Cybersecurity Services: What They Actually Cover, What They Cost, and How to Buy Them
TL;DR: What Cybersecurity Services Cover (and What They Cost)
Cybersecurity services are third-party protection of your network, endpoints, data, and compliance posture. The core categories are MDR, vulnerability assessments, penetration testing, incident response retainers, and compliance advisory. For a mid-market buyer, MDR typically runs $15 to $40 per endpoint per month. This guide is for IT Directors at 50 to 500 employee companies.
According to the IBM Cost of a Data Breach Report 2024, the average breach now costs $4.88M, and recovery time for companies without an IR plan is materially worse than for those that have rehearsed one.
Managed Service vs. Security Software: The Distinction Most Buyers Miss
CrowdStrike Falcon and SentinelOne Singularity are tools. They generate alerts. A managed service employs people who act on those alerts at 11 PM on a Thursday, when your in-house IT lead is asleep.
Think through the scenario. Ransomware detonates. The endpoint agent fires a high-severity alert. Who isolates the host? Who pulls memory? Who calls the CFO?
If you don't have an MDR provider or a 24/7 SOC, the answer is nobody, until Monday. By Monday, the attacker has been in your environment for 60 hours.
The staffing math explains why most mid-market firms outsource. A three-person internal SOC runs roughly $300K to $450K a year in salaries alone. The US Bureau of Labor Statistics put the median information security analyst wage at $120,360 in 2023, and you'd need three to cover shifts. That's before Splunk licensing, before training, before turnover. We've broken the full math down in our managed security services vs in-house TCO guide.
Software-only works for sub-25 person shops with no compliance exposure. The moment SOC 2, HIPAA, or CMMC enters the conversation, software alone won't pass an audit. Auditors want evidence that someone reviewed the alerts. CrowdStrike Falcon Go sits around $59.99 per endpoint per year, but the tool can't write your incident response runbook.
The 5 Core Cybersecurity Services and What Each Delivers
MDR (Managed Detection and Response). 24/7 alert triage, threat hunting, and active containment. Tools deployed: CrowdStrike Falcon, SentinelOne Singularity, or Microsoft Defender XDR. Pricing for mid-market: $15 to $40 per endpoint per month, depending on tier and EDR included. This is your front line against ransomware and phishing-driven account takeover.
Vulnerability Assessment and Penetration Testing. These aren't the same thing. Vulnerability scanning is automated and scheduled. Tenable Nessus Professional lists around $4,990 per year. Penetration testing is human-driven adversarial work, typically $15K to $45K for a focused engagement against external and internal scope. For more detail on scoping, see our penetration testing cost guide.
SIEM and Log Management. Aggregates logs from firewalls, identity providers, endpoints, and cloud workloads. Required for SOC 2 CC7.1, which mandates detection of anomalies, and for HIPAA audit log review. Splunk for a mid-market client typically runs $2,000 to $5,000 a month on consumption pricing. Microsoft Sentinel is competitive if you're already on E5.
Incident Response Retainer. Guaranteed SLA for breach response. Retainers run $15K to $50K a year and buy you contractual response time. Break-glass hourly is $300 to $500 an hour with no SLA, which is what you pay when you didn't plan ahead. CyberStar's IR SLA is on-site next business morning, written into the MSA, not the pitch deck.
Compliance Advisory. Gap assessments, policy authoring, evidence collection, and auditor liaison for SOC 2, HIPAA, CMMC, and NIST CSF. This is distinct from the CPA firm that performs the SOC 2 attestation. Your advisor cannot also be your auditor. That separation matters.
Matching Services to Company Size
50 to 100 employees, no compliance mandate. MDR plus endpoint protection plus an annual vulnerability scan. That's the minimum viable stack. Roughly $3K to $7K a month all-in.
100 to 250 employees, SOC 2 Type II in scope. Add SIEM, identity management (Okta Workforce Identity starts at $6 per user per month for SSO), and an IR retainer. Add a compliance automation platform like Drata or Vanta, $15K to $30K a year for a company your size. Our SOC 2 readiness playbook walks through what auditors actually ask for.
250 to 500 employees, HIPAA or CMMC in scope. Full MDR, SIEM, annual penetration test, compliance advisory retainer, and policy management. Add cloud security posture management for AWS or Azure workloads. Endpoint MDR doesn't cover your S3 buckets.
Once your remote workforce crosses 30% of headcount, zero trust network access stops being a buzzword. NIST CSF PR.AC-3 requires that remote access be managed, and ZTNA is how you satisfy that control without standing up a legacy VPN concentrator.
7 Questions to Ask a Cybersecurity Vendor Before You Sign
- What's your published IR SLA, and is it in the MSA? If it's only in the sales deck, it's marketing. Walk away.
- Which compliance frameworks do your controls map to? Ask for the mapping document. SOC 2 CC6 and CC7 control families should be specifically referenced.
- Do you operate your own SOC, or resell another MSSP? This determines your escalation path and where your data lives.
- What's your MTTD and MTTC from the last 12 months of real engagements? Industry benchmarks from the SANS 2023 SOC Survey show wide variance. Get real numbers, not averages.
- How do you handle alerts outside business hours? Automated playbook, on-call analyst, or a follow-the-sun SOC. The answer matters.
- What tools do you deploy, and will you lock me into proprietary tooling? If you fire them, can you keep the EDR licences in your name?
- Two reference clients in my industry and size range who faced a real incident. Not happy-path references. Incident references.
For a deeper procurement checklist, see how to select a cybersecurity partner.
ROI Framework: How to Justify the Spend to Your CFO
Start with the breach baseline. IBM's 2024 figure is $4.88M average. Mid-market companies without IR capability skew worse on recovery time, which drives the bulk of that cost.
Calculate annualised loss expectancy. ALE equals asset value times exposure factor times annual rate of occurrence. Example: your patient records system is valued at $2M of operational disruption per day of downtime. Exposure factor for a ransomware event is 0.4 (you'd recover 60% from backups). Annual rate of occurrence based on your sector is 0.15. ALE = $2M × 0.4 × 0.15 = $120K a year.
A $60K MDR retainer that drops your annual rate from 15% to 3% changes the ALE to $24K. You've reduced expected loss by $96K against a $60K spend. That's the conversation to have with your CFO.
Cyber insurance is the other lever. HIPAA penalties from HHS OCR reach $1.9M per violation category per year at the wilful neglect tier, so the avoidance math is real.
How CyberStar Delivers Cybersecurity Services
Our methodology is the 5-Star Cyber Shield: Protect, Detect, Recover, Comply, Train. Each pillar maps to specific services. Protect is endpoint, identity, and network controls. Detect is MDR and SIEM. Recover is backup testing and IR. Comply is the advisory layer. Train is the phishing simulation and user awareness piece that CISA keeps reminding us is still where 80% of breaches start.
A control nobody can evidence is not a control, whatever the outgoing provider's status reports said. An auditor tests the artefact, never the assurance.
Backups become a recovery plan only once somebody has restored from them end to end. Until that has happened, the recovery time objective written into your plan is an estimate rather than a commitment.
The difference is rule tuning, not brainpower. Detections shaped around your actual environment catch what vendor defaults wave through. Every MSP has a SOC. Not every SOC is watching.
We're vendor-agnostic on tooling. We'll deploy CrowdStrike or SentinelOne based on what's already in your stack and what your team can operate, not reseller margin. I once audited a mid-market client running 14 security tools at $28K a month. Three of them did essentially the same job. We consolidated to 6 tools at $11K a month with better coverage. Vendors love to sell you overlapping products.
We serve mid-market clients across Nashville and Charlotte with on-site response capability.
If you're within 90 days of a SOC 2 or HIPAA audit and don't know where you stand, book a free 30-minute audit with Mike.
FAQ
What's the difference between an MSSP and an MDR provider? An MSSP traditionally manages security infrastructure, firewalls, log collection, and patch cycles. An MDR provider focuses on detection and active response to threats on endpoints and identity. MDR is a subset of capabilities that prioritises threat hunting and containment, not infrastructure management. Many providers do both, but ask which one they actually invest in.
How much do cybersecurity services cost for a 100-person company? A realistic range for a 100-employee company with SOC 2 in scope: MDR at $2,500 a month, SIEM at $2,000, Okta at $600, IR retainer at $20K annually, compliance automation at $20K annually, and an annual pen test at $20K. That's roughly $100K to $130K a year all-in.
Do I need cybersecurity services if I already have antivirus software? Antivirus detects known malware signatures. Modern ransomware uses living-off-the-land techniques that AV doesn't catch. You need EDR plus a human watching alerts. AV alone hasn't been sufficient since around 2017.
What cybersecurity services are required for SOC 2 Type II compliance? SOC 2 Type II requires evidence across CC6 (logical access), CC7 (system monitoring), and CC8 (change management) at minimum. That translates to identity management, SIEM with log retention, vulnerability management, and documented incident response, all operating consistently over the audit period (typically 3 to 12 months).
How quickly can a cybersecurity provider respond to a breach? With a retainer, response should start within 1 to 4 hours of declaration. CyberStar's contractual SLA is on-site next business morning. Without a retainer, you're calling around at 2 AM looking for break-glass IR at $400 an hour, and most reputable firms are already booked.
Know exactly where your security stands.
Get your free security assessment →Know exactly where your security stands.
Most IT directors are one audit away from a nasty surprise. We remove the guesswork.
- A full assessment of your environment, mapped to SOC 2 and HIPAA.
- A prioritised remediation plan you can act on, whether you hire us or not.
- Managed protection across endpoints, data, and incident response.
- Fixed monthly pricing, so there are no per-incident surprises.
The assessment is free, and the plan is yours to keep.