The short answer
Outage monitoring is worth it when the hours it saves cost more than the plan. Work out what one hour of outage costs you, divide the tier price by that number, and you get the hours a month the plan must save. Watch saves detection time, Respond saves response time, Managed saves drives and overnight hours.
This case study is an illustrative scenario. The business is a composite and the numbers are worked examples to show the method, not results from a named client.
How do you tell if outage monitoring is worth it for a small business?
Compare two numbers: the monthly price of a tier, and the cost of the outage hours it saves you each month. Divide the price by your cost per outage hour. The result is your break-even in hours. If the plan realistically saves more hours than that, it pays for itself. If not, it does not.
Written as a formula:
- Break-even hours per month = tier price per month ÷ cost of one outage hour.
- Hours saved per month = incidents per month × hours saved per incident.
- Worth it when hours saved per month is greater than break-even hours per month.
Monitoring never makes outages disappear. What it changes is the length of each one. Every outage has three gaps: from failure to someone knowing, from knowing to someone acting, and from acting to fixed. Each tier attacks a different gap, and that is how you estimate "hours saved per incident" for each one. A tier that shortens a gap you do not have saves you nothing, however good it sounds.
The rest of this article works through a composite business so you can see the arithmetic. Use it as a template. Replace every number with your own, then take the tier prices from the pricing page and finish the sum yourself.
What does one hour of outage actually cost your business?
It depends on which service fails. For each one, add revenue per hour times the share you really lose, staff idle times their loaded wage, and missed calls times booking rate times booking value. A dead phone line at opening can cost many times more than a slow website at midnight.
This is a small version of what NIST calls a business impact analysis. Its contingency planning guide sets out three steps: identify the business processes a system supports and the impact and estimated downtime if it fails, identify the resources needed to recover, and set recovery priorities [1]. The same guide defines Maximum Tolerable Downtime, the total time an owner is willing to accept a process being down, and Recovery Time Objective, how long one system can stay down before that limit is at risk [1]. The Canadian Centre for Cyber Security's baseline controls ask small organizations to assess the same thing in plainer terms: the injury if a system is not available [2].
Take a composite business: a trades company with a dispatch office, eight staff in the office and on the road, most jobs booked by phone, the rest through a website form. Call its revenue per open hour R and the loaded hourly wage W. Its owner estimates:
- Phones down during business hours: half of that hour's bookings are lost for good, and three office staff are mostly idle. One hour costs about 0.5R + 3W.
- Website form down: most people who cannot book online call instead. One hour costs about 0.05R.
- Ad account paused on a declined card: no idle staff, but leads stop. One hour costs about 0.1R.
Notice how different those are. Averaging them would hide the one that matters. Do the break-even on the service that costs the most, then treat the others as a bonus.
When does Watch pay for itself?
Watch pays for itself when finding out sooner is the problem. It runs up to 60 checks, as often as every 60 seconds, and alerts your team by SMS, email or voice. Hours saved per incident is the time you used to spend not knowing, usually until a customer complained, minus a few minutes.
Without monitoring, most small businesses find out about an outage from a customer, a staff member or a sudden quiet. For the trades company, the owner remembers two phone outages last year that nobody noticed for about 90 minutes each, and a website form that was broken for most of a weekend.
- Hours saved per incident (Watch) = typical time to discovery without monitoring − time to alert.
- Watch worth it when (incidents per month × hours saved per incident × cost per outage hour) is greater than the Watch price.
For the phone outages, that is roughly 1.4 hours saved each time, at 0.5R + 3W an hour. Watch also includes a war room timeline and one public status page, which cut the calls asking "are you open?" but are hard to value, so leave them out of the sum. If the answer only works with the soft benefits added in, it does not really work.
Watch does nothing about the second gap. You still have to stop what you are doing, work out what failed and fix it. If you can do that in ten minutes, Watch is probably the whole answer.
When does Respond pay for itself?
Respond pays for itself when the response, not the discovery, eats the hours. It adds the MapleMonitor agent setting priority and running your runbook, pre-approved customer updates by SMS, email or voice, a conference line per war room, balance and social checks, and written outage summaries. Count the owner hours each incident no longer takes.
For the trades company, the owner spends about an hour per phone incident on things other than the fix: phoning the crew, texting customers booked for the morning, answering "what happened?" afterwards. Respond takes most of that on, using only wording the owner approved at setup.
- Hours saved per incident (Respond) = Watch hours saved + owner hours no longer spent coordinating + staff hours no longer spent fielding customer calls.
- Extra checks: account balance checks catch a declined card before ads pause. Hours saved = typical hours an account stayed paused before anyone noticed.
Value the owner's hours honestly. An owner hour at 7 a.m. is not free just because nobody pays it as wages; it is time not spent quoting jobs. Many owners use R divided by the number of people who generate revenue as a rough hourly value. Whatever figure you pick, use the same one for every tier so the comparison stays fair.
When does Managed pay for itself?
Managed pays for itself when failures happen out of hours or need skills you do not have. It adds, per site, people on call 24/7 behind the agent, remote repair before anyone drives in, test calls to your phone lines and runbooks written for your business. Count drives avoided and opening hours no longer lost.
Because Managed is per site, run the sum per location:
- Drive hours avoided = overnight or weekend incidents fixed remotely × round-trip hours.
- Opening hours kept = incidents that would have been found at opening × hours from opening to fix.
- Value = drive hours × the driver's hourly value + opening hours kept × cost per outage hour.
The alternative is covering those hours yourself. A business open 50 hours a week has 118 hours a week with nobody there, about 6,100 hours a year. Covering that properly takes a rotation of several people, not one. Statistics Canada found that among businesses with ten or more employees, the most common reason for not having cyber security staff was using consultants or contractors instead [3]. The Cyber Centre's advice is to plan in advance for incidents you cannot manage on your own [2]. If no overnight incident in the last year would have been found late at opening, the Managed rows of your sum will be close to zero, and that is a real answer.
When do the add-ons pay for themselves?
Each add-on has its own break-even. The outage status line pays when callers hang up during outages. Extra 50 checks pay when you need more than 60. An extra status page pays when you run separate brands. Hands-on incident hours pay when you would otherwise call a technician. Price each against the hours it saves.
- Outage status line. Callers to your number hear about the outage and can get a live update from our receptionist. Value = calls during outages × share who would otherwise not call back × booking rate × booking value.
- Extra 50 checks. Only matters once your list of phones, sites, domains, certificates, mailboxes and accounts exceeds 60. Before buying, cut checks that would not change what you do.
- Extra status page. Worth it when two brands or locations have different customers who should not see each other's incidents.
- Hands-on incident work by the hour. Compare hours of work against the hours your usual technician would bill, including travel.
Security monitoring, such as sign-ins from outside Canada, is not an add-on here; it is MapleSIEM, sold separately. Run its sum separately too. The rule for every add-on is the same as for the tiers: if you cannot name the hours it would have saved last year, wait until the war room timelines show you a pattern before buying it.
What does the break-even look like with worked numbers?
For the composite trades company, Watch saves about 3 hours a year on phones, Respond adds about 4 more owner and staff hours, and Managed at one site adds drive and opening hours. Divide each tier price by the cost per outage hour, compare, and the tier that clears break-even with room to spare is the one to pick.
| Tier | What it saves | Hours saved a year | Value a year |
|---|---|---|---|
| Watch | 2 incidents × 1.4 hours found sooner | 2.8 outage hours | 2.8 × (0.5R + 3W) |
| Respond | Watch + 2 incidents × 1 owner hour + 2 × 1 staff hour on calls | 2.8 outage hours + 2 owner + 2 staff hours | Watch value + 2 owner hours + 2W |
| Managed | Respond + 1 overnight incident fixed remotely: 1 hour drive + 1.5 opening hours kept | 4.3 outage hours + 3 owner + 2 staff hours | Respond value + 1 drive hour + 1.5 × (0.5R + 3W) |
To finish the sum, put in your own R and W, multiply out the last column, and compare each row with twelve months of that tier's price. For this composite business, with phone outages only a few times a year, the likely answer is Watch. That is the point of doing the arithmetic.
How often do outages really happen?
Less often than vendors imply, and more often than owners remember. Uptime Institute reports that per-site outage rates in data centres have declined for five years running, but improvement is slowing, and third-party providers account for about two-thirds of publicly reported outages [4]. Your own failure log is the number that counts.
The Uptime figures describe large operators, not a dispatch office, so do not copy them into your sum. What carries over is the pattern: more failures now start outside your building, in connectivity and in the providers you depend on, and failures to follow procedures are the leading cause of human-error outages [4]. Written runbooks exist for exactly that reason. For your own sum, count the outages you can name from the last twelve months, per service, and treat that as a floor. The ones nobody noticed are, by definition, missing from the list.
For cyber incidents specifically, Statistics Canada found 16% of businesses with ten or more employees were impacted in 2023, down from 21% in 2019 [3]. The same survey found monitoring network and business systems was the most common cyber security activity businesses reported, at 46% [3]. NIST's incident response guidance frames the goal as reducing both the number and the impact of incidents [5]; monitoring works on impact.
Which tier fits, and who should buy nothing?
Many very small businesses need only Watch, and some need nothing. If an outage hour costs you close to zero, because customers email and can wait, the break-even is out of reach at any price. Watch fits when you can fix things yourself; Respond when coordinating is the burden; Managed when failures happen overnight across sites.
- Nothing: a sole proprietor whose customers reach them by email and whose website is a brochure. A calendar reminder to check the domain renewal and certificate is enough.
- Watch: a single location where the owner or a staff member can fix most failures once they know, and the main cost is finding out late.
- Respond: a business where each incident means an hour of phoning crews and customers, or where ad and account balances quietly lapse.
- Managed: several sites, phones that must answer at opening, and no one on staff who can fix them at 5 a.m.
BDC notes that many entrepreneurs do not think about technology risk until something bad happens, and that the right time is before the crisis [6]. Before is also the right time to decide that the risk is small. Choosing nothing on purpose, with the sum written down, is a plan too.
What should you do this week?
Spend twenty minutes on a one-page impact list. Write down every service customers touch, what one hour of each being down costs using the formula above, and every outage you remember from the last twelve months with how long it took to notice. Then divide each tier price by your costliest hour.
If the break-even hours are more than you can honestly expect to save, stop there; you have your answer, and it cost nothing. If they are fewer, start with the lowest tier that clears the bar. After three months of war room timelines you will have a real incident count instead of a remembered one, and you can run the sum again with better numbers.
Keep the page. Put it with your written incident plan, next to the names of who is responsible and who to call [2]. When a provider changes, a new location opens or a phone system is replaced, the hourly costs change too, and the page tells you in five minutes whether the tier you picked still makes sense. Revisit it at least once a year, and after any outage that cost more than you expected.