Management buy-in for an IT security budget usually stalls on one argument: nothing bad has happened yet. Years without an incident get treated as proof that the current setup works, and the size of the number barely enters into it. This is what that logic cost one manufacturing client of mine over three years, in figures I have in writing because I sent them by email as they happened.

This is an anonymised, composite case from my own client work; figures are rounded.

The Environment Nobody Wanted to Touch

2021. A 120-employee, family-owned manufacturing company in southern Germany, 35 years in business, brought me in for a look at their IT. What I found:

Seventeen Windows Server 2008 R2 boxes, end of life since 2020. A domain existed, mostly because Exchange needed one, but nothing was managed through it: 120 machines configured one by one, every user a local admin. Backup was a USB drive an employee plugged in on Fridays, when he remembered. Email ran on on-prem Exchange 2010, no MFA, and the CFO checked it from his iPad at the airport. The firewall was a consumer Fritz!Box with the company name as the password.

None of this is exotic. It's the default state of a lot of SMBs that have never had a reason to think about it.

What I Recommended, and What It Was Worth

I put four things in writing: Microsoft 365 Business Premium across all 120 seats for identity, device management, and email security, at roughly €28,800 a year. Decommissioning the 2008 servers. MFA on every account, immediately. A real backup, not the Friday USB drive.

The responses, paraphrased from the same emails:

The CFO did the multiplication (€20 times 120 people times 12 months) and asked what exactly they'd get for that money, since email already worked fine. The CEO pointed out the servers had run for twelve years, so why would they fail now. The office manager, who "knew computers," mentioned that her nephew had set up the USB backup and it had been fine for years.

They approved nothing. The decision was to revisit next quarter.

Why Is "Nothing Bad Has Happened Yet" the Most Expensive Sentence in IT?

Nothing changed in year two, except the failure rate. The Exchange server crashed twice; I rebuilt it both times over a weekend. Three laptops got crypto-locked by commodity malware, and the response was to buy new laptops, not to investigate how. The server room's fifteen-year-old wall-unit AC started grinding; a replacement quote came in at €3,500, and the CFO asked if a fan would do instead. The USB backup drive itself got lost at some point. Nobody knew what, if anything, had been on it.

Somewhere in that year, the CFO said something I still think about: "Philipp, you keep telling us to spend money, but nothing bad has actually happened. Maybe we're doing fine."

Nothing bad had happened because I'd been catching problems before they became incidents. That part is invisible by design, which is exactly why it never shows up in anyone's cost-benefit calculation.

What Documentation Actually Buys You

I kept every recommendation in writing: the date, the cost, the response. In SMB IT security budget conversations, "we told you" and "we can prove we told you" are two different professional positions, and only one of them holds up in a board meeting.

That habit turned out to matter more than any single recommendation I made. What it protected, and what it didn't prevent, is Part 2 of this story: what happened when new leadership arrived and started cutting the few safeguards that were still standing.

Zero Trust. Zero Drama. Zero Bullshit.

Which of your own recommendations has been sitting on “revisit next quarter” the longest, and do you still have the email that proves you made it?

If you want to see how I'd put that list in front of your management: drop me a note. Thirty minutes, I'll show you.

Talk it through with me

Frequently Asked Questions

Why do small businesses decline security recommendations they can afford?

The price is rarely the real objection. What's actually happening is survivorship bias: years without an incident get read as evidence the setup works, when it's often evidence someone's been preventing incidents without anyone noticing.

What does Microsoft 365 Business Premium cost for a small business?

Pricing varies by region and licensing agreement, but for a 100+ seat SMB the ballpark is in the €20–25 per user, per month range, which is small compared to the cost of a single serious incident.

How do I get management buy-in for an IT security budget?

Tie every recommendation to a specific business consequence, not a technical feature: a person, a date, a number. Put it in writing. A good pitch doesn't guarantee buy-in, but the paper trail protects you either way.

Is an unsupported end-of-life server actually risky if it's “been fine for years”?

Years without failure change nothing about the underlying risk: no security patches, no vendor support, and an increasingly slow path back if it does fail. “Fine for years” describes the past, not the odds going forward.