Regulatory and Compliance requirements are driving Cyber Security initiatives within many organizations. The Payment Card Industry has PCI, health care has HIPAA, and many others.
Organizations are required to meet or exceed the requirements set forth by these regulatory bodies if they want to remain compliant and be allowed to process credit card transactions or manage private health information.
Outside of direct compliance requirements, organizations utilize industry frameworks such as the NIST Cyber Security Framework or CIS Critical Security Controls, to assess their security maturity against a set of best practices.