Cybersecurity may be one of the Australian channel’s strongest growth opportunities, but turning demand into sustainable profit is not straightforward.
The recent techpartner.news State of the MSP report found security was the leading source of expected revenue or profit growth among managed service providers, as nominated by two-thirds of respondents.

It’s not hard to see why, with Gartner forecasting Australian information-security spending will exceed $7 billion in 2026. Security services are the largest segment, including consulting and professional and managed security services, with Gartner forecasting that spending will increase by 6.9 percent from 2025 to reach $3.7 billion this year.
Unfortunately, that growth is underpinned by continuing demand. In 2024-25, the Australian Signals Directorate’s Australian Cyber Security Centre received more than 84,700 cybercrime reports and responded to 1253 cybersecurity incidents - an increase of 11 percent.

However, the growing requirement among customers for cybersecurity services does not guarantee an easy path to profit, with established managed security service providers (MSSPs) reporting that many customers remain unwilling, or unable, to pay for the level of protection they need. That tension is reflected in data from an ACSC small-business study, which found 48 percent of Australian small businesses spent less than $500 a year on cybersecurity.
An influx of new competitors is also placing downward pressure on prices by commoditising foundational services, with experienced providers shifting away from product-led selling towards operational, risk-led service models built around ongoing customer outcomes.
And these aren’t the only changes.
According to Isabelle Thilliez, strategic sales executive and marketing lead at ONGC Systems, providers like hers are also contending with vendors selling directly, continued merger and acquisition activity, and larger clients bringing more security capability in-house.

“There is a lot of competition, and the competition is evolving,” Thilliez said.
“So, we need to evolve with it as well.”
By 2030, the strongest channel partners are likely to combine automation and scale with senior expertise, effective governance, and demonstrable improvements in customer security. But reaching that position will require them to navigate persistent pricing pressure, rapidly evolving artificial intelligence capabilities, intensifying competition, and an increasingly demanding regulatory environment.
One of the core challenges for established cyber partners is the growing number of competitors offering increasingly standardised foundational services.
According to the founder and CEO at Otto IT, Milan Rajkovic, some providers are discounting or foregoing work that would previously have been considered essential – and lucrative – in order to win new business. This includes detailed onboarding and security uplift projects.
He said this behaviour was clouding customers’ expectations, as prospective customers were often surprised to learn that their existing arrangements did not provide adequate protection.
“I would assume (providers) are asking what corners they can cut to get this done faster,” Rajkovic said.
The CEO at Gridware, Ahmed Khanji, said the gaps in quality between different services providers were most clearly exposed by the ongoing increase in successful attacks.

“Every MSP says they will keep you cyber-secure, but they are keeping me in business, because thousands of organisations are still suffering cybersecurity attacks in Australia each year, and pretty much all of them have an MSP,” Khanji said.
“But I do see it from the MSP’s perspective. A lot of customers want the whole world without having to pay for anything.”
The tension between rising expectations and resistance to higher costs is shaping how security is positioned and sold in 2026. For some providers, that has meant making security a non-negotiable part of the broader managed-service relationship, where security is no longer treated as a prerequisite for delivering reliable managed services, and as a core part of the provider’s own risk management.
Rajkovic said Otto IT would decline to work with customers that refused to adopt an appropriate security package, except where a separate security specialist was already involved.

“We will turn clients away if they won’t take on a security package from us,” he said.
Faced with price pressure and growing competition, established providers are looking for ways to deliver more value without diluting the service.
For many, that means using AI to increase the productivity of senior staff, improve customer interactions, and make security services more efficient. Experienced security providers, however, contend this will not immediately result in a decreased need for human skills – if ever.
“We are actually investing in more senior resources,” Rajkovic said.
“A senior resource is able to utilise AI to do lower-end tasks in a fraction of the time.”
Senior resources might also prove invaluable in helping clients navigate another reality of cybersecurity in 2026 - the increasingly complex regulatory environment.
Principle among these is the Privacy Act, which generally applies to Australian organisations with annual turnover above $3 million, as well as certain smaller organisations. Many businesses also fall within the remit of the Security of Critical Infrastructure (SOCI) Act and industry-specific regimes.
The consequences of these regulatory environments mean cyber incident now extend well beyond containment and recovery. Organisations may face prolonged scrutiny and be required to show that they took reasonable steps to identify and manage their risks.
As Darren Hopkins, partner at the advisory firm McGrathNicol explained, the greatest financial exposure may not be the headline penalty itself.

“If you are investigated by the Privacy Commissioner on the back of a breach, it is not the penalty you worry about - it is the two or three years in court and the cost of having to defend yourself.”
The growing emphasis on compliance comes at a time when notifications are at a record high. The OAIC received 1,205 notifiable data-breach reports in calendar 2025, the highest annual total since mandatory reporting began in 2018, and 8 percent more than in 2024. Between January and June 2025, malicious or criminal attacks caused 59 percent of notified data breaches. Cyber incidents were the predominant form of malicious attack, and each cyber incident affected an average of just over 10,000 people.
The result of this growing compliance burden is an expansion of the addressable market for compliance, governance, and assurance services.
The rapid adoption of artificial intelligence is adding another layer to that challenge. While many organisations are focused on the productivity gains AI might deliver, fewer have developed an equally mature understanding of the security, privacy, and governance risks it introduces. A 2025 report from the Governance Institute on AI deployment and governance found gaps in governance, inadequate training and uneven readiness, particularly outside large organisations.
“Most organisations are working out how they are going to use it and benefit from it,” Hopkins said.
“Not everyone is thinking about how to secure it.”
For technology partners, this creates an opportunity to extend into areas such as AI governance, data classification, access controls, third-party risk, and the safe deployment of tools such as Microsoft Copilot.

This overall shift is already evident in requests for proposals. According to Steven MacDonald, director of the cyber security practice at Interactive, customers are increasingly referencing recognised security frameworks such as NIST and Essential Eight maturity levels when seeking external support.
“I am seeing (Essential 8) ML1 and ML2 being called out specifically in multiple RFPs that are coming through,” MacDonald said.
While the pace of change in cyber security makes it difficult to predict exactly what services will look like by the end of the decade, ONGC’s Thilliez said partners would need to remain agile as AI created both new opportunities and new threats.

“We are just at the beginning of the wave of what AI is going to bring, from both sides - from the innovation it can bring to organisations in Australia, but also what the threats are going to look like in the future,” Thilliez said.
Hence, MacDonald believed the security partner of 2030 was unlikely to succeed by simply adding more tools or more junior analysts.
“People are everything in cybersecurity,” said MacDonald. “The technology is amazing, but people are at the heart.”
MacDonald said AI was already enabling security teams to perform work that had previously been difficult or uneconomic, but warned that the technology still required human checks and balances.
“At two o’clock in the morning, somebody doesn’t want to hear from an AI voice that their business has been compromised,” he said.

“Security is still a team sport, and we have a new team member.”
That distinction will become increasingly important as AI takes on more analysis, reporting, and detection work. Gridware’s Khanji expects lower-level activities, including basic risk assessments and gap analyses, to be among the first areas disrupted.
“The companies that are using AI to complement their services are going to be many steps ahead,” Khanji said.
For some providers, that is already changing the shape of their workforce. Rajkovic said Otto IT was investing in more senior employees who could use AI to complete lower-level tasks faster, rather than relying on inexperienced staff to perform work beyond their capabilities.
The result may be a cyber partner with fewer people performing repetitive tasks, but a greater concentration of specialists able to interpret findings, understand business context, and take responsibility for the decisions that follow.
Automation may also give smaller providers access to capabilities that previously required much greater scale. The founder and managing director of the one-year-old MSSP Summit Cyber Group, Owen Robbins, said his company was using AI, automation, and integrations to generate reports, identify insights, and improve services without reducing the value delivered to customers.

“We are not trying to race to the bottom,” Robbins said.
“We are leveraging automation and AI to deliver even more value into the services to justify the price.”
That approach points to another likely source of differentiation. As widely available security platforms become harder to distinguish, partners may increasingly compete through the operational layer they build around them.
By 2030, the strongest cyber partners are likely to combine several qualities that do not always sit easily together - automation and human judgment, scale and specialisation, standardised delivery and customer-specific advice.
Their value will lie less in the products they resell than in their ability to turn those products into an accountable security operation - one that can help customers prevent incidents, respond when they occur, and demonstrate that risks are being actively managed.