a mid-market company is a fraction of that. Almost nobody under 1,500 people should be building a rota, and companies that try usually end up with three tired analysts and gaps at three in the morning anyway.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The tooling line, which is where budgets break

Tooling is the part executives underestimate, because the people cost is visible on an org chart and the tooling arrives as fourteen separate invoices. The figures below are annual, Canadian dollars, for a 250 person company.

Annual security tooling and testing for a 250 person Canadian company, CAD
ItemLowHighSkippable?
Endpoint detection and response$15,000$40,000No
Identity, single sign-on and MFA tier$18,000$55,000No
Log aggregation or SIEM$20,000$90,000Scope it down, do not skip it
Vulnerability scanning$8,000$25,000No
Email security above what the suite includes$6,000$20,000Sometimes
Compliance or evidence platform$8,000$30,000Yes under 30 people, no once you are in an audit cycle
Security awareness training$3,000$12,000No, and see what to buy
Penetration test, annual$8,000$25,000No if a customer asks for the report
Backup and recovery above the platform default$6,000$28,000No
Tooling and testing, per year$92,000$325,000Before any audit fee

The high column is not a worst case. It is what you pay when tools are bought reactively one at a time, usually because a questionnaire asked for each of them. The low column is what a person who has done this before pays, by scoping the SIEM to what needs retaining and by using platform-included capability rather than buying a second one. The difference between the columns is roughly the cost of the leadership that avoided it.

When building is genuinely right

Building internally is the right answer when at least two of these are true.

  1. Security work is continuous rather than project shaped, because you ship software daily or run infrastructure customers depend on around the clock.
  2. Someone needs to be present, not merely available: incident command, a regulator on site, or a team that needs coaching rather than direction.
  3. You are federally regulated and the regulator expects a named senior accountable individual inside the institution. See OSFI regulated institutions.
  4. Security is part of what you sell, so the person leading it is in front of customers often enough that a fractional arrangement would be noticed.
  5. You are past about 500 staff, where the coordination load alone consumes a full-time person regardless of how good the tooling is.

Below those conditions, the common failure is not overspending. It is buying a single engineer, giving them no leadership and no budget, and then concluding after two years that security hires do not work. A blended arrangement, one engineer internally and leadership on retainer, is what most Canadian companies of 100 to 300 people should be comparing against, not a pure build. That comparison is on vCISO versus a full-time CISO, and the salary detail is on CISO salary in Canada.

The blended option, costed

Three ways to cover security at a 200 person Canadian company, CAD per year
OptionPeople costTotal with toolingWeakness
Full internal build: head of security plus engineer$330,000 to $480,000$425,000 to $700,000Four to seven months to hire, and single points of failure at both roles
Blended: one internal engineer plus a vCISO retainer$200,000 to $290,000$295,000 to $510,000The retainer has to be defended at budget time every year
Fully outsourced leadership and managed operations$95,000 to $200,000$190,000 to $420,000Nobody inside the company owns the outcome, which shows up in an incident

All of these numbers assume a company large enough to be building a team. At 20 to 50 people the equivalent cost is invisible rather than budgeted, absorbed as founder and engineering hours: 30 people and no security person puts a figure on it, and the first security hire covers whether the first person on this table should be hired at all.

Price the alternative before you approve the headcount

Send us the scope you were about to post as a job and we will put it in front of Canadian providers so the board sees both numbers.

Get matched

Common questions

How much does an in-house security team cost in Canada?

About $215,000 to $365,000 CAD a year at 50 to 100 staff, $425,000 to $700,000 at 100 to 250, and $760,000 to $1.2 million at 250 to 500. Roughly three quarters of that is loaded payroll and the rest is tooling and testing. Audit fees for a certification sit on top.

What is the first security hire we should make?

An engineer, not a leader, if you already have someone senior who can make decisions and defend a budget. A leader, if you do not. The failure mode is hiring one engineer with no leadership, because they produce a backlog of findings and have no authority to prioritise or fund the fixes. If leadership is what is missing, a retainer buys it faster and cheaper than a search does.

What percentage of IT spend should security be?

Commonly reported ranges put security at roughly 5 to 15 per cent of IT spend, with regulated financial institutions at the top of that and companies with no regulatory driver at the bottom. It is a sanity check rather than a target, because it rewards companies with bloated IT budgets. Benchmarks and better ratios are on security budget benchmarks.

Can one person be our whole security function?

Up to about 150 people, with modern platform tooling and a genuinely low risk profile, one strong generalist plus outside help for testing and monitoring can carry it. What one person cannot do is cover an on-call rota, be the sole approver of their own work, or go on holiday during an audit. Plan for the second pair of hands before you need it, even if the second pair is bought rather than hired.