SMB Stack Brief

Security · Explainer

Is free Have I Been Pwned enough, or does a business need a paid service?

Direct answer

Free HIBP is enough to spot-check individual addresses. For a business, the paid Domain Search (from $4.39/month for one domain) is the baseline, because it continuously monitors every address on your domain instead of one at a time. You only need a managed service above that, Dark Web ID, SpyCloud, Flare, when you need someone to act on alerts (forced resets, remediation), and those price by quote. Ladder: free search → paid Domain Search → managed service, escalating only when the previous rung stops meeting the need.

Updated August 2026 · Reviewed by the SMB Stack Brief desk

What "free" covers

The free Have I Been Pwned search lets anyone type an email address and see which known breaches it appeared in. It is genuinely useful and genuinely free, good for checking your own accounts or investigating a specific address. Its limit for a business is that it is a manual, one-address-at-a-time lookup, not continuous coverage of your staff domain.

Where paid Domain Search earns its keep

HIBP Domain Search verifies you control a domain, then monitors every address under it and alerts you on new breaches. Pricing is transparent and per-domain: $4.39, $21.59, $36.99, $159 and $319 per month for 1, 3, 5, 10 and 20 domains. For most small businesses this is the right buy, ongoing coverage of the whole team for the price of a couple of coffees.

When to escalate beyond HIBP

Move to a managed service only when the bottleneck is action, not awareness: you want forced resets pushed to staff, account-takeover blocking, or remediation of malware-exfiltrated data. Dark Web ID, SpyCloud and Flare provide that but sell by quote. The layered posture the CISA and FTC SMB guidance describes, MFA, a password manager, patching, monitoring, matters more than which monitor you pick; monitoring is the trigger, not the whole defence.

The MFA caveat

"We have MFA" does not retire monitoring. Infostealer malware can lift a live session cookie and replay an authenticated session past MFA, and reused passwords still endanger other accounts. NIST SP 800-63B advises rotating credentials on evidence of compromise, and monitoring is how you get that evidence.

Note, unrelated to the free-vs-paid decision above: BreachTrigger alerts when a public company files a material-incident 8-K with the SEC. It is not a HIBP-style credential monitor and does not belong on this free-vs-paid ladder, it answers a different question (has a public-company vendor disclosed a breach?), not this one.

Primary sources

Frequently asked questions

Is the free version of Have I Been Pwned enough for a business?
For monitoring a single personal address, the free search is enough. For a business, the free search checks one address at a time and does not continuously monitor your whole domain, that is what HIBP Domain Search (from $4.39/month) adds. So free is fine for spot checks; paid Domain Search is the small-business baseline for ongoing coverage.
What does HIBP Domain Search add over the free search?
Domain Search monitors every email address on a domain you control and notifies you when any of them appears in a new breach, rather than requiring you to check addresses one by one. It is priced per number of domains from $4.39/month, verified from HIBP.
When should a business pay for a managed service instead of HIBP?
When you need someone to act on alerts, forced password resets across staff, account-takeover prevention, malware-victim remediation, rather than just be notified. Managed services (Dark Web ID, SpyCloud, Flare) add that but price by quote. If your team can action HIBP alerts itself, paid HIBP Domain Search is usually enough.