— By Craig Lusher, Principal Solutions Architect at Continent 8 Technologies
This blog looks at why security investment so often stalls, and how Continent 8 Technologies’ new Loyalty+ programme is designed to give eligible customers a clearer route to strengthening their cyber resilience.

Most organisations already know their security could be better. Far fewer have an obvious route to getting there.
That gap is rarely about awareness. In iGaming and online sports betting, security sits on board agendas, in supplier contracts and under regulatory scrutiny. The difficulty is more practical. Security work competes for budget against everything else a business needs to fund, and the case for spending money on a problem that has not happened yet is always harder to make than the case for spending it on one that has.
The evidence has not made that argument any easier to win. Verizon’s 2026 Data Breach Investigations Report analysed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries. It found third parties involved in 48% of breaches, a 60% rise year on year, and recorded exploitation of vulnerabilities overtaking stolen credentials as the most common way into an organisation for the first time in 19 years, accounting for 31% of breaches against 13% for credentials. Remediation is not keeping pace: only 26% of the vulnerabilities in CISA’s Known Exploited Vulnerabilities catalogue were fully patched during 2025, with a median remediation time of 43 days.
The cost when something does go wrong has climbed as well. IBM’s 2026 Cost of a Data Breach Report puts the global average at $4.99 million, up 12% on the previous year. More than a quarter of organisations hit by a malicious attack said it was AI-driven, and those incidents added around $1 million each to the total. Downtime carries a separate bill. ITIC’s research into the hourly cost of downtime found that more than 90% of mid-size and large enterprises lose over $300,000 for every hour of outage, with 41% putting their exposure between $1 million and more than $5 million an hour.
For a sector built on interconnected platforms, specialist suppliers and always-on services, the third-party and downtime figures tend to be the ones that land hardest.
Why security investment stalls
In practice, security spend is often triggered by something external. A regulator asks a question, a customer sends a security questionnaire, a penetration test result lands, or an incident forces the issue. Each of those produces a purchase, but not necessarily a plan.
The result is familiar. Controls accumulate one at a time, chosen to answer whichever question was being asked at the time, and the joins between them are rarely revisited. Meanwhile the work that has no immediate trigger, such as testing an application nobody has looked at for two years, running a phishing simulation, or checking whether your brand is being spoofed somewhere, keeps sliding down the list because nothing is forcing it up.
None of this reflects badly on the teams involved. It reflects how budgets work. Money that is already committed to infrastructure is easier to defend than money that has to be found for something optional.
What Loyalty+ does
Loyalty+ is Continent 8’s new security credits programme. Eligible contracts are automatically enrolled in the Loyalty+ programme, enabling customers to earn security credits worth 5% of the Total Contract Value (TCV) of invoiced Continent 8 spend. These credits can then be redeemed against our qualifying cybersecurity services.
One credit is worth one US dollar when it is redeemed, so there is no conversion to work out and no ambiguity about what a balance is worth. There is nothing to buy and no sign-up process. If you have new invoiced spend with us, you earn credits automatically under the programme terms.
For contracts of twelve months or longer, the credits for the whole term are granted when you sign, rather than trickling in month by month. A customer on $20,000 a month across cloud and colocation, signing a 24-month term, has 24,000 credits available from day one, worth $24,000 against security services.
The practical effect is that the security work which normally waits for a trigger already has funding attached to it before the trigger arrives.
Credits can only be redeemed against Continent 8 security services, within that, the choice is entirely yours. If you already have a supplier for penetration testing, direct your balance somewhere else. If you want to trial a service before committing budget to it, credits let you do that without a business case.
What you can redeem against
The catalogue covers two broad groups: one-time engagements, such as VAPTs and Audits and ongoing solutions, such as MSOC (Managed Security Operations Centre), EDR and MDR services, Threat Exchange, the SafeBait platform and dark web monitoring.
You can pay part in credits and part in cash, so a balance that does not quite cover a piece of work is still useful. The minimum redemption is 250 credits. Subscriptions funded with credits carry a minimum twelve-month commitment, and continue at the standard rate afterwards unless you cancel. Your Account Manager holds the current credit price of each service and can arrange redemptions, though some engagements, penetration testing in particular, need scheduling and take a few weeks to organise.
The rules worth knowing
Credits expire twelve months after they are granted. When you redeem, the oldest credits in your balance are used first, so your more recent credits keep their full validity. We aim to remind you around 60 days and again around 30 days before anything is due to expire.
When you renew a contract, you receive a fresh allocation for the new term, any unused credits carry over, and the expiry clock resets from the renewal date. If you end all of your Continent 8 services, you have 90 days from your final service ending to redeem what remains.
Credits have no cash value. They cannot be exchanged for money or account credit, transferred to another customer, applied to non-security services, or refunded. The programme is offered at our discretion and the full terms are available from your Account Manager.
We should also say what Loyalty+ is not. It does not make an organisation secure, and no programme of this kind could. It funds work that we think is worth doing, and the value of that work depends entirely on what you choose to do with the findings.
Where this goes next
The version launching now is deliberately simple. Every customer earns at the same 5% rate, and the mechanics are kept easy to explain.
Continent 8 has been protecting the iGaming and online sports betting industry for decades. In a sector where one organisation’s exposure can reach across connected platforms, suppliers and players, we have a direct interest in the security maturity of the businesses we work with, not only our own. Loyalty+ is one attempt to act on that.
For eligible Continent 8 customers, it turns spend you have already committed into security work you might otherwise have deferred. To find out what your balance could be, speak to your Account Manager or visit https://www.continent8.com/loyalty. T&Cs apply https://www.continent8.com/loyalty-tc/.