Essay summary
The evolution of professional trust rarely announces itself through dramatic events. It reveals itself through changing behaviours. In business, the clearest early signal emerged not from cybersecurity professionals or regulators — but from procurement. And what procurement is now asking has profound implications for every small business and independent professional.
How Major Shifts Actually Happen
When major changes occur within business environments, they are rarely recognised immediately.
The industrial revolution was not identified as a revolution while it was happening. The internet was initially viewed as a technical curiosity. Even the widespread adoption of cloud computing was often discussed as a technology trend long before its broader implications became clear.
Significant shifts tend to reveal themselves gradually through changing behaviours rather than dramatic announcements.
The evolution of trust appears to be following a similar pattern.
Procurement Noticed First
Interestingly, some of the earliest indicators have emerged not from cybersecurity professionals, regulators or technology vendors, but from a far less visible corner of the business world.
Procurement.
For decades, procurement was primarily concerned with a familiar set of questions.
Can the supplier deliver? Can they meet deadlines? Are they financially stable? Can they provide the required service at a competitive price?
These questions remain important. But over the past decade, a new category of questions has quietly appeared alongside them.
How do they protect information? Who has access to client data? What security controls exist? How do they manage risk? What happens if they experience a breach?
The first people to recognise a changing environment are often those whose responsibilities place them directly in its path.
Why Procurement Sees It First
The emergence of these questions is revealing.
Procurement departments are not typically interested in technology for its own sake. They are interested in reducing uncertainty. Their role is to identify and manage risks that could affect the organisation purchasing the service.
Viewed through that lens, cybersecurity becomes something more than a technical discipline.
It becomes a trust indicator.
This distinction matters because it changes the conversation entirely.
Historically, cybersecurity was often viewed as an internal operational concern — something that existed within IT departments, compliance teams and technical functions. Many organisations treated it as something separate from the commercial aspects of business.
Procurement does not have that luxury.
Procurement evaluates consequences.
A supplier breach can become a customer breach. A contractor's weakness can become an organisational weakness. A poorly managed information environment can quickly become a reputational event affecting multiple parties.
In an increasingly connected economy, risk travels.
Trust travels with it.
What the Research Shows
The significance of this shift is becoming difficult to ignore.
Research by KPMG found that 94 per cent of procurement managers say cybersecurity standards are important when awarding work to an SME supplier, and 86 per cent would consider removing a supplier from their roster following a breach. (KPMG / Cyber Streetwise, Small Business Reputation & The Cyber Risk, 2016)
Organisations that once evaluated suppliers primarily on capability and price are increasingly evaluating them on their ability to protect information and manage digital risk.
This development represents something larger than changing procurement practices.
It represents a change in what organisations value.
The New Commercial Reality
Capability remains important. Price remains important. Experience remains important.
But they are no longer the only considerations.
Trustworthiness is becoming commercially measurable.
That observation may have profound implications for small businesses.
Historically, smaller organisations often competed by being more agile, more responsive or more specialised than larger competitors. In many cases, these advantages remain intact.
However, a new challenge has emerged.
Clients increasingly expect the same standards of information stewardship regardless of organisational size.
A five-person consultancy may be asked questions that would once have been reserved for multinational corporations. A sole practitioner may find themselves completing supplier security questionnaires. A specialist contractor may discover that demonstrating trustworthy practices is becoming just as important as demonstrating technical expertise.
Trustworthiness is becoming commercially measurable.
Why Risk Now Travels Through Supply Chains
This is not occurring because organisations have suddenly become more cautious.
It is occurring because the structure of risk has changed.
Information now flows through supply chains in ways that were previously unimaginable. According to the Verizon 2025 Data Breach Investigations Report, the percentage of breaches involving third parties doubled — reaching 30 per cent of all recorded breaches.
Data moves between organisations, cloud services, contractors and platforms with extraordinary speed. The consequence is that trust is no longer confined within organisational boundaries.
It has become interconnected.
Procurement professionals understand this instinctively because they occupy the point where those connections converge. Long before many businesses recognised trust as a strategic issue, procurement departments were already adapting to its implications.
In retrospect, perhaps this should not be surprising.
The first people to recognise a changing environment are often those whose responsibilities place them directly in its path.
The Signal
Today, procurement appears to be sending a signal.
The signal is not really about cybersecurity.
It is about trust.
And increasingly, trust appears to be influencing who wins the work.
For small businesses and independent professionals, that signal is worth paying attention to. Not because compliance is required. But because the organisations that respond to it first may find themselves with an advantage that, once established, becomes progressively harder for competitors to replicate.
About Klevely
Klevely exists for exactly this moment. When procurement asks about your security posture, we help you answer — with a real Zero Trust security setup that's verifiable, demonstrable, and built for teams of one to fifty.
Join the early access list