The Business of Cyber Security

Sector Overlays: How Regulation Stacks by Vertical

On Nov 1, 2025, the final tranche of New York's amended cybersecurity rule (23 NYCRR Part 500, Second Amendment) took effect, mandating multi-factor authentication for every user of a covered financial institution's systems and a maintained asset inventory. Five weeks earlier, the proposed overhaul of the HIPAA Security Rule (the first since 2013, with an HHS-estimated ~$9B year-one cost) remained unfinalized after its comment period closed in March 2025. Cybersecurity regulation does not apply uniformly; it stacks by sector, as each heavily-regulated vertical layers its own rulebook on top of the cross-cutting federal/state baseline (16a). The most-regulated verticals (finance, healthcare, critical infrastructure, defense) become the deepest, most defensible demand pools, and each one spawns a distinct lane of vertical-specialist security vendors that form, scale, and get acquired on the sector's own regulatory cadence.

Vertical rulebooks create vertical M&A lanes

The horizontal regimes (16a/16b) set a floor that applies to everyone. The sector overlays sit on top and are far more prescriptive — they dictate specific controls (MFA, encryption, incident reporting windows, asset inventories), name specific regulators with examination and fining power, and run on sector-specific deadlines. The consequence mirrors the 16c calendar-catalyst logic but at vertical resolution: a finance-specific mandate creates demand a generalist tool can't fully serve, which rewards a finance-native security vendor, which becomes an acquisition target for a platform wanting that vertical's regulated install base. The deeper and more enforced the overlay, the more durable the vertical's profit pool (02b) and the more an acquirer will pay for a credible foothold in it. The four overlays below are the ones that most reliably originate deals.

Each sector overlay stacks on the baseline — and seeds its own vendor lane Cross-cutting floor (16a/16b) → vertical rulebook → vertical-specialist security demand Horizontal baseline — SEC disclosure · state privacy quilt · GDPR/NIS2/DORA (16a · 16b) Financial NYDFS Part 500 GLBA · PCI DSS 4.0 DORA (EU) Healthcare HIPAA Security Rule (overhaul pending) · FDA 524B Critical Infra TSA pipeline/rail NERC CIP · EPA CIRCIA (pending) Defense CMMC · DFARS FedRAMP · IL4/5 ITAR FinServ-native GRC, fraud, payments sec. Health-data sec. PHI, medical- device security OT/ICS security Dragos, Claroty, Nozomi (03h) Gov-grade / certified vendors + integrators (14a) Source: sector statutes (see Sources). Vendor lanes illustrative. Exhibit: The Business of Cyber Security.
The same cross-cutting baseline supports four very different vertical rulebooks — and each rulebook seeds a distinct vendor lane that platforms acquire to enter that regulated install base. Deepest enforcement (defense, critical infra) → most defensible demand. See [Certifications as Moats](16d-certifications-moats.md), [Federal Integrators](14a-federal-integrators.md), [OT/ICS](03h-ot-ics.md).

Financial services

Finance is the deepest-regulated commercial vertical, with overlapping rulebooks and regulators that examine and fine. New York's NYDFS Part 500 is the bellwether: its Second Amendment phased in new obligations through a final tranche effective Nov 1, 2025 — MFA for all users (NYDFS guidance favoring phishing-resistant, token-based MFA over SMS/push) and a maintained, policy-governed asset inventory. Stacked alongside are the GLBA Safeguards Rule (FTC-enforced, with a 30-day breach-notification requirement added in 2024), PCI DSS v4.0, whose 51 future-dated requirements became mandatory Mar 31, 2025 (notably MFA for all access to the cardholder-data environment and stronger payment-page script controls), Sarbanes-Oxley IT-controls expectations, and — in the EU — DORA (16b), live since Jan 17, 2025, with its critical-ICT-third-party oversight regime. Finance funds a permanent demand pool for GRC/TPRM (03i), fraud/AML, identity (03a), and payments security, and a finance-native compliance vendor with a regulated install base is a recurring platform target.

Healthcare

Healthcare's overlay is anchored by the HIPAA Security Rule, whose proposed overhaul — the first major update since 2013 — HHS/OCR issued on Dec 27, 2024 and published in the Federal Register on Jan 6, 2025; the comment period closed Mar 7, 2025, drawing nearly 5,000 comments and an organized industry pushback (a Feb 2025 letter from CHIME and 100+ hospital systems urging withdrawal over the HHS-projected ~$9B year-one cost). As of Jun 2026 no final rule has issued, and the prior spring-2026 target has passed (final-rule timing unverified/uncertain this run — added to backlog). The proposal would make many formerly "addressable" controls mandatory (encryption, MFA, asset inventories, network segmentation). Layered on top: FDA medical-device cybersecurity authority under Section 524B of the FD&C Act (premarket cyber requirements, with FDA "refuse-to-accept" enforcement since Oct 1, 2023), plus HHS 405(d) guidance and state health-data laws. Healthcare is a large, breach-prone vertical whose demand is set to step up whenever the rule finalizes — a forward pool for PHI data security (03g), identity, segmentation, and medical-device/OT security (03h).

Critical infrastructure

Critical infrastructure is where regulation is moving most aggressively, because the threat is most kinetic (15c, Volt Typhoon pre-positioning). Unlike the others it is sub-sector by sub-sector: TSA security directives govern pipelines and rail (the current pipeline directive, Pipeline-2021-02F, effective May 3, 2025, descended from the post-Colonial-Pipeline 2021 actions, with prescriptive mitigation, contingency-planning and testing obligations); NERC CIP standards govern the bulk power system; the EPA has pushed (and litigated) water-system cybersecurity expectations; and CIRCIA — the cross-sector 72-hour incident-reporting mandate — remains unfinalized as of Jun 2026 (16a). This overlay is the direct demand engine behind the OT/ICS security lane (03h) — Dragos, Claroty, Nozomi, Armis — and is precisely the lane Accenture entered by acquiring Dragos/runZero/NetRise (announced Jun 18, 2026; 14a). Sub-sector-specific rules with hard testing requirements make locally-credentialed OT vendors scarce and acquisition-attractive.

Defense

Defense is the overlay where the rulebook is a certification stack (16d): CMMC (the contractual phase-in began with the DFARS clause effective Nov 10, 2025, ramping over ~3 years to ~Nov 2028; ~80,000 contractors will need Level 2 against ~80 accredited assessors), FedRAMP and DoD IL4/IL5 for cloud, DFARS 252.204-7012, and ITAR export controls. Because access to the defense market is gated by these authorizations, the overlay does double duty — it both manufactures demand and creates the moat (16d) — and it channels spend through the federal integrators (14a), who buy certified product companies to serve it. This is the most defensible demand pool in the whole map, but also the most procurement-gated and lumpiest.

Falsifiable bear case

(1) Overlays slip or soften. The healthcare overhaul has already blown past its target and faces a ~$9B-cost industry revolt; CIRCIA remains unpublished; a deregulatory administration narrowed SEC enforcement (16a). Demand underwritten to an overlay that doesn't finalize fails the 16c way. (2) Horizontal platforms absorb the vertical. If a generalist platform (Microsoft, Palo Alto, CrowdStrike) can configure to a vertical's controls and obtain the vertical's certifications itself, the finance-native or health-native specialist's premium compresses — the vertical lane collapses into a feature. (3) Compliance ≠ security spend that compounds. Some overlays drive one-time attestation work (consulting hours) rather than durable software ARR; a vendor riding a one-off compliance wave looks like recurring demand until the wave passes. The thesis — deeper, enforced overlays = deeper, more defensible vertical demand — holds best where the overlay is continuous and examined (finance, defense) and weakest where it is prospective or attestation-only.

→ / angle


Sources: NYDFS Part 500 final requirements effective Nov 1 2025 — Hogan Lovells · NYDFS final rules: MFA & asset inventory — Greenberg Traurig · PCI DSS v4.0 future-dated requirements mandatory Mar 31 2025 — PCI SSC blog · HIPAA Security Rule NPRM (published Jan 6 2025) — Federal Register · HIPAA Security Rule still pending finalization — Alston & Bird · TSA Pipeline Security Directive SD02F effective May 3 2025 — Dragos · Accenture–Dragos/runZero/NetRise OT push (Jun 18 2026) — SecurityWeek


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.