West Midlands Cyber

The Two-Speed Cyber Economy

As cyber assurance becomes increasingly important to procurement and supply-chain participation, organisations with mature security capabilities gain an economic advantage. What happens to SMEs that cannot keep pace?

Contents

Britain’s Two-Speed Cyber Economy: The Regional Consequences

The UK has developed substantial national cyber capability, but that capability is not distributed evenly across the organisations expected to use it. National institutions, major employers, regulated operators and mature technology businesses increasingly work with sophisticated approaches to threat intelligence, assurance, incident response and resilience. Much of the wider economy operates under different conditions, with smaller security teams, less formal governance and limited capacity to interpret an expanding body of regulation, standards and technical guidance.

CYBERUK 2026 brought this disparity into sharper focus because the UK’s policy ambition is itself becoming more sophisticated. Government is strengthening cyber regulation, the National Cyber Security Centre continues to develop differentiated guidance and assurance frameworks, and cyber resilience is becoming more closely connected to supply-chain security, emerging technology and national economic security. These developments can improve resilience, but their effect depends on whether organisations possess the capability to translate national expectations into operational practice.

The originating analysis, CYBERUK 2026: System Ambition, Operational Reality, and the Two-Speed Cyber Economy, characterised the resulting divide as a two-speed cyber economy. The concept does not imply a simple distinction between secure large businesses and insecure SMEs. It describes a wider capability gradient in which organisations differ significantly in their access to expertise, governance, investment, assurance and specialist support, even when they participate in the same supply chains or depend on the same digital infrastructure.

For the West Midlands, this is an economic as well as a security issue. Industrial supply chains connect large organisations with smaller manufacturers, engineering businesses, technology providers and professional services firms whose cyber maturity can vary substantially. As customers and regulators demand stronger assurance, differences in cyber capability can affect not only exposure to incidents but also firms’ ability to participate in increasingly security-conscious markets.

What does this mean for your business? The West Midlands Cyber Hub examines how rising cyber expectations are increasingly influencing procurement, customer requirements and the ability of SMEs to compete for work, in the companion article “Could Cyber Security Become a Barrier to Winning Business?”.

Key Takeaways

  • UK cyber capability is increasingly sophisticated at national and enterprise level, but business evidence shows substantial differences in governance and resilience according to organisational size.
  • In 2025/26, 70% of large businesses had a formal cyber security strategy compared with 27% of businesses overall, while formal incident-response plans ranged from 21% of micro businesses to 76% of large businesses.
  • Supply-chain assurance exposes the same divide: 48% of large businesses reviewed cyber risks from immediate suppliers, compared with 12% of micro businesses and 22% of small businesses.
  • The capability gap can become commercially significant when smaller suppliers must satisfy cyber requirements established by larger customers, regulators or public procurement.
  • Regional cyber infrastructure can help close the execution gap by connecting national standards with proportionate expertise, assurance, skills and implementation support.

Business Size Is Associated with a Significant Capability Gradient

The 2025/26 Cyber Security Breaches Survey provides unusually clear evidence of differences in cyber maturity across the business population. Seventy-two per cent of businesses considered cyber security a high priority for senior management, suggesting that recognition of the issue is now widespread. Formal capability is considerably less uniform. Only 30% had conducted a cyber risk assessment during the previous year, 27% had a formal cyber security strategy and 25% had an incident-response plan. (gov.uk)

Organisation size changes the picture markedly. Formal cyber strategies were reported by 27% of businesses overall but by 70% of large businesses. Incident-response plans were held by 21% of micro businesses, rising to 57% among medium businesses and 76% among large organisations. Board-level responsibility for cyber security reached 68% among large businesses, substantially above the 31% recorded across the business population. (gov.uk)

These differences should not be reduced to an assumption that smaller firms simply take cyber security less seriously. Organisational capacity matters. A large company can maintain specialist security staff, procure external services, commission testing, interpret regulatory developments and distribute responsibilities across technology, risk, legal and operational teams. A microbusiness may rely on a generalist IT provider or an individual whose cyber responsibilities sit alongside several other functions.

The resulting capability gradient affects what organisations can reasonably implement. Guidance that appears straightforward to a mature security function can require significant interpretation for a smaller business, particularly when it concerns risk assessment, supplier assurance, incident classification or recovery planning rather than an individual technical control.

Better Detection Can Make Mature Organisations Look More Exposed

One of the complications in comparing cyber maturity is that organisations with stronger security capability frequently identify more hostile activity. In 2025/26, 42% of micro businesses identified a cyber breach or attack, compared with 46% of small businesses, 65% of medium-sized organisations and 69% of large businesses. (gov.uk)

Part of that difference is likely to reflect exposure. Larger businesses usually have more employees, systems, external services and commercially valuable assets. They may consequently present attackers with a larger attack surface. Detection capability is also relevant, however, because organisations with security monitoring, specialist staff and formal reporting processes are more likely to recognise activity that would remain invisible elsewhere.

DSIT explicitly warns that the survey measures breaches and attacks organisations have identified and that some incidents will remain undetected. A lower recorded prevalence among smaller businesses therefore cannot be treated automatically as evidence of lower underlying cyber risk. (gov.uk)

This creates an important feature of the two-speed economy. Mature organisations can appear statistically more exposed precisely because they are better able to see what is happening. Less mature organisations may report fewer incidents while possessing less confidence that they would recognise a compromise promptly.

Regional resilience cannot therefore be assessed simply by counting incidents. Capability measures such as monitoring, risk assessment, incident preparation and recovery provide necessary context for interpreting prevalence.

Supply Chains Connect Organisations Operating at Different Speeds

The capability divide becomes more consequential when businesses are connected through supply chains. Large organisations may operate mature security programmes while depending on smaller suppliers with substantially less formal governance. The security of the commercial system consequently reflects relationships between organisations operating at different levels of capability.

The Breaches Survey found that only 15% of businesses reviewed cyber risks associated with their immediate suppliers in 2025/26, while 6% assessed risks in the wider supply chain. Among large businesses, immediate supplier assessment reached 48%; among medium businesses it was 30%, compared with 22% of small businesses and 12% of micro businesses. (gov.uk)

Those figures expose two related issues. The first is that even comparatively mature organisations do not universally assess supplier cyber risk. The second is that smaller businesses, which can themselves depend on extensive networks of technology and service providers, are least likely to conduct formal supplier assessment.

For the West Midlands, this has particular relevance in industrial supply chains. A large manufacturer may have sophisticated internal security while purchasing components, engineering services, logistics, software and specialist support from numerous smaller organisations. Those suppliers may in turn depend on managed IT services and cloud platforms. Cyber dependency therefore extends beyond the contractual relationship immediately visible to the largest organisation.

A regional economy cannot eliminate these differences by requiring every supplier to reproduce the security function of its largest customer. The more realistic objective is proportionate assurance: identifying which suppliers and dependencies could create material operational risk, establishing appropriate baseline requirements and providing credible routes for smaller organisations to satisfy them.

Assurance Can Narrow the Gap or Turn It into a Market Barrier

Procurement is one of the principal mechanisms through which cyber expectations spread beyond directly regulated organisations. Cyber Essentials requirements, customer security questionnaires, contractual clauses and sector-specific assurance arrangements can influence businesses that would otherwise have little direct interaction with national cyber policy.

The mechanism can improve security by creating commercial incentives for firms to adopt controls and demonstrate them. The latest Breaches Survey provides some evidence of movement: 5% of businesses held Cyber Essentials certification in 2025/26, compared with 3% the previous year, while certification among small businesses increased from 5% to 12%. (gov.uk)

The same process can create barriers where assurance requirements are fragmented or disproportionate. A smaller supplier serving several large customers may encounter multiple questionnaires and overlapping requirements, each demanding similar information in different formats. Businesses with dedicated compliance and security functions can absorb that administrative burden more readily than firms whose technical and commercial responsibilities are concentrated among a small number of people.

Cyber assurance consequently has two possible economic effects. Well-designed requirements can raise the baseline while giving customers meaningful confidence in suppliers. Poorly coordinated requirements can increase the fixed cost of participation in supply chains without producing a corresponding improvement in resilience.

For West Midlands SMEs, the distinction is strategically important. As cyber maturity becomes more relevant to procurement, access to proportionate certification, implementation support and interpretation of customer requirements can influence competitiveness as well as security.

The Cyber Sector Has Its Own Scale Divide

The two-speed effect is not confined to cyber buyers. The structure of the UK’s cyber security sector itself shows substantial differences between small providers and large firms.

DSIT’s 2026 Cyber Security Sectoral Analysis identifies 2,603 firms active in the UK cyber sector, generating approximately £14.7 billion in revenue and £9.1 billion in gross value added. The number of firms generating more than £10 million in annual cyber revenue has risen to 241, compared with 219 the previous year and 105 two years earlier, demonstrating considerable development of the sector’s middle tier. (gov.uk)

Revenue nevertheless remains highly concentrated. Large firms account for approximately £10.4 billion, or 70%, of sector revenue, compared with around £2.9 billion generated by medium-sized firms, £1.3 billion by small firms and £251 million by microbusinesses. Large companies are also structurally different: only 17% are dedicated pure-play cyber businesses, with the remainder diversified firms whose cyber activity forms part of a wider technology, defence, professional-services or other portfolio. (gov.uk)

At the smaller end of the market, the position reverses. Eighty-four per cent of micro cyber firms are dedicated providers, and SMEs derive approximately 83% of their cyber revenues from dedicated firms. This means the businesses most dependent on the cyber market itself are disproportionately concentrated among smaller providers, while many of the largest participants can draw on wider organisational resources and customer relationships.

The distinction matters for regional economic development. Increasing the number of cyber startups does not automatically create a balanced regional sector if those firms struggle to progress into sustainable mid-sized providers. A functioning ecosystem needs routes from technical capability to customer validation, procurement, recurring revenue and investment.

Investment Does Not Automatically Follow Capability

The UK’s cyber sector has continued to grow while private investment has weakened. Dedicated cyber firms raised £184 million across 47 investment deals in 2025, compared with £206 million across 59 deals in 2024. DSIT records year-on-year declines in dedicated cyber investment since the peak reached in 2022. (gov.uk)

That trend sits alongside strong sector economics. Revenue increased by 11% to £14.7 billion in the latest analysis, while gross value added rose by 17% to £9.1 billion. Employment increased more slowly, by approximately 3%, producing a substantial increase in estimated GVA per employee. The sector is therefore creating greater economic value without a corresponding acceleration in employment or investment.

For regional cyber firms, this combination makes commercial progression particularly important. An environment in which venture investment is less abundant places greater weight on customer revenue, procurement access and the ability to demonstrate repeatable demand. Regional ecosystems that concentrate principally on startup formation may therefore address only the beginning of the growth process.

This is another form of the two-speed problem. Established providers with customer relationships and sufficient scale can participate in growing demand, while smaller specialists may possess valuable technical capability without having the commercial infrastructure required to capture it. Closing that gap requires attention to procurement and market access as well as conventional innovation support.

National Capability Requires a Local Execution Layer

The UK’s cyber institutions increasingly provide a sophisticated national framework. The NCSC offers guidance ranging from practical support for small organisations through Cyber Essentials to the Cyber Assessment Framework used in higher-consequence environments. Government is strengthening regulation through the Cyber Security and Resilience Bill, while sector policy increasingly connects cyber security with economic growth, emerging technology and national resilience.

The existence of these mechanisms does not mean they are equally accessible to every organisation. A large regulated operator can employ specialists to interpret frameworks and maintain compliance programmes. A small supplier may know that a customer has introduced new cyber requirements without understanding which controls are proportionate, how to implement them or what evidence will satisfy the buyer.

The missing capability is therefore partly translational. Organisations need routes from national policy and standards to decisions about systems, suppliers, investment and operational practice. This is particularly important where cyber expectations enter businesses indirectly through customers rather than through regulation.

Regional cyber infrastructure can provide that intermediate layer by connecting organisations with expertise, training, certification support, universities, providers and peers facing similar problems. Its purpose should not be to create alternative regional standards. Fragmenting the national framework would increase complexity. The economic value lies in making established standards more usable and connecting them to the sectors and supply chains in which they have to operate.

The Capability Gap Is Becoming an Economic Issue

The two-speed cyber economy should not be understood simply as a maturity problem that will disappear as smaller businesses gradually adopt more controls. Several forces are making the consequences of the gap more significant.

Regulation is expanding towards additional technology dependencies. Larger organisations are scrutinising suppliers more closely. Cyber assurance is entering procurement. AI and cloud adoption are increasing dependence on external platforms and services. At the same time, smaller organisations continue to operate with substantially less formal risk management and incident preparation than their larger counterparts.

For the West Midlands, these developments intersect with an economy in which large organisations and extensive SME supply chains depend upon one another. Cyber maturity can therefore affect market participation: businesses unable to demonstrate proportionate security may encounter greater difficulty entering or remaining within high-assurance supply chains, even where their products and services are otherwise competitive.

The appropriate response is not to impose enterprise-scale cyber programmes on every SME. It is to make progression possible. Businesses need a comprehensible baseline, practical routes to assurance, access to specialist expertise when their risk justifies it and a clear understanding of how customer or regulatory expectations change as they grow.

That provides a more demanding measure of regional cyber development than counting cyber firms, events or programmes. A mature regional ecosystem should reduce the distance between national cyber ambition and the capability of organisations throughout the economy to act upon it. If that distance remains large, the UK can continue to develop world-class cyber institutions while significant parts of its productive economy operate at a very different speed.