Cyber: The Next Great Divide — and Opportunity
Cybersecurity has quietly become the defining fault line between businesses that scale and those that stumble.
What was once treated as an IT hygiene issue—sometimes even a nice-to-have—is increasingly a strategic capability. It sits behind customer trust, enterprise procurement, investor confidence and, ultimately, business value.
The World Economic Forum’s Global Cybersecurity Outlook 2025 captures the challenge well: complexity is increasing faster than many organisations can adapt. AI-enabled fraud, ransomware-as-a-service, geopolitical risk and attacks through increasingly interconnected supply chains are expanding the threat surface.
But where risk increases, markets tend to emerge.
And cybersecurity is becoming one of the most significant technology opportunities of the decade.
From threat to market
The commercial logic is straightforward. As the economic cost of cyber incidents increases, businesses have little choice but to spend more on prevention, resilience and insurance.
For founders, the opportunity is not simply to build another security product. It is to turn an increasingly complex problem into something customers can understand, deploy and measure.
That creates opportunities across AI-driven threat detection, managed security for SMEs, cyber-resilience analytics, privacy technology, compliance automation and tools that translate technical vulnerabilities into financial and operational risk.
The next generation of cybersecurity businesses will not simply protect data.
They will protect confidence.
And that matters because cyber is moving from the server room to the boardroom.
Complexity is creating inequality
One of the most striking findings in the WEF report is the widening gap between large and small organisations.
Thirty-five per cent of smaller organisations report that their cyber resilience is inadequate—a significant increase from 2022—while larger enterprises have generally become better equipped to manage the threat.
But this is not simply a problem for smaller companies.
Large organisations increasingly depend on complex ecosystems of suppliers, platforms and technology partners. Their security is therefore partly determined by the resilience of businesses they do not control.
The weakest point in the system may no longer sit inside the enterprise itself. It may be a supplier several steps down the chain.
That has important implications for founders.
If you sell into large enterprises, demonstrating cyber resilience is increasingly part of the price of entry. Security standards, data governance and resilience will become progressively more important within procurement and due diligence.
If you sell cybersecurity capability, the opposite is true: your addressable market is expanding. Every smaller company participating in a critical supply chain increasingly needs security capabilities that historically only large enterprises could afford.
That creates a substantial market for products that make enterprise-grade security accessible to smaller organisations.
AI: the double-edged sword
AI is accelerating both sides of the cybersecurity equation.
According to the WEF, 66% of organisations expect AI to have the greatest impact on cybersecurity in the coming year, yet only 37% have processes in place to assess the security of AI tools before deploying them.
That gap creates opportunity.
As businesses race to deploy generative AI, they also need ways to understand what those systems can access, how models behave, where sensitive data is going and what new vulnerabilities are being introduced.
AI assurance, model-risk monitoring, identity protection and AI-native security architecture are therefore becoming important new categories.
At the same time, attackers have access to the same technology.
Deepfakes, synthetic voices and increasingly convincing phishing attacks dramatically reduce the cost of sophisticated fraud. The widely reported Arup case—in which an employee was deceived during a deepfake video call as part of a fraud resulting in a multimillion-pound loss—demonstrated how quickly the distinction between digital and human security is disappearing.
Cybersecurity can no longer simply protect the system.
It increasingly needs to protect the person using it.
Regulation can become a moat
Regulation is also raising the bar.
Europe’s Cyber Resilience Act and NIS2, alongside evolving cybersecurity requirements in the US and elsewhere, are increasing the compliance burden on companies operating across digital supply chains.
At first glance, that looks like another cost.
For the right businesses, it can become an advantage.
Products that automate compliance, provide continuous assurance or make security standards easier to evidence can turn regulation into a source of recurring demand.
For founders building cybersecurity businesses, the ability to embed regulatory requirements into the product can also create defensibility. Once security and compliance infrastructure becomes part of a customer’s operating environment, replacing it becomes considerably harder.
In other words, regulation does not simply create friction.
It can create switching costs.
The skills shortage is a market too
Technology is only part of the problem.
Organisations continue to struggle to recruit and retain experienced cybersecurity professionals. That shortage places further pressure on already stretched security teams—and creates another opportunity for technology.
Automation, managed services and AI copilots can allow scarce specialists to manage significantly more infrastructure without requiring security headcount to grow at the same rate.
For founders, this is a useful way to think about AI more broadly.
Some of the strongest AI opportunities may not replace specialist expertise. They will amplify scarce expertise, allowing a relatively small number of highly skilled people to operate at much greater scale.
Cybersecurity is a particularly clear example.
Cybersecurity and enterprise value
There is another reason founders should care about cybersecurity: eventually, someone else may diligence the business.
Investors and acquirers increasingly need to understand not only a company’s financial performance, but the resilience of the infrastructure supporting it.
A serious breach can damage customer relationships, expose regulatory liabilities, interrupt operations and reveal weaknesses in systems or governance. Conversely, strong security practices can make enterprise customers more comfortable adopting a product and reduce perceived risk for an investor or buyer.
Cyber maturity is therefore becoming part of business quality.
That is particularly relevant for SaaS, AI, data, FinTech and other technology businesses where much of the company’s value depends on intellectual property, proprietary data and customer trust.