The UK’s cyber economy is changing, bringing new opportunities and new expectations for businesses. We look at what the latest sector evidence means for West Midlands SMEs, technology companies and organisations looking to strengthen their cyber capability.
Contents
- Contents
- What the Changing UK Cyber Economy Means for West Midlands Businesses
- Key Takeaways
- The Cyber Market Is Growing Differently
- West Midlands Cyber Capability Is Larger Than Company Addresses Suggest
- Cyber Security Is Becoming More Closely Connected with Winning Business
- Supply Chains Create Cyber Dependencies in Both Directions
- AI Is Creating New Security Requirements
- Industrial Businesses Face a Different Cyber Context
- Investment Has Become More Selective
- Cyber Businesses Need to Progress from Expertise to Market Position
- What Businesses Can Do with This Changing Market
- Cyber Capability Is Becoming Part of Business Capability
What the Changing UK Cyber Economy Means for West Midlands Businesses
The UK’s cyber security economy is becoming larger, more productive and more closely connected with the wider digital economy. The latest government sector analysis identifies 2,603 cyber security firms generating £14.7 billion in annual revenue and £9.1 billion in gross value added (GVA). Revenue increased by 11% over the previous year and GVA by 17%, while employment grew by a much more modest 3% to approximately 69,600 full-time equivalent roles.
Those figures describe a sector that is changing as well as growing. Cyber capability is increasingly embedded within larger technology businesses, product companies and organisations serving digitally dependent industries, while demand is expanding around areas such as artificial intelligence, connected products, operational technology and supply-chain assurance. The originating analysis, The UK Cyber Economy Is Changing Shape, and the West Midlands May Be Better Positioned Than It Realises, examined the economic significance of those changes and their particular relevance to the West Midlands.
For businesses across the region, however, the practical question is different. Changes in the cyber economy affect not only companies selling cyber security products and services, but also organisations buying technology, participating in supply chains, adopting AI or trying to demonstrate that they can protect customer and operational data. Cyber capability is increasingly linked to how businesses operate, compete, and grow.
Read the wider regional analysis. The West Midlands Cyber Cluster examines the structural changes taking place across the UK cyber economy and what they mean for the West Midlands cyber sector, its companies and future growth, in the companion article “The UK Cyber Economy Is Changing Shape — What It Means for the West Midlands“.
Key Takeaways
- UK cyber-sector revenue increased by 11% to £14.7 billion while employment grew by only 3%, indicating that productivity and higher-value capability are becoming increasingly important to sector growth.
- The West Midlands accounts for an estimated 8% of UK cyber employment despite containing around 6% of cyber office locations, suggesting that regional capability extends beyond companies headquartered or formally registered here.
- SMEs face a dual challenge: improving their own resilience while responding to growing customer, procurement and supply-chain expectations around cyber assurance.
- AI, connected products and industrial technology are creating new areas of cyber demand that are particularly relevant to the West Midlands’ technology and manufacturing economy.
- Businesses should treat cyber capability increasingly as part of operational resilience and commercial readiness rather than as an isolated IT requirement.
The Cyber Market Is Growing Differently
Headline sector growth remains strong, but the relationship between revenue, employment and productivity has changed.
UK cyber security revenue increased from £13.2 billion to £14.7 billion in the latest sector analysis, while GVA rose to £9.1 billion. Employment increased by around 2,300 roles, or 3%, the lowest growth recorded since the sectoral analysis series began in 2018.
At the same time, estimated GVA per employee rose from £116,200 to £131,200, an increase of approximately 13%.
For cyber businesses, this points to a market in which growth cannot be understood solely by headcount. Product development, automation, intellectual property and specialist expertise can allow businesses to increase economic output without expanding employment at the same rate.
That has consequences for companies trying to grow within the sector. Building a successful cyber business increasingly requires a clear commercial proposition and access to customers, rather than assuming that rising national demand will translate automatically into company growth.
The structure of the market reinforces this point. Large companies generated approximately £10.4 billion, or 70%, of UK cyber revenue, compared with £2.9 billion from medium-sized firms, £1.3 billion from small firms, and £251 million from microbusinesses.
There is nevertheless evidence that more companies are reaching meaningful commercial scale. DSIT identifies 241 cyber providers generating more than £10 million in annual cyber revenue, compared with 219 in the previous year and 105 two years earlier.
For West Midlands cyber SMEs, the opportunity is therefore real, but so is the progression challenge. Starting a specialist business and developing technical capability are only the first stages. Sustainable growth depends on turning that expertise into repeatable customer demand.
West Midlands Cyber Capability Is Larger Than Company Addresses Suggest
Regional cyber economies can be difficult to measure because cyber capability does not sit exclusively within companies that describe themselves as cyber businesses.
The latest sector analysis estimates that the West Midlands contains approximately 6% of UK cyber office locations but around 8% of cyber employment. Registered employment data produces a lower regional share of around 3%, illustrating how different measures can produce substantially different pictures.
Part of the explanation lies in the structure of the market.
Nationally, 69% of cyber providers are classified as dedicated cyber businesses and 31% as diversified organisations whose cyber activity forms part of a broader commercial operation. Among large companies, only 17% are dedicated cyber firms, while 83% are diversified.
For West Midlands organisations, this means the regional cyber market extends beyond recognisable security vendors. Relevant expertise may sit inside consultancies, engineering businesses, technology providers, managed services companies and larger employers.
It also changes how businesses should think about finding cyber capability.
A company looking for support with industrial systems, AI security or supply-chain assurance may require expertise that does not fit neatly into a conventional list of local cyber companies. Connecting businesses with appropriate capability therefore depends on understanding the problem first and then identifying the relevant specialist, provider, university or support organisation.
That is one of the functions a regional cyber ecosystem can perform more effectively than a simple supplier directory.
Cyber Security Is Becoming More Closely Connected with Winning Business
For most SMEs, cyber security has traditionally been approached primarily as a risk-management issue: protect systems, reduce the likelihood of disruption and respond effectively if something goes wrong.
That remains essential, but commercial considerations are becoming more prominent.
Large organisations increasingly need to understand the security of suppliers that access their data, systems or operational environments. Regulated businesses face obligations that can extend into their supply chains. Procurement teams may request evidence of security controls or certification before allowing a supplier to participate in a contract.
The result is that cyber maturity can influence whether a business is ready to sell to certain customers.
This is particularly relevant to the West Midlands because much of the regional economy operates through complex business-to-business supply chains. Smaller engineering, technology and professional-services firms can find themselves serving customers whose security requirements are considerably more developed than their own.
Businesses do not need to replicate the cyber programmes of their largest customers. They do, however, need to understand what those customers expect and establish controls proportionate to the access, information and dependencies involved.
Cyber Essentials can provide a useful baseline for many organisations, particularly where customers or public-sector procurement frameworks recognise it. Other businesses may require stronger identity controls, supplier management, incident planning or specialist assurance because of the nature of their operations.
The commercial objective is to avoid discovering these requirements only when a contract or tender is already at stake.
Supply Chains Create Cyber Dependencies in Both Directions
Supply-chain cyber risk is often described from the perspective of large organisations assessing smaller suppliers. For SMEs, the dependency works in both directions.
Smaller businesses themselves rely extensively on external technology.
Cloud applications, managed IT providers, payment systems, accounting platforms, software-as-a-service products and outsourced infrastructure allow SMEs to obtain sophisticated capability without building large internal technology teams. This can improve productivity, but it also means that operational resilience depends partly on suppliers over which the business has limited direct control.
The practical task is therefore not to eliminate external dependency. It is to understand which dependencies are important enough to manage deliberately.
A business should know which suppliers hold sensitive information, which have privileged access to systems and which services would cause serious disruption if unavailable. Contractual arrangements, authentication, backups, exit planning and incident communications can then be considered according to the significance of the service.
The same principle applies when the SME becomes a supplier itself.
If a business provides software, managed services, engineering support or another service that creates meaningful customer dependency, customers are increasingly likely to ask similar questions about its security.
Cyber resilience consequently becomes part of the relationship between businesses rather than an internal technical concern confined to either buyer or supplier.
AI Is Creating New Security Requirements
Artificial intelligence provides one of the clearest examples of how changes in the technology economy create new cyber demand.
DSIT identified 111 UK cyber companies explicitly offering security capability relating to AI, compared with 66 previously, an increase of 68%. Thirty-two were identified as specialist providers.
The areas being addressed include model security, advisory services, runtime and infrastructure protection, and red teaming.
This growth reflects the speed with which organisations are adopting AI-enabled services and incorporating them into ordinary business processes.
For SMEs, the immediate security issues are often relatively practical. Employees may enter commercially sensitive information into externally hosted AI services. Organisations may adopt tools without understanding how data is retained or processed. AI functionality may be added to existing software platforms, creating new permissions or data flows that have not been considered through existing governance.
Businesses developing AI products face additional questions concerning model access, data integrity, application security and the infrastructure through which services are delivered.
The objective should not be to make cyber security an obstacle to experimentation. Businesses are more likely to obtain sustainable value from AI when they understand which information and processes are becoming dependent on it and manage those dependencies accordingly.
The rapid growth of AI-security capability within the UK cyber market suggests that this will become an increasingly significant part of the commercial security landscape.
Industrial Businesses Face a Different Cyber Context
The West Midlands’ industrial economy gives some of these changes particular regional relevance.
Manufacturers and engineering businesses increasingly depend on connected machinery, remote maintenance, production-management systems, industrial software and digitally integrated suppliers. Cyber incidents affecting those environments can therefore have operational consequences beyond the loss of data.
The UK cyber market remains much more heavily weighted towards general services than specialist industrial capability. DSIT’s provider taxonomy identifies around 7% of firms with SCADA or industrial-control-system capability, while analysis of provider websites finds industrial or operational-technology security among approximately 10% of offerings.
That does not mean the West Midlands should attempt to turn every cyber company into an OT specialist.
It does indicate a potential alignment between regional demand and a relatively specialist part of the national cyber market.
For manufacturers, the practical requirement is to ensure that cyber decisions reflect how the business actually operates. Corporate IT controls remain important, but industrial environments can involve legacy equipment, long replacement cycles, specialist vendors and systems where availability or safety limits the way security controls can be implemented.
Understanding those differences is essential when selecting providers or assessing risk.
For cyber businesses, industrial customers can provide opportunities to develop specialist expertise against real operational requirements. That can create a stronger commercial proposition than attempting to compete solely in already crowded areas of generic cyber consultancy.
Investment Has Become More Selective
Strong sector growth has not produced a corresponding increase in private investment.
Dedicated UK cyber firms raised approximately £184 million across 47 investment deals during 2025, compared with £206 million across 59 deals in 2024. Investment has declined year on year since the high levels recorded in 2022.
That creates an important distinction between a growing market and an easy funding environment.
Cyber founders may operate in a sector with increasing revenues and substantial national policy attention while still finding capital difficult to secure. Investors need evidence that an individual company can capture part of that market.
For West Midlands cyber SMEs, this increases the value of commercial validation.
A company that can demonstrate paying customers, successful deployments and a credible route into a defined market is in a stronger position than one relying principally on the general growth of cyber security demand.
The region’s wider economy can contribute to that validation. Manufacturers, professional organisations, universities and public bodies all encounter security problems that can provide testing, customer discovery or commercial opportunities where procurement and innovation mechanisms allow.
Funding can help a company develop. Customer evidence helps establish whether it has something capable of growing.
Cyber Businesses Need to Progress from Expertise to Market Position
The UK cyber economy contains a large population of smaller dedicated providers. Among microbusinesses, 84% are dedicated cyber firms, compared with 64% of small businesses and 51% of medium-sized businesses.
This structure demonstrates the accessibility of cyber as an entrepreneurial market, but it also highlights the difficulty of progression.
Technical expertise is essential but does not automatically create differentiation. Customers need to understand why a provider is particularly suited to their problem, and smaller businesses need routes into markets where they can demonstrate that capability.
For West Midlands cyber companies, regional specialisation can help.
A provider that develops deep expertise in industrial resilience, supply-chain assurance, AI security or another field connected with identifiable regional demand can build evidence that subsequently supports expansion into national and international markets.
This does not require every company to pursue the same specialism. It requires businesses to understand where their capability intersects with customer demand strongly enough to produce a defensible market position.
Regional business support is most useful when it assists that progression rather than concentrating solely on company formation.
What Businesses Can Do with This Changing Market
The changing cyber economy has different implications depending on whether an organisation buys cyber services, sells them or simply depends increasingly on digital technology.
For businesses buying cyber support, the priority is to start from operational and commercial requirements rather than purchasing technology in isolation. Understanding critical systems, important suppliers, customer expectations and realistic incident scenarios makes it easier to identify which controls and expertise are actually required.
For organisations participating in larger supply chains, cyber requirements should be investigated before they become procurement obstacles. Customer questionnaires, contractual security clauses and certification expectations can often be anticipated, allowing improvements to be planned rather than implemented under commercial pressure.
Technology adopters should also include security when introducing AI, connected systems or new cloud services. The relevant question is not simply whether a tool is secure in abstract terms, but what information, access and operational dependency the organisation is placing around it.
Cyber providers face a different task. The expanding national market creates opportunities, but sector growth alone does not provide differentiation. Companies need evidence of where they solve a problem better than alternatives and a route towards customers capable of validating that proposition.
These are areas in which local relationships can have practical value. The West Midlands Cyber Hub can help regional organisations navigate available cyber support, connect with programmes and events, and find routes into the wider community of businesses, specialists and institutions operating across the region.
Cyber Capability Is Becoming Part of Business Capability
The most important change in the UK cyber economy is not simply that the sector has become larger. Cyber capability is becoming more deeply connected with the technologies and commercial relationships on which ordinary organisations depend.
That changes the significance of cyber for West Midlands businesses.
For an SME supplying a larger customer, demonstrable security can influence commercial readiness. For a manufacturer, cyber resilience can affect production continuity. For a company adopting AI, security increasingly forms part of responsible technology adoption. For a cyber startup, the region’s wider economy can provide customers and operational problems against which specialist capability can be developed.
The latest sector data therefore describes more than the fortunes of cyber security companies. It reflects a wider economic transition in which security, resilience and digital dependency are becoming harder to separate.
West Midlands organisations do not all require sophisticated internal cyber functions, nor should smaller businesses attempt to imitate the security programmes of large enterprises. The more practical objective is proportionate capability: understanding the digital dependencies that are economically important to the organisation, establishing appropriate controls and being able to demonstrate that capability where customers, regulators or partners require it.
As cyber becomes more embedded in business operations and commercial relationships, that ability will increasingly form part of what it means to be a digitally capable organisation.