Security · Explainer
Is free Have I Been Pwned enough, or does a business need a paid service?
Free HIBP is enough to spot-check individual addresses. For a business, the paid Domain Search (from $4.39/month for one domain) is the baseline, because it continuously monitors every address on your domain instead of one at a time. You only need a managed service above that, Dark Web ID, SpyCloud, Flare, when you need someone to act on alerts (forced resets, remediation), and those price by quote. Ladder: free search → paid Domain Search → managed service, escalating only when the previous rung stops meeting the need.
Updated August 2026 · Reviewed by the SMB Stack Brief desk
What "free" covers
The free Have I Been Pwned search lets anyone type an email address and see which known breaches it appeared in. It is genuinely useful and genuinely free, good for checking your own accounts or investigating a specific address. Its limit for a business is that it is a manual, one-address-at-a-time lookup, not continuous coverage of your staff domain.
Where paid Domain Search earns its keep
HIBP Domain Search verifies you control a domain, then monitors every address under it and alerts you on new breaches. Pricing is transparent and per-domain: $4.39, $21.59, $36.99, $159 and $319 per month for 1, 3, 5, 10 and 20 domains. For most small businesses this is the right buy, ongoing coverage of the whole team for the price of a couple of coffees.
When to escalate beyond HIBP
Move to a managed service only when the bottleneck is action, not awareness: you want forced resets pushed to staff, account-takeover blocking, or remediation of malware-exfiltrated data. Dark Web ID, SpyCloud and Flare provide that but sell by quote. The layered posture the CISA and FTC SMB guidance describes, MFA, a password manager, patching, monitoring, matters more than which monitor you pick; monitoring is the trigger, not the whole defence.
The MFA caveat
"We have MFA" does not retire monitoring. Infostealer malware can lift a live session cookie and replay an authenticated session past MFA, and reused passwords still endanger other accounts. NIST SP 800-63B advises rotating credentials on evidence of compromise, and monitoring is how you get that evidence.
Note, unrelated to the free-vs-paid decision above: BreachTrigger alerts when a public company files a material-incident 8-K with the SEC. It is not a HIBP-style credential monitor and does not belong on this free-vs-paid ladder, it answers a different question (has a public-company vendor disclosed a breach?), not this one.