Cost of an in-house security team
A minimum credible in-house security function in Canada costs about $250,000 to $400,000 CAD a year at 100 people, and about $700,000 to $1.2 million at 500. Most of that is payroll, and most of the surprise is the tooling underneath it.
Standing up an internal security function in Canada costs roughly $250,000 to $400,000 CAD a year at 100 staff, $450,000 to $750,000 at 250, and $700,000 to $1.2 million at 500. Those figures are people plus the tooling and testing a function needs to be more than a job title. Audit fees for a certification sit on top, and are covered on fractional CISO cost.
Work this out before hiring anyone. The first hire is the cheapest part and the least useful in isolation. One security person with no tooling, no budget and no executive cover produces a list of things that are wrong and no authority to fix any of them. The number below is what it costs to avoid that outcome.
What does an internal security function cost by company size?
| Company size | Team shape | People, loaded | Tooling and testing | Total per year |
|---|---|---|---|---|
| 50 to 100 | One security engineer, leadership bought in | $155,000 to $215,000 | $60,000 to $150,000 | $215,000 to $365,000 |
| 100 to 250 | Head of security plus one engineer | $330,000 to $480,000 | $95,000 to $220,000 | $425,000 to $700,000 |
| 250 to 500 | CISO, two engineers, one GRC analyst | $620,000 to $880,000 | $140,000 to $320,000 | $760,000 to $1,200,000 |
| 500 to 1,500 | CISO, five to eight across engineering, GRC and operations | $1,150,000 to $1,900,000 | $250,000 to $600,000 | $1,400,000 to $2,500,000 |
The people line, worked properly
Loaded cost is base plus bonus plus statutory employer cost plus benefits, which in Canada adds roughly 20 to 30 per cent to base at these salary levels. Recruiting is on top and is not annual, but at the turnover this field runs it recurs more often than a budget assumes.
| Role | Base | Loaded | What they actually do |
|---|---|---|---|
| CISO or head of security | $190,000 to $290,000 | $240,000 to $380,000 | Owns the program, the budget and the board conversation |
| Security engineer | $110,000 to $165,000 | $140,000 to $210,000 | Identity, logging, endpoint, cloud configuration, the actual fixing |
| GRC or compliance analyst | $80,000 to $120,000 | $100,000 to $155,000 | Evidence, questionnaires, policy upkeep, audit coordination |
| Security analyst, detection | $85,000 to $130,000 | $108,000 to $166,000 | Alert triage. Three of them do not make a 24 hour rota |
| Application security engineer | $130,000 to $185,000 | $165,000 to $235,000 | Only worth hiring if you ship your own software |
The rota arithmetic that kills the build case
Round the clock monitoring with your own staff needs a minimum of five to six analysts once you account for coverage, holidays, illness and attrition. At $108,000 to $166,000 loaded each, that is $540,000 to $1,000,000 CAD a year before tooling. A managed detection service covering the same hours for a mid-market company is a fraction of that. Almost nobody under 1,500 people should be building a rota, and companies that try usually end up with three tired analysts and gaps at three in the morning anyway.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
The tooling line, which is where budgets break
Tooling is the part executives underestimate, because the people cost is visible on an org chart and the tooling arrives as fourteen separate invoices. The figures below are annual, Canadian dollars, for a 250 person company.
| Item | Low | High | Skippable? |
|---|---|---|---|
| Endpoint detection and response | $15,000 | $40,000 | No |
| Identity, single sign-on and MFA tier | $18,000 | $55,000 | No |
| Log aggregation or SIEM | $20,000 | $90,000 | Scope it down, do not skip it |
| Vulnerability scanning | $8,000 | $25,000 | No |
| Email security above what the suite includes | $6,000 | $20,000 | Sometimes |
| Compliance or evidence platform | $8,000 | $30,000 | Yes under 30 people, no once you are in an audit cycle |
| Security awareness training | $3,000 | $12,000 | No, and see what to buy |
| Penetration test, annual | $8,000 | $25,000 | No if a customer asks for the report |
| Backup and recovery above the platform default | $6,000 | $28,000 | No |
| Tooling and testing, per year | $92,000 | $325,000 | Before any audit fee |
The high column is not a worst case. It is what you pay when tools are bought reactively one at a time, usually because a questionnaire asked for each of them. The low column is what a person who has done this before pays, by scoping the SIEM to what needs retaining and by using platform-included capability rather than buying a second one. The difference between the columns is roughly the cost of the leadership that avoided it.
When building is genuinely right
Building internally is the right answer when at least two of these are true.
- Security work is continuous rather than project shaped, because you ship software daily or run infrastructure customers depend on around the clock.
- Someone needs to be present, not merely available: incident command, a regulator on site, or a team that needs coaching rather than direction.
- You are federally regulated and the regulator expects a named senior accountable individual inside the institution. See OSFI regulated institutions.
- Security is part of what you sell, so the person leading it is in front of customers often enough that a fractional arrangement would be noticed.
- You are past about 500 staff, where the coordination load alone consumes a full-time person regardless of how good the tooling is.
Below those conditions, the common failure is not overspending. It is buying a single engineer, giving them no leadership and no budget, and then concluding after two years that security hires do not work. A blended arrangement, one engineer internally and leadership on retainer, is what most Canadian companies of 100 to 300 people should be comparing against, not a pure build. That comparison is on vCISO versus a full-time CISO, and the salary detail is on CISO salary in Canada.
The blended option, costed
| Option | People cost | Total with tooling | Weakness |
|---|---|---|---|
| Full internal build: head of security plus engineer | $330,000 to $480,000 | $425,000 to $700,000 | Four to seven months to hire, and single points of failure at both roles |
| Blended: one internal engineer plus a vCISO retainer | $200,000 to $290,000 | $295,000 to $510,000 | The retainer has to be defended at budget time every year |
| Fully outsourced leadership and managed operations | $95,000 to $200,000 | $190,000 to $420,000 | Nobody inside the company owns the outcome, which shows up in an incident |
All of these numbers assume a company large enough to be building a team. At 20 to 50 people the equivalent cost is invisible rather than budgeted, absorbed as founder and engineering hours: 30 people and no security person puts a figure on it, and the first security hire covers whether the first person on this table should be hired at all.
Price the alternative before you approve the headcount
Send us the scope you were about to post as a job and we will put it in front of Canadian providers so the board sees both numbers.
Get matchedCommon questions
How much does an in-house security team cost in Canada?
About $215,000 to $365,000 CAD a year at 50 to 100 staff, $425,000 to $700,000 at 100 to 250, and $760,000 to $1.2 million at 250 to 500. Roughly three quarters of that is loaded payroll and the rest is tooling and testing. Audit fees for a certification sit on top.
What is the first security hire we should make?
An engineer, not a leader, if you already have someone senior who can make decisions and defend a budget. A leader, if you do not. The failure mode is hiring one engineer with no leadership, because they produce a backlog of findings and have no authority to prioritise or fund the fixes. If leadership is what is missing, a retainer buys it faster and cheaper than a search does.
What percentage of IT spend should security be?
Commonly reported ranges put security at roughly 5 to 15 per cent of IT spend, with regulated financial institutions at the top of that and companies with no regulatory driver at the bottom. It is a sanity check rather than a target, because it rewards companies with bloated IT budgets. Benchmarks and better ratios are on security budget benchmarks.
Can one person be our whole security function?
Up to about 150 people, with modern platform tooling and a genuinely low risk profile, one strong generalist plus outside help for testing and monitoring can carry it. What one person cannot do is cover an on-call rota, be the sole approver of their own work, or go on holiday during an audit. Plan for the second pair of hands before you need it, even if the second pair is bought rather than hired.