Published: 25/08/26

Why aren’t growing businesses using cyber security to unlock revenue?

Many businesses view cyber security as an insurance policy: a cost with minimal visible upside, but catastrophic potential downside. You invest primarily to stop the worst from happening.

As someone who leads both the sales and marketing efforts for SEP2, cyber security company, I want to challenge that mindset. What if cyber security isn’t just a cost centre, but a direct driver of business growth and revenue?

In my role, I constantly analyse data on why organisations buy from us. Time and time again, I hear this phrase from growing businesses and startups:

“We need your product if we win this large contract.”

In essence, these organisations are looking to deploy MDR, vCISO, or another service solely to clear a hurdle in a tender process or pitch. I completely understand this approach. It allows finance to offset the investment against a new deal as a “cost of delivery,” while keeping overheads low without stalling the sales pipeline.

But the really interesting part is what happens next.

From a “Cost of Delivery” to a Deal Winner

Once these controls are in place and the contract is won, our customers often come back with the same feedback: their effective security posture is actively helping them win more business.

Here’s why:

  • It opens hidden doors: Prospects often disqualify vendors before even making contact if basic security controls aren’t present. Plus, with buyers increasingly using AI to source suppliers, prompts like “Find me a provider that does [X], but they must be ISO 27001 compliant” are becoming common. If you don’t have the accreditation, you won’t even show up in the results.
  • It boosts win rates: Many sales reps don’t track cyber security as a core sales metric, but buyers certainly do. A security leader will sanity-check any new vendor. In a 50/50 decision between you and a competitor, if they have a 24/7 SOC and you don’t, you lose. And trust me as a sales leader: prospects rarely admit the real reason you lost, instead, they’ll give a polite, generic reason so they can move on.
  • It turns into a marketing differentiator: Our clients frequently want to create joint case studies, such as these, and actively advertise their security posture to stand out against their competition.

A Shift in Mindset

A few weeks ago, I had a breath of fresh air. A prospect came to us with a completely different mindset:

“We are new to the market, and our branding centres on reliability and trustworthiness. Therefore, we want to bake top-level security in from day one.”

This raises an important question: Will more growing organisations start taking this proactive approach? Or will the reality of MVPs mean most businesses only invest when there is an immediate plus sign at the bottom of a specific deal sheet?

In our commercial leadership team, we always ask: “Can we draw a direct line to revenue from this investment?”

When it comes to cyber security, I see that line clear as day.

Two Final Challenges

To wrap up, I’d like to offer two challenges:

  1. For Cyber Leaders in growing organisations: Challenge your executive team to invest in cyber security early, not out of fear, but because of the commercial opportunities it unlocks.
  2. For Cyber Sales Leaders: Stop selling on FUD (Fear, Uncertainty, and Doubt). Let’s start talking to customers about the actual revenue strong security can bring in.

Get the Latest

Wingman Insights

Photo of Paul Starr

Get thoughtful, people-powered cyber insights in your inbox once a month with our Wingman Insights newsletter

Name(Required)

By submitting this form, you are agreeing to our privacy policy.