Two sides of the same regulated table
Incumbent or challenger, the requirement underneath is identical: a secure foundation that holds up when someone with authority starts looking.
If you're a regulated enterprise, the job is to cut risk and foreign dependency, answer to OSFI, Bill C-26, or PHIPA, and modernize without handing your security posture to whoever you outsourced it to.
For fintech, healthtech, climatetech, edtech & other digital native businesses the job is to sell into those regulated buyers. That means clearing their security review on the first pass, before you've stood up a security team big enough to do it for you.