
Nicole Junkermann sees cybersecurity as the precondition hiding inside every other investment thesis
Nicole Junkermann has been making an argument about cybersecurity for years that most investors have yet to fully price. The founder of NJF Holdings — which names cybersecurity among its five core areas of conviction alongside longevity, sport, life sciences and deep tech — argues that security is not a sector to invest in alongside the others. It is the assumption that all of them depend on holding.
Run a thought experiment across the fashionable investment themes of the decade. AI: models trained on proprietary data, deployed into critical workflows — worthless if the data is poisoned or stolen. Digital health: the most sensitive information humans possess, moving between systems that were never designed to hold it. Autonomous vehicles: software making physical decisions at speed, an attack surface with a body count. Fintech: money reduced entirely to code. Every one of these theses contains an unstated assumption — that the systems underneath will hold. Cybersecurity is the name of that assumption.
"Cybersecurity isn't a sector you invest in alongside the others," Nicole Junkermann says. "It's the precondition for all of them. Every thesis in our portfolio — AI in medicine, financial infrastructure, autonomous systems — is really two bets: one on the technology, and one on the security holding underneath it. Investors price the first bet obsessively and barely look at the second. That gap won't survive contact with the next decade."
The economics Nicole Junkermann says make cybersecurity one of the least discretionary budgets in enterprise
Part of the neglect is aesthetic. Security produces no demos, no consumer moments; its successes are invisible by definition - the breach that didn't happen, the system that stayed boring. Capital, which loves a story, has historically preferred the visible layer.
The economics underneath tell a different story. Security spending is among the least discretionary in all of enterprise budgets - it survives recessions, because the threat does. The revenue is overwhelmingly recurring. Switching costs are high, since ripping out a security stack is the one migration no CIO volunteers for. And demand compounds with every other technology trend rather than competing against them: each new AI deployment, each connected vehicle, each digitised hospital enlarges the attack surface and the budget defending it. Few categories are handed structural tailwinds by their neighbours' growth.
The threat side compounds too, and faster. AI has cut the cost of attack more dramatically than the cost of defence - phishing at native-speaker fluency in any language, vulnerability discovery at machine speed, deepfakes of chief executives approving payments. "The same technology revolution investors are celebrating is arming the other side", Nicole Junkermann says. "Offence is getting cheaper faster than defence. That asymmetry is the single most under-priced fact in technology - and correcting it is where a generation of security companies will be built."
Why Nicole Junkermann sees security as the production of trust rather than a defensive expenditure
There's a larger frame behind her position, consistent with the investment philosophy she has published under the Human Code: that in an era when AI can fabricate convincing content, identities and institutions at negligible cost, trust becomes one of the scarcest commodities of the century. "I invest in infrastructure that builds trust - across borders, sectors, and generations," as she has put it. Security, on this reading, isn't a defensive expenditure at all. It's the production of trust - the thing that lets a patient share data, a bank move money, a factory connect its machines. Industries run on it the way they run on energy, and it's priced, she argues, the way energy was before anyone thought to meter it.
The discipline, as ever with Nicole Junkermann, is in where not to invest. The security market's weakness is fragmentation - thousands of point solutions selling fear at renewal time. Her filter mirrors her approach elsewhere: the infrastructure layer over the product layer. Identity, encryption, the security of AI systems themselves - the dependencies other companies must build on - rather than the app of the season.
How geopolitical necessity made cybersecurity spending into non-optional for UK investors
For the UK the frame has hardened from commercial to geopolitical. The past few years of attacks on British institutions - hospitals, councils, supply chains, household-name retailers - have made the point more effectively than any white paper: critical national infrastructure now includes the digital layer, and state-adjacent actors probe it continuously, in peacetime, as policy. That shift changes the investment case. Security spending backed by national resilience requirements is about as non-discretionary as demand gets, and the UK - with GCHQ-adjacent talent, a serious research base and Europe's deepest security cluster after Israel's - is unusually placed to supply it. Resilience, long a word for pamphlets, is becoming a budget line. Investors would be wise to read it as one.




















