CSPs are measuring security revenue wrong


This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.


For CSPs, security is not adjacent revenue. It is revenue assurance.

For a communications service provider, DDoS tends to appear in two different conversations. The first takes place within network operations, where an attack is treated as a threat to infrastructure, service availability and the stability of the wider network. The second takes place within the commercial organisation, where DDoS protection is packaged as an optional security service attached to the core connectivity product. Internally, separating the two makes sense. To the customer, however, they are usually part of the same promise.

I was reminded of this recently while working with a prominent CSP that we have supported for some time. One of its larger enterprise customers subscribed to the provider’s connectivity service and had also purchased its existing DDoS protection add-on. The protection was not delivering the outcome the customer expected, and the situation had deteriorated to the point where the customer was considering cancelling the entire account. The connectivity contract, worth considerably more than the security component, had been placed at risk by what appeared on paper to be an auxiliary service.

An alternative DDoS platform had already been deployed within the CSP’s network, so the customer was given the opportunity to try that service instead. The outcome was positive: the immediate protection problem was resolved, confidence in the provider was restored and the customer chose not only to retain the connectivity relationship but to expand the security portion of the contract. It would be easy to present this as a story about one technology performing better than another, but that would miss the more important lesson. The smallest part of the original contract had almost caused the loss of the largest part, and subsequently helped to protect and grow it.

The revenue is sitting in the wrong column

CSPs usually measure a security service in much the same way as any other product. They look at its revenue, margin, attach rate, sales pipeline and number of active customers. These are all necessary measures, particularly when the provider needs to justify investment in specialist platforms, people and operational support. However, they capture only the revenue generated directly by the security service. They do not show how much core connectivity revenue that service influences or protects.

This distinction matters because customers do not experience a provider through its internal product structure. They do not separate the IP transit team from the managed security team when a protected service becomes unavailable. Nor do they spend much time deciding whether the underlying failure belongs to a network, a mitigation platform, a configuration or a third-party supplier. They see that they bought connectivity, paid extra to keep it available during an attack, and were left exposed when the protection was needed.

The resulting dissatisfaction does not remain neatly contained within the security line item. It spreads across the account. Questions about one service quickly become questions about the competence, judgement and responsiveness of the provider as a whole. At renewal time, the customer is not merely deciding whether to retain a DDoS add-on. It is deciding whether the CSP can still be trusted with the connectivity on which its own business depends.

If security is measured only according to its standalone revenue, much of its commercial contribution is attributed elsewhere or disappears entirely. A retained connectivity contract is recorded as connectivity revenue. An expansion may be credited to the account team. Churn that never occurred has no obvious place in a product dashboard. Yet security may have materially influenced all three outcomes.

Connectivity is only a commodity while it works

There is a familiar argument that connectivity has become a commodity. Price competition is intense, the underlying service can be difficult for customers to differentiate, and providers increasingly look to cloud, managed services, cybersecurity and other adjacent offerings for growth. Current GSMA Intelligence research reflects that direction: services beyond traditional core telecoms accounted for an average of 28% of revenue among major operators by 2024, while the GSMA’s Mobile Economy 2026 report identifies cybersecurity as more than 20% of the addressable B2B technology-services opportunity beyond core connectivity.

The temptation is to interpret this entirely as a diversification story. Under that model, connectivity supplies the customer relationship and additional services increase revenue per account. Security becomes one more item in an expanding catalogue, competing with other products for sales attention and investment. That may be commercially convenient, but it understates the particular role that network security plays.

Not every adjacent service reinforces the core product in the same way. A customer can usually replace or remove an unrelated application without concluding that its network provider has failed. DDoS protection is different because it exists to preserve the usability of the connection under hostile conditions. It is sold separately, but its outcome is inseparable from the availability of the service beneath it.

This is especially apparent with enterprise customers whose public services, applications or digital transactions depend on continuous connectivity. During normal conditions, providers may appear broadly interchangeable and purchasing conversations may revolve around price, capacity and contractual terms. During an attack, the distinction becomes much clearer. The customer discovers whether it bought bandwidth or whether it bought a provider capable of keeping its business reachable.

Connectivity may be priced like a commodity, but its failure is experienced like a broken promise. For that reason, the commercial importance of DDoS protection can be much greater than its percentage contribution to the invoice.

DDoS has a commercial blast radius

The problem is made harder by the way responsibility is divided inside many CSPs. Network operations may view DDoS primarily through the effect it has on backbone capacity, infrastructure and downstream customers. The product team may focus on whether the contracted protection service meets its specifications. Sales and account teams encounter the issue later, when the customer is already dissatisfied, and the renewal is in danger. Each team sees a legitimate part of the problem, but the commercial blast radius runs across all of them.

A mitigation service can therefore succeed according to one internal measure and still fail according to another. The provider’s wider network may remain stable while the targeted customer continues to experience disruption. Attack traffic may be detected and dropped while legitimate transactions suffer unacceptable latency or false positives. A dashboard may demonstrate that a large quantity of traffic was blocked, but the customer will judge the outcome using a more straightforward test: could its users still access the service?

This is why DDoS protection cannot be managed merely as a feature attached to a circuit. It affects network operations, customer experience and account retention simultaneously. The relevant measures should reflect that wider role. Alongside direct security revenue and product margin, CSPs should be asking how security affects renewal rates, churn risk, customer lifetime value, service expansion and the retention of strategically important accounts.

This does not mean assigning every successful renewal to the security team or inventing inflated numbers to make an auxiliary portfolio look more valuable. It means recognising commercial influence that conventional product reporting overlooks. If a relatively small security service determines whether a much larger connectivity account stays or leaves, treating its value as only the amount charged for that service gives management an incomplete picture.

From additional revenue to revenue assurance

The telecoms industry already understands the principle of revenue assurance: protecting income that the business has earned but might otherwise lose through leakage, process failures or other weaknesses. Security belongs in a similar strategic conversation, even if the mechanism is different. It protects revenue by maintaining the trust and service availability on which the customer relationship rests.

That shift in perspective changes the investment question. Instead of asking only whether the security portfolio can become a large standalone business, a CSP can also ask which parts of its core revenue would be harder to retain without credible protection. A DDoS service may never rival connectivity in total revenue, but that is not the appropriate test if its presence improves retention, differentiates the provider and gives customers a reason to expand rather than reconsider the relationship.

It also changes how providers should approach delivery. CSPs have a structural advantage in network security because they already carry the traffic and operate close to the point where attacks can be identified and mitigated. That does not mean every provider must develop every capability internally or attempt to transform itself overnight into a full-scale security vendor. Specialist partners can provide technology and expertise, but the CSP must still own the service outcome. Customers rarely accept an internal supplier boundary as an explanation for why their protection failed.

Credibility therefore depends on more than adding a security SKU to the catalogue. The service needs to be integrated into operations, tested against realistic conditions and supported by people who understand how to respond when customer traffic does not behave as expected. Account teams also need to understand what the service protects and how to escalate problems before dissatisfaction becomes a cancellation discussion. The commercial promise and the operational capability have to describe the same thing.

The part of the contract that keeps the rest of it sold

In the case I described, the security service did not suddenly become the largest source of revenue in the account. It did something more important: it helped preserve the core connectivity contract, repaired the customer’s confidence and created room for the relationship to grow. The value appeared partly as security revenue, but much of it remained recorded under connectivity.

As CSPs look beyond their core services for growth, they should resist treating every additional offering as a separate commercial island. Some services do more than add revenue. They make the main product more credible, more resilient and harder for the customer to replace. DDoS protection is one of them because it addresses the moment when the value of connectivity is tested most severely.

Security may sit beside connectivity in the product catalogue, but it does not sit beside it in the customer’s experience. When protection fails, the whole account can be placed at risk. When it works, the benefit extends well beyond the security charge on the invoice. CSPs that measure only the direct revenue will continue to underestimate what their security services are really doing for the business.

For CSPs, security is not adjacent revenue. It is revenue assurance.

About The Author

Donny Chong
Donny Chong

Donny Chong is a Product & Marketing Director at Nexusguard, where he's responsible for designing the company’s solutions for the enterprise segment. He has contributed to TechFinitive under the Opinions section.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.