Been thinking about what it actually takes to run a solo cybersecurity business not the big firm model, but someone working alone, doing audits, pen tests, maybe bug bounties, keeping things simple.
I keep seeing messages like:
- You’ll never break 40k your first year if you don’t have clients lined up.
- Selling a 5 k audit takes as much effort as a 50k gig.
So my question for someone standing up a solo cybersecurity service in 2026, what’s a realistic income range to aim for in year one and year two? And what are the variables that make the biggest difference niche, client size and repeat work?
Just trying to set my expectations I want to build something I can live off, not just mess around.
