
The UK was the anomaly in EMEA cyber-security in 2025. While the wider region posted steady growth, the UK market contracted by 11 per cent. At first glance, this might look like weakening demand. In reality, it reflects something far more deliberate. UK organisations entered 2025 facing both economic pressure and an impending regulatory overhaul. When the Cyber Security and Resilience Bill was finally introduced in November, it confirmed what most CISOs had anticipated all year. Heavy compliance obligations are on their way, and they are set to reshape spending priorities for years ahead.
That expectation created a freeze. Rather than move forward with refresh cycles or invest in new layers of tooling, organisations held back discretionary spend and redirected budgets towards the essentials they knew would withstand legislative scrutiny. Much of the year became an exercise in strategic restraint. The market did not shrink because security became less important, but because security leaders refused to buy anything that might become redundant once the Bill’s details were finalised.
The most visible consequence was the extraordinary collapse in cloud security spending. This category, defined as security of the cloud service itself, fell by almost 70 per cent. UK organisations hit pause on public cloud native controls because they had no clarity on whether these tools would satisfy the incoming regulatory framework. Without that clarity, paying premiums for overlay controls made little sense. At the same time, CFOs were looking for fast OpEx reductions in a tight fiscal climate. Metered cloud security services were among the easiest costs to cut. As workloads began to shift back into fixed cost and controlled environments, security budgets followed. It was a decisive move away from dispersed cloud risk toward infrastructure that could be governed and audited with confidence.
This brings us to where the budget went. Infrastructure protection increased by almost 15 per cent, and data security by just over 10 per cent. These gains were not opportunistic. They were intentional. Infrastructure protection, which we define as control methodologies underpinning defence in depth, became the safest investment path for critical national infrastructure providers. Organisations in this space spent much of 2025 strengthening their control architectures so they could demonstrate readiness for audits they expect to begin soon after the Bill becomes law.
At the same time, the UK made a quiet but key shift toward sovereign AI preparation. The growth in data security is tied to the desire to run private AI models safely on domestic infrastructure rather than expose sensitive data to public AI interfaces. Organisations spent 2025 scrubbing and protecting internal data lakes, enforcing classification, hardening governance frameworks and preparing the infrastructure needed to host models locally. The government’s voluntary AI Cyber Code of Practice, published in January, gave this movement further momentum. It stressed data integrity and secure architectural design as central components of responsible AI development. Firms listened, and they budgeted accordingly.
Some categories were the inevitable casualties of this waiting year. Network security fell by more than 17 per cent, and endpoint security slipped by just over 13 per cent. These declines do not indicate that perimeter and device controls are losing relevance. They simply show that CISOs chose to stretch the lifespan of existing hardware rather than commit to refresh cycles that might be overtaken by regulatory requirements in 2026. In a year marked by caution, sweating assets was the rational choice. The result is a growing backlog of systems that will need urgent modernisation once the Bill becomes fully enacted.
All of this sets the stage for 2026. When the new legislation comes into force, likely by the middle of 2026, we expect a rapid release of pent up spending. Network and endpoint estates that have been kept on life support will have to be upgraded to meet mandatory resilience and reporting standards. Many firms have delayed these investments as long as possible. They will not be able to delay them any longer.
The larger structural change is even more significant. Cloud security as a standalone concept is fading. The behaviour of the UK market in 2025 shows a clear preference for integrated platforms that provide universal workload protection across public cloud, private cloud and on-premise environments. Organisations want one consistent security posture across all compute locations, not a patchwork of cloud-specific tools. The winners in 2026 will be the vendors who can make that promise real.
The UK did not lose momentum in 2025. It recalibrated. It strengthened its foundations for a regulatory environment that will demand demonstrable resilience and secure AI development. The decisions made this year were cautious by design. The decisions required next year will be unavoidable.
Joe Turner is Chief Analyst for Cybersecurity at CONTEXT
Main image courtesy of iStockPhoto.com and nuttapong punna
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543