Cyber security services cost different amounts because an external penetration test, a Microsoft 365 monitoring service and an ISO 27001 program solve different problems. The number of users is only one factor. Devices, cloud platforms, locations, log volume, compliance obligations, response hours and the condition of your current controls can change the work substantially.
This 2026 guide explains how Stanfield IT scopes cyber security pricing in Australia, what a genuine Stanfield proposal included, which pricing models are common and how to compare two proposals fairly. Review our complete Cyber Security Services offering. It covers assessment, managed detection and response, vulnerability management, penetration testing, Essential Eight, ISO 27001 support and incident response.
Direct answer: a genuine anonymised Stanfield IT proposal issued in April 2026 for an Australian organisation with approximately 130 users priced managed Microsoft 365 security monitoring at $75 per user per month, managed awareness training at $9 per user per month, a quarterly phishing simulation program at $125 per month, security reporting at $150 per month, and optional cyber incident response at $250 per hour. The managed cyber subtotal was $11,195 per month excluding GST.
This is one real proposal, not a market average, fixed package or promise of what another environment will cost. Fixed-project work such as risk assessments and penetration tests is quoted after scope is confirmed.
| Quoted service | 2026 Stanfield proposal price | Quantity | Extended monthly price |
|---|---|---|---|
| Managed Microsoft 365 security monitoring | $75/user/month | 130 users | $9,750 |
| Managed cyber security awareness training | $9/user/month | 130 users | $1,170 |
| Quarterly phishing simulation program | $125/month | 1 program | $125 |
| Managed security reporting | $150/month | 1 report | $150 |
| Managed cyber security subtotal | Equivalent to $86.12/user/month across this scope | Approximately 130 users | $11,195 ex GST |
| Optional ad-hoc cyber incident response | $250/hour | As approved | Not included in the monthly subtotal |
Pricing basis and limitations: these figures come from one Stanfield IT proposal delivered on 23 April 2026 and have been anonymised for this guide. They are shown excluding GST. They represent quoted—not necessarily contracted—pricing for that scope. They do not include every form of MDR, every security tool, a penetration test, major remediation, forensic investigation or after-hours emergency coverage. Prices and service designs change, so a current written proposal remains the source of truth.
What is included in cyber security services?
Cyber security is not one product. A complete program usually works across five linked activities: assess, protect, detect, respond and recover. The right combination depends on what the business relies on, the information it holds, the threats it faces and what capability already exists internally.
Assess
Identify critical systems, information, threats and control gaps. This can include a business risk assessment, Essential Eight maturity assessment, cloud review or focused technical assessment.
Protect
Strengthen identity, multi-factor authentication, privileged access, secure configuration, patching, endpoint, email, network and backup controls.
Detect
Collect and review useful security signals from identities, endpoints, email, cloud and supported infrastructure. Validate alerts and separate genuine risk from noise.
Respond and recover
Use agreed escalation, containment, evidence preservation, communications and recovery processes. Review what happened and reduce the chance of recurrence.
Licences and tools may be part of the price, but they are not the whole service. Buyers should look for analyst time, configuration, tuning, remediation ownership, escalation, reporting and management. A low software-only price can become expensive if nobody is responsible for acting on what the tool finds.
That context matters. The ASD Annual Cyber Threat Report 2024–25 recorded more than 84,700 cybercrime reports—about one every six minutes—and an average self-reported financial cost of $80,850 per business cybercrime report. That figure is an incident-loss statistic, not a cyber security services price or a guaranteed saving.
The OAIC received 1,205 data-breach notifications in calendar 2025, an 8% increase over 2024 and the highest annual total since the Notifiable Data Breaches scheme began. Those notifications do not mean every organisation needs the same service; they reinforce the need to scope protection and response around the information and operational risk actually present.
Cyber security service pricing at a glance
The table below is an original scope comparison. It deliberately separates the pricing unit from the service outcome. This makes it easier to compare proposals that may use different commercial models.
| Service | Typical scope | Common pricing model | Main pricing variables | Best suited to | Typical engagement length or recurrence |
|---|---|---|---|---|---|
| Cyber risk assessment | Business context, systems, identities, devices, cloud, policies, recovery, findings and prioritised roadmap | Fixed project after discovery | Users, sites, platforms, evidence depth, interviews, framework mapping and report detail | Businesses that need a clear baseline and investment priorities | Usually several weeks; repeat annually or after major change |
| Managed detection and response | Monitoring, alert triage, escalation, tuning and agreed response across selected identities, endpoints and cloud services | Per user, per endpoint, per log source or fixed monthly service | Coverage, operating hours, data volume, retention, tools, response authority and service levels | Businesses that need continuous visibility and specialist response capability | Ongoing monthly service, normally with onboarding |
| Vulnerability management | Asset discovery, authenticated scanning, analyst review, risk prioritisation, remediation tracking and validation | Per asset/device or fixed monthly fee | Asset count and type, internal/external scope, scan frequency, authentication, reporting and remediation support | Businesses that need an ongoing reduction program, not a one-off scan | Monthly or quarterly operating cycle |
| Penetration testing | Authorised testing of defined external, internal, web, cloud, wireless or identity scope with evidence and remediation advice | Fixed project | Targets, application complexity, test method, user roles, testing window, retest and reporting requirements | Businesses validating exploitable risk before audit, renewal, launch or major change | Point-in-time project; commonly annual and after material change |
| Essential Eight | Maturity assessment, evidence review, gap report, target state, uplift roadmap and optional implementation | Fixed assessment, project uplift and/or ongoing management | Scope, starting maturity, target maturity, evidence quality, technical change and exception management | Australian organisations using ASD guidance for practical baseline uplift | Assessment over several weeks; uplift staged over months; reassess regularly |
| ISO 27001 support | ISMS scope, gap analysis, risk process, policies, evidence, internal audit support and continual improvement | Fixed phases, day rate or monthly program | ISMS boundary, locations, processes, documentation, existing controls, readiness and certification timeline | Organisations needing a formal information security management system or independent certification | Often a multi-month program with ongoing ISMS maintenance |
| Incident response | Triage, containment, investigation, evidence, recovery coordination, reporting and lessons learned | Hourly emergency work, prepaid block or retainer | Urgency, availability, affected systems, forensic depth, data volume, legal/insurer coordination and recovery effort | Organisations preparing for or managing a suspected compromise | Retainer is ongoing; live response can run from hours to weeks |
How cyber risk assessment costs are set
A cyber security risk assessment is normally a fixed project once the environment and required evidence are understood. A short questionnaire is cheaper to deliver than a verified assessment, but it does not provide the same confidence.
A practical Stanfield assessment can review business-critical systems and data, Microsoft 365 or Google Workspace, identity and MFA, endpoints, email, cloud platforms, networks, backups, patching, policies, incident readiness and supplier dependencies. It should produce an executive summary, prioritised findings, responsible owners and a roadmap rather than a raw scanner export.
What changes the assessment price?
- The number of users, sites, business units and technology platforms in scope.
- Whether the assessment is broad and business-led or requires deep technical validation.
- The framework mapping required, such as Essential Eight or ISO 27001.
- The quality of existing documentation, asset registers and prior assessment evidence.
- The number of interviews, workshops and leadership presentations required.
- Whether remediation planning, tool configuration or implementation is included.
Stanfield IT quotes this work individually because the available internal proposal dataset used for this article does not contain enough comparable current assessment engagements to publish a responsible range. That is more honest than dressing up an unverified market figure as Stanfield pricing.
Managed detection and response costs
Managed Detection and Response (MDR) is usually recurring because detection only works when signals are collected, reviewed, tuned and escalated continually. Pricing may be per user, per endpoint, per log source or a fixed monthly amount for a defined environment.
In the anonymised 130-user proposal, Stanfield quoted $75 per user per month for managed Microsoft 365 security monitoring. The scope covered activities such as user and sign-in review, dormant-account control, investigation and remediation of software vulnerabilities, security alert and incident monitoring, privileged-access review, device compliance, cloud app oversight, threat-protection status and mail quarantine. That is materially broader than simply supplying an endpoint licence.
Questions that materially change an MDR quote
- Is monitoring business-hours only, continuous visibility or a genuine staffed 24/7 service?
- Which identities, endpoints, servers, email systems, cloud services and network devices are included?
- Are licences, onboarding, data ingestion and log retention included?
- Does the provider only notify you, or can it isolate devices, disable accounts or take other agreed containment action?
- What response time applies to validated high-severity incidents?
- Are threat hunting, detection engineering and monthly tuning included?
- Where does MDR stop and a separately charged incident-response engagement begin?
Do not assume “24/7” means the same thing in every proposal. It may describe automated tool availability, alert receipt, an on-call escalation path or a fully staffed security operations function. Ask the provider to define the people, service level and actions available at 2:00 am.
Vulnerability management costs
Vulnerability management is an operating cycle: discover assets, scan, validate, prioritise, remediate, rescan and report. It is often priced per asset or as a fixed monthly service because the work repeats as software, configurations and threats change.
The ASD’s 2026 Guidelines for Cyber Security Documentation distinguishes an automated vulnerability scan, a broader vulnerability assessment and a penetration test. Buyers should do the same. A scanner licence or quarterly PDF is not equivalent to a managed service that establishes owners, follows remediation and confirms that fixes worked.
Main vulnerability-management price drivers
- Number and type of endpoints, servers, network devices, cloud assets and applications.
- Authenticated versus unauthenticated scanning and the effort needed to maintain access.
- Internal, external and cloud scanning frequency.
- Analyst review, asset criticality and exploitability-based prioritisation.
- Remediation advice only versus hands-on patching and configuration changes.
- Rescanning, exception management, executive reporting and audit evidence.
A low scan price can be reasonable when the client owns every remediation step. It is poor value when findings accumulate because nobody has authority, time or technical access to close them.
Penetration testing costs
Penetration testing is normally a fixed project based on a written rules-of-engagement document. Price depends more on the testable scope and application complexity than the number of employees.
An external infrastructure test, an internal network test and an authenticated web-application test require different methods and time. Black-box, grey-box and white-box access also change how efficiently the tester can reach meaningful depth. The quote should identify targets, exclusions, testing windows, escalation contacts, data-handling arrangements, report format and whether a retest is included.
What usually increases a penetration-test quote?
- More external IPs, internal segments, applications, APIs, cloud accounts or wireless locations.
- Complex applications with several user roles, workflows or integrations.
- After-hours testing, change windows and extensive safety constraints.
- Social engineering, physical testing or specialist cloud and identity scenarios.
- Detailed evidence for auditors, customers or regulated environments.
- Remediation workshops and one or more retests after fixes.
Stanfield IT has not inserted a dollar range here because the internal evidence available for this article did not include enough comparable penetration-test proposals. Ask for a fixed quote that states exactly what is tested. An attractive number without a target list and retest position is not comparable.
Essential Eight and ISO 27001 support costs
Compliance-related work often has three separate costs: assessment, uplift and maintenance. Combining them into one vague line item makes it difficult to see what is being delivered.
Essential Eight
Essential Eight services can include an evidence-based maturity assessment, gap report, target maturity decision, implementation roadmap, technical uplift and ongoing reporting. Essential Eight is not a certificate or badge.
The ASD Essential Eight Assessment Process Guide explains that duration depends on system size and complexity. Direct testing and configuration review provide stronger evidence than policies, screenshots or verbal assurances. That evidence depth affects cost.
ISO 27001
ISO 27001 support can include ISMS scoping, gap analysis, risk assessment, control implementation, policies, evidence management, internal audit preparation and continual improvement. The ISO/IEC 27001 standard is designed around an information security management system and a risk process adapted to the organisation’s size and needs.
Advisory support and the independent certification audit are different services. Stanfield IT can support the technology and management-system work within scope, but ISO does not certify organisations and Stanfield IT does not issue the certificate. An independent certification body charges separately.
Commonly separate compliance costs
- Initial gap or maturity assessment.
- Technical remediation, projects and new licences.
- Policy development, risk workshops and staff time.
- Evidence collection, internal audit and management review.
- Independent certification-body audit fees for ISO 27001.
- Annual surveillance, reassessment and ongoing ISMS management.
Incident-response retainers and emergency work
Incident response can be bought in three ways: emergency hourly work, a prepaid block of hours or a retainer that establishes readiness and priority access. These are not equivalent.
The anonymised 2026 Stanfield proposal listed optional cyber incident response at $250 per hour excluding GST. It did not represent a full forensic retainer, guaranteed 24/7 availability or an unlimited response service. Availability and scope still needed to be confirmed when an incident occurred.
A proper retainer may include environment familiarisation, contact validation, access preparation, an incident-response plan, playbooks, tabletop exercise, agreed service levels and a bank of response hours. Live work can include triage, containment, log collection, forensic analysis, identity reset, recovery coordination, insurer and legal liaison, executive updates and post-incident improvement.
The OAIC’s data-breach response guidance uses the sequence contain, assess, notify and review. Privacy Act coverage and notification obligations depend on the entity and incident; cyber responders should work alongside legal and privacy specialists when that advice is required. Separately, covered Australian businesses that make a ransomware or cyber-extortion payment may have a 72-hour reporting obligation under the applicable federal regime.
Emergency work that may be excluded
- After-hours or public-holiday loading.
- Specialist digital forensics, malware reverse engineering or eDiscovery tools.
- Travel, onsite attendance and secure evidence storage.
- Legal advice, privacy advice, crisis communications and regulatory submissions.
- Data restoration, system rebuilds and infrastructure replacement.
- Third-party vendor, cloud, recovery or forensic platform charges.
Per-user, per-device, per-project and monthly pricing
Per user
Works well for identity, Microsoft 365, awareness training and user-centred managed security. Confirm how shared, service, contractor and inactive accounts are counted.
Per device or asset
Common for endpoint protection and vulnerability management. Confirm whether servers, mobile devices, network equipment and cloud assets use different rates.
Fixed project
Best for defined assessments, penetration tests and implementation work. The scope, assumptions, exclusions, deliverables and change process must be written.
Fixed monthly service
Creates predictable operating cost for ongoing monitoring, management and reporting. Check volume limits, onboarding, minimum term and out-of-scope rates.
Hybrid pricing is common because different services are consumed differently. A proposal may use per-user security monitoring, per-device endpoint controls, fixed monthly reporting and a separate fixed penetration-testing project. That can be sensible if each line is clearly defined.
What causes cyber security pricing to increase?
- Broader coverage: more identities, devices, servers, cloud services, sites, applications and suppliers create more work and more security data.
- Deeper assurance: configuration testing, authenticated scanning and hands-on validation cost more than questionnaires and policy review.
- Longer operating hours: true 24/7 analyst coverage and defined response service levels require more capability than business-hours monitoring.
- Poor starting condition: undocumented systems, unsupported software, weak admin controls and accumulated vulnerabilities create onboarding and remediation work.
- Higher data and log volume: SIEM ingestion, retention and investigation effort can materially affect MDR price.
- Complex compliance: several entities, locations, regulated data types, customer assurance demands and extensive evidence increase assessment and governance effort.
- More active response authority: a service that can contain threats and coordinate recovery carries more responsibility than alert forwarding.
- Custom reporting and governance: board packs, insurer evidence, customer questionnaires, committee attendance and audit support take additional time.
- Short deadlines: urgent tenders, certification dates and incident work compress delivery and may require dedicated resources.
- Separate specialist costs: licences, independent auditors, legal advisers, forensic platforms and third-party vendors may sit outside the provider’s fee.
APP 11 guidance from the OAIC similarly recognises that reasonable security measures depend on factors including an organisation’s size, resources, operational complexity, information sensitivity, potential harm and the practicality of safeguards. A responsible scope reflects those differences.
What should a cyber security proposal include?
- The business outcome and risk being addressed.
- Exact in-scope users, identities, devices, sites, systems, cloud services and applications.
- Service hours, response target, escalation path and after-hours arrangement.
- Who monitors, who validates and who is authorised to contain a threat.
- Included licences, tooling, data ingestion, storage and retention.
- Onboarding, discovery, baseline configuration and initial remediation.
- Testing method, evidence standard, report format and retest position.
- Remediation ownership: provider, internal team, current MSP or a shared model.
- Executive and technical reporting, review meetings and action tracking.
- Assumptions, dependencies and client responsibilities.
- Clear exclusions and rates for approved out-of-scope work.
- Contract term, minimum quantities, price-review method, exit assistance and data return.
What is often excluded?
Common exclusions include project remediation, major configuration uplift, unsupported systems, third-party licences not listed, independent audit fees, legal and privacy advice, penetration-test retests, live incident forensics, after-hours response, data recovery, onsite travel and work caused by material changes to the environment.
An exclusion is not automatically unreasonable. The problem is discovering it after a critical alert, audit deadline or incident. Ask for exclusions in writing and obtain the applicable rate before signing.
How to compare cyber security providers
Normalise the proposals before comparing price. Put the same quantities and requirements in one worksheet, then mark each item as included, optional, excluded or unclear.
| Comparison area | Question to ask | Why it matters |
|---|---|---|
| Monitoring coverage | Business hours, automated 24/7, on-call, or staffed 24/7? | The same phrase can describe very different services. |
| Response authority | Will you alert us, guide us or actively contain the threat? | Notification without action leaves the client carrying the urgent response. |
| Assets counted | Which users, endpoints, servers, identities, cloud services and log sources are included? | Different counting rules can hide a large price difference. |
| Remediation | Who fixes findings and confirms closure? | Finding a weakness is not the same as reducing it. |
| Incident boundary | What is included before separate incident-response charges begin? | Major incidents often sit outside routine MDR. |
| Evidence and reporting | Do we receive technical findings, executive reporting, owners and action tracking? | Leaders and technical teams need different levels of detail. |
| Onboarding | Are discovery, deployment, tuning and initial remediation included? | A low monthly fee may conceal a large transition cost. |
| Provider assurance | How does the provider protect privileged access to our environment? | A security provider becomes part of the client’s supply-chain risk. |
The ASD’s guidance for engaging a managed service provider recommends defining security expectations and evidence upfront, including incident notification, access boundaries and logging. Those requirements belong in the commercial conversation, not in an unwritten assumption.
When should you start with an assessment?
Start with an assessment when leadership cannot confidently answer what the critical assets are, where the most serious control gaps sit, which tools are already licensed or who owns remediation. It gives competing providers a common baseline and prevents the budget being absorbed by low-priority products.
Move directly to a managed service when scope is already clear, controls are in reasonable condition and the immediate gap is ongoing monitoring or operational capacity. Even then, onboarding should validate users, devices, access, logging, escalation and recovery before the service is treated as fully operational.
Use a focused project when there is a defined question: whether an internet-facing service can be exploited, whether Essential Eight controls meet a target maturity level, whether Microsoft 365 is configured safely or whether a recent remediation actually worked.
Get a scope you can compare
Tell Stanfield IT what you need to protect, what evidence you need and what capability you already have. We will help separate urgent risk reduction, one-off projects and ongoing managed security into a clear written scope.
Frequently asked questions
How much do cyber security services cost in Australia?
There is no responsible single market price. In one genuine 2026 Stanfield proposal for about 130 users, the managed cyber scope totalled $11,195 per month excluding GST and optional incident response was $250 per hour. Assessments and tests are fixed-price after scoping.
How much should a small business spend on cyber security?
Do not begin with an arbitrary percentage of revenue. Start with critical systems, information sensitivity, likely threats, legal and customer obligations, current controls and the business impact of disruption. Fund the highest-risk gaps first and include ongoing operation, not only licences.
What is included in managed cyber security services?
Depending on scope, managed services may include identity, endpoint, email and cloud monitoring; alert triage; vulnerability management; awareness training; escalation; response support; reporting and continual control improvement. The proposal should list each included environment and action.
Are cyber security services priced per user or per device?
Both models are common. Identity, Microsoft 365 and awareness services often use per-user pricing. Endpoint and vulnerability services may use per-device or per-asset pricing. Monitoring may also depend on log sources, ingestion and retention. Hybrid proposals are normal.
How much does a cyber risk assessment cost?
Stanfield IT prices risk assessments as fixed projects after confirming systems, locations, evidence depth, framework mapping, interviews and required deliverables. We have not published a numeric range because the verified proposal dataset for this article was not large enough to support one.
Does MDR include active containment and incident response?
Only when the written scope says so. Some services forward alerts, some guide the client and others can take agreed containment action. Major forensic investigation and recovery may become a separate incident-response engagement. Ask where that boundary sits.
What is the difference between vulnerability scanning and a penetration test?
A scan automates checks for known vulnerabilities. Vulnerability management adds validation, prioritisation, remediation ownership and ongoing tracking. A penetration test is authorised, objective-led testing that attempts to demonstrate practical exploitability within a defined point-in-time scope.
How often should penetration testing be performed?
Annual testing is common, but risk should set the frequency. Test after major applications, infrastructure, identity or cloud changes; before important customer or assurance commitments; and after material remediation where validation is required.
Is Essential Eight assessment pricing separate from remediation?
It should be clear whether the quote covers assessment only, a roadmap, technical uplift, evidence support or ongoing management. The starting maturity, target maturity and required evidence can change the work significantly. Essential Eight is a maturity model, not a certification.
What costs sit outside ISO 27001 consulting?
Possible separate costs include staff time, technical remediation, new tools, policy and evidence work, internal audit support, independent certification-body fees and ongoing surveillance. Stanfield IT can support work in scope but does not issue ISO 27001 certificates.
What does an incident-response retainer include?
A retainer may include environment familiarisation, access preparation, contact validation, plans, playbooks, exercises, priority response terms and a bank of hours. Emergency hourly support without those readiness elements is not the same service.
Why can two cyber security proposals be very different?
They may count different assets, cover different hours, include different licences, retain different log volumes, provide different response authority or exclude remediation and incidents. Normalise the scope, quantities, service levels and exclusions before comparing totals.
Should we start with an assessment or a managed service?
Start with an assessment when risk, scope and priorities are unclear. Start with a managed service when the environment and operating requirement are already understood. Use a focused project when you need a specific answer, such as whether a defined system can be exploited.
Sources and methodology
The pricing example in this guide is based on a Stanfield IT proposal issued on 23 April 2026 and anonymised for publication. The service comparison table is Stanfield IT’s original analysis. Australian context and framework statements were checked against the following primary sources:
- ASD Annual Cyber Threat Report 2024–25
- OAIC: Data-breach notifications reached an all-time high in 2025
- OAIC Quick Reference Guide for Responding to Data Breaches
- OAIC Australian Privacy Principle 11 guidance
- ASD Essential Eight Maturity Model
- ASD Essential Eight Assessment Process Guide
- ASD Cyber Security Incident Response Planning Guidance
- Department of Home Affairs mandatory ransomware payment reporting guidance
- ISO/IEC 27001:2022
Last reviewed: 31 July 2026. All Stanfield IT prices shown exclude GST. This guide is general business information, not legal, privacy, regulatory, insurance or certification advice.