Industrials
Why cyber risk is now a number on the balance sheet
Cybersecurity is not just a technical issue but also a strategic economic one. Decisions about how much to spend protecting digital assets have become financial choices that shape a company’s resilience and growth, and recent incidents have shown how directly that cost reaches national economies. When Jaguar Land Rover halted global production for five weeks in August 2025, more than 5,000 organisations in its supply chain were affected, and the Cyber Monitoring Centre put the total financial impact on the UK economy at c £1.9bn. The Bank of England subsequently cited the disruption as one reason Q325 GDP growth came in below its forecast, and the government extended a £1.5bn loan guarantee to keep suppliers solvent. Incidents of that scale are rare, but the aggregate cost is not. KPMG and UK government research puts the average cost of a significant cyberattack at close to £195,000 per business, or c £14.7bn in annual economic losses.
Much of today’s operational technology was designed to run on closed, proprietary networks rather than on the internet. Older industrial control systems running substations, water treatment works and production lines were designed for decades-long lifespans and environments air-gapped from corporate IT. Parliament’s POSTnote on the cyber resilience of UK digital infrastructure notes that many systems cannot support modern security features and are managed by staff without cybersecurity expertise. Connectivity has removed the isolation without removing the design constraint, and operations technology governance has not kept pace. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, only 32% of organisations with industrial environments monitor operational technology with dedicated tooling and only 16% report on it to their board.
That blind spot is diagnostic as much as defensive, because without monitoring operators often cannot tell whether an outage was due to equipment failure, human error or cyberattack. Addressing this requires specialist capability few operators hold in-house, which is where companies such as NCC Group stand to benefit, providing operational technology consulting and network detection and response for industrial environments. Physical security systems sit on those same networks, so suppliers able to provide evidence of cyber assurance are better placed to win contracts. Certification under the National Protective Security Authority’s Cyber Assurance of Physical Security Systems (NPSA CAPSS) scheme places a product in NPSA’a Catalogue of Security Equipment, which infrastructure and government buyers use when sourcing. Synectics obtained CAPSS certification in 2026 for the Synergy platform it supplies to operators, including National Grid.
Cyber attackers have worked out that the cheapest route into a well-defended organisation runs through a poorly defended supplier. The share of large companies naming third-party and supply chain vulnerabilities as their greatest barrier to resilience rose to 65% in 2026 from 54% a year earlier according to World Economic Forum’s Global Cybersecurity Outlook 2026. The difficulty is that most organisations rate their own exposure more favourably than the evidence supports. NCC Group’s State of Supply Chain Security report found 94% of respondents were confident they could respond to a supply chain attack and 92% trusted their suppliers to follow best practice.
Alongside individual supplier weakness sits concentration risk, because large numbers of organisations depend on the same handful of platforms. The Amazon Web Services (AWS), Microsoft Azure and Cloudflare outages of late 2025 were not attacks, but they showed how a provider’s failure can cascade across thousands of businesses. Firms concerned about that shared dependency may opt for dedicated infrastructure instead, which is where a company such as Beeks Group is positioned to benefit here, supplying private, certified trading infrastructure to banks and exchanges.
Power grids, telecommunications networks, aviation and trading systems all rely on precise positioning, navigation and timing (PNT) systems from global navigation satellites systems (GNSS), and in 2023 the UK government estimated that a 24-hour GNSS outage could cost the economy c £1.4bn. PNT signals are weak and largely unencrypted, which makes them vulnerable to jamming or spoofing. Operators therefore need to test and monitor timing performance, which is the market Calnex Solutions serves with its synchronisation products that are used across power communications, financial networks and critical infrastructure.
Holding accurate time through an outage requires equipment inside the network, which is where Adtran’s Oscilloquartz division competes with it’s PNT+ platform pairing jamming and spoofing detection with atomic clocks and satellite backup so that timing survives GNSS loss. Space and seabed infrastructure remain comparatively challenging to secure in cyber risk planning despite enabling core functions of critical infrastructure. Only 15% of World Economic Forum respondents account for space assets in their risk mitigation and 18% for undersea cables, which carry 99% of international data traffic.
The UK’s Cyber Security and Resilience Bill aims to bring managed service providers, data centres and large load controllers into scope, which will allow regulators to designate critical suppliers and require incident notification within 24 hours and a full report within 72. Penalties will reach £17m or 4% of worldwide turnover. In the EU, the Network and Information Systems Directive 2 (NIS2) covers 18 critical sectors and holds senior management accountable, while the Cyber Resilience Act’s reporting obligations apply from 11 September 2026 ahead of full compliance in December 2027.
For most organisations this compliance is a rising cost, but it also creates demand for services that remove a compliance obligation rather than manage it. Card payments are the clearest example, because any system touching cardholder data falls within the scope of the Payment Card Industry Data Security Standard (PCI DSS) and must be audited. That is where companies such as PCI Pal stands to benefit, because keeping card data out of a contact centre means a reduction in the systems that need PCI DSS certification.
Cyber skill capability rather than budget now separates resilient organisations from exposed ones. Among those the World Economic Forum classifies as insufficiently resilient, 85% report lacking the workforce skills needed to achieve their cybersecurity objectives, against 22% of highly resilient organisations. Work that cannot be staffed internally is bought in, and the European IT services companies with existing customer relationships are the most direct beneficiaries.
Softcat is positioned for mid-market demand, selling bundled managed security services with 24/7 monitoring and incident response to UK customers that do not run their own security operations centre (SOC). Computacenter focuses on the other end of the market, where large corporate and public sector clients buy security hardware and software through its technology sourcing arm and then rely on its professional and managed services to deploy, integrate and operate it. Proact has built its offer explicitly around NIS2, pairing incident monitoring and a standby incident response team with more than 400 SOC analysts.
Non-human identities, meaning the service accounts, workloads, machine credentials and AI agents that software uses to authenticate to other software, already outnumber human ones by more than 80 to one, according to CyberArk research cited in KPMG’s Cybersecurity considerations 2026. AI agents, service accounts and machine credentials are created and deleted at machine speed, and KPMG argues they require the same governance as employees. The cryptography beneath those credentials carries a deadline, because public key encryption will be vulnerable to mature quantum computing, and ‘harvest now, decrypt later’ collection means data stolen today can be decrypted once that capability exists.
The cost of responding is now being budgeted. The US Office of Management and Budget has estimated federal migration to post-quantum cryptography at US$7.1bn between 2025 and 2035 for prioritised systems alone. Doing this at scale means reissuing credentials without rebuilding the systems around them, which is where a company such as Intercede stands to benefit. Its MyID platform manages the lifecycle of public key infrastructure (PKI) and Fast IDentity Online (FIDO) credentials for government, defence and financial services customers, and now issues post-quantum certificates using the algorithms the National Institute of Standards and Technology (NIST) standardised in 2024.
In the World Economic Forum’s 2026 survey, CEOs ranked cyber-enabled fraud, meaning scams and impersonation that use digital channels to trick people into handing over money or credentials rather than breaching systems directly, as their top cyber risk concern. 73% of respondents said that they or someone in their network had been personally affected during 2025, and the Global Anti-Scam Alliance’s Global State of Scams 2025 report puts worldwide losses at US$442bn during 2024.
Defending against cyber-enabled fraud means reaching consumers rather than enterprises, and the operators and banks that already have them as customers are the natural distribution channel. F-Secure is built around exactly that structure, selling consumer scam protection, identity monitoring and banking protection through more than 200 service provider partners. For operators and banks absorbing fraud complaints and call centre costs, security has become a retention tool as well as a product.
Three tests can separate durable exposure from thematic noise in the cybersecurity space. The first is whether demand is mandated or discretionary, because spending driven by the EU NIS2 and Digital Operational Resilience Act (DORA), the UK Cyber Security and Resilience Bill or PCI DSS will survive a budget freeze in a way optional projects do not. Certification works the same way, since schemes such as NPSA CAPSS or Level 1 PCI DSS take time and money to obtain and, once written into procurement frameworks, exclude uncertified suppliers from the tender altogether. The second test is whether revenue is recurring, since managed detection, monitoring and credential management renew annually while a hardware refresh and one-off consultation do not. The third is proximity to the physical layer, where switching costs are highest and replacement cycles longest.
The risks are equally clear. Deadlines slip, as the EU’s simplification agenda and the UK bill’s phased implementation to 2028 both show, pushing revenue recognition to the right. Much of the IT channel remains geared to hardware cycles and vendor margin rather than security services, so the security narrative and the earnings driver are not always the same thing. Exposure to the cybersecurity theme is therefore best judged on the share of revenue that is contracted and security-related, rather than on how prominently cybersecurity features in a company’s positioning.
Insecure operational technology infrastructure has become an economic number as well as a technical challenge. A single attack on Jaguar Land Rover cost the UK economy c £1.9bn and was cited by the Bank of England in its account of weak Q325 growth, while the UK National Cyber Security Centre now handles around four nationally significant incidents a week. Regulation is converting resilience from a choice into an obligation, with turnover-linked penalties attached and extending compliance to managed service providers, data centres and critical suppliers. For investors, durable exposure sits where spending is mandated, where revenue recurs and where the assets being defended are physical.
Megatrends: digital economy, disruptive technologies
*PCI Pal is a client of Edison Investment Research.
Industrials | thematic
TMT | thematic
Financials | thematic
Industrials | thematic
Industrials | thematic
TMT | thematic
Financials | thematic
Industrials | thematic
Industrials
European auto equities have materially underperformed, but the medium-term outlook may be less negative than recent equity performance implies. The sector has fallen c 30% cumulatively over three years and c 32% over five years, versus gains of c 43% and c 38%, respectively, for MSCI Europe. The fundamental concerns are real: vehicle demand has weakened, Chinese competition has intensified, profitability remains under pressure and electrification is reshaping industry value pools. However, forecasts point to stabilisation rather than structural volume decline, while the STOXX Europe 600 Automobiles & Parts Index (SXAP) trades at just 0.60x book value. For a contrarian investor, the opportunity is therefore selective: a strong cyclical recovery may not be required if volumes stabilise, self-help supports margins and earnings expectations begin to find a floor.