New client contracts required proof of a documented cybersecurity program they did not have.
Built and documented access controls, an incident response plan, and staff security training.
Passed every client security review since; no lost contracts over compliance.