For most small businesses in Rockland County, cybersecurity isn’t a separate line item, it’s built into a managed IT agreement that starts at $995 a month, and the risk assessment that tells you where you stand costs nothing.
I get asked this on almost every first call, usually phrased as though there’s a menu somewhere with prices on it. There isn’t. No menu. Not for a business your size.
What there is, and what I can actually explain, is which controls belong in a monthly agreement, which ones get quoted separately, and what the whole thing is worth measuring against. That last part matters more than the monthly figure, and most people skip straight past it.
If you want the broader picture of what managed IT runs across the region, the tri-county pricing guide covers the full number. This one is narrower. It’s the security half, for Rockland County specifically, written by the person who configures the stack rather than the person who sells it.

The Honest Answer Is Usually “It’s Already In There”
Most of our clients sitting in the $2,000 a month managed IT range have their security controls built into that agreement. Not bolted on. Not a second invoice. The controls an insurer asks about, the ones a regulator expects, they’re part of what the monthly fee buys.
That surprises people who’ve been shopping around, because plenty of providers do quote security as a separate monthly product on top of a lower base rate. Sometimes that’s honest packaging. Sometimes it’s the same controls, split across two lines, so the headline number looks competitive.
Worth checking which one you’re being handed. Ask directly.
The floor for managed services is $995 a month. A business with heavier compliance obligations or more locations sits higher, and our cybersecurity work scales with what’s actually in the environment rather than with a per-product menu.
What the Monthly Fee Already Covers
Here’s the layer-by-layer version. I’ve left dollar amounts off the individual rows on purpose, because quoting a per-control price would be inventing a number, and the whole point is that these aren’t sold separately at this size.
| Layer | What It Actually Does | How It’s Usually Priced |
|---|---|---|
| Multi-factor authentication | Stops a stolen password from being enough on its own | In the agreement |
| Endpoint detection and response | Watches behavior on the machine, not just known signatures | In the agreement, per device |
| Patching and updates | Closes the holes attackers actually use first | In the agreement |
| Backup with tested restores | Turns a ransomware event into a bad week instead of a closure | In the agreement, storage scales with data |
| Email filtering and spoofing controls | Catches most of what actually arrives, before anyone reads it | In the agreement |
| Staff awareness training | Addresses the part no product covers | In the agreement |
| Risk assessment | Tells you which of the above you’re actually missing | Free |
| Remediation of what the assessment finds | One-time work to close existing gaps | Scoped and quoted separately |
Two rows in that table are worth arguing about. Just two. They’re also the two most people get wrong.
Endpoint detection is the first. If your current provider says you’re covered and what’s actually installed is traditional antivirus, those are different products with different answers on an insurance form, and I wrote out the distinction in the EDR versus antivirus breakdown. Backup is the second. Nightly jobs running isn’t the same as a restore somebody has tested. Not close. The difference only ever shows up on the worst day.
If You Can’t Do Everything at Once, Do It in This Order
Not every business can absorb the whole thing in one quarter. Fine. Normal, actually. There’s a defensible order, and it’s not the order most vendors pitch.
- Multi-factor authentication first, on email and remote access, enforced rather than offered. It’s the cheapest meaningful control there is and it blocks the most common way small businesses actually get hit. The distinction between enforced and merely available is the whole game, which is why insurers ask about it that way.
- Backups you’ve actually restored from. Not configured. Restored.
- Then endpoint detection across every machine, because that’s the control that catches what gets past the first two.
- Patching on a schedule somebody owns, rather than whenever a user clicks the reminder.
- Training last of the essentials, though “last” here still means this year.
CISA publishes a small-business guidance set and a Cyber Essentials starting point that line up closely with that sequence, and neither costs anything to read. If a provider hands you a proposal that inverts this order, leading with an expensive monitoring product before MFA is enforced everywhere, ask why.

The Comparison That Makes the Monthly Number Look Small
This is the part I actually want owners to sit with. The monthly figure means nothing in isolation.
A ransomware recovery for a business our size typically runs $50,000 to over $100,000 in direct costs, and that’s before business interruption, lost revenue, and the weeks of rebuilding that follow. The Verizon Data Breach Investigations Report puts breach costs for a business this size between $120,000 and $1.24 million.
Set that against a monthly agreement and the arithmetic stops being complicated. It isn’t close.
What I won’t tell you is that spending more always buys more safety. Most clients don’t need a $50,000 enterprise security stack, and I’ve talked people out of buying one. Past a certain point you’re paying for capability that assumes a security team you don’t employ, and shelfware protects nobody. None of it. The controls above, actually running and actually documented, cover the realistic threat to a twenty-person business in this county far better than an expensive product nobody has configured.
What This Looks Like in Rockland
A few things are genuinely local here. One affects price.
We’ve run out of Garnerville since 2004, which means Rockland clients aren’t paying a travel premium baked into the rate to cover a technician driving in from another county. That’s not a discount so much as an absence of a markup other providers have to carry.
The rest is business mix. Rockland runs heavy on professional practices, medical and dental offices, construction and contracting firms, and the small manufacturers along the Route 303 and 9W corridors. Practices holding patient or financial records land toward the upper half of any range, because the controls a regulator expects are real work. A contractor with a field crew and no regulated data sits lower. Same rate card either way. Different environment.
What Rockland Owners Ask Me About Security Costs
We already pay for managed IT. Are we paying twice if we add security?
A provider quoted us a separate monthly security fee on top of the base rate. Is that normal?
What’s the cheapest thing we could do this month that actually moves the needle?
Our current provider says security is included. How do we verify that?
We’re eight people. Is there a size where this stops being worth it?
What would you tell us not to buy?
The assessment is free and comes before any quote. You’ll get a written picture of where you stand, and it’s yours whether you hire us or not.
