Security has a marketing problem: when it works, nothing happens. No headline, no war story, no visible win — just another quiet quarter. Which makes it the easiest budget line to squeeze and the hardest to defend, unless you price what "nothing" is actually worth. So let's price it.
The downtime math
Start with a number every operator knows: what an hour of downtime costs you. Payroll for people who can't work, revenue that doesn't book, SLA penalties, the jobs that slip. For a 100-person services firm, even conservative math lands in the thousands per hour — and real incidents aren't measured in hours. Industry reporting has consistently put average ransomware downtime at three weeks or more. Multiply your hourly number by 500 and you have the honest denominator for every security investment you're evaluating.
The recovery bill nobody budgets
Downtime is only the visible cost. Add forensics and incident response retainers billed at crisis rates, legal counsel, breach notification obligations, credit monitoring for affected parties, and the months of staff time redirected to rebuilding. Then add the quiet costs: the customer who "went another direction" at renewal, the deal that stalled when word got around, the insurance premium that doubles at your next renewal — if you're offered a renewal at all.
Prevention now has a price signal
The useful shift of the last three years: prevention stopped being unpriceable. Your insurance questionnaire attaches a premium delta to every major control. Your enterprise customers' security reviews attach revenue to your posture — pass and the deal proceeds, fail and it doesn't. Between premium savings, avoided exclusions, and unblocked deals, a serious security program frequently justifies itself before you count a single avoided incident.
How to measure a program that's working
Don't measure by absence of incidents — that's luck plus time. Measure the things that predict absence: MFA coverage percentage (the honest number, including that one legacy account), median time to patch critical vulnerabilities, backup restore test results with dates, phishing report rates (reports going up is good — it means people are catching them), and the shrinking list of open items from your last assessment. These are numbers a board can track quarter over quarter, and they're the same evidence your insurer wants anyway. One artifact, three audiences.
The honest comparison
A managed security program for a growing company costs a defined amount per month — ours is scoped fixed-fee like everything we sell. A single meaningful incident costs an undefined amount, at the worst possible time, with your customers watching. You are already paying one of these two numbers; the only question is whether you chose it. Our security practice is built to make the chosen number as small as competence allows — book a conversation and we'll walk your actual math, not a scare-slide.
