What a 20 person company spends on security
About $20,000 to $60,000 CAD a year, not counting anyone's time, and the median company sits near the bottom of that. What separates the two ends is whether you sell to businesses that run security reviews.
A Canadian company of about 20 people should expect to spend $20,000 to $60,000 CAD a year on security, excluding staff time. That is the per-employee band on security budget benchmarks applied at 20 people. Building the budget line by line lands in the same place. A startup selling to consumers or small businesses lands near $20,000. A company selling to banks, hospitals or large enterprises lands near $60,000, and most of the difference is one penetration test and the advisory hours around it.
$20,000 to $60,000 Annual security spend at 20 staff, CAD, tools and services
$1,000 to $2,800 Per employee per year, the underlying band
The budget, line by line
Every figure is Canadian dollars a year for a 20 person software company on a major cloud provider with a single production environment. The low column is what a careful company pays. The high column is the same company once large customers start asking questions.
| Line | Low | High | Skip it if |
|---|---|---|---|
| Identity, single sign-on and multi-factor authentication | $2,000 | $6,000 | Never skip. This is the highest value line on the page |
| Endpoint protection and device management | $1,500 | $4,000 | Never skip, and check what your laptop vendor already includes |
| Password manager for the whole company | $600 | $1,500 | Never skip. It is the cheapest line here |
| Logging and alerting beyond cloud defaults | $1,200 | $5,000 | You can defer the paid tier, not the retention setting |
| Vulnerability and dependency scanning | $0 | $5,000 | The free tiers are genuinely adequate at this size |
| Security awareness training | $600 | $2,500 | You have fewer than 15 staff and do it in person |
| Cyber liability insurance premium | $3,000 | $10,000 | No customer contract requires it and you hold nothing sensitive |
| Backup and recovery beyond the default | $1,000 | $4,000 | Never skip. Test the restore, which is the part people skip |
| External penetration test | $8,000 | $15,000 | Nobody is asking for one yet, and then run it every second year |
| Outside advisory hours | $3,000 | $10,000 | You have no decisions pending that you have not made before |
| Total per year | $21,000 | $63,000 | Staff time is not in either column |
What to buy first, in order
If you have $5,000 CAD and not $30,000, the order matters more than the total. This one removes the most risk per dollar.
- Multi-factor authentication everywhere, especially on the cloud console, the email tenant and the code repository. Mostly a configuration change and the single largest reduction in real risk available to you.
- A password manager for everyone, with shared vaults replacing the spreadsheet and the pinned chat message.
- Backups you have restored from at least once, with the restore written down and dated.
- Device encryption and a managed way to wipe a lost laptop.
- An offboarding checklist that removes access the same day, run by someone other than the departing person's manager.
- Log retention turned up, before you need the logs rather than after.
- Cyber insurance, once a customer contract requires it or you hold personal information at any scale.
- An external penetration test, when a customer asks or when you have shipped something you cannot review yourselves.
The first six cost almost nothing beyond time, which is the point of what you can do with no budget at all. A company that has done those six and bought nothing else is in better shape than one that bought a compliance platform and did three.
What to leave until you are 50 people
| Purchase | Annual cost, CAD | Why it can wait |
|---|---|---|
| Compliance automation platform | $8,000 to $30,000 | It collects evidence for an audit. With no audit committed, it produces a dashboard nobody owns |
| Managed detection and response | $18,000 to $60,000 | Valuable, and it needs someone internally to act on what it finds at three in the morning |
| A monthly vCISO retainer | $36,000 to $72,000 | Under 25 people a small team rarely has enough to lead. Buy advisory hours against specific decisions instead |
| A security engineer | $140,000 to $210,000 loaded | Hands with no decisions to implement. See your first security hire |
| SOC 2 Type 2, your first audit | $40,000 to $90,000 first year | Worth every dollar when customers demand it, and pure cost when they do not |
The line most 20 person companies get wrong
Cyber insurance. The application is a control questionnaire, and companies answer it optimistically to get a better price. An inaccurate application is what an insurer points at when it declines a claim, which makes it the most expensive paperwork in the budget. Have the person who answers customer questionnaires answer the insurance application, the same way.
Build the number for your own company
Tell us your headcount, what you hold and who is asking. We will tell you which lines apply this year and which can wait, before you talk to anyone selling something.
Get matchedCommon questions
Is $20,000 CAD a year really enough for a 20 person company?
For a company with no regulated data, no large customers and no contractual security obligations, yes, provided the money goes to the top of the ordered list rather than to whatever was demonstrated most recently. The number stops being enough the moment a customer starts a security review, because that adds a penetration test and advisory hours in the same quarter and takes you toward the top of the range.
Should security come out of the engineering budget or its own line?
Its own line, even if it is small, because a line inside engineering gets spent on engineering when a release is late. The amount matters less than having a named owner who can spend it without a fresh approval each time. Under about $30,000 CAD a year, give the security owner discretion up to a few thousand dollars per item and review the total quarterly.
How much should we budget for a first SOC 2?
Between $40,000 and $90,000 CAD in the first year, all in, which includes the audit fee, readiness support, a platform if you buy one and the penetration test the auditor will expect. That is a separate budget from the one on this page and it should be triggered by customer demand rather than by a planning cycle. The full breakdown is on SOC 2 cost in Canada.
We have no budget at all this year. What do we do?
The first six items in the ordered list above, which are configuration and process rather than purchases, plus writing down who owns security. That is a genuinely defensible position for a 20 person company to be in, and it answers more questionnaire items than most paid tools do.
Does this include the cost of people's time?
No, and the time is usually larger than the budget. At 20 to 30 people security absorbs roughly 10 to 20 hours a month of senior technical attention, which is $11,000 to $31,000 CAD a year of loaded cost that never appears on a purchase order. The 30 person breakdown shows where those hours go.