Cybersecurity: what’s changing now?

Last updated: 11 September 2026
market research pitch 2026 statistics cybersecurity market

In our cybersecurity market deck, you will find everything you need to understand the market

SUMMARY

Cybersecurity is currently being rebuilt around a world where people, software, cloud workloads, machine identities and AI agents can all hold meaningful access to company systems.

The biggest shift is happening at the point of entry. Exploited software vulnerabilities now account for roughly one-third of breaches in both Verizon and Mandiant datasets, putting vulnerable internet-facing infrastructure ahead of the stolen-password model many companies still instinctively prepare for.

Identity is expanding at the same time. Machine identities already vastly outnumber human ones, and AI agents add another class of actor that can read data, call APIs and change systems without behaving like either a traditional application or an employee.

AI is already useful to attackers, but mostly because it improves the economics of familiar cybercrime. Faster research, better phishing, voice cloning, code generation and automation matter today more than the still-emerging idea of fully autonomous hacking agents.

Voice phishing shows how attackers adapt when technical defenses improve. Email filtering and MFA can be strong, yet a convincing call to a help desk can sometimes bypass both by persuading a human to reset access legitimately.

Ransomware is becoming a strange two-sided market: it appears in more breaches even as more victims refuse to pay. Attackers are responding with faster hand-offs between specialists and more deliberate attacks on backups, identity systems and virtualization infrastructure.

Third-party exposure is turning security into a control problem rather than just a visibility problem. A company may discover that a supplier has weak authentication or excessive permissions and still lack the authority to fix it quickly.

The security industry is consolidating around these changes. Google, Palo Alto Networks, ServiceNow and CrowdStrike are building broader platforms that connect cloud exposure, identity, endpoints, assets, permissions and increasingly AI-agent activity.

Security operations are becoming more automated too, but autonomy is arriving unevenly. Machines are moving quickly into alert investigation and correlation, while humans remain much closer to actions such as disabling accounts, isolating systems or changing important permissions.

The deeper pattern is that cybersecurity is becoming about relationships and blast radius: which identity can reach which system, which vulnerable asset leads to which data, which supplier holds which permissions, and what happens when one control fails.

Market map chart showing top companies and startups in the cybersecurity market

This market map, featured in our cybersecurity market deck, highlights top companies and startups in the cybersecurity market

What is actually changing in cybersecurity right now?

Cybersecurity is currently being rebuilt around a much messier reality: companies have to protect people, software, cloud infrastructure, machine identities and increasingly AI agents at the same time.

The old picture of cybersecurity was easier to understand. Employees had accounts, laptops connected to corporate networks, and security teams tried to keep attackers outside. That model already weakened with cloud computing and remote work. AI agents are stretching it further because software can increasingly receive permissions and act on a company's behalf.

The way attackers get in is changing too. Verizon's latest Data Breach Investigations Report found that software vulnerabilities caused 31% of breaches, overtaking stolen credentials as the leading initial access method. Mandiant independently found exploits behind 32% of the incidents it investigated, the sixth year in a row that exploitation ranked first.

Meanwhile, identity has expanded far beyond employee passwords. Palo Alto Networks says machine identities outnumber human identities by more than 80 to one. Add autonomous agents that can open files, call APIs or change systems, and security teams suddenly have many more actors capable of doing something privileged.

The industry's response is already visible in where billions of dollars are going. Google bought Wiz, Palo Alto Networks bought CyberArk and Koi, ServiceNow bought Veza and Armis, while CrowdStrike keeps expanding Falcon from endpoint protection into identity, cloud and other security functions.

Put those developments together and the direction is pretty clear. Cybersecurity today increasingly comes down to understanding who or what can reach a system, what that system can reach next, and how quickly a company can contain the damage when one layer fails.

Earlier security model What companies increasingly have to protect
Employees and laptops Humans, machines and AI agents
Corporate networks Cloud, endpoints, SaaS and distributed infrastructure
Passwords and malware Identities, permissions, vulnerabilities and software dependencies
Individual security tools Connected security platforms
Keeping attackers out Prevention, containment and recovery

If you want more recent data on this point, please see our latest cybersecurity market report.

Are AI cyberattacks actually taking off?

Yes, AI is already changing cyberattacks, although most of the impact today comes from making familiar attacks faster and cheaper.

Verizon found generative AI supporting 15% of the attack techniques identified in its latest breach dataset. That can include researching victims, finding weaknesses, generating phishing material, modifying malicious code or speeding up other repetitive work.

Social engineering is an obvious beneficiary. A criminal can research a target, write natural messages in several languages and produce convincing impersonation material much faster than before. Voice cloning adds another channel. Malware development and vulnerability research also become easier when models can generate code, explain unfamiliar systems and suggest ways around technical obstacles.

Attackers do not need a fully autonomous hacking agent to benefit from AI. Cutting ten minutes of work from something repeated against thousands of targets can already change the economics of an attack.

The spectacular claims still deserve some caution. Fully autonomous agents capable of selecting targets, breaking into networks, moving through systems and monetizing access with almost no human involvement are becoming more credible technically, but they still do not explain most breaches we see today.

The World Economic Forum's latest survey captures that gap well. Some 94% of cyber leaders expect AI to be the biggest force shaping cybersecurity, and 87% reported growing AI-related vulnerabilities.

Google Trends chart showing rising interest in cybersecurity

As this chart shows, and as featured in our cybersecurity market deck, search interest in cybersecurity has been trending upward

Have software vulnerabilities really become a bigger problem than stolen passwords?

Yes. Software vulnerabilities are currently the leading way attackers get into breached organizations in Verizon's global dataset, and Mandiant is seeing almost exactly the same pattern.

Verizon puts vulnerability exploitation at 31% of breaches. Mandiant found exploits responsible for 32% of the incidents it investigated, marking six consecutive years in which exploitation was its most common initial infection method.

The consistency between the two datasets is more important than either percentage alone. These organizations investigate different populations of incidents using different methodologies, yet both are finding roughly one-third of compromises beginning with vulnerable software.

Attackers particularly like internet-facing infrastructure such as VPN appliances, firewalls, gateways, file-transfer products and virtualization systems. Many of these products sit in highly privileged positions. Some also lack the endpoint monitoring that security teams rely on to catch malicious behavior after a laptop or server has been compromised.

Mandiant has repeatedly found sophisticated attackers persisting inside edge devices, identity systems and virtualization infrastructure for exactly that reason.

Email phishing is moving the other way in Mandiant's investigations. It fell from 14% of initial infections to 6%, while exploitation remained at 32%.

Patching a critical internet-facing appliance can no longer comfortably wait for the next IT cycle.

Why is voice phishing suddenly working so well?

Voice phishing is working because attackers have realized that convincing a support employee can be easier than defeating modern authentication technology.

Mandiant saw voice phishing jump to 11% of initial infections in its latest investigations, enough to become the second most common entry method it observed. Email phishing fell to 6%.

That reversal is striking. Security teams have spent years building filters for malicious attachments, suspicious links, fake domains and abnormal email behavior. A phone conversation with an IT help desk slips around much of that machinery.

The attacker can impersonate an employee who has lost a phone, needs an MFA reset or cannot access an account. If support resets authentication after a convincing conversation, the attacker receives legitimate access without cracking MFA.

AI makes this easier by helping criminals gather personal information, prepare scripts and clone voices. But the weakness being exploited is often a human process: how does a company prove that the person asking for a reset is really the employee they claim to be?

That is why account recovery and help-desk identity checks are becoming much more important parts of phishing defense.

Chart illustrating yearly VC funding for cybersecurity startups

This chart, included in our cybersecurity market deck, illustrates yearly VC funding for cybersecurity startups

Is identity becoming the new cybersecurity perimeter?

Yes. Identity is currently becoming the main control point in enterprise cybersecurity because companies can no longer rely on network location to tell them who should be trusted.

A person might log into Salesforce from home. A cloud workload might access a production database. A deployment pipeline might hold credentials powerful enough to change an entire environment. An AI agent might read email, update files and call internal APIs. All of them need an identity, and each identity comes with permissions.

The scale has changed dramatically. Palo Alto Networks says machine identities now outnumber human identities by more than 80 to one. Nearly half of those machine identities can carry sensitive or privileged access, according to figures cited around the recent wave of identity-security acquisitions.

Large cybersecurity companies are spending accordingly. Palo Alto Networks completed its roughly $25 billion CyberArk acquisition to add privileged identity protection across humans, machines and AI agents. ServiceNow bought Veza to map who and what can access applications, data and AI systems. CrowdStrike has also been expanding continuous authorization inside Falcon.

Traditional identity systems were largely built to answer a fairly stable question: can this employee access this application? Modern security increasingly has to decide whether a person, workload or agent should still be allowed to perform a particular action at that moment.

If you want more recent data on this point, please see our latest cybersecurity market report.

Are AI agents creating a new kind of cybersecurity risk?

Yes. AI agents are creating a security problem companies have barely had to manage before: software with broad permissions can increasingly decide and act for itself.

A normal application follows predefined logic. An employee can make independent decisions but usually acts at human speed. An AI agent can combine both characteristics: it can reason through a task and then execute actions across connected systems very quickly.

Imagine an agent that can read corporate email, search internal files, open tickets and modify cloud resources. Even when every individual permission is legitimate, manipulating the agent could give an attacker a path across several systems at once.

The market has started reacting unusually quickly. Palo Alto Networks bought Koi to monitor coding agents and other autonomous tools running on endpoints. It then acquired Portkey, whose AI gateway already processes trillions of tokens, to control interactions between models and agents. ServiceNow's Veza acquisition extends access governance to AI agents, while other major security platforms are adding similar controls.

Companies are also taking AI security more seriously internally. The World Economic Forum found that the share of surveyed organizations with a process for assessing AI security jumped from 37% to 64% in a year. That is a very fast increase, although it still leaves more than one-third without such a process.

The hard part is permission. An agent useful enough to automate meaningful work needs access to meaningful systems, which gives security teams less room for error.

Chart showing CrowdStrike’s playbook in the cybersecurity market

This chart, included in our cybersecurity market deck, breaks down CrowdStrike’s playbook in cybersecurity

Is ransomware getting worse or losing its power?

Ransomware is currently hitting more breached organizations, but victims are getting much less willing to pay.

Verizon found ransomware involved in 48% of breaches, up from 44% in its previous dataset. At the same time, 69% of victims refused to pay and the median ransom payment fell from $150,000 to $139,875.

Those numbers tell a more interesting story than simply saying ransomware is “up.” Attack volume is increasing while payment conversion is falling.

Attackers can keep that business attractive by lowering the cost of reaching victims and dividing the work between specialists. Mandiant found that 30% of ransomware incidents it investigated began with a prior compromise. One group gets inside an organization, then another group takes over the access and carries out the ransomware operation.

Mandiant has even observed hand-offs between initial-access groups and follow-on attackers happening in less than 30 seconds. That gives ransomware something resembling an industrial supply chain.

Criminals have also become more aggressive about targeting backups, identity infrastructure and virtualization systems. Taking those recovery options away increases the pressure on companies even when victims have decided they would rather not pay.

Ransomware measure Latest direction
Breaches involving ransomware 44% → 48%
Victims that did not pay 69%
Median ransom payment $150,000 → $139,875
Mandiant ransomware cases beginning with prior compromise 30%

Why are third-party cyberattacks becoming so hard to control?

Third-party cyberattacks are becoming harder to control because companies depend on more external software and infrastructure than their own security teams can directly fix.

A business may have strong controls internally while relying on dozens or hundreds of SaaS providers, cloud services, software libraries, contractors and technology suppliers. Every important connection adds another path an attacker could potentially exploit.

The latest breach data shows how far this has gone. Verizon recorded a sharp increase in third-party involvement in breaches. The World Economic Forum separately found that 65% of large organizations saw third-party and supply-chain vulnerabilities as their biggest obstacle to cyber resilience, up from 54%.

The awkward part is remediation. Verizon's research into third-party cloud exposure found that only 23% of outside organizations fully fixed missing or badly configured multifactor authentication. Half of those MFA issues still took about a month to resolve. Weak-password and permission problems could take many months.

A security team can discover that a supplier has a weakness without having the authority to repair it.

Concentration makes the risk worse. If thousands of companies depend on the same cloud service, identity provider or widely used enterprise product, one successful compromise can spread far beyond the original target.

This is why companies increasingly need continuous visibility into which suppliers can access what, rather than relying only on periodic vendor questionnaires.

Chart showing the projected CAGR of the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates yearly funding for cybersecurity startups

Is cyber fraud becoming a bigger problem than ransomware?

For CEOs, cyber fraud has already overtaken ransomware as the cyber threat they worry about most.

The World Economic Forum found that 77% of respondents had seen cyber-enabled fraud and phishing increase, while 73% said they or someone in their network had personally experienced cyber fraud over the previous year. CEOs ranked fraud and phishing first among cyber concerns. CISOs still put ransomware first.

That disagreement is useful. CISOs naturally focus on attacks that can compromise infrastructure, encrypt systems or expose corporate data. Executives and ordinary employees increasingly encounter a different side of cybercrime through impersonation, payment scams, fake messages and identity theft.

Voice phishing is part of the same shift. As discussed above, Mandiant now sees attackers using live phone conversations often enough for voice phishing to rank ahead of email phishing among the entry methods it investigated.

Generative AI makes these scams much easier to produce at scale. Attackers can personalize messages, translate them naturally and imitate a person's writing or voice without the cost that customized fraud once required.

Cybersecurity, identity protection and fraud prevention are starting to overlap much more closely.

If you want more recent data on this point, please see our latest cybersecurity market report.

Are cybersecurity teams actually getting better at catching hackers?

Yes, companies are catching more intrusions themselves, but the hardest attackers can still remain inside for months.

Mandiant found that organizations internally discovered malicious activity in 52% of its latest investigations, up from 43% in the previous year. External notification moved in the opposite direction, falling from 43% to 34%.

That is genuine progress. Learning about an attack from your own security tools is usually much better than receiving a call from a customer, government agency or another outside organization.

Yet Mandiant's global median dwell time increased from 11 days to 14. The apparent contradiction comes from the kind of attacks security teams are dealing with.

Cyber-espionage operations and North Korean IT-worker cases had a median dwell time of 122 days. These attackers benefit from remaining invisible rather than quickly encrypting systems or making ransom demands. Some campaigns hidden inside edge infrastructure lasted much longer still.

Companies are therefore improving at detecting noisier attacks while the best stealth-focused attackers deliberately hide in places where telemetry is weaker.

Chart comparing business model options for XDR and MDR cybersecurity vendors

This chart, included in our cybersecurity market deck, compares the main business model options for XDR and MDR cybersecurity vendors

Are security operations centers actually becoming autonomous?

Security operations centers are becoming partly autonomous now, especially for repetitive investigation work, but humans still control the decisions capable of causing serious disruption.

Security teams already had automation long before generative AI. The newer agents can handle a longer sequence of work: inspect an alert, gather context from several systems, compare behavior, decide whether an incident looks suspicious and prepare or sometimes execute a response.

That is useful because large companies produce more security alerts than humans can reasonably investigate one by one.

CrowdStrike, Palo Alto Networks, Microsoft and other large vendors are increasingly building agent-style investigation into their security products. The aim is to reduce the amount of routine triage analysts have to do rather than simply generate another dashboard full of alerts.

There is an obvious limit. A security agent capable of disabling accounts, isolating computers or changing network permissions has powerful access of its own.

For now, machines are moving fastest into searching, correlating and initial investigation, while people stay closer to irreversible or high-impact decisions.

Are big cybersecurity platforms squeezing out smaller tools, and why is M&A so aggressive?

Yes. Large cybersecurity platforms are gaining ground because companies are tired of stitching together dozens of security products, and that is one reason acquisitions are running at a record pace.

For years, enterprises bought specialist software for endpoint protection, cloud security, identity, data protection, vulnerability management, analytics and incident response. Some of those tools were excellent individually. Managing the whole stack became the problem.

CrowdStrike's latest financial results show how strong the appetite for consolidation currently is. Annual recurring revenue tied to customers using Falcon Flex passed $2.29 billion and grew 101% year over year. Falcon Flex makes it easier for customers to consume several CrowdStrike modules under a broader commercial agreement rather than buying each product independently.

Palo Alto Networks has spent years pushing the same platform strategy. Identity became much more central after the CyberArk acquisition, while Koi and Portkey extend the platform into AI-agent security. Google has gone even further in cloud security by completing its acquisition of Wiz and keeping Wiz as a multicloud security platform inside Google Cloud.

ServiceNow is joining the same race from another direction. Veza gives it identity and permission visibility, while Armis adds continuous discovery and security across connected assets. ServiceNow can then connect those findings directly to the workflows companies already use to fix problems.

Momentum Cyber counted 219 cybersecurity acquisitions in the first half of the year, putting the market on pace for 438 deals if that rate continued. That would be the highest annual count the firm has ever tracked.

The individual acquisitions reveal where buyers are placing their bets. Google completed Wiz for cloud and AI security. Palo Alto Networks completed CyberArk for identity, Koi for agentic endpoint security and Portkey for AI-agent governance. ServiceNow completed Veza for identity and Armis for asset visibility and exposure management.

Cloud security is being pulled into this consolidation rather than remaining a separate niche. Wiz, for example, maps relationships between vulnerabilities, permissions, workloads and sensitive data so security teams can see which combinations create a genuine attack path. Endpoint, identity and data-security vendors are increasingly trying to build similar relationship maps.

Startup financing keeps supplying the market with potential acquisition targets. Crunchbase counted about $18 billion invested in security and privacy startups during 2025, up roughly 26% from the year before. Another $10.6 billion went into the sector during the first half of 2026.

The quarterly picture is less euphoric. Second-quarter funding fell roughly 30% from both the previous quarter and the year-earlier period, even though cybersecurity remains around historically high funding levels.

Smaller vendors can still win if they discover a new problem early and solve it dramatically better. The difficult position now is the company selling one familiar security feature that an incumbent can bundle into an existing platform.

Recent acquisition What the buyer gains
Google → Wiz Cloud and AI security
Palo Alto Networks → CyberArk Human, machine and AI identity
Palo Alto Networks → Koi Security for endpoint AI agents
Palo Alto Networks → Portkey AI-agent gateway and governance
ServiceNow → Veza and Armis Identity plus asset and exposure visibility

If you want more recent data on this point, please see our latest cybersecurity market report.

Chart illustrating revenue distribution by customer segment in the cybersecurity market

This chart, featured in our cybersecurity market deck, illustrates revenue distribution by customer segment in the cybersecurity market

Is cybersecurity moving from stopping attacks to surviving them?

Yes. Cybersecurity today increasingly assumes that some attacks will get through, so recovery and blast-radius control are becoming part of the core security architecture.

Ransomware makes this easy to see. Nearly half of the breaches in Verizon's latest dataset involved ransomware, while 69% of victims refused to pay. Refusing a ransom is much easier when a company has working backups, can rebuild systems quickly and has prevented the attacker from taking over everything at once.

Attackers know this. Mandiant has seen groups deliberately target backups, virtualization infrastructure and identity services because destroying recovery options puts much more pressure on a victim.

Third-party incidents reinforce the same logic. A company cannot guarantee that every supplier will remain secure. It can limit what those suppliers can reach, isolate critical systems and prepare for the possibility that one external account becomes compromised.

The same thinking explains growing attention to segmentation, privileged-access controls, immutable backups and recovery exercises.

A good security program these days has to answer two questions: how do we stop the attack, and what happens if we fail?

Is geopolitics really changing corporate cybersecurity?

Yes. Geopolitical risk now affects cybersecurity decisions at ordinary large companies, particularly those operating critical infrastructure or across several countries.

The World Economic Forum found that 64% of organizations were already accounting for geopolitically motivated cyberattacks in their risk strategies. Among the largest organizations, 91% had changed their cybersecurity strategy because of geopolitical volatility.

Mandiant's incident work shows a related shift in attacker behavior. Financially motivated groups still represented the largest share of threat clusters it observed, but their share fell from 55% to 41%. Cyber-espionage groups doubled from 8% to 16%.

That mix changes what defenders have to look for. A ransomware operator normally wants the victim to know an intrusion happened because getting paid requires contact. An espionage group may want to stay invisible for months.

It also affects buying decisions. Governments and regulated companies are paying more attention to where security data is stored, who controls critical software and whether important infrastructure depends too heavily on foreign suppliers. Data sovereignty has consequently become a real purchasing issue in parts of Europe and other heavily regulated markets.

Chart showing how identity verification platform technology has evolved over time

This chart, included in our cybersecurity market deck, shows how identity verification platform technology has evolved over time

Does post-quantum cybersecurity really need attention already?

Yes. Post-quantum cybersecurity has moved into implementation even though nobody has yet demonstrated a quantum computer capable of breaking today's widely used public-key encryption at useful scale.

NIST now explicitly tells organizations that the time to migrate has arrived. Its first three finalized post-quantum standards—ML-KEM, ML-DSA and SLH-DSA—are ready for implementation.

That removes one of the main reasons companies previously had for waiting. Security teams can start finding where RSA, elliptic-curve cryptography and other vulnerable algorithms sit inside their infrastructure and plan how to replace them.

This inventory stage can be painfully slow. Cryptography is buried inside hardware, operating systems, certificates, VPNs, authentication systems, applications and software supplied by third parties. NIST says large migrations can historically take 10 to 20 years.

Its current transition work is built around moving systems away from quantum-vulnerable public-key algorithms by roughly the middle of the next decade, with weaker configurations expected to disappear earlier.

There is also the “harvest now, decrypt later” problem. An attacker can steal encrypted information today and keep it until future computing power makes decryption possible. Long-lived secrets therefore face the risk before a cryptographically relevant quantum computer actually exists.

Post-quantum cryptography is nowhere near the most common cybersecurity emergency companies face today. But for infrastructure that takes years to replace or data that must remain secret for a long time, waiting for the quantum threat to become immediate would be far too late.

So what is really changing in cybersecurity now?

Cybersecurity is currently shifting toward identity, software exposure, AI-agent control, platform consolidation and resilience, and the evidence is strong enough to call this a structural change rather than another short-lived security trend.

Attackers have changed where they look for the easiest entry. As seen above, Verizon now puts exploited vulnerabilities ahead of stolen credentials, while Mandiant has seen exploits lead its incident investigations for six straight years. At the same time, voice phishing is rising sharply because attackers can sometimes bypass technical security by convincing the humans responsible for account recovery.

The object being protected has changed too. Employees are only one group of identities inside a modern company. Applications, workloads, APIs, automation tools and AI agents all receive permissions, and some can reach highly sensitive systems. This is why identity has moved to the center of acquisitions involving CyberArk, Veza and other security companies.

AI is accelerating both offense and defense. Criminals can research, personalize and automate attacks much faster. Security teams can investigate enormous amounts of telemetry with agents of their own. The harder problem may eventually be securing autonomous agents themselves, because useful agents need enough permission to take real actions.

The vendor landscape is consolidating around these changes. Google-Wiz, Palo Alto-CyberArk, Palo Alto-Koi, Palo Alto-Portkey, ServiceNow-Veza and ServiceNow-Armis form a surprisingly consistent pattern. Large vendors want cloud context, identity information, asset visibility and AI controls inside fewer platforms. CrowdStrike's latest Falcon Flex numbers show that customers are also spending heavily through this broader platform model.

Finally, companies are getting more realistic about failure. Ransomware remains widespread, suppliers can be compromised, sophisticated espionage groups can stay hidden for months, and no company can patch every vulnerability immediately.

Security today is becoming much more centered on relationships: which identity can reach which system, which vulnerable asset leads to which data, which supplier has which permissions, and which AI agent can perform which action. The vendors that can understand those relationships and control them in real time are increasingly the ones shaping where cybersecurity goes next.

If you want more recent data on this point, please see our latest cybersecurity market report.

Table scoring and prioritizing the main pain points faced by companies in the cybersecurity market

In our cybersecurity market deck, we identify pain points entrepreneurs should prioritize

OUR METHODOLOGY

This analysis asks what is actually changing in cybersecurity now. We broke that broad question into narrower areas: how attackers are getting in, how identity and permissions are changing, where AI is affecting offense and defense, how ransomware and fraud are evolving, what third-party exposure is doing to risk, how detection and security operations are changing, where the vendor market is consolidating, and which longer-term shifts are already influencing security decisions.

We prioritized recent evidence from large breach datasets, frontline incident investigations, enterprise surveys, standards bodies, company financial disclosures and completed acquisitions. Where two independent sources measured similar developments, we compared the direction of the evidence rather than pretending their datasets were directly interchangeable. The close agreement between Verizon and Mandiant on vulnerability exploitation is a good example.

For emerging areas such as AI agents and autonomous security operations, we separated capabilities already visible in real products, incidents and enterprise deployments from more speculative claims about fully autonomous systems. We treated acquisitions, customer spending and product expansion as stronger evidence of where the industry is committing resources than announcements or marketing language on their own.

The final conclusions come from aggregation. We gave the most weight to changes appearing across several independent dimensions at once: actual attacks, enterprise behavior, security architecture, purchasing decisions, capital allocation and standards. That is why identity, software exposure, AI-agent control, platform consolidation and resilience feature so heavily in the final view.

Key sources include Verizon's Data Breach Investigations Report, Mandiant's M-Trends 2026, Mandiant's M-Trends Executive Edition, the World Economic Forum's Global Cybersecurity Outlook 2026, Palo Alto Networks on CyberArk, Palo Alto Networks on Koi, Palo Alto Networks on Portkey, Google on its completed Wiz acquisition, ServiceNow on Veza, ServiceNow on Armis, CrowdStrike's latest financial results, Microsoft's work on the agentic SOC, Momentum Cyber's market review, Crunchbase's cybersecurity funding analysis, and NIST's post-quantum cryptography guidance.

Chart illustrating revenue distribution by region across Europe, Asia, North America, Africa, and South America in the cybersecurity market

This chart, included in our cybersecurity market deck, illustrates revenue distribution by region across Europe, Asia, North America, Africa, and South America in the cybersecurity market

Who is the author of this content?

NEW MARKET PITCH TEAM

We track new markets so founders and investors can move faster

We build living "market pitch" documents for emerging markets: AI, synthetic biology, new proteins, and more. Instead of outdated PDFs or hallucinated LLM answers, our clients get a clean, visual, always-updated view of what's really happening: key players, deals, regulations, and signals that matter. Learn more about us.

Back to blog