For years, cybersecurity has sat in the accounts as the label no one wants: a cost centre. Something approved reluctantly, measured by what it spends and justified with fear. In 2026 that label no longer fits. Security has become a precondition for winning business: without it, some contracts do not get signed and some markets stay shut.
This isn't spin; it is a change in how buying works. When a regulated customer picks a supplier, security is already in the tender; when an insurer decides whether to cover you, it looks at your controls before your turnover; and when someone comes to buy your company, due diligence now tends to audit your security alongside your books, Cybersecurity companies like Hard2bit are hired for this purpose. It is worth understanding what security returns, in pounds and in contracts, before treating it as insurance you hope never to claim.
Cybersecurity has moved from a defensive expense to a business lever: it opens markets, cuts measurable losses and sustains the trust that keeps customers.
With NIS2 in force, regulated companies are obliged to demand security from their suppliers. Without a certification in hand, a supplier is shut out of tenders and large accounts, however good the product.
The cost of going without is quantifiable: IBM puts the average breach at US$4.44m, and insurers now make cover conditional on specific controls.
This is not an IT project; it is a board decision. NIS2 places accountability on the governing body, and the spend is justified by its return, not by fear.
What the rules now force buyers to demand
The sharpest push comes from regulation. The NIS2 Directive does not only require essential and important entities to manage their own risk: it requires them to manage the risk in their supply chain. In practice that means contractual clauses, security questionnaires and audit rights that regulated companies pass down to their suppliers, whether large firms or small ones. That is why NIS2 readiness has stopped being a concern only for the big players.
The incentive cuts both ways. For the regulated company, non-compliance can cost up to 10 million euros or 2% of worldwide turnover for essential entities. For the supplier, failing to demonstrate aligned security means losing the contract to a competitor that can. That is where certification stops being a nice-to-have: ISO 27001 certification for the European market and large accounts, ENS compliance if you work with the Spanish public sector, and SOC 2 if you sell into the United States.
In financial services the pressure comes from a different direction but lands in the same place: DORA requires firms to prove digital operational resilience and to keep a register of ICT providers, so each third party's security becomes part of what the regulator reviews.
The objection: “security is a cost that does not sell”
The usual pushback is reasonable and worth taking seriously. Security does not show up on the customer's invoice, it earns no revenue on its own, and it consumes budget that could go to product or sales. Seen that way, every pound on security is a pound not earned. It is why so many boards have treated it as a necessary evil, handed to IT and reviewed only when something breaks.
Why that objection no longer holds
The answer isn't to lean on fear, but to look at the return. There are three advantages, and all three can be measured.
Advantage 1: it opens doors that used to be shut
Security has moved inside the buying process. When a large customer weighs two equivalent suppliers and only one can show a certification in order and answer a security questionnaire without scrambling, the decision all but makes itself. Certification shortens the sales cycle — it spares weeks of the buyer's technical review — and in regulated sectors it is simply the price of entry. It is already in what procurement asks for when buying cybersecurity, not in theory.
And that work isn't a one-off. The regulated customer who brought you into its chain will run the assessment again, and here strong third-party risk management works in your favour: the supplier who arrives with evidence in order answers in days; the one who hunts for it each time, in weeks — if the customer waits at all.
Advantage 2: it turns a huge loss into a controlled cost
The second return is the one you avoid. According to IBM's Cost of a Data Breach 2025 report, a security breach costs an average of US$4.44m worldwide and US$10.22m in the United States; the study, across 600 organisations in 16 countries, also recorded the first fall in cost in five years, credited to faster detection and containment. Put plainly: the controls that detect and contain sooner are not an expense — they are the difference between a scare and a seven-figure number.
Insurance confirms it from the other side. Insurers no longer cover blindly: they require MFA, EDR, immutable backups and a tested response plan as a condition of issuing the policy, and they verify posture with outside-in scans before they sign. Without those controls, the premium jumps, or the insurer declines. Security here is not a cost added to the insurance: it is what makes the cover available in the first place.
Advantage 3: it sustains the trust that keeps customers and protects value
The third return is harder to put in a spreadsheet, but it counts. Your security posture shapes whether a customer renews, how you come through due diligence when someone wants to buy the company, and a reputation that takes years to build and one incident to dent. The budget is now defended like any other investment, and the market bears that out: Gartner puts worldwide information-security spending at around US$213bn in 2025, with more growth forecast for 2026.
This is also the underlying reason separating cybersecurity from compliance is a mistake: when the business depends on demonstrating security, the technical work and the regulatory evidence are the same conversation, and they are best brought to the board together through a cyber-resilience dashboard the board can actually follow.
What to do in practice
The opposite mistake would be to rush out and certify everything just in case. The sensible sequence starts with knowing what to protect: a risk assessment that ranks assets, threats and business impact, not a generic checklist of controls. From there, the certification is chosen by who you sell to, and pursued when a specific market asks for it, not before.
And you do not need to build a security team from scratch to get there. Many companies cover the operation with a managed security service (MSSP) or a managed SOC, and leave leadership with what cannot be delegated: deciding how much risk to accept and answering for it. What is worth having from the start is the evidence — policies, logs and controls you can show — because today customers and insurers ask for proof, not promises. It is one of the digital supply-chain lessons of the last two years.
The cost of standing still
Standing still has a price too; it just arrives later and at a worse moment: a tender lost for want of a certificate, a customer who leaves after a questionnaire you could not answer, an unaffordable insurance premium, or the accountability NIS2 places on the governing body when risk management fails. None of those invoices appears in the security budget, but the company pays every one of them.
The decision that belongs to the board
The useful question for leadership is no longer how much security costs, but how much of the business depends on it. Treated as investment, it has a return you can measure in contracts won, losses avoided and customers kept. Treated as insurance you hope never to claim, it will keep looking expensive until the day it turns out to have been cheap. And that is a board decision, not one for IT.