Chester Wisniewski at Sophos explores how the vendor-organisation relationship can be strengthened

The sheer scale of cyber-tech stacks is daunting, and the number of tools professionals have to manage and rely on is rapidly growing. Just last year, Gartner estimated that the average large organisation had over 45 cyber-security tools. Pair this with a compliance landscape that is becoming increasingly complex, with new regulations coming through on a regular basis, the pressure on IT and cyber-security leaders has never been greater.
That is a lot to juggle for security professionals being forced to place more and more trust in their vendors. At the same time, organisations have never trusted their vendors less. Independent research commissioned by Sophos shows only 5% of IT leaders say that they have full trust in their vendors. As cyber-security becomes a board-level imperative, organisations are demanding more from their vendors, whom they look to for a strategic relationship. But this relationship has been slowly breaking down as demands rise.
With upcoming regulations such as the UK’s Cyber Security and Resilience Bill (CSRB), primed to put cyber-security vendors in the spotlight, organisations will be forced to examine these relationships more closely. And it looks like they might not like what they find.
So, what is stopping vendors from building trust, and how can they change their ways?
In the not-too-distant past, vendors didn’t occupy such a prime position in organisations’ priority lists. For a long time, whether rightly or wrongly, cyber-security was viewed as a tick-box exercise. Organisations selected vendors purely based on the services they provided and proof of their technical expertise. If the right box was ticked, they were happy.
But, thanks to globalisation and digitalisation, the scope of a security vendor has exploded. Today, vendors don’t just protect your website or your data; they are responsible for protecting the day-to-day operations of organisations. Everything from commercial activity to employee data and payroll sits squarely under their remit. Take the infamous UK retailer hack last year: it didn’t just cost £100 million in direct costs related to the breach; the total bill ended up well over £300 million once the knock-on effects across the wider business and lost sales were estimated. While that might be a fairly extreme example, the average cost of a single significant cyber-attack in the UK is estimated to be around £195,000. No matter where costs land between these two figures, they remain a concern for those bottom lines.
And it’s not just the revenue impact that is pushing organisations to pay closer attention to their cyber-security vendors. Nearly a decade ago now, we saw the Data Protection Act come into effect in the UK, establishing vendor liability for customer data. Soon, we’ll see the CSRB bring managed security vendors specifically under scope for the first time, establishing stricter standards for organisations to hold their providers to.
All this simply cements what’s been clear for a while now. Security vendors can no longer sit back and let their technical prowess and solutions catalogue do the talking for them. Organisations aren’t just looking for a technical partner; they’re looking for a cyber-security provider that they can trust not just with their data, but with their business operations, compliance, and performance.
These movements toward greater accountability have exposed just how little trust organisations have in their cyber-security vendors, but where is the sector falling short?
Admittedly, trust is far from easy. It notoriously takes years to build, and only seconds to break. But most vendors haven’t even got past that first stage of building trust. According to our research, 79% of organisations report it is challenging to even assess the trustworthiness of new cyber-security vendors. You’d imagine that this uncertainty might dissipate once a contract begins, as a vendor begins work in earnest and starts to prove themselves to their customer. But, concerningly, 62% of organisations report facing the same challenge with their existing providers. Even once contracts are signed, and work begins, that trust gap remains.
Across the board, vendors appear to be getting stuck with a black-box approach. Sure, their services and their products might be working well, but they lack the transparency that customers need to verify their work. Organisations reported struggling to access the technical details (43%) or even to find the information needed to make confident decisions about their vendors (38%). While they might be drowning in vendor claims, technical data remains buried under sales talk or is poorly explained. Especially for smaller organisations, which, due to their size, suffer from a lack of cyber-security knowledge and skills, this creates a major barrier to trust. Because you can’t trust what you don’t understand.
And all of this has a material impact on an organisation’s day-to-day operations. As well as dealing with a degree of anxiety, 42% said that lacking full trust had pushed them to increase their requirements for oversight. This should be a wake-up call for vendors. We should be making our customers’ operations easier, not harder.
Cyber-security vendors can’t snap their fingers and create trust. Especially considering that so far, vendors have by and large failed to earn it. There will be a lot of work involved to build stronger foundations for a long-term relationship.
But we can trace much of these concerns and issues back to one common thread - transparency. Any good relationship, whether it be business or personal, is built on openness. To trust someone, you first need to get to know them. And the same goes for cyber-security vendors. They must prioritise clearer information around their services and products, but that’s not all.
Organisations identified verifiable proof as a key driver of trust. They are tired of hearing all the claims; they just want to see the proof. To start building trust, security providers need to have digital infrastructure such as Trust Centres set up - digital hubs that can act as a one-stop shop for prospects and clients to verify compliance, security, and data privacy postures. Everything from security certifications, policies, and audit reports needs to be constantly updated here.
Put yourself in your customers’ shoes. For something as vital as cyber-security, you would never just take a provider’s word for it. You’d need evidence and third-party verification. When looking for certification, you’re not just trawling through reports; you’re looking for a provider’s presence in news media and analyst reports. All of this backs up your technical prowess on paper, proving to your customers and prospects that other people trust and respect you too - and crucially, closing that trust gap along the way too.
Chester Wisniewski is Director, Global Field CISO at next-generation security leader Sophos. Their report The Cybersecurity Trust Reality in 2026 is available here
Main image courtesy of iStockPhoto.com and nathaphat
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543