Cyber security services, as a market, resolve into five families however many names providers coin: monitoring services that watch your systems around the clock; response services that act when something is found; testing services that probe your defences on schedule; compliance services that map you against standards and questionnaires; and advisory services that decide what the programme should be. Every line on every proposal belongs to one family, and the buying order for a small organisation is not the order providers pitch them. This page is the catalogue view: what each family contains, its unit of pricing, the family most organisations should buy first, and the one every organisation already owns without noticing. For the deeper cuts, the guides on this site take each family separately; this page exists so the whole market fits in one read, and so the proposal on your desk can be sorted into families in five minutes.
The five families and their pricing units
Monitoring prices per user or device per month and is the market's recurring core; response is sold inside monitoring contracts as included hours plus a rate, or standalone as a retainer; testing prices per engagement, scoped by system count, and recurs annually; compliance work prices per engagement or as a subscription when a standard must be maintained; advice prices by the day or as a fractional retainer. The families interlock: monitoring without response is a smoke alarm with no fire brigade, testing without remediation budget is a report that ages, and advice without any of the others is a plan without hands.
The buying order that fits a small organisation
First, the free family nobody sells: configuration, multi-factor authentication, sender authentication, the payment procedure, because it closes the commonest losses at the cost of hours. Second, monitoring with response included, per-user, because the overnight shift cannot be self-supplied. Third, annual testing once there is something to test, a vulnerability assessment before a penetration test, walk before the sparring partner. Compliance and advisory services are bought when an external force, a client questionnaire, an insurer, a regulator, summons them, which is also when they are cheapest to scope, because the demand defines the deliverable.
Reading a proposal against the catalogue
Take the proposal and mark each line with its family. Gaps show immediately: many small-organisation proposals are monitoring-heavy with no tested-recovery line and no response definition, which the it security service guide on this site treats in detail. Duplicates show too, response hours inside the monitoring line and again as a retainer. Then ask the one cross-family question: what do you need from us to start, because every real provider answers with an inventory and your written policies. That set is the artefact this whole site exists to produce: the free sheet counts it from your facts, and Hardenvo Pro generates the documents the engagement will be scoped against.
Questions people ask about cyber security services
What are the main types of cyber security services?
Five families: monitoring (around-the-clock watching), response (acting on what is found), testing (scheduled probing), compliance (mapping to standards and questionnaires) and advisory (deciding the programme). Every proposal line belongs to one.
Which cyber security service should a small business buy first?
After the free configuration wins (multi-factor authentication, sender records, payment procedure): monitoring with response included, because nobody on staff watches at 3am. Testing follows annually; compliance and advice when a client or insurer summons them.
How do I evaluate a cyber security services proposal?
Sort every line into its family, look for the missing recovery and response definitions, strike the duplicates, and ask what they need from you to start. The answer is your inventory and written policies, which the free sheet on this site counts and prices.