forumNew topic

How many thousand lira should a small business allocate annually for cybersecurity, there was no consensus on this until now

PPelin D***Expert
Job title
Finance Manager
Organization type
early-stage startup
Joined
Nov 2023
Message
138
#1

I run a sales company with 15 staff. I've started worrying after hearing recent news about cyber attacks. I'm thinking it could happen to us too.

Security software and consulting services seem very expensive. Is it really that much? Is there a feasible budget for an SME?

Which areas should we spend on, which can we put on the back burner?

MMustafa T***ExpertCommunity member
Joined
Apr 2026
Message
150
Most Helpful#2

The cybersecurity budget for SMEs varies depending on the size of the business and the amount of sensitive data. The general guideline is to allocate 0.5-2% of revenue.

Basic needs for a 15-person company: antivirus software, firewall, backup system, employee training. An annual budget of approximately 20-30 thousand TL is considered reasonable.

Avoid: expensive consultants, software not yet needed. Prioritize: basic protection, employee training, data backups.

Correction: I misremembered the figure, it was a bit lower.

PPolat A***MemberCommunity member
Joined
Apr 2023
Message
413
#3

we have 12 people too the budget the security consultant suggested was terrifying. honestly then i bought a simple antivirus, 2 months later the computers got slow... edit: need to change the antivirus

TTuğçe C***Expert
Job title
Human Resources Specialist
Sector
Law
Organization type
40-person manufacturing company
Joined
Feb 2023
Message
185
#4

Starting budget for 15 people: - Antivirus: 2000-3000 - Firewall: 3000-5000 - Backup: 2000-3000 - Training: 1000 - Total: ~8000. Annually.

HHasan Ö***MemberCommunity member
Joined
Dec 2024
Message
39
#5

hiring a security consultant is expensive but if you see what they do at first, it'll seem cheap later. we paid 30k and saw the value it brought in 6 months

İİlker C***MemberCommunity member
Joined
May 2023
Message
29
#6

Adaptive budget logic: First year set up basic infrastructure (antivirus backup). Second year add advanced solutions (remote access, data management). Hire a consultant in the third year.

OOya G***Member
Job title
Production Manager
Sector
Catering
Organization type
300-person organization
Joined
Oct 2023
Message
66
#7

Isn't software licensing really harmful? I've seen many employees working with pirated copies, but is it worth the risk?

VVildan B***Member
Job title
Production planning
Sector
Livestock
Organization type
workshop
Joined
Feb 2023
Message
388

Doki · Mobile app · 2023

#8

starting simple isn't a big deal what matters is starting and making it routine! get everyone antivirus in one go, start the next day. that's it

TTolga A***MemberCommunity member
Joined
Nov 2023
Message
346
#9

This thread is archived.

JJülide S***Veteran
Job title
Secretary
Sector
Food wholesale
Organization type
family business
Joined
Jun 2024
Message
1
#10

i have a question. any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

if I were you, I'd go this route.

PPolat K***MemberCommunity member
Joined
May 2023
Message
329
#11

We need to make a distinction here. Hasty decisions become decisions you have to fix six months later.

Correct me if I'm wrong.

EEsra T***Member
Job title
Data Analyst
Sector
Livestock
Organization type
workshop
Joined
Feb 2024
Message
66
#12

exactly like that and payment information changs are never verified through the channel they came from.

that's all, sorry if I went on too long.

FFurkan Y***MemberCommunity member
Joined
Feb 2023
Message
53
#13

My questions are cleared up, thanks. Start with a small trial; don't commit to everything at once.

LLeyla Ç***Expert
Job title
Front office accounting
Sector
Security services
Organization type
medium-sized business
Joined
Jan 2026
Message
1
#14

Absolutely. If I were to add anything: Forgotten test environments are more often the entry point than live systems.

If permission and scope aren't in writing, don't start that test. That's all, sorry if I went on too long.

RRamazan A***MemberCommunity member
Joined
Feb 2023
Message
34
#15

Sorry, but this doesn't apply in every case. The answer varies greatly by industry; there is no one-size-fits-all rule.

Most incidents start with a leaked password, not a vulnerability.

MMurat Ç***Expert
Job title
Project manager
Sector
Accounting & advisory
Organization type
medium-sized business
Joined
Oct 2022
Message
246
#16

I have an objection here. Taking measures without an inventory leaves doors you haven't seen open.

Hasty decisions become decisions you have to fix six months later. Correct me if I'm wrong.

YYasemin Y***MemberCommunity member
Joined
Oct 2023
Message
3
#17

Saved.

MMetin G***MemberCommunity member
Joined
Sep 2024
Message
219
#18

I have an objection here. Everyone rushing into cybersecurity budget for SMEs gets stuck at the same point.

Proven by experience.

FFurkan B***ExpertCommunity member
Joined
Jul 2025
Message
32
#19

Timely topic. The real issue isn't the number, but what it's based on.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently. Good luck with that.

IIrmak B***Member
Job title
Data Analyst
Sector
Furniture manufacturing
Organization type
sole proprietorship
Joined
Feb 2025
Message
46
#20

Thanks a lot, I'll try it today.

Reply