What Does Cybersecurity Actually Cost a Kenyan Business?
What drives the cost of cybersecurity for a Kenyan business — licences versus the people who watch them, why 24/7 monitoring is priced the way it is, and how to sequence spend so the first shilling does the most work.
Ask what cybersecurity costs and you will get a number for a product. That is the wrong unit. Nobody buys "cybersecurity" — they buy a set of overlapping, mostly recurring commitments, and the licence fee is usually the smallest line on the invoice.
This guide sets out what actually drives the number, in the order the money tends to leave the building, so you can build a budget that survives contact with a real quote.
The tools are the cheap part, and this surprises people
Endpoint protection, a firewall, email filtering, a SIEM — these are licences, they scale predictably with headcount or data volume, and you can compare them on a spreadsheet. This is why vendors lead with them and why buyers anchor on them.
But a tool that nobody is watching is not a control. It is a subscription. The overwhelming majority of security failures we are called into involve a product that was correctly licensed, correctly installed, and generating alerts that no human had looked at for months. The licence was paid. The outcome was not purchased.
What you are really paying for is attention, at 3am
The genuine cost driver in security is continuous human attention. Attackers do not work office hours — ransomware is deliberately detonated on Friday nights and public holidays, precisely because that is when nobody is looking.
Covering 24/7/365 with your own staff requires a rota of several trained analysts, not one person with an on-call phone. That is a permanent, salaried commitment, and it is why in-house security operations is out of reach for most organisations below a certain size — the cost is not the tooling, it is the headcount arithmetic. This is the fundamental economic reason managed detection and response exists: the cost of the rota is shared across many clients.
- One analyst does not equal coverage — a genuine 24/7 rota needs a team.
- Alert triage is continuous work, not a project with an end date.
- The scarce input is trained people, and in this market they are scarce.
The cost drivers that actually move your quote
When a credible provider scopes you, these are the variables they are pricing. If a quote arrives without anyone having asked about them, it is a guess.
- Endpoint count — laptops, servers, mobile devices. The most common single driver.
- Log volume — a SIEM is priced on data ingested, and a chatty application can dominate your bill.
- Coverage hours — business-hours monitoring and true 24/7 are different products at different prices.
- Response depth — alerting you to a compromised machine is one service; isolating it on your behalf at 3am is another.
- Regulatory obligations — a regulated entity needs evidence, reporting and retention that an unregulated one does not.
- Estate complexity — cloud, on-premise and legacy systems together cost more than any one of them alone.
Sequence matters more than total spend
Most organisations we meet have bought in the wrong order. They own an expensive tool and lack the basics it assumes. There is a sequence in which the first shilling does disproportionate work, and it is unglamorous.
Know what you own, before you protect it — you cannot defend an asset inventory you do not have. Then multi-factor authentication, which remains the single highest-return control against the credential theft that begins most incidents. Then patching, with an owner and a deadline. Then backups that have actually been restored from, in a test, by someone who wrote down how long it took. Only then does detection and response earn its keep — because now it is watching an estate you understand.
An organisation that has done those four things properly and bought nothing else is in better shape than one that has bought a premium platform and done none of them. We have seen both, in the same week.
Where the money is genuinely wasted
On overlapping tools bought by different people at different times, each solving a slice of the same problem, none fully deployed. Audit what you already own before buying anything — it is common to find a capability already paid for inside an existing licence tier.
On compliance theatre: spend that produces a document rather than a defence. A certificate obtained without changing how the organisation operates has cost you money and bought you a false sense of security, which is worse than no security, because it stops you looking.
And on annual penetration tests treated as the whole programme. A test is a point-in-time snapshot. It tells you what was true on the day. It is not monitoring, it does not protect you in month seven, and it was never intended to.
Key takeaways
- The licence is the smallest cost. Continuous human attention is the real one.
- A tool nobody watches is a subscription, not a control.
- Endpoints, log volume, coverage hours and response depth are what move a quote.
- Sequence beats spend: inventory, MFA, patching and tested backups come first.
- Overlapping unused tools and compliance theatre are where budgets quietly die.
Frequently asked questions
Is it cheaper to build an in-house security team or use a managed service?
Below a certain size the arithmetic is not close. Genuine 24/7 coverage requires a rota of several trained analysts, and that salaried commitment usually exceeds the cost of a managed service that spreads the same rota across many clients. In-house begins to make sense at larger scale, or where regulation or data sensitivity requires that the capability sit inside the organisation. Our guide comparing an in-house SOC with a managed SOC works through the trade-off in detail.
What is the minimum a small business should spend on security?
Ask instead what the minimum a small business should do is, because the highest-return controls are cheap or free: multi-factor authentication everywhere, a real asset inventory, a patching routine with an owner, and backups that someone has actually restored from in a test. Doing those four things properly puts you ahead of many far larger organisations that have bought tooling and skipped the basics.
Why do cybersecurity quotes vary so widely for the same company?
Usually because the providers scoped different things, and one of them did not scope at all. Check whether the quote covers business hours or genuine 24/7 coverage; whether the provider merely alerts you or actually responds and contains on your behalf; and how log ingestion is priced, since that line can grow substantially once real data volumes arrive. Compare like for like, and be suspicious of any number produced without questions.
Do we still need a penetration test if we have monitoring?
Yes — they answer different questions. Monitoring tells you what is happening right now across your estate. A penetration test tells you what an attacker could achieve if they tried, including business-logic flaws no monitoring tool will surface. Neither substitutes for the other, and a programme with only one of them has a predictable blind spot.