At a quickening pace over the last 18 months, global financial institutions are treating security as a primary driver of capital allocation. Security, in this context, should be understood broadly to mean issues of global and national security, resilience, and geopolitics.
The most prominent example is J.P. Morgan’s launch of its Security and Resiliency Initiative in October 2025 – a $1.5 trillion, 10-year plan to facilitate, finance, and invest in industries critical to economic security and resiliency, including supply chain and advanced manufacturing, defense and aerospace, energy independence and resilience, frontier and strategic technologies, and pharma and health tech.
Other institutions have expressed similar investment theses. BlackRock has identified five mega forces that drive investment opportunity, one of which is geopolitical fragmentation and economic competition, noting “we see countries favoring national security and resilience over economic efficiency.” Morgan Stanley’s key themes investment outlook last year stated, “Government, country, corporate and personal security is no longer just a protective measure, but also a growth opportunity.”
Upstream, this is impacting how capital flows. National and global security issues increasingly impact how investors allocate capital across industries and to specific companies. Downstream, this trend is likely to have much broader and difficult-to-measure impacts. Specifically, it should be expected that security will increasingly be viewed in commercial terms and companies’ relative positioning on security issues will play a greater role in competitive advantage.
Beyond financial institutions, other audiences that shape commercial outcomes – customers, policymakers, and regulators specifically – are converging on the same logic.
Customers are increasingly making buying decisions based on security issues. This is especially true in critical infrastructure industries. In telecommunications for example, a recent McKinsey study found that “cybersecurity has emerged as the leading trigger, overtaking traditional factors such as price, coverage, or service reliability” for customers who switched providers – a pattern that is appearing in adjacent sectors as well.
Meanwhile, policymakers are signaling that they expect the private sector to lean forward on security issues. Treasury Secretary Scott Bessent told an audience of business leaders at the EXIM Annual Conference in April 2026 that the administration is building an “economic shield that protects supply chains, secures critical resources, and reinforces the resilience of the United States and its allies.” He closed, “Our success depends upon the people in this room. You all have the power to determine whether America leads or falls behind in the next decade. Your actions will make the difference.”
Among federal agencies, there is also a growing recognition that regulation can only go so far in addressing national security challenges. Senior government officials have signaled a desire to see companies step up proactively. As such, national security-related regulatory action is likely to be increasingly context-dependent (i.e., is this company committed to the mission or not?).
The cumulative result is that businesses need to be more proactive in positioning around security issues in service of their commercial objectives. Increasingly, stakeholders are not merely evaluating whether a company manages security risks effectively. They are evaluating whether the company understands the broader security challenges facing its sector and is visibly contributing to solutions.
Despite the need, companies do not have a framework for strategic positioning on security issues. Most of the existing literature about security as it relates to business is focused on a company’s security posture, namely its cyber and physical security measures, geopolitical risk management, supply chain security and resilience, crisis management, and regulatory compliance. This is all internally focused. Significantly less attention has been paid to how businesses communicate, and are perceived, externally on security issues – especially issues of national and global security significance.
To navigate this, businesses need to consider their Strategic Security Positioning. I’ve defined this concept as the degree to which a company demonstrates – through both its posture and its engagement – that it understands and is actively addressing the national security challenges facing the sectors it operates in or serves, and, in doing so, gains commercial advantage that competitors cannot quickly replicate.
To assess a company’s Strategic Security Positioning, it is helpful to look at both the business’s security posture (i.e., how strong are the company’s internal strategies, policies, and processes for managing security issues?) and at its engagement (i.e., how effectively does the company articulate its understanding of security challenges and its efforts to address them?).
The types of questions to consider include: Has the company elevated security issues (including cyber, physical, geopolitical, supply chain, etc.) to board-level priority, with appropriate leadership and resourcing? Has the company taken visible, voluntary actions that demonstrate its commitment to the security challenges facing its sector and those of its customers? Do the company’s actions, relationships, communications, and underlying posture present a coherent picture across investors, customers, policymakers, and regulators?
The underlying drivers which have led stakeholders to look more closely at a business’s Strategic Security Positioning – namely mounting global security threats, geopolitical fragmentation, and convergence between public sector and private sector security considerations – are only set to grow. Raising these issues proactively at board and c-suite levels can help to put a strategy in motion. The companies that move first will define the standard against which their competitors are measured.