You asked three cybersecurity providers for a quote and got three descriptions of different things. One talks about a "full audit", another about "continuous pentesting", the third just lists acronyms: EDR, SOC, XDR. None of them say how many hours of human work are included or what you actually get at the end. Choosing this way is a gamble, and for a company of 10 to 50 employees a bad security purchase is expensive to unwind. This guide gives you a method to compare quotes properly, ask the questions that matter and spot when someone is selling you a slide deck instead of a service.
Define what you are protecting before you request a single quote
No provider can give you a useful quote if you do not already know what you need protected. Before the first call, answer three questions with your team:
- Which systems, applications and data are critical for running the business tomorrow morning? A frozen ERP, a leaked customer list and an offline sales site do not carry the same weight.
- What is a client or partner requiring of you? Many small companies buy security because a larger client sent a security questionnaire or now requires an audit before signing. That specific requirement needs to be in the scope.
- What would hurt the most: losing the data, losing access to the systems, or losing a client's trust once they learn about an incident? The answer changes which kind of service should come first.
With those answers written down, any provider has to fit their offer to your problem, not the other way round. If a salesperson starts pitching their product before asking you this, that is already a first warning sign.
The questions that separate a real provider from a dashboard reseller
Some companies do the work with qualified people. Others resell a license for an automated tool with a nice interface on top. Both will call themselves a "cybersecurity service". The difference shows in how they answer these questions:
- Who actually does the work? A named analyst with verifiable experience, or a tool that runs on its own?
- Are the tests manual, automated, or a mix? An automated vulnerability scan has value, but it does not replace penetration testing carried out by a person who thinks like an attacker.
- What exactly do I receive at the end? A generic PDF generated by the tool, or a report that is explained, prioritized and specific to my systems?
- Who explains it to me? Is there a person who sits down with me to walk through the results, or does the report just land in my inbox?
- What happens if you find something critical halfway through the contract? Do you flag it the same day, or do I find out in the quarterly report?
- How many hours of human work does the price include, versus hours spent running an automated tool?
A serious provider answers this directly, with names, timelines and concrete examples. One that only resells a license gets vague or answers your question with more acronyms.
How to read a quote without getting shortchanged
Two quotes with similar prices can cover entirely different things. Before you compare the bottom line, check these five points:
Scope
Which systems, domains, applications or IP ranges are actually covered? A quote that just says "your infrastructure security" without listing what is in scope has no real scope, and a poorly defined scope is the most common cause of disputes after signing.
Asset count
How many devices, servers, applications or users does the price cover? If your company grows from 20 to 35 employees mid-year, what happens to the price and to the coverage?
Frequency
Is this a one time snapshot once a year, or ongoing monitoring? An annual security assessment is a reasonable starting point, but a company that ships changes every week needs something more frequent than a yearly review.
What is excluded
Ask for the explicit exclusion list, not just the list of what is included. Third party cloud systems, mobile apps and outside vendors commonly fall outside scope without anyone mentioning it in the first meeting.
Remediation support
Finding a problem is the easy part. Ask whether the price includes help fixing it, even if it is just guidance, or whether the provider hands you the report and disappears until the next review. Vulnerability management with no help on the fix side leaves many small companies holding a list of issues nobody internally knows how to resolve.
Contract terms that matter to a small company
Beyond the technical service, the contract has clauses that decide how much room you have to move if something does not work out:
- Lock-in: does it tie you to twelve or twenty four months, or can you leave with a reasonable notice period? A provider that only works with a long lock-in is betting on you not leaving, not on you staying happy.
- Notice period: how many days ahead do you need to give notice to avoid renewal? Put it on the calendar the day you sign, because it is the clause most companies forget until it is too late.
- Price increases: does the contract say how and when the price can go up, or is that left entirely to the provider?
- Data handling: if the provider will touch systems holding personal data about customers or staff, what does the contract say about how that data is handled? A security provider that cannot explain this clearly is a contradiction in itself.
Red flags that should make you stop and reconsider
Some phrases and behaviours are enough to rule out a provider without comparing price any further:
- They promise "total security" or "one hundred percent guaranteed protection". Nobody can guarantee that, and whoever says it either does not understand the field or is counting on you not knowing either.
- They sell through fear, describing worst case scenarios before ever asking what your business actually needs protected. Fear sells quotes, not security.
- The quote has no scope defined in writing, just a price and a list of technical terms.
- There is no named person accountable for your account. If nobody takes ownership of explaining what is happening, nobody will take ownership when something goes wrong.
Making the call once the quotes are in front of you
Line the quotes up side by side and compare scope, frequency, what you receive and who explains it to you before you look at the price. A low price with a narrow scope usually hides fewer real hours of work, and a high price only earns its keep if someone can tell you in one sentence what they will actually do for you every month.
If, after going through this, what you actually need is someone to govern your company's security on an ongoing basis, triage what is urgent and walk you through decisions like this one without depending on a single technical vendor, that role exists: it is what a Virtual CISO does. It does not replace the comparison you just made. It makes the next one easier.
Want to know how exposed your website is?
Ciphraverse's Security Assessment checks websites, portals and e-commerce with a professional external audit designed for SMEs.