← Back to the cybersecurity blog

What cybersecurity brings to a business: from cost centre to a licence to sell

By Adrián González · CEO · Published: 07 August 2026 · Updated: 07 August 2026
What cybersecurity brings to a business

For years, cybersecurity has sat in the accounts as the label no one wants: a cost centre. Something approved reluctantly, measured by what it spends and justified with fear. In 2026 that label no longer fits. Security has become a precondition for winning business: without it, some contracts do not get signed and some markets stay shut.

This isn't spin; it is a change in how buying works. When a regulated customer picks a supplier, security is already in the tender; when an insurer decides whether to cover you, it looks at your controls before your turnover; and when someone comes to buy your company, due diligence now tends to audit your security alongside your books, Cybersecurity companies like Hard2bit are hired for this purpose. It is worth understanding what security returns, in pounds and in contracts, before treating it as insurance you hope never to claim.

Cybersecurity has moved from a defensive expense to a business lever: it opens markets, cuts measurable losses and sustains the trust that keeps customers.

With NIS2 in force, regulated companies are obliged to demand security from their suppliers. Without a certification in hand, a supplier is shut out of tenders and large accounts, however good the product.

The cost of going without is quantifiable: IBM puts the average breach at US$4.44m, and insurers now make cover conditional on specific controls.

This is not an IT project; it is a board decision. NIS2 places accountability on the governing body, and the spend is justified by its return, not by fear.

What the rules now force buyers to demand

The sharpest push comes from regulation. The NIS2 Directive does not only require essential and important entities to manage their own risk: it requires them to manage the risk in their supply chain. In practice that means contractual clauses, security questionnaires and audit rights that regulated companies pass down to their suppliers, whether large firms or small ones. That is why NIS2 readiness has stopped being a concern only for the big players.

The incentive cuts both ways. For the regulated company, non-compliance can cost up to 10 million euros or 2% of worldwide turnover for essential entities. For the supplier, failing to demonstrate aligned security means losing the contract to a competitor that can. That is where certification stops being a nice-to-have: ISO 27001 certification for the European market and large accounts, ENS compliance if you work with the Spanish public sector, and SOC 2 if you sell into the United States.

In financial services the pressure comes from a different direction but lands in the same place: DORA requires firms to prove digital operational resilience and to keep a register of ICT providers, so each third party's security becomes part of what the regulator reviews.

The objection: “security is a cost that does not sell”

The usual pushback is reasonable and worth taking seriously. Security does not show up on the customer's invoice, it earns no revenue on its own, and it consumes budget that could go to product or sales. Seen that way, every pound on security is a pound not earned. It is why so many boards have treated it as a necessary evil, handed to IT and reviewed only when something breaks.

Why that objection no longer holds

The answer isn't to lean on fear, but to look at the return. There are three advantages, and all three can be measured.

Advantage 1: it opens doors that used to be shut

Security has moved inside the buying process. When a large customer weighs two equivalent suppliers and only one can show a certification in order and answer a security questionnaire without scrambling, the decision all but makes itself. Certification shortens the sales cycle — it spares weeks of the buyer's technical review — and in regulated sectors it is simply the price of entry. It is already in what procurement asks for when buying cybersecurity, not in theory.

And that work isn't a one-off. The regulated customer who brought you into its chain will run the assessment again, and here strong third-party risk management works in your favour: the supplier who arrives with evidence in order answers in days; the one who hunts for it each time, in weeks — if the customer waits at all.

Advantage 2: it turns a huge loss into a controlled cost

The second return is the one you avoid. According to IBM's Cost of a Data Breach 2025 report, a security breach costs an average of US$4.44m worldwide and US$10.22m in the United States; the study, across 600 organisations in 16 countries, also recorded the first fall in cost in five years, credited to faster detection and containment. Put plainly: the controls that detect and contain sooner are not an expense — they are the difference between a scare and a seven-figure number.

Insurance confirms it from the other side. Insurers no longer cover blindly: they require MFA, EDR, immutable backups and a tested response plan as a condition of issuing the policy, and they verify posture with outside-in scans before they sign. Without those controls, the premium jumps, or the insurer declines. Security here is not a cost added to the insurance: it is what makes the cover available in the first place.

Advantage 3: it sustains the trust that keeps customers and protects value

The third return is harder to put in a spreadsheet, but it counts. Your security posture shapes whether a customer renews, how you come through due diligence when someone wants to buy the company, and a reputation that takes years to build and one incident to dent. The budget is now defended like any other investment, and the market bears that out: Gartner puts worldwide information-security spending at around US$213bn in 2025, with more growth forecast for 2026.

This is also the underlying reason separating cybersecurity from compliance is a mistake: when the business depends on demonstrating security, the technical work and the regulatory evidence are the same conversation, and they are best brought to the board together through a cyber-resilience dashboard the board can actually follow.

What to do in practice

The opposite mistake would be to rush out and certify everything just in case. The sensible sequence starts with knowing what to protect: a risk assessment that ranks assets, threats and business impact, not a generic checklist of controls. From there, the certification is chosen by who you sell to, and pursued when a specific market asks for it, not before.

And you do not need to build a security team from scratch to get there. Many companies cover the operation with a managed security service (MSSP) or a managed SOC, and leave leadership with what cannot be delegated: deciding how much risk to accept and answering for it. What is worth having from the start is the evidence — policies, logs and controls you can show — because today customers and insurers ask for proof, not promises. It is one of the digital supply-chain lessons of the last two years.

The cost of standing still

Standing still has a price too; it just arrives later and at a worse moment: a tender lost for want of a certificate, a customer who leaves after a questionnaire you could not answer, an unaffordable insurance premium, or the accountability NIS2 places on the governing body when risk management fails. None of those invoices appears in the security budget, but the company pays every one of them.

The decision that belongs to the board

The useful question for leadership is no longer how much security costs, but how much of the business depends on it. Treated as investment, it has a return you can measure in contracts won, losses avoided and customers kept. Treated as insurance you hope never to claim, it will keep looking expensive until the day it turns out to have been cheap. And that is a board decision, not one for IT.

Frequently asked questions

What does cybersecurity actually do for a business?

Three measurable things: market access (more customers and tenders now require certifications and controls before they will work with you), loss reduction (a serious incident costs millions and halts operations), and trust (customers renew, and acquirers value a company with strong security posture more highly). It has moved from a defensive cost to a condition for earning revenue.

Why do people say security “opens markets”?

Because security has entered the buying process. Companies regulated by NIS2 are obliged to demand assurances from their suppliers through clauses, questionnaires and audits. Faced with two similar suppliers, the one that can demonstrate security — with ISO 27001, ENS or SOC 2 — wins the contract, and the one that cannot is shut out. Certification also shortens the sales cycle by sparing weeks of buyer review.

What does NIS2 require of me as a supplier to a regulated company?

Even if you are not an essential or important entity, your regulated customer is obliged to pass security requirements down to you by contract: risk management, incident reporting, access control and, often, audit rights. In practice you will have to answer security questionnaires and demonstrate controls. Not being able to is reason enough to lose the contract.

How much does a security breach really cost?

According to IBM's Cost of a Data Breach 2025 report, the global average is 4.44 million dollars and 10.22 million in the United States, across a sample of 600 organisations in 16 countries. In 2025 the cost fell for the first time in five years, credited to faster detection and containment — meaning that investing in detecting and containing sooner directly reduces the bill for an incident.

ISO 27001, ENS or SOC 2: which do I need?

It depends who you sell to. ISO 27001 is the reference standard for European customers and large accounts; ENS is effectively required if you work with, or supply, the Spanish public sector; SOC 2 is what US customers usually ask for. The sensible approach is to certify for your target market and when a specific customer or tender requires it, rather than stacking frameworks just in case.

Does cybersecurity affect insurance and company valuation?

Yes, both. Insurers require specific controls — MFA, EDR, immutable backups, a tested response plan — as a condition of cover and verify posture with outside-in scans; without them the premium jumps or there is no policy. And in an acquisition, due diligence audits security the way it audits the accounts: a weak posture lowers the price or stalls the deal.

Is this only for large companies?

No. It is supplier SMEs that feel the shift most, because they receive their regulated customers' security demands without a large team to meet them. The good news is that the team is not required: with a managed service and an orderly set of evidence, a small company can clear the bar that opens those contracts.

Where do you start without overspending?

With a risk assessment that says what to protect and why, rather than buying isolated controls. From there you choose the certification by target market, prioritise the highest-impact controls, and document the evidence customers and insurers will ask for. Day-to-day operation can be outsourced; the decision on how much risk to accept cannot.

Not sure which EU rules reach you — or what meeting them costs?

NIS2 and DORA reach further than most companies expect, usually through a contract with a customer already in scope. We work out what genuinely applies to you in a 30-minute call with a technical consultant, not a salesperson, and you leave with priorities ranked and a price range. With what comes out of that call, we turn it into a fixed proposal. ISO 27001, NIS2, DORA and ENS — Spain's framework for suppliers to the public sector.

If your situation is different, tell us anyway — we also take one-off questions on cybersecurity and regulatory compliance.

Based in Spain · Working across the EU and LATAM · ENS High · ISO 27001 · We usually reply in under 24 business hours