The Business of Cyber Security

Demand Engines and Non-Discretionary Spend

Most software is bought because a buyer wants a capability. Security is different: a large share of it is bought because an attacker, a regulator, or an insurer forces the buyer to. That distinction shapes the economics of the industry — cyber budgets grow through recessions, multiples hold up, and M&A is structurally defensive rather than discretionary. The three demand engines — threat, regulation, and insurance — each convert an external event into a line item, and demand the buyer did not choose is the deepest moat in the market.

Through the 2022–23 software downturn, when nearly every other IT category was cut, security spending kept compounding double digits, and Gartner now projects roughly $244B for 2026, up ~12% in constant currency off ~$213B in 2025 (the reported-dollar increase is larger). Budgets that rise while everything around them is cut are a signature of non-discretionary demand: three forces — threat, regulation, and insurance — remove the choice. (Gartner via Software Strategies, Mar 2026)

Engine 1 · Threat

The first and oldest demand engine is the adversary. Security spend rises because the cost and frequency of incidents rise, and because every breach in the headlines re-prices risk in every boardroom. The mechanism is concrete: a material breach forces incident response, then remediation, then new controls, then a higher steady-state budget — and the threat of one does the same pre-emptively. The anchoring figure is the IBM Cost of a Data Breach: a global average of ~$4.44M per breach in 2025 (down ~9% from $4.88M in 2024 as AI-assisted containment shortened breach lifecycles — the first decline in years, and itself a demand signal for AI-driven defense). Ransomware remains the dominant forcing function, and AI is now lowering the attacker's cost of phishing, malware, and reconnaissance — expanding the surface faster than any single vendor can cover it. (IBM Cost of a Data Breach 2025, via Help Net Security)

Why it matters for M&A: threat-driven demand is most intense at the newest surface. Each new technology layer (cloud, then SaaS, then AI agents) opens a new attack surface, which forces new spend, which funds a new category — the supply-side fragmentation engine described in Consolidation & Aggregation. The deal flow follows the threat: where attackers move, budget moves, and acquirers follow.

Engine 2 · Regulation

The second engine is compliance. Regulation converts security from a judgment call into a legal obligation with deadlines, penalties, and personal liability — which is the purest form of non-discretionary demand because the buyer cannot opt out without breaking the law. The 2023–26 wave is the most aggressive on record, and it is global:

Why it matters for M&A: regulation is demand made into software — the entire GRC/compliance-automation category (Vanta, Drata, AuditBoard) exists to discharge it, and "compliance as a deadline-driven catalyst" is a recurring deal thesis. A regulatory deadline is a dated demand event you can underwrite. (See Regulation, GRC & TPRM.)

Engine 3 · Insurance

The third and least-appreciated engine is the cyber insurer. To obtain or renew coverage, organizations must now satisfy the insurer's control requirements — MFA, EDR, immutable backups, an IR plan, often segmentation — on the insurer's timeline, not their own. The insurer thus becomes a buyer behind the buyer, steering demand toward specific categories and even specific vendors as a condition of underwriting. This converts security purchases into a prerequisite for an unrelated business need (risk transfer), which is why it counts as a third involuntary engine. As insurers move toward active/embedded insurance — bundling monitoring and controls with the policy — the line between insurer and vendor blurs further. (See Cyber Insurance.)

How the three engines converge

The three engines are independent in origin but identical in effect: each takes an external event the buyer doesn't control — an attack, a statute, a renewal — and converts it into a mandated control, which becomes non-discretionary budget, which becomes durable vendor demand. That convergence is the structural reason cyber spend compounds through cycles and the reason its revenue is worth a premium multiple: demand that the customer cannot switch off is the highest-quality revenue in software.

Demand you didn't choose — three engines, one effect Each engine converts an external event the buyer can't control into mandated controls → non-discretionary budget → durable vendor demand. 1 · Threat breach cost ~$4.44M avg (IBM '25) ransomware · AI-scaled attacks 2 · Regulation SEC 4-day · NIS2 24/72h · DORA GDPR · AI Act/CRA · personal liability 3 · Insurance coverage = MFA · EDR · backups · IR insurer = buyer behind the buyer Mandated controls not "want" — "must" on someone else's clock Non-discretionary spend ~$244B 2026, ~12%cc compounds through cycles Demand the customer can't switch off = the highest-quality revenue in software = the premium multiple. Source: Gartner (spend) via Software Strategies Mar 2026; IBM Cost of a Data Breach 2025; SEC/EU regulatory texts. Exhibit: The Business of Cyber Security.
Three engines, one shape: an external event the buyer can't control → a mandated control → budget that can't be cut → durable demand. This is the economic root of cyber's recession-resistance and its premium multiples. See Unit Economics (why durable revenue prices higher) and the consolidation thesis.

The bear case

The thesis is strong but not absolute. Three qualifications. (1) "Non-discretionary" still has a ceiling. Budgets compound but at a rate, and that rate softens in downturns even if it stays positive; vendors that price as if demand were infinite get re-rated when growth normalizes (the 2022 and 2026 cyber-stock resets; see Bear Case). (2) Mandated ≠ vendor-specific. Regulation forces a control, not a product — if the control commoditizes (MFA is now table-stakes, often free in the platform), the demand persists but the margin migrates to whoever bundles it cheapest (the Microsoft-bundle problem). (3) Compliance can be satisfied at the floor. Buyers forced to spend will often buy the minimum that passes audit, capping willingness-to-pay for best-of-breed. The demand is real and durable; the open question is always who captures it — which routes straight back to the aggregation thesis.

Cross-references: Demand & How Buyers Buy, Threat Economy, Regulation, Cyber Insurance, Unit Economics, Consolidation & Aggregation, GRC & TPRM, The Bear Case.

Sources — Spend: Gartner via Software Strategies (Mar 2026). Breach cost: IBM Cost of a Data Breach 2025 (~$4.44M global avg, −9% YoY), via Help Net Security. Regulation: SEC 4-business-day rule in force Dec 18 2023 (Cybersecurity Dive); DORA fully in force Jan 17 2025; NIS2 24h/72h reporting, first admin penalties reported Q1 2026 (reported, not primary-verified).


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.