How Much Does Email Security Cost for a Small Business?
A clear, direct answer to this question — written for UK business owners and IT decision-makers.
Direct Answer
Microsoft Defender for Office 365 Plan 1 costs £1.80 per user per month when purchased standalone, or is included in Microsoft 365 Business Premium. AMVIA's managed email security service — including configuration, ongoing management, DMARC setup, and phishing simulation — starts from £5 per user per month on top of your M365 licence.
Key Points
What you need to know.
The Short Answer
Phishing is the number one attack type — 85% of businesses that experienced a breach identified phishing as the cause (DSIT 2025).
For UK Businesses
Phishing was the most disruptive breach for 65% of businesses.
Cost Considerations
93% of cyber crimes against businesses were phishing-based.
Next Steps
35% of businesses that experienced breaches reported impersonation of the organisation or staff.
Quick Comparison
| Feature | Option A | Option B |
|---|
Frequently Asked Questions
Ransomware is malicious software that encrypts your data and demands payment for its return. Approximately 19,000 UK businesses were hit by ransomware in 2025. The median UK ransom demand has doubled to $5.37 million, and average recovery costs reach $2.58 million excluding the ransom itself.
UK businesses typically allocate 13.2% of their total IT budget to cybersecurity. More than half of UK small businesses increased their cybersecurity spending in 2024. 85% of UK firms plan to boost their cyber budget for 2026. The cost of prevention is significantly less than the average breach cost of £3,550.
The average cost of the most disruptive breach is £3,550 for UK businesses. For businesses that experienced negative outcomes such as data loss or financial theft, the average cost rises to £8,260. Medium and large businesses face average costs of £10,830 per disruptive incident.
Yes. 50% of small businesses (10-49 employees) reported a cybersecurity breach in 2025. UK small businesses face around 65,000 hack attempts daily, with approximately 4,500 successful breaches. More than a quarter of SMBs say a single cyber attack could put them out of business entirely.
BEC is a type of fraud where attackers impersonate executives or suppliers to trick employees into transferring funds or sharing sensitive data. BEC attacks increased 33% in 2025. The average loss per BEC incident is $137,000. Even organisations with fewer than 1,000 employees face a 70% weekly probability of a BEC attempt.
Need More Detail?
Speak to an AMVIA expert for advice tailored to your business.
Related Questions
Email Security and Phishing Protection
Managed email security including DMARC, anti-phishing, and simulated phishing campaigns.
Microsoft 365 Security
Microsoft Defender for Office 365 configuration and ongoing management for UK businesses.
What Is Phishing?
How phishing attacks work and what email security controls can prevent them.
Cybersecurity Guide for UK SMEs
A complete guide to cybersecurity controls including email security priorities.