Skip to content

Posts from the ‘Analyst Research: Gartner’ Category

Gartner’s $247.5B security forecast makes post-quantum firewall refreshes the only upgrade through 2030

Gartner information security forecast 2024 to 2030 showing spending rising from $192.9 billion to $372.8 billion by software, services, network and consumer security, with six KPI tiles below the chart for 2026 and 2030 totals, new spending, the firewall revision, 2027 firewall growth and securing AI
Security spending climbs to $372.8B by 2030, and post-quantum firewall refreshes drew the only upgrade. Click any chart to open it full size. Source: Gartner (G00862059, Sept. 24, 2026), analysis by softwarestrategiesblog.com.

The 3Q26 Gartner information security forecast raised exactly one growth rate.

Gartner now projects firewall equipment spending to grow 13.4% in 2027 in constant currency, up from the 7.8% in its June forecast. Network security equipment overall rises to 12.8% from 8.7%. Post-quantum cryptography (PQC) is the cause. Many installed firewalls can’t run the new algorithms, which forces early replacement.

Every other business category in the 41-category forecast kept the constant-currency outlook it had 91 days earlier.

Published September 24, the forecast puts worldwide end-user spending at $247.5 billion in 2026, up 13.6% in current U.S. dollars and 12.7% in constant currency.

Spending reaches $372.8 billion by 2030. Gartner frames that as $373 billion and a 10.8% compound annual growth rate in constant currency from 2025 through 2030.

I built this analysis from Gartner’s 3Q26 report (G00862059), the full detailed dataset of 13,489 rows covering 47 countries, 9 regions, 41 categories and 7 years, and a line-by-line comparison against the 2Q26 file Gartner released in June (G00855892).

For the 2Q26 update that first counted securing AI inside the forecast, see Gartner’s $248.2B security forecast makes securing AI the only segment accelerating through 2030.

Each bar in the hero chart stacks four parts of Gartner’s forecast in current U.S. dollars. Navy is business security software, mid-blue is security services, sky blue is network security and light blue is consumer security software. Bold figures above the bars give each year’s total, with Gartner’s constant-currency growth rate in italics.

Six tiles underneath carry the 2026 and 2030 totals, the $125.4 billion in new spending between 2026 and 2030, the 2030 firewall revision in constant currency, the change in Gartner’s 2027 firewall growth forecast and the securing AI trajectory.

Both the 56% software share and the $80.5 billion software tile include consumer security software.

Gartner information security forecast puts 2026 at $247.5B and 2030 at $372.8B

Gartner splits the market into security software, security services and network security. Software keeps gaining share in every year of the forecast.

Each column in the chart below adds to 100% of total spending. Navy is security software, including consumer. Mid-blue is security services and sky blue is network security.

A panel on the right lists each market’s 2024 and 2030 spending and share. I calculated the shares from Gartner’s current-dollar figures.

Security software share rising from 49.6% in 2024 to 55.6% in 2030 while services fall from 39.3% to 33.6%
Share of worldwide information security spending by market, 2024 to 2030, current U.S. dollars. Data from Gartner G00862059 (September 2026). Shares calculated by softwarestrategiesblog.com.

Total market 2026. $247.5 billion, up $29.7 billion from $217.7 billion in 2025.

Security software 2026. $126.9 billion including $9.0 billion of consumer security software. Software reaches $207.4 billion by 2030, 55.6% of all spending, up from 49.6% in 2024.

Security services 2026. $93.5 billion. Services reach $125.4 billion by 2030, but their share falls from 39.3% in 2024 to 33.6%. Constant-currency CAGR is 7.5%, the slowest of the three markets.

Network security 2026. $27.0 billion, growing 15.0% in constant currency. It reaches $40.0 billion by 2030. Gartner raised the 2025 to 2030 CAGR for this market to 10.9%, up from 9.8% in 2Q26.

2026 to 2030 net new spending. $125.4 billion. Security software captures $80.5 billion of it, or 64%. Services add $31.9 billion. Network security adds $13.0 billion.

Gartner’s near-term call is unchanged from June. Growth slows to 11.2% in 2027 in constant currency, then decelerates to 9.6% by 2030.

Gartner names security service edge (SSE), cloud-native application protection platforms (CNAPPs), cloud security posture management, cloud access security brokers, web application firewalls, encryption and enterprise data loss prevention as the areas where 2027 budgets will grow.

It also expects AI trust, risk and security management (AI TRiSM) adoption to rise as generative AI use widens data, application and governance risk.

Post-quantum firewall refreshes drew the only growth upgrade

Gartner’s revision table compares 3Q26 against 2Q26 for all 11 subsegments. Ten of them show 0.0% growth-rate change in every year from 2026 through 2030. Network security equipment is the exception, at +4.1 points in 2027, +1.1 in 2028, +0.4 in 2029 and -0.2 in 2030.

I ran the same comparison across all 41 categories in the detailed files. In constant currency, firewall equipment is the only category Gartner raised.

It gains $1.08 billion in 2027, $1.50 billion in 2028, $1.77 billion in 2029 and $1.84 billion in 2030. The other 40 categories, including consumer security software, match the June file to the dollar in constant currency.

In the chart below, each bar is the firewall equipment increase in constant currency. Because no other category moved, the bars are also the net change for the whole market. The total is unchanged in 2025 and 2026 and turns positive in 2027, when the firewall upgrade starts.

Gartner 3Q26 versus 2Q26 information security forecast revisions in constant currency, showing firewall equipment as the only category raised, by $1.08 billion in 2027 rising to $1.84 billion in 2030, with all other 40 categories unchanged
3Q26 vs. 2Q26 revisions by year in constant currency. Firewall equipment is the only category Gartner raised; the other 40 are unchanged. Data from Gartner G00862059 and G00855892. Revision math by softwarestrategiesblog.com.

Gartner states the cause directly. “Postquantum cryptography (PQC) requirements will drive premature hardware refreshes, initially among government, financial and defense organizations, due to the inability of many existing firewalls to support the processing demands and crypto-agility required through software or firmware updates,” the report says.

Gartner’s timing is specific. The report says “selected products may support algorithms such as FIPS 203/ML-KEM by late 2026.” Broader vendor availability follows in 2027. By 2028, Gartner expects every major firewall vendor to offer PQC-capable platforms.

Gartner expects at least 20% of customers in government, financial services and defense to upgrade in 2027, rising to more than 30% in 2028.

Firewall equipment growth in 2027 raised to 13.4% from 7.8% in Gartner's 2Q26 forecast
Firewall equipment spending and year-over-year growth, 2Q26 vs. 3Q26 forecasts, constant currency. Data from Gartner G00862059 and G00855892. Chart by softwarestrategiesblog.com.

In the top panel, the chart compares firewall equipment spending in Gartner’s 2Q26 forecast (light blue) with 3Q26 (sky blue), in constant currency. Revised values carry dark-blue labels and the 2027 and 2030 increases are marked above the bars.

Year-over-year growth sits in the bottom panel, with June’s forecast dashed and September’s solid. Both lines match through 2026, split in 2027 and converge by 2030.

That shift shows up in one year. In June, Gartner expected firewall equipment growth to fall from 16.1% in 2026 to 7.8% in 2027. Now 2027 growth holds at 13.4%.

Gartner’s revision lifts the 2027 firewall market from $20.8 billion to $21.9 billion in constant currency, and the 2030 market from $25.7 billion to $27.6 billion.

In current dollars firewall equipment reaches $28.6 billion by 2030, still the largest network security category by a wide margin.

Every region gets the upgrade at nearly the same rate. Each region’s 2030 firewall forecast rose between 6.9% and 7.8%. North America takes $834 million of the $1.84 billion. Europe takes $414 million. Together they account for 68%.

Each bar in the next chart is one region’s 2030 firewall revision in constant currency. The label shows the dollar increase, that region’s share of the $1.84 billion total and its revised 2030 firewall market. Sky-blue bars mark North America and Europe. Lighter bars are the other seven regions.

2030 firewall revision by region with North America adding $834 million and Europe $414 million
2030 firewall equipment revision by region, 3Q26 vs. 2Q26, constant currency. Data from Gartner G00862059 and G00855892. Revision math by softwarestrategiesblog.com.

Why a firmware update will not close the gap

Gartner’s argument rests on hardware. Many installed firewalls cannot meet PQC processing and crypto-agility demands through software or firmware updates. The engineering behind that is straightforward. ML-KEM public keys and ciphertexts are larger than the elliptic-curve exchanges they replace, and hybrid key exchange runs both algorithms in the same handshake.

A firewall that inspects encrypted traffic at line rate has to absorb that overhead on every session.

Federal policy points the same way. The National Security Agency’s CNSA 2.0 guidance says traditional networking equipment such as VPNs and routers should “support and prefer CNSA 2.0 by 2026, and exclusively use CNSA 2.0 by 2030.”

According to Keyfactor’s summary of the federal timeline, new National Security System acquisitions are expected to be CNSA 2.0-compliant by default from January 1, 2027, and NIST IR 8547 proposes deprecating RSA, ECDSA, EdDSA and Diffie-Hellman at the 112-bit security level after 2030, with disallowance in 2035.

Vendor roadmaps line up with Gartner’s 2027 inflection. Cisco’s Secure Firewall PQC roadmap targets ML-KEM support in Secure Firewall Threat Defense 10.5 and ASA 9.25 for general availability in late 2026.

ML-DSA signature support is planned for FTD/ASA 11.0 in the second half of 2027, and SLH-DSA support is also planned for 11.0.

Gartner names the sectors with procurement mandates first. That is why the revision lands in 2027 and fades by 2030. Gartner models the refresh as a pull-forward, with 2030 growth now slightly below the June forecast at 6.8% versus 7.0%.

After two increases, the 2026 number dips

I have tracked Gartner’s 2026 security number through four quarterly updates. The 4Q25 update projected $244.2 billion. 1Q26 raised it to $246.2 billion. 2Q26 raised it again to $248.2 billion. 3Q26 is the first update in that run to come in lower, at $247.5 billion.

Gartner 2026 worldwide information security spending as published in each quarterly update: $244.2 billion in 4Q25, $246.2 billion in 1Q26, $248.2 billion in 2Q26 and $247.5 billion in 3Q26
Gartner’s 2026 worldwide information security spending as published in each quarterly update, current U.S. dollars. Data from Gartner 4Q25, 1Q26, 2Q26 (G00855892) and 3Q26 (G00862059) forecasts. The y-axis starts at $240 billion to make the revisions visible.

Each bar in the chart above is the 2026 total as published in one quarterly update. The labels inside the bars show the change from the previous update, at +$2.0 billion, +$2.0 billion and -$0.8 billion.

An axis starting at $240 billion keeps the revisions visible. All four estimates sit within 2% of each other.

The entire $788 million drop is currency, not lower demand. Gartner’s revision table puts the 2026 change at -$788 million in current dollars, with 0.0% change in every 2026 growth rate. In the detailed files, the 2026 total is unchanged in constant currency.

Japan shows the currency effect most clearly. Its 2030 forecast is $1.37 billion lower in current dollars than in June, yet $49 million higher in constant currency, all of it from the firewall increase.

Gartner’s notes flag exchange-rate volatility, Strait of Hormuz disruption expected to continue into 2027, energy prices more than 50% above pre-war levels and the risk that inflation and rising interest rates erode business confidence.

Gartner expects the conflict’s main near-term effect on IT spending to be a rebalancing of sourcing, vendor relationships and regional exposure rather than a material cut.

Where the $125.4 billion in new spending goes

Growth rates show where momentum is. Dollar additions show where budgets actually move. Fifteen of the 41 categories capture 76% of all new spending between 2026 and 2030.

Bars in the next chart show the dollars each of the 15 largest categories adds between 2026 and 2030, colored by market. The indigo line, read on the right axis, is the cumulative share of the $125.4 billion total.

It reaches 15% with the first category, 46% after five, 65% after ten and 76% after fifteen.

Pareto chart of 15 security categories capturing 76% of $125.4 billion in new spending from 2026 to 2030
Net new spending added between 2026 and 2030 by category, current U.S. dollars, with cumulative share. Data from Gartner G00862059. Dollar additions and shares calculated by softwarestrategiesblog.com.

Other security software, including securing AI. +$19.2 billion, from $18.3 billion to $37.5 billion. The largest single dollar gain in the forecast.

Endpoint protection platforms (enterprise). +$11.7 billion, from $21.3 billion to $32.9 billion.

Cloud security posture management. +$9.8 billion, from $6.3 billion to $16.1 billion.

Firewall equipment. +$8.8 billion, from $19.7 billion to $28.6 billion. Post-quantum refreshes make firewalls the fourth-largest source of new dollars, ahead of cloud workload protection.

Cloud workload protection platforms. +$8.2 billion, from $7.5 billion to $15.7 billion.

Managed security operations. +$7.0 billion, from $15.6 billion to $22.7 billion. The largest services gain.

Five categories alone account for $57.8 billion, or 46% of new spending. Three of them sit in cloud security or in other security software, where Gartner counts securing AI. Endpoint protection and the firewall, a category many security leaders had written off as a replacement-cycle business, make up the other two.

The 10 fastest-growing categories through 2030

Ranked by 2025 to 2030 CAGR in constant currency, cloud security takes the top three spots. Gartner’s cloud security subsegment grows from $16.6 billion in 2026 to $38.4 billion by 2030, a 24.1% CAGR and the fastest of the 11 subsegments.

In the chart, bar length is each category’s 2025 to 2030 CAGR in constant currency. The label gives the CAGR and the category’s 2026 and 2030 market size in current dollars.

Navy marks security software and sky blue marks network security. The dashed line is the 10.8% market CAGR, so every bar crosses it by at least 1.2 points.

Ten fastest-growing security categories led by cloud security posture management at a 27.6% CAGR
Top 10 of 41 categories by 2025-2030 CAGR in constant currency, with 2026 and 2030 market sizes in current U.S. dollars. Data from Gartner G00862059. Ranking by softwarestrategiesblog.com.
  1. Cloud security posture management. 27.6% CAGR. $6.3 billion in 2026 to $16.1 billion in 2030.
  2. Cloud access security brokers. 24.3%. $2.8 billion to $6.5 billion.
  3. Cloud workload protection platforms. 21.0%. $7.5 billion to $15.7 billion.
  4. Zero trust network access. 20.9%. $3.0 billion to $6.4 billion. The fastest-growing network security category.
  5. Threat intelligence. 19.0%. $3.1 billion to $6.1 billion.
  6. Consent and preference management. 18.6%. $1.0 billion to $2.0 billion.
  7. Other security software, including securing AI. 18.5%. $18.3 billion to $37.5 billion.
  8. Network detection and response. 12.4%. $2.6 billion to $4.1 billion.
  9. Subject rights request automation. 12.3%. $1.5 billion to $2.3 billion.
  10. Vulnerability assessment. 12.0%. $4.1 billion to $6.4 billion.

Gartner’s own opportunity map plots the 11 subsegments on two axes. The horizontal axis is the 2025 to 2030 CAGR. The vertical axis is dollars added over the same period. Bubble size is the 2030 market. The dashed vertical line marks the overall 10.8% CAGR.

Cloud security and other security software sit alone on the right, the only two subsegments growing faster than 15%. Infrastructure protection is the largest subsegment at $62.7 billion by 2030 and adds the most dollars, about $26 billion, while growing at the market average.

Gartner Figure 1 bubble chart of 2030 information security segment opportunities by size and growth
Figure 1: Information Security Market Opportunities, 2030 Segment Forecast. Source: Gartner, G00862059 (September 2026). Original figure by Gartner. Commentary and independent analysis by softwarestrategiesblog.com. Please click to expand.

Securing AI becomes the largest line item in 2029

Gartner places securing AI inside other security software. The report sizes the market for securing AI ecosystems and AI agents at $3 billion in 2026 and $16 billion by 2030, citing its companion analysis, Forecasting the $16.4 Billion Opportunity in Securing AI.

That makes securing AI about 16% of the other security software category in 2026 and about 43% by 2030, by my calculation.

Of the $19.2 billion the category adds over the period, roughly $13 billion comes from securing AI. The rest of the category grows from about $15.3 billion to about $21.5 billion.

Other security software is also the only category whose growth accelerates every year of the forecast, from 16.3% in 2026 to 20.1% in 2030 in constant currency. It passes enterprise endpoint protection in 2029, $31.1 billion against $30.1 billion, and finishes 2030 at $37.5 billion against $32.9 billion.

By 2030 securing AI alone, at $16 billion, is roughly the size of cloud security posture management ($16.1 billion), managed detection and response ($15.7 billion) or cloud workload protection ($15.7 billion), and larger than SIEM ($11.2 billion).

Gartner’s second AI number is larger. Gartner’s AI-amplified security forecast projects AI-amplified security, meaning existing security products with AI built in, rising from $49 billion in 2026 to $204 billion by 2030.

I covered the full AI-amplified forecast in Gartner’s AI security forecast exposes 162x services growth that still trails software 2 to 1 in new spending.

Each bar in the next chart equals Gartner’s 3Q26 total for that year. The navy segment is Gartner’s AI-amplified security spending. The light-blue segment is everything else in the information security market, calculated by subtracting AI-amplified spending from the total.

Each segment shows its dollars and its share of that year’s total. The indigo note repeats Gartner’s securing AI figures, which sit inside other security software rather than in the AI-amplified total.

Everything else, the light-blue segment, shrinks from $182.9 billion (95%) in 2024 to $168.4 billion (45%) in 2030, even as the total nearly doubles.

AI-amplified security rising from 20% of security spending in 2026 to 55% in 2030
AI-amplified security spending as a share of total information security spending, 2024 to 2030. Data from Gartner, Forecast Analysis: AI-Amplified Security, Worldwide, 2026 (August 2026) and Gartner G00862059 (September 2026). The share combines two Gartner forecasts and is an illustrative softwarestrategiesblog.com calculation, not a Gartner-published ratio.

Set against the 3Q26 totals, AI-amplified spending rises from 20% of the market in 2026 to 39% in 2028, 47% in 2029 and 55% in 2030. Treat that as an illustration of direction, since the two forecasts were built separately.

By the end of the decade, most security dollars will buy products where AI does part of the detection, triage or response work.

Gartner’s report expects AI code security assistants and cybersecurity AI assistants to automate event triage, false-positive reduction and code remediation, and it expects organizations to shift from reactive defense toward continuous threat exposure management (CTEM).

North America is 53% of 2030 spending, and China grows fastest

On the left, the chart shows each region’s 2030 spending in current dollars and its share of the world total. On the right is each region’s 2025 to 2030 CAGR in constant currency. The dashed line marks the 10.8% world rate, and indigo marks China and Japan, the two fastest-growing regions.

2030 security spending by region with North America at $197.7 billion and China growing fastest at 15.4%
2030 information security spending by region in current U.S. dollars and 2025-2030 CAGR in constant currency. Data from Gartner G00862059. Shares calculated by softwarestrategiesblog.com.

North America. $129.2 billion in 2026, 52.2% of the world. $197.7 billion by 2030, 53.0%. 11.4% CAGR. The United States alone reaches $181.1 billion in 2030.

Europe. $64.0 billion in 2026 to $91.3 billion by 2030. 8.6% CAGR, the slowest of the nine regions.

China. $10.7 billion in 2026, up 24.5% in current dollars. $18.7 billion by 2030. 15.4% CAGR, the fastest region.

Japan. $12.6 billion in 2026 to $22.2 billion by 2030. 13.1% CAGR, second fastest, with 17.6% constant-currency growth in 2026.

Emerging markets. Emerging Asia/Pacific grows at 11.1%, Sub-Saharan Africa at 10.5%, Latin America at 9.3%, and the Middle East and North Africa at 9.1%.

At the country level, China (16.2%), Indonesia (13.9%), Japan (13.1%) and Taiwan (12.4%) post the fastest constant-currency CAGRs among the 47 countries in the file.

All 41 categories, ranked

Growth rates spread wide across the full ranking. Seven categories grow faster than 18% a year. Twenty-nine grow below the 10.8% market rate. Two shrink.

Bars rank all 41 categories by 2025 to 2030 CAGR in constant currency. Each bar carries its CAGR, and the right-hand column lists the category’s 2030 market size in current dollars. Click the chart to open it full size.

Navy is security software, mid-blue is security services and sky blue is network security. Indigo marks the two shrinking categories, and a dashed line marks the 10.8% market rate.

All 41 Gartner security categories ranked by CAGR, with network access control and IDPS shrinking
All 41 information security categories ranked by 2025-2030 CAGR in constant currency, with 2030 market size in current U.S. dollars. Data from Gartner G00862059. Ranking by softwarestrategiesblog.com.

Network access control declines at a 17.7% CAGR, from $922 million in 2026 to $382 million in 2030. Intrusion detection and prevention systems fall at 8.3% a year, from $785 million to $548 million.

Both sit inside network security equipment, the same subsegment where firewalls, zero trust network access and network detection and response all grow. My read is that standalone network appliances are being absorbed into firewall platforms and ZTNA, which is consistent with Gartner’s comments on platform consolidation.

User authentication grows at 3.1%, the slowest positive rate in the forecast, while access management grows at 9.2% to $12.1 billion and identity governance and administration at 10.2% to $7.1 billion. My read is that identity spending is shifting from the login event to governing who and what holds access.

A reading note on Gartner’s Table 1

Readers working from the PDF of the Gartner information security forecast should check the growth columns in Table 1. For the last three rows, the growth rates appear offset by one row. The table shows 16.3% to 20.1% growth next to security consulting services and 9.0% to 5.6% next to other security software.

Gartner’s detailed dataset shows the reverse. Other security software accelerates from 16.3% to 20.1%, security consulting services slows from 9.6% to 5.0%, and security professional services slows from 9.0% to 5.6%. The dollar values in the table are correct. Every growth rate in this post comes from the detailed file.

What security leaders should do with this forecast

Inventory every firewall and VPN concentrator for PQC capability now. Gartner’s refresh window opens in 2027 for government, financial services and defense. Organizations that sell into those sectors, or connect to them, will face the same questions in their own procurement and supplier reviews. Ask vendors which appliance generations support ML-KEM in hardware at full inspection throughput, and get the answer in writing.

Budget the refresh as a 2027 and 2028 capital item. Gartner’s revision adds $1.08 billion to 2027 and another $0.43 billion in 2028, then only $0.26 billion and $0.07 billion more in 2029 and 2030. Waiting for 2029 means buying when lead times and pricing reflect peak demand.

Plan for securing AI as a line item, not a pilot. At $16 billion by 2030, securing AI will be comparable in size to CSPM and MDR. Governance gaps are already visible. Gartner’s first AI governance hype cycle found 34% of enterprises govern AI with policies they only partly follow, which I covered in Gartner’s 2026 AI Governance Hype Cycle.

Push cloud security consolidation. CSPM, CASB and CWPP are the three fastest-growing categories, and Gartner lists SSE and CNAPP adoption alongside tool consolidation and cost control as 2027 budget priorities. Consolidating onto those platforms is the most direct way to fund the growth without adding consoles and contracts.

Re-test services contracts against AI-assisted operations. Services share drops from 39.3% to 33.6% by 2030. Managed security operations still adds $7.0 billion, so outsourcing is not shrinking. What changes is the mix of human hours and AI triage inside each contract, and pricing should reflect it.

Frequently asked questions

How much will worldwide information security spending be in 2026? Gartner forecasts $247.5 billion in 2026, up 13.6% in current U.S. dollars and 12.7% in constant currency.

How big will the security market be by 2030? $372.8 billion, which Gartner frames as $373 billion and a 10.8% constant-currency CAGR from 2025 through 2030.

What changed in the 3Q26 Gartner information security forecast? Firewall equipment growth for 2027 rose to 13.4% from 7.8% in constant currency, driven by post-quantum firewall refreshes. Every other business category kept its constant-currency outlook from June.

Which security category grows fastest? Cloud security posture management, at a 27.6% CAGR from 2025 to 2030, reaching $16.1 billion.

How large is the securing AI market? Gartner sizes securing AI at $3 billion in 2026 and $16 billion by 2030, counted inside other security software.

How I built this analysis

All market sizes are Gartner end-user spending from the 3Q26 detailed forecast file (G00862059), in current U.S. dollars unless noted. All growth rates and CAGRs are constant currency, matching Gartner’s reporting convention, with 2024 as the constant-currency base year.

Revisions compare the 3Q26 and 2Q26 (G00855892) detailed files category by category in constant currency, which separates forecast changes from exchange-rate effects. Dollar additions, shares, rankings, regional splits and the AI-amplified ratio are my calculations.

Securing AI figures ($3 billion in 2026, $16 billion by 2030) are Gartner’s, as stated in the 3Q26 report. The AI-amplified figures come from Gartner’s August 2026 AI-amplified security forecast.

Earlier analysis in this series:

For each month’s AI agent attacks, exploited CVEs and breaches with primary sources, see my monthly AI security news briefing.

This post is my personal analysis of Gartner’s information security research and does not represent my employer.

Sources

Gartner’s $239B AI forecast: Agentic workflows take half of GenAI model revenue

Detailed 2024–2030 GenAI revenue chart with annual spending, agentic shares and dollar allocations; intermediate agentic shares are explicitly labeled SSB scenarios.
Gartner publishes the agentic share of GenAI model revenue for 2025 (5%) and 2030 (50%). The 2024 and 2026 to 2029 bars are my estimates and are labeled SSB. By 2030, agentic revenue reaches about $69.6 billion of $139.2 billion. Source: Gartner, G00855897 and G00861842. Chart and analysis by softwarestrategiesblog.com.

Agentic workflows will drive 50% of generative AI model revenue by 2030, up from 5% in 2025. Gartner published that projection on September 17, 2026, in its forecast analysis of the generative AI models market (G00861842). The number changes how every enterprise buyer should read the firm’s $239 billion AI platforms and models forecast.

Multistep reasoning, tool integration, and repeated validation steps multiply the inference events behind every completed business process. Gartner puts the impact at $38 billion in additional spending by 2030 from scaling agentic workflows alone.

Falling inference prices won’t offset it. Cheaper units unlock deeper automation, and deeper automation drives up token volume per task faster than prices fall. Gartner calls this a structural tailwind for GenAI model spending.

That consumption flywheel sits inside a market growing from $39 billion in 2025 to $239 billion by 2030 at a 42.8% compound rate, per Gartner’s June 25 forecast (G00855897). I built this analysis from both Gartner reports and Gartner’s country-level dataset, which covers 1,316 rows across 9 regions and 7 years. For the agentic spending crossover that sets up this post, see Gartner’s $5.95 trillion AI forecast puts the chatbot era on a 2027 deadline (August 5, 2026).

$239 Billion by 2030 and Where It Breaks Down

Dollar figures are current U.S. dollars. Gartner reports growth in constant currency, so its rates won’t always match growth calculated from the dollar totals. The regional CAGRs here are my calculations from Gartner’s dollar data.

Gartner splits the market into two halves. AI platforms grow from $26.3 billion in 2025 to $100 billion by 2030, a 30.0% CAGR. GenAI models grow from $13 billion to $139.2 billion, a 59.9% CAGR.

GenAI models overtake AI platforms in 2027. By 2030, models command 58% of total spending.Four-segment annual AI market breakdown from 2024 to 2030, with exact annual levels, constant-currency growth, dollar additions, and GenAI market share.

Source: Gartner, G00855897. Chart and analysis by softwarestrategiesblog.com.
  • Total market 2026. $64.3 billion, up 60.7% year over year, adding $25 billion in net new spending.
  • AI platforms 2026. $36 billion, growing 34.7%. Data science and ML platforms account for $26.4 billion and app development platforms for $9.5 billion.
  • GenAI models 2026. $28.3 billion, growing 113.5%. Foundation models reach $23.4 billion and DSLMs and specialized models $4.9 billion.
  • 2030 total. $239.2 billion. GenAI models reach $139.2 billion and AI platforms $100 billion.

Where platform and model spending goes

Gartner maps all four segments by 2030 market size and CAGR. Foundation GenAI models reach $105.4 billion at a 55.2% CAGR. DSLMs reach $33.9 billion at 83.4%, the fastest growth rate in the forecast.

AI Platforms and Models Opportunities.
Source: Gartner, AI Platforms and Models Opportunities, G00855897 (June 2026). Commentary by softwarestrategiesblog.com.

Data science and ML platforms carry roughly three times the spending of app development platforms. The ratio rises from about 2.8 to 1 in 2025 to 3.3 to 1 in 2030.

All annual platform subsegment spending, ratios, market shares, and constant-currency growth rates from 2024 to 2030.
Source: Gartner, G00855897. Chart and analysis by softwarestrategiesblog.com.

DSLMs Are the Fastest-Growing Segment in This Forecast

Domain-specific language models and specialized GenAI models grow at an 83.4% CAGR from 2025 to 2030. That outpaces foundation models at 55.2% and AI platforms at 30.0%. The segment goes from $1.6 billion in 2025 to $33.9 billion by 2030.

GenAI Models Spending Segmented Into Foundation Models, and DSLMs and Specialized Models, 2024–2030.
Source: Gartner, GenAI Models Spending Segmented, G00861842 (September 2026). Commentary by softwarestrategiesblog.com.

The share shift tells the structural story. DSLMs were 5.5% of GenAI model spending in 2024. By 2030 they will command 24.3%.

Detailed annual foundation-model and DSLM spending, segment shares, growth rates, and DSLM dollar additions for 2024–2030.
Source: Gartner, G00855897 and G00861842. Chart and analysis by softwarestrategiesblog.com.

Slower percentage growth, larger dollar additions

Gartner’s growth rates for DSLMs decelerate from 452.0% in 2025 to 34.5% in 2030. The dollar additions do the opposite. Each year adds more net new spending than the last, climbing from $1.3 billion to $8.6 billion.

Six annual DSLM growth rates in both constant currency and current dollars, annual dollar additions, and a complete 2024–2030 table.
Source: Gartner, G00855897 and G00861842. Chart and analysis by softwarestrategiesblog.com.

The 2Q26 revisions confirm the direction. Gartner raised its 2030 DSLM forecast by $14.3 billion and cut its 2030 foundation model forecast by $32.1 billion. The pattern holds in every year. DSLM revisions climb from $189 million for 2025 to $1.3 billion for 2026 to $14.3 billion for 2030. Foundation model revisions run negative every year, from $2.7 billion for 2025 to $32.1 billion for 2030.

All 2025–2030 forecast revisions for foundation models, DSLMs, and combined GenAI, with reconstructed first-quarter and second-quarter levels.
Source: Gartner, G00855897, Table 2. Chart and analysis by softwarestrategiesblog.com.

Agentic AI Rewrites Inference Economics

Gartner’s September analysis names agentic workflows as the single largest driver of GenAI model spending growth through 2030. The mechanism runs on volume, not price.

Agentic workflows consume more tokens per completed task than conversational AI. Each autonomous process generates multiple inference events as task complexity rises, demanding advanced reasoning, larger context windows, and repeated validation. I tracked the agentic spending crossover in Gartner forecasts agentic AI will overtake chatbot spending by 2027 (February 16, 2026). The September data shows the trajectory accelerating.

Forecast Driver Impact on GenAI Model Spending.
Source: Gartner, Forecast Driver Impact on GenAI Model Spending, G00861842 (September 2026). Commentary by softwarestrategiesblog.com.

Gartner identifies three forces operating at once. Agentic workflows add $38 billion. Multimodal expansion adds $32 billion. Open-weight substitution and inference internalization remove $25 billion. The net effect grows the revenue pool while shifting where the money lands.

  • Agentic share of GenAI revenue. 5% in 2025, growing to 50% by 2030.
  • Spending impact. $38 billion in additional spending by 2030 from scaling agentic workflows.
  • Token economics. Consumption shifts from model calls per user interaction to model calls per completed business process.
  • Production commitments. 75% of foundation model monetization locked into multiyear commitments by 2030, up from 20% in 2025.

Gartner Forecasts Frontier Revenue Will Concentrate by 2030

Gartner expects two or three suppliers to dominate the GenAI LLM marketplace in North America and Asia/Pacific by 2030. It forecasts the top two vendors will hold 85% of the foundation model revenue pool in those regions. The firm’s 2025 market share data shows Anthropic, OpenAI, and Google together accounted for 63% of enterprise spending.

The concentration thesis goes beyond model quality. Sustained investment in model development, inference capacity, reliability, security, integration, and global distribution creates a cost structure that favors vendors able to keep reinvesting at scale.

Gartner places GenAI in the Trough of Disillusionment in 2026. In that phase, enterprises lean toward frontier models delivered through their incumbent SaaS providers. That preference narrows the field for standalone frontier model companies and sets up a winner-take-all race to become the model provider software vendors choose. For how every credible forecast sizes this market, see my roundup of agentic AI forecasts and market estimates, 2026.

North America Commands 54% of the Market Through 2030

All nine regional forecasts for 2024–2030 with annual dollar amounts, 2030 shares, and current-dollar versus constant-currency CAGRs.
Gartner’s China region includes China, Hong Kong, and Taiwan. Source: Gartner country-level dataset, G00855897. Chart and analysis by softwarestrategiesblog.com.

North America holds near 54% of worldwide spending from 2024 through 2030. Spending rises from $13.2 billion in 2024 to $130 billion in 2030, a 43.4% CAGR from a 2025 base of $21.5 billion.

Detailed 2024–2030 spending trajectories for the U.S., Europe, and Gartner’s China region, with annual growth, world shares, and both CAGR bases.
Source: Gartner, G00855897. Chart and analysis by softwarestrategiesblog.com.

The United States alone reaches $33.1 billion in 2026 and $123 billion by 2030. Gartner’s China region, which includes Hong Kong and Taiwan, grows fastest of the three at a 58.3% CAGR, from $4.1 billion in 2025 to $40.9 billion in 2030. Europe grows at 40.8% to $45.1 billion, with the United Kingdom at $4.8 billion in 2026, France at $2.2 billion, and Germany at $1.9 billion.

  • North America 2030. $130 billion (54.4% share), 43.4% CAGR (2025 to 2030).
  • Europe 2030. $45.1 billion (18.8% share), 40.8% CAGR (2025 to 2030).
  • China region 2030. $40.9 billion (17.1% share), 58.3% CAGR (2025 to 2030).

Open-Weight Models Are Eroding the Paid Revenue Pool

Gartner projects 30% of routine, high-volume enterprise GenAI inference will run on open or enterprise-controlled models by 2030, up from 5% in 2025. That substitution takes $25 billion out of the GenAI model revenue pool by 2030.

Production traffic already shows the split. Vercel’s AI Gateway routes tens of trillions of tokens a month between production applications and AI labs. In August, open-weight models processed 56% of gateway tokens but accounted for 14% of estimated spending, according to Vercel’s September production index. In December 2025, open-weight token share was 7%.

Vercel monthly open-weight shares in December, April, and August; August token and spending split; calculated spend-per-token indices.
Source: Vercel AI Gateway Production Index, September 2026. Chart and analysis by softwarestrategiesblog.com.

The mix is moving fast. In a post Chamath Palihapitiya amplified on September 19, Guillermo Rauch reported a snapshot of 78.4% open-weight and 21.6% closed-weight token volume.

Tokens versus spending on a single day

Vercel’s September 18 daily export shows DeepSeek V4.1 Flash at 59.3% of all token volume. GLM 5.3 Flash took 7.5%, DeepSeek V4 Flash 0731 took 2.7%, and Kimi K3 took 2.5%.

Spending looks different. Anthropic accounted for 64% of estimated gateway spend in August. In July, Anthropic took 65.1% of spend on 30% of token volume, and its average price per token ran 4.4 times the average across every other lab.

The September 18 export makes the gap concrete. Claude Opus 4.8 accounted for 13.7% of estimated spend, Claude Opus 5 for 9.0%, Claude Sonnet 5 for 5.5%, and Claude Sonnet 4.6 for 4.3%. DeepSeek V4.1 Flash, with 59.3% of tokens, accounted for 5.1% of spend.

Complete daily Vercel rankings with ten named models plus Other for both token volume and spending, and four-model spending-per-token comparisons.
Source: Vercel AI Gateway dated export, CC BY 4.0. Chart and analysis by softwarestrategiesblog.com.

Vercel’s data covers traffic routed through its gateway, not the whole market. Its spend figures are estimates based on list prices. It shows the same pattern Gartner forecasts but doesn’t prove Gartner’s $25 billion number.

For buyers, the lesson is to budget for workload mix, not token volume alone. The models moving the most tokens aren’t the ones capturing the most spend. Route suitable workloads to lower-cost models and save premium models for work that justifies the price.

Palihapitiya went further on September 19, predicting the top three models would be open source within 12 months. He named Nebius, Iren, Baseten, Together, and Fireworks as the clouds he expects to benefit. That’s his forecast, not something the usage data establishes.

What This Means for Enterprise Buyers

Gartner reports AI budgets are getting a harder look, and money is moving to providers that can prove their value on cost, speed, and reliability. Here are five takeaways for leaders making AI platform and model decisions over the next 12 months. For how security spending fits this picture, see Gartner’s $248.9B security forecast makes securing AI the only segment accelerating through 2030 (July 6, 2026).

  1. Build for model routing, not model loyalty. The market is fragmenting by workload. Enterprises locked into a single provider risk overpaying for tasks a smaller, specialized model handles at the required quality. The DSLM forecast makes the case for evaluating specialized models before assuming every task needs a frontier model.
  2. Budget for agentic inference volumes. Agentic workflows consume far more tokens per completed task than conversational AI. A budget sized for chatbot-level consumption won’t survive production agentic workloads.
  3. Evaluate open-weight alternatives for routine workloads. Gartner expects 30% of high-volume enterprise inference to shift to open or enterprise-controlled models by 2030. The Vercel data shows that shift underway. Start identifying which production workloads can move now.
  4. Watch the consolidation timeline. If frontier revenue concentrates in North America and Asia/Pacific as Gartner forecasts, assess provider resilience and migration options now.
  5. Demand platform-level governance and cost attribution. The AI platform market reaches $100 billion by 2030 because enterprises need orchestration, evaluation, cost visibility, and policy enforcement. For more on the governance gap, see Gartner’s $244.2B security forecast shows enterprises spend 17x more on AI tools than securing AI itself (March 24, 2026).

Bottom line

Gartner’s forecast puts a number on the tension running through every enterprise AI budget. The market nearly quadruples from $64 billion in 2026 to $239 billion by 2030. Agentic workflows drive half of GenAI model revenue by the end of that window.

Open-weight models absorb a growing share of token volume while frontier providers keep the lion’s share of spend. The $38 billion agentic addition and the $25 billion revenue pool reduction pull the market in two directions at once.

Enterprises that build for model routing, budget for agentic consumption, and negotiate multiyear commitments with the surviving frontier providers will be better positioned in 2030. Enterprises that treat AI spending as a single-vendor procurement decision will not.

Related on Software Strategies Blog

This post is my personal analysis of Gartner’s AI platforms, models, and generative AI research and does not represent my employer.

Sources

Gartner’s $5.95 trillion AI forecast puts the chatbot era on a 2027 deadline

Spending on the chatbots and assistants embedded in enterprise software peaks at $272.6 billion in 2027 and then shrinks every year through 2030. Gartner buried that projection inside the 2Q26 update of its worldwide AI spending forecast, published July 24, and it matters more than the headline total. By 2030, embedded chatbot spending falls back to $205.8 billion, a hair above its 2025 starting point.

Embedded agenticAI takes the money instead, growing from $88.2 billion in 2025 to $1 trillion by 2030, an 11.4x expansion inside a single software category.

None of that slows the topline. Worldwide AI spending reaches $2.67 trillion in 2026, up 49.5% from 2025, on its way to $5.95 trillion by 2030. The figure Gartner published in May was $2.59 trillion for this year. Ninety days later, the client-facing number runs $74.8 billion higher, and the firm added $496.8 billion to its comparable 2025 through 2030 outlook in a single quarter.

Four tables below show where the money lands, which segments stall, and what Gartner changed its mind about between April and July.

Where $5.95 trillion lands

Infrastructure stays the biggest line through 2030 at $2.79 trillion, even as its share of total spending slides from 55% in 2025 to 46.9% at the end of the window. AI-optimized servers alone reach $981.7 billion by 2030, a 3.4x jump from 2025, and AI processing semiconductors add another $656.4 billion. O

One caution before quoting the total anywhere. Gartner’s note flags the forecast as a view across the whole AI value chain, so the chip and the server it ships inside both get counted. Read $5.95 trillion as the size of the AI economy, not as net end-user budgets.

Devices carry more of the infrastructure number than most readers expect. Business and consumer AI devices combine for $904.4 billion in 2030, and $647.4 billion of that is consumer hardware, the AI PCs and phones landing in shopping carts rather than data centers.

Growth flattens fast after next year. Total spending rises 49% in 2026 and 36% in 2027, then steps down to 21%, 18% and 15% through 2030, while infrastructure decelerates from 51% growth this year to 9% at the end of the forecast.

Of the $883.8 billion in net-new AI spending arriving in 2026, infrastructure absorbs $502.5 billion, or 57 cents of every new dollar. The shape of the curve says the buildout peaks now and software inherits the growth.

Farther down the board, AI cybersecurity at $220.9 billion and AI agents and assistants at $219.9 billion finish 2030 within $1 billion of each other. Gartner created the agents category only this quarter.

Agentic AI crosses $1 trillion inside enterprise software

Gartner rebuilt its segmentation this quarter, splitting cross-functional and consumer agents out of AI software and adding consumer agents to the forecast for the first time. The new structure exposes a replacement cycle the old rollup hid. Inside enterprise software, agentic AI overtakes chatbots in 2027, the same year chatbot spending tops out, and from that peak to 2030 the embedded chatbot line surrenders $66.8 billion.

Cross-functional agents, the ones that work across software from multiple vendors, start from a base of zero. Gartner books $347 million for cross-functional agentic AI in 2026 and $78.1 billion in 2030, a number it raised this quarter on the thesis that these agents begin cannibalizing traditional SaaS by decade’s end. The ceiling matters as much as the curve. Against $1.21 trillion in total 2030 AI software spending, $78.1 billion says the incumbents hold the decade, because data access, integration complexity and execution reliability hold the category back from serious SaaS competition until 2030, in Gartner’s read.

The buy-versus-build verdict is just as lopsided. Agent builder platforms, the tooling for constructing your own agents, reach only $12.6 billion by 2030, so embedded agentic AI outspends them nearly 80 to 1. The first production agent most companies run will ship inside software they already own. Gartner describes exactly that race, with vendors across software categories embedding agentic AI to defend their installed bases against cross-functional challengers.

Consumer agents barely register yet in dollar terms. Gartner carries $26.9 million for consumer agentic AI in 2026, then $17.7 billion in 2027 as paid consumer agents arrive at scale, building to $51.8 billion by 2030. Adding consumer agents and assistants lifted Gartner’s 2030 total by $133 billion. For how these agent numbers stack against other analyst estimates, see my roundup of agentic AI forecasts and market estimates, 2026.

AI security expands 8.5x and splits in two

AI cybersecurity grows from $25.9 billion in 2025 to $220.9 billion in 2030, an 8.5x expansion at a 53.5% compound rate. Spending in the category grew 140% in 2025, and Gartner models another 98% jump this year. AI cybersecurity and AI data were also the only two markets left completely untouched between the 1Q26 and 2Q26 forecasts, which makes security the steadiest conviction in the entire model. For the standalone security spending outlook, see my breakdown of Gartner’s 2Q26 information security forecast.

Two markets move at different speeds inside the category. AI-amplified security, meaning AI capability inside security tooling, carries the volume and reaches $204.5 billion by 2030. Securing AI, the discipline of protecting AI systems themselves, runs smaller and faster, from $1.5 billion in 2025 to $16.4 billion in 2030 at a 60.4% compound rate.

Set the security numbers against the agent forecast and an exposure gap opens. The 2030 outlook has enterprises running $1.08 trillion of embedded and cross-functional agentic software while spending $16.4 billion to secure AI systems, roughly $66 of agentic software for every $1 of securing-AI budget. AI observability and governance tooling adds just $3.9 billion more. A software wave that large riding on a security ratio that thin is the budget argument CISOs should be starting now.

The fastest growth goes to whatever cuts the bill

Rank every segment by compound growth and one pattern jumps out, because the fastest-growing lines are the ones that make AI cheaper. Synthetic data generation leads the entire forecast at a 142.5% compound rate, expanding 84x from $146 million in 2025 to $12.2 billion in 2030. AI-ready datasets, the licensed real-data alternative, peak at $583 million in 2029 and then decline, leaving synthetic data outselling licensed data 22 to 1 by 2030. Gartner is forecasting the substitution of purchased data itself.

Domain-specific language models tell the same cost story at larger scale. DSLMs and specialized models grow 210% in 2026 and compound at 84.5% through 2030, rising from 12.2% of all model spend to 24.3%. Cost pressure also explains the strangest revision in the update. Gartner cut $57.8 billion in cumulative dollars from its generative AI model forecast while raising the segment’s 2026 growth rate from 110% to 117%, which nets out to more deployments running on cheaper models and smaller checks. Arunasree Cheparthi, a senior principal research analyst at Gartner and one of the forecast’s authors, said in the firm’s July 20 platforms and models announcement that spending “is shifting toward providers who can demonstrate clear value.”

What Gartner changed in 90 days

Between the April forecast and this one, Gartner added $500.8 billion to AI infrastructure across the 2025 through 2030 window, the largest revision in the update, and did it while flagging memory-related price increases. The note calls infrastructure demand inelastic to that pricing pressure, because hyperscalers keep buying AI-optimized servers on the conviction that model capabilities improve through 2030.

Software took the other side of the trade. AI software gained $191.9 billion and application development platforms picked up $10.7 billion. Gartner lifted the 2026 app-dev growth rate from 28% to 39% as enterprises build custom AI applications and demand usage tracking to prove the spend. The cuts land on everything that resembles consulting or plumbing. AI services lost $80.7 billion across the window, with every single year revised down, and platforms for data science and machine learning lost $68.2 billion, including an 8% cut to 2027 alone.

The services cut hides a structural shift rather than a retreat. Gartner still sizes AI services at $1.25 trillion in 2030, but the growth belongs to indirect services, which compound at 34.5% and pass direct, consulting-led engagements in 2028. Direct AI services compound at 15.7%, less than half the indirect rate. Buyers are routing transformation budgets through software and cloud purchases instead of billable hours.

Three dates to plan against

2027 is the year chatbot spending tops out and agentic AI takes over inside enterprise software, which gives any vendor still selling assistant-branded features through the end of next year to ride what growth remains. By 2028, indirect services pass consulting-led engagements and infrastructure growth drops to 15%, so the buildout stops flattering everyone’s numbers. And 2030 arrives with $1.08 trillion of agentic software guarded by $16.4 billion of securing-AI spend. The first two dates decide where the money goes, and the third decides what happens when it arrives unprotected.

This post is my personal reflection on Gartner’s AI spending research from an industry analyst perspective. It does not represent my employer.

Source: Gartner, Forecast: AI Spending, Worldwide, 2025-2030, 2Q26, Kay Arnott, Jon Erensen, Amarendra, Adrian O’Connell, Arunasree Cheparthi, Naresh Singh, Peter Middleton, Hardeep Singh, Shailendra Upadhyay, Rishi Padhi, 24 July 2026, G00855896.

Roundup of agentic AI forecasts and market estimates, 2026

Roundup of agentic AI forecasts and market estimates, 2026

Agentic AI spending is projected to reach $201.9 billion in 2026 (Gartner), overtaking chatbot spending by 2027.  Four independent firms size the standalone market at $7–8 billion with 40%+ CAGRs. But adoption lags the money: only 23% of organizations have scaled agent deployments (McKinsey), and 40% of projects face cancellation by 2027 (Gartner).

Fortune Business Insights projects $7.29 billion in 2025, reaching $139.19 billion by 2034 at 40.5% CAGR. Precedence Research sizes it at $7.55 billion in 2025, growing to $199.05 billion by 2034 at 43.84% CAGR. MarketsandMarkets puts the figure at $7.06 billion in 2025, reaching $93.20 billion by 2032 at 44.6% CAGR. Deloitte’s TMT Predictions 2025 estimates $8.5 billion in 2026, growing to $35 to $45 billion by 2030.

Every major forecast agrees on direction. None agrees on scale. The standalone agentic AI market lands between $7 billion and $8.5 billion. Gartner’s broader view, counting agentic capabilities embedded across enterprise software, reaches $201.9 billion in 2026. That 25x gap is not a contradiction. It is a measurement problem, and the takeaways below reflect both realities. The following are the key takeaways from agentic AI forecasts published in 2026 so far:

Key takeaways

Worldwide AI spending will reach $2.52 trillion in 2026, growing 44% year-over-year. That number jumped roughly $500 billion from the September forecast, which had pegged the market just above $2 trillion. Infrastructure takes $1.37 trillion, 54% of total spend. AI software follows at $452.5 billion, up 60%. AI services add $588.6 billion. AI-optimized servers alone account for $421.6 billion, growing to 49%. Gartner expects spending to grow by another 30% in 2027 and surpass $3 trillion. I have tracked these forecasts through multiple iterations. The revisions keep going in one direction. Source: Gartner press release, January 15, 2026

 

Gartner projects $4.71 trillion in global AI spending by 2029. The fastest growth isn’t in infrastructure. Synthetic data generation leads all categories at 178% CAGR, followed by the broader AI Data market at 155%. Agentic AI compounds at 119%, expanding from $15 billion to $753 billion by 2029. AI Infrastructure, the largest category by dollars, grows at just 29%. The money is following the bottlenecks. Source:  Gartner 4Q25: $4.71T AI Market Proves Agentic AI and Data Readiness Are the Only Race That Matters, Software Strategies Blog, January 22, 2026 Link: https://softwarestrategiesblog.com/2026/01/22/gartner-4q25-agentic-ai-data-readiness-4-71t-market/

 

The AI cybersecurity market is predicted to hit $51.3 billion in 2026, nearly doubling from $25.9 billion in 2025. But the category masks a structural imbalance. AI-amplified security, where AI defends the enterprise, captures 94.5% of spending at $48.5 billion. Securing AI, where the enterprise defends its own AI systems, gets $2.8 billion. Enterprises are investing 17x more in using AI as a security tool than in protecting the AI itself. Both sub-segments grow at similar CAGRs (74% vs. 72%), which means the dollar gap widens every year. By 2029, AI-amplified security reaches $160.4 billion, while securing AI hits just $11.6 billion. One is a tool. The other is the thing that needs protecting. Source: Gartner Forecasts Agentic AI Will Overtake Chatbot Spending by 2027, Software Strategies Blog, February 16, 2026 Link: https://softwarestrategiesblog.com/2026/02/16/gartner-forecasts-agentic-ai-overtakes-chatbot-spending-2027/

 

AI Data sits alone in the upper-right quadrant of Gartner’s spending map, compounding at 155% CAGR with 277% growth in 2026. AI Cybersecurity and AI Models cluster above 67% CAGR. AI Infrastructure anchors the chart as the largest bubble, but grows at just 29%. Global AI spending reaches $1.8 trillion in 2025 and $4.7 trillion by 2029. The acceleration is not in compute. It is in data readiness, security architecture, and agentic capabilities. By 2028, software with agentic capabilities crosses 50% of total application software spend, up from 2% in 2024. Non-agentic software spending starts declining in 2027. Source:Data Readiness and Security Are Driving AI’s $4.7 Trillion Run, Software Strategies Blog, December 22, 2025 Link: https://softwarestrategiesblog.com/2025/12/22/data-readiness-security-driving-ai-4-7-trillion/

Gartner’s AI spending forecast reaches $2.53 trillion in 2026 and $4.71 trillion by 2029. Eight markets. One pattern. AI Infrastructure dominates absolute dollars at $1.37 trillion in 2026 but grows at just 29% CAGR. AI Data, the smallest segment at $3.1 billion, compounds at 155%. AI Cybersecurity nearly doubles to $51.3 billion. AI Software hits $452.5 billion, growing 60% year-over-year as agentic capabilities reshape the category. The growth rates tell you where the bottlenecks are breaking. Source: Data Readiness and Security Are Driving AI’s $4.7 Trillion Run, Software Strategies Blog, December 22, 2025 Link: https://softwarestrategiesblog.com/2025/12/22/data-readiness-security-driving-ai-4-7-trillion/

Nearly nine in ten organizations now use AI in at least one business function, up from 78% a year ago, but nearly two-thirds have not begun scaling it across the enterprise. Only 6% qualify as high performers where AI contributes more than 5% to EBIT. Sixty-two percent of organizations are at least experimenting with AI agents, yet in no individual business function are more than 10% scaling them. High performers are three times more likely than peers to fundamentally redesign workflows and three times more likely to have senior leaders demonstrating ownership of AI initiatives. More than one-third of high performers commit over 20% of their digital budgets to AI, and about three-quarters have reached the scaling phase, versus one-third of other organizations. Source: McKinsey / QuantumBlack, The state of AI in 2025: Agents, innovation, and transformation, November 2025

Valued at $638.23 billion in 2024, the global AI market is projected to reach $3,680.47 billion by 2034, expanding to a CAGR of 19.20%. North America holds 31.80% market share. The software segment dominates at 51.40%, while machine learning leads by technology at 36.70%. Healthcare is expected to record the highest CAGR of 36.50% across end-use segments. Among regions, Asia-Pacific is expected to grow at 19.8% CAGR from 2025 to 2034, with AI projected to add up to $3 trillion to the region’s GDP by 2030, driven by national AI strategies in China, India, and Japan. Source: Precedence Research, AI Market Size, Growth & Trends, September 2025

Nearly $7 trillion. That’s the capital outlay data centers will require by 2030 to keep pace with demand for compute power. Of that, $5.2 trillion goes toward AI-ready facilities and $1.5 trillion toward traditional IT workloads. Global demand for data center capacity could almost triple by 2030, with about 70% of new demand coming from AI workloads. Three investment scenarios range from $3.7 trillion (constrained demand) to $7.9 trillion (accelerated demand, adding 205 incremental GW). The 60% majority of investment—$3.1 trillion—flows to technology developers and designers producing chips and computing hardware. Source: McKinsey, The cost of compute: A $7 trillion race to scale data centers, April 2025

Inference already consumed half of all AI compute in 2025. That number will grow to two-thirds in 2026 and reach 75% of all AI compute needs by 2030. Global data center capacity is projected to nearly double from 103 gigawatts to 200 GW by 2030, yet U.S. data centers already face a capacity shortfall exceeding 11 GW, with the cumulative gap expected to exceed 40 GW by 2028. North American data center capacity alone will increase eightfold, from 5.6 GW in 2024 to 44 GW by 2030. Operators are increasingly deploying edge facilities closer to end users to reduce latency as inference-dominated workloads drive a fundamental redesign of data center architectures. Source: Avid Solutions, 13 Data Center Growth Projections, January 2026

 

Generative AI could add the equivalent of $2.6 trillion to $4.4 trillion annually to the global economy, increasing the projected impact of all AI by 15 to 40%. About 75% of the value falls across four areas: customer operations, marketing and sales, software engineering, and R&D. Half of today’s work activities could be automated between 2030 and 2060, with a midpoint in 2045—roughly a decade earlier than previously estimated. When embedding effects in existing software are included, the total economic benefit rises to $6.1 trillion to $7.9 trillion annually. Source: McKinsey, The economic potential of generative AI, June 2023

The global AI market hit $294.16 billion in 2025 and is projected to grow to $2,480.05 billion by 2034, at a CAGR of 26.60%. The Banking, financial services and insurance (BFSI) segment holds 18.90% market share, while healthcare is expected to record the highest CAGR of 36.50%. In the U.S. alone, the AI market was estimated at $146.09 billion in 2024 and is predicted to reach $851.46 billion by 2034. The number of AI companies funded globally in 2024 totaled 2,049, with U.S.-funded companies accounting for 1,143, signaling strong investor confidence in the sector’s expansion potential. Source: Fortune Business Insights, AI Market Size, Growth & Trends by 2034

Big Tech’s AI capex hit $405 billion in 2025, up from a $250 billion estimate at the start of the year. Sell-side analysts have underestimated AI spending every quarter for two years running. A decade ago, Big Tech’s trailing-twelve-month capex was $24 billion—15x less than today. AI data center costs are projected at $3 trillion to $8 trillion, with gigawatt capacity expected to grow 3.5x by 2030. Source: IO Fund, Big Tech’s $405B Bet, November 2025

The global AI market was valued at $371.71 billion in 2025 and is projected to reach $2,407.02 billion by 2032, growing at a CAGR of 30.6%. Hyperscalers accounted for 53% of chip purchases in 2023, spurring 156% market growth from 2023 to 2024. While demand from hyperscalers is expected to moderate, growth of 41% is still forecast from 2025 to 2026. Enterprises are moving from cloud reliance to in-house AI infrastructure investments, particularly for cost-effective inference solutions, as edge AI gains traction through AI-enabled PCs and mobile devices. Source: Markets and Markets, AI Market Report 2025-2032

At $602 billion projected for 2026, hyperscaler capex has entered uncharted territory. Amazon, Microsoft, Google, and Meta will each exceed $100 billion individually, pushing capital intensity to 45-57% of revenue. Total hyperscaler capex from 2025-2027 is projected at $1.15 trillion, more than double the $477 billion spent from 2022-2024. Morgan Stanley and JP Morgan suggest the technology sector may need to issue $1.5 trillion in new debt over the next few years to finance AI infrastructure construction. The sheer scale of debt issuance mirrors patterns seen during the fiber-optic buildout of the late 1990s. Source: Multiple sources compiled by Introl, January 2026

The number of software companies using consumption-based pricing more than doubled between 2015 and 2024, as AI introduces new variable costs that make traditional perpetual licenses obsolete. SaaS remains dominant, but the next wave is outcome-aligned pricing that scales with actual AI usage. Software businesses that successfully adopt consumption-based pricing aligned with usage and outcomes may be better positioned to capture AI-driven value and differentiate themselves in a rapidly evolving market where the cost of each AI inference adds a new variable to the P&L. Source: McKinsey, AI adjusts the software bill, January 27, 2026

Data center capacity needs for AI and non-AI workloads could almost triple by 2030, with AI capacity increasing 3.5 times and making up roughly 70% of the total. Under a continued-momentum scenario, total capacity demand rises from 82 GW in 2025 to 219 GW by 2030, with incremental AI capacity ranging from 13 GW in 2025 to 31 GW in 2030, totaling 124 GW of new AI capacity. Non-AI workloads grow from 38 GW to 64 GW over the same period. Average power densities in AI-ready data centers have more than doubled in just two years and are expected to rise nearly four times by 2027. Source: McKinsey, Data center demands (Week in Charts), May 2025

U.S. data-center spending exceeded half a trillion dollars in 2025. The U.S. and China drove a massive expansion in AI-related computing capacity through 2024, with the U.S. pulling further ahead in the first half of 2025. AI-related trade accounted for nearly half of all merchandise trade growth in that period, despite representing only 15% of total trade volume. The infrastructure boom is reshaping international commerce, with surging demand for servers, graphics cards, and related components essential to AI training and inference now a dominant force in global supply chains. Source: Federal Reserve Board, FEDS Notes: The Global Trade Effects of the AI Infrastructure Boom, February 2026

The generative AI market is expanding from $71.36 billion in 2025 to $890.59 billion by 2032, at a CAGR of 43.4%. North America accounted for 43.05% of global revenue in 2025. Text remains the dominant data modality due to its foundational role in enterprise workflows, while the services segment is gaining traction for scalability and cost-effectiveness. Foundation model delivery platforms verticalized adoption across industries, and the rapid scaling of AI-native infrastructure are the three key forces driving the market as of 2025. The 43.4% CAGR makes this one of the fastest-expanding technology subsegments in history. Source: MarketsandMarkets, Generative AI Market Report, Global Forecast to 2032

The generative AI market reached $37.89 billion in 2025 and is projected to hit $1.2 trillion by 2035, a 37% compound annual growth rate. Transformer architectures account for more than 42% of technology revenue, driven by text-to-image and text-to-video applications. Software captures over 65% of total revenue. North America holds 41% of the market. Asia-Pacific is the fastest-growing region at a 27.6% CAGR through 2035. Financial services is expected to lead sector growth at 36.4%, fueled by fraud detection, risk management, and regulatory compliance demands. Source: Precedence Research, Generative AI Market Size, January 2026

GPUs captured 89% of AI processor revenue in 2025, but FPGA and ASIC alternatives are growing at a 17% CAGR through 2031. Hardware accounted for 68% of all AI infrastructure spending last year. North America held 40% of the market, backed by $52.7 billion in CHIPS Act grants and hyperscalers operating roughly 60% of global AI compute capacity. Liquid cooling reached 18% of AI server racks as power densities crossed 100 kilowatts per rack, the threshold where air cooling fails. Asia-Pacific is projected to grow fastest at 16.4% CAGR through 2031, driven by China’s $50 billion semiconductor fund and $15 billion in hyperscaler commitments across India. Source: Mordor Intelligence, AI Infrastructure Market Size, Trends & Growth Drivers 2031

Nearly one in four Americans has already made a purchase through AI. Morgan Stanley Research estimates agentic shoppers will drive $190 billion to $385 billion in U.S. e-commerce spending by 2030, capturing 10% to 20% of market share. Grocery and consumer packaged goods lead adoption, with 49% of AI-assisted buyers transacting in those categories. AI shopping agent users are projected to reach 126 million by 2030, up from near zero today, while traditional e-commerce users decline from 264 million to 149 million over the same period. Source: Morgan Stanley Research, Agentic Commerce Market Impact Outlook, December 2025 Link: https://www.morganstanley.com/insights/articles/agentic-commerce-market-impact-outlook

Gartner forecasts agentic AI will overtake chatbot spending by 2027

 

Agentic AI spending grows 141% in 2026 to $201.9 billion. By 2027, it will overtake chatbot and assistant spending for the first time. Then chatbot spending starts declining. I’ve tracked Gartner’s AI forecasts through multiple iterations. This crossover changes where security risk concentrates for every security professional reading this.

The crossover is in the segment-level data tables of Gartner’s Forecast: AI Spending, Worldwide, 2024–2029, 4Q25. The headline number is well known: $2.53 trillion in 2026, $4.7 trillion by 2029 at 33% CAGR. The segment breakdowns are not. Eight markets. Nineteen sub-segments. The sub-segment data tells a different story than the top line.

This is Gartner’s first dedicated AI spending forecast, and I’ve been waiting for it. Gartner states that comparisons to previous AI estimates are not meaningful because the scope widened, adding AI cybersecurity, agentic AI as a separate segment from chatbots, AI data technology, and expanded infrastructure coverage. Gartner writes, “This is the first iteration of the forecast on AI spending that Gartner has published. Gartner has significantly expanded and modified its AI forecast coverage. Spending comparisons to previous iterations are therefore not meaningful as the scope has widened. This includes both coverage of new markets and broadened definitions of the types of AI spending that are reflected in some market segments.”

Forrester’s Predictions 2026: Cybersecurity and Risk arrives at the same warning from a different angle: an agentic AI deployment will cause a publicly disclosed breach in 2026, leading to employee dismissals. Two firms. Same conclusion. The spending data explains why.

CAPTION: Total worldwide AI spending, 2024–2029. $1.14T to $4.71T. 33% CAGR. Growth decelerates from 54% (2025) to 16% (2029) as the base expands. Source: Gartner Forecast: AI Spending, 4Q25 (December 2025).

The full market breakdown

AI infrastructure dominates at $1.37 trillion, 54% of the total. AI software follows at $452.5 billion, growing 60% year-over-year. AI services add $588.6 billion. AI cybersecurity and AI data are the outliers: growing at 74% and 155% CAGR, respectively, rates that dwarf everything else in the forecast.

Source: Gartner Forecast: AI Spending, Worldwide, 2024–2029, 4Q25 (December 19, 2025). All figures in U.S. dollars. CAGR = 2024–2029. Gartner press release: https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026

Infrastructure takes 54% of every AI dollar

AI-optimized servers alone account for $421.6 billion in 2026, growing to $699.7 billion by 2029. AI processing semiconductors add $289.4 billion. AI-optimized IaaS hits $38.3 billion at 71% CAGR, the fastest-growing infrastructure sub-segment. AI network fabric, a new category in this forecast, reaches $28.7 billion.

Infrastructure’s share drops from 54% to 48% by 2029 as software and services scale faster. The capital-intensive build-out phase is not over.

The agentic crossover nobody is planning for

Gartner now splits AI software into chatbots/assistants and agentic AI. The spending lines cross in 2027.

CAPTION: Agentic AI spending overtakes chatbot/assistant spending by 2027. Chatbots peak at $264.7B then decline. Agentic AI grows at 119% CAGR to $752.7B by 2029. Source: Gartner Forecast: AI Spending, 4Q25 (December 2025). AI Software segment, Table 1-2.

Source: Gartner Forecast: AI Spending, 4Q25 (December 2025). CAGR = 2024–2029.

Chatbots talk to people. Agents act on behalf of people. They access databases, execute transactions, chain multi-step workflows without human approval at each step. The attack surface has moved well beyond conversation windows. Agents are autonomous decision engines with production access.

Gartner’s Top Trends in Cybersecurity for 2026 lists agentic AI oversight as the number-one trend. Forrester’s Predictions 2026: Cybersecurity and Risk goes further: an agentic AI deployment will cause a public breach this year, and employees will lose their jobs for it. Forrester senior analyst Paddy Harrington calls it a “cascade of failures,” not a single point of error. Two analyst firms. Different methodologies. Same conclusion. Security strategies built for chatbot-era risk have a shelf life measured in quarters, not years.

AI cybersecurity is two markets, not one

Gartner created a dedicated AI cybersecurity market for the first time in this forecast. It nearly doubles in 2026. But the category name hides a structural split that matters more than the growth rate.

Source: Gartner Forecast: AI Spending, 4Q25 (December 2025). CAGR = 2024–2029.

Two sub-segments. Two very different problems.

AI-amplified security ($48.5 billion, 94.5% of the market) is what most enterprises mean when they say “AI cybersecurity.” This is AI working for your security team. Machine learning models that analyze network traffic patterns and flag anomalies faster than a human analyst can. Natural language processing that reads threat intelligence feeds and correlates indicators of compromise across millions of data points in seconds. Automated triage systems that prioritize which of the 11,000 daily alerts actually need a human response. AI-powered endpoint detection that identifies malware variants that signature-based tools miss. Behavioral analytics that learn what normal looks like for each user and flag deviations. Security orchestration platforms that automate incident response playbooks, reducing mean time to containment from hours to minutes.

This is the category where enterprises are spending aggressively. And for good reason. The math on analyst workloads demands it. Security operations centers are drowning in alerts, facing a persistent talent shortage, and defending attack surfaces that expand every quarter. AI-amplified tools address all three.

Securing AI ($2.8 billion, 5.5% of the market) is the other problem. AI-amplified security puts AI to work defending the enterprise. Securing AI reverses the relationship entirely — defending the AI itself. Protecting the models, the training data, the inference pipelines, the agent workflows, and the decision outputs that enterprises are deploying at $2.53 trillion in 2026. Prompt injection defenses. Model access controls. Training data poisoning detection. Output validation. Agent permission boundaries. Audit trails for autonomous decisions.

The distinction matters because they protect different things. AI-amplified security protects your enterprise using AI. Securing AI protects the AI itself. One is a tool. The other is the thing that needs protecting. Enterprises are investing 17 times more in the tool than in protecting the thing the tool runs on.

Shadow AI is not just employees using ChatGPT

Gartner names the mechanism driving AI software growth: vendor push. Software providers are integrating GenAI and agentic AI into existing product lines. AI software grows from $143 billion in 2024 to $981 billion by 2029 at 47% CAGR.

For CISOs, vendor push changes the equation. AI capabilities are being added to tools already in production. Often without explicit procurement decisions. The AI features embedded in your existing ERP, CRM, and developer platforms may already exceed what your security team has inventoried. Shadow AI is vendors activating AI inside products you already own.

The smallest market with the biggest growth rate

AI data technology: $134 million in 2024. $3.1 billion in 2026. $14.6 billion by 2029. The 155% CAGR is the highest in the forecast. The 277% year-over-year growth in 2026 is the steepest single-year jump of any segment.

Synthetic data generation is the standout sub-segment, going from $41 million to $6.8 billion by 2029. Gartner is direct: enterprises need AI-ready data with proper labeling, quality checks, and compliance. For organizations running AI projects on ungoverned data, the readiness gap compounds every quarter.

CAPTION: AI spending markets ranked by five-year CAGR. AI Data (155%) and AI Cybersecurity (74%) lead. AI Infrastructure is the largest by absolute dollars. Source: Gartner Forecast: AI Spending, 4Q25 (December 2025).

Indirect services are the governance blind spot

Indirect AI services, where AI is a supporting component in a larger project, grow from $78.4 billion in 2024 to $255.9 billion in 2026 at 50% CAGR. Direct AI services hit $332.8 billion. By 2028, indirect overtakes direct.

Indirect AI means capabilities embedded in consulting and implementation projects that procurement does not classify as AI. If you cannot see it in your AI inventory, you cannot govern it.

Servers are a bigger market than AI software

AI-optimized servers alone hit $421.6 billion in 2026, just below the entire AI software market at $452.5 billion. By 2029, servers reach $699.7 billion. Cloud providers are building capacity for AI workloads that have not materialized at scale. The infrastructure is ahead of the applications.

The enterprise agentic stack is showing up in spending data

Gartner’s DSML segment includes a dedicated agent builder platforms sub-segment at $5.0 billion in 2026, reaching $13.7 billion by 2029. AI observability and governance adds $1.3 billion, growing to $4.0 billion. The xOps sub-segment (MLOps, DataOps, ModelOps) is the largest at $15.0 billion.

Together, these form the tooling layer for building, monitoring, and governing agents in production. The enterprise agentic stack is materializing in the spending data. Most organizations have not formalized it in their architecture.

The numbers that belong in your next board deck

If you take one thing from this forecast into a budget meeting, take this table. I built it from the raw spreadsheet data. Six years of AI deployment spending next to AI security spending. The bottom row is the one that gets the questions.

Source: Gartner Forecast: AI Spending, 4Q25 (December 2025). All percentages derived from Gartner’s published data tables (Tables 1-1 and 1-2).

The ratio improves over time. Securing AI goes from 0.07% in 2024 to 0.25% by 2029. But watch the absolute numbers. In 2029, enterprises will spend $4.71 trillion deploying AI and $11.6 billion securing it. The percentage gets better. The dollar gap gets wider. Every year, the market grows its way into a larger exposure.

Where I think this lands

Three things worth tracking from the segment data:

The agentic crossover. Agentic AI overtakes chatbot spending in 2027. The enterprise risk profile shifts from conversational data leakage to autonomous decision-making at scale. CISOs who build agentic governance frameworks in 2026 position themselves before the inflection. The spending curve says the window is narrowing.

The securing-AI gap. $2.8 billion to protect AI systems in a year when $2.53 trillion deploys them. Enterprises are enthusiastic about using AI for defense. The investment in defending AI itself has not caught up.

Data readiness is the bottleneck. The 277% growth in AI data spending confirms that AI without governed data delivers diminished returns. Data classification investments directly enable or constrain AI ROI.

If your security budget is growing at 12% and AI deployment inside your enterprise is growing at 44%, the gap compounds every quarter. You cannot close it by holding steady. The organizations getting this right treat AI security as a proportion of AI deployment, not a fixed line item.

—

Sources

Gartner, Forecast: AI Spending, Worldwide, 2024–2029, 4Q25, December 19, 2025, ID G00843179.

Gartner press release (January 15, 2026): https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026

Gartner, Top Trends in Cybersecurity for 2026 (February 5, 2026): https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026

Gartner, IT Spending Forecast 1Q26 (February 3, 2026): https://www.gartner.com/en/newsroom/press-releases/2026-02-03-gartner-forecasts-worldwide-it-spending-to-grow-10-point-8-percent-in-2026-totaling-6-point-15-trillion-dollars

Forrester, Predictions 2026: Cybersecurity and Risk (October 2025): https://www.forrester.com/blogs/predictions-2026-cybersecurity-and-risk/

All dollar figures in U.S. dollars. Growth rates and CAGR derived from Gartner’s published data tables (Tables 1-1 and 1-2).

15 fastest-growing security categories in Gartner’s 3Q25 Information Security Forecast

15 fastest-growing security categories in Gartner's 3Q25 Information Security Forecast

Cloud Security Posture Management is growing at a 31.23% CAGR. Zero Trust Network Access at 23.25%. Threat Intelligence at 22.17%. The overall security market? Just 10.55%. Fifteen categories are outpacing the market by two to three times, collectively capturing $106 billion in new spending by 2029. Enterprise security budgets aren’t just expanding. They’re being redirected.

And the driver? Brutally simple.

Gartner estimates 99% of cloud security failures through 2025 will be the customer’s fault, primarily due to misconfigurations. Organizations are responding by investing aggressively in technologies that automate what humans simply can’t manage manually across hundreds of cloud accounts, thousands of APIs, and millions of potential attack vectors.

What these growth rates say about Gartner’s view of the market 

These fifteen categories represent $106.4 billion in new spending by 2029, growing from today’s baseline. What do they have in common? Three characteristics that explain why enterprises are pouring money into them:

  • Automation at Scale. Every high-growth category automates processes that break when done manually, whether it’s scanning cloud configurations, managing consent across jurisdictions, or detecting behavioral anomalies in network traffic. There’s no other way to keep pace.
  • Proactive vs. Reactive. These technologies prevent problems rather than clean up after them. CSPM catches misconfigurations before breaches. ZTNA eliminates the attack surface that VPNs create. Tokenization protects data even if systems are compromised. Security teams are finally getting ahead of the threat curve instead of playing catch-up.
  • Measurable ROI. IBM’s 2025 Cost of a Data Breach Report shows organizations using AI and automation extensively save $1.9 million per breach and reduce breach lifecycle by 80 days. With U.S. breach costs hitting $10.22 million, these investments pay for themselves with a single prevented incident.

15 fastest-growing security categories in Gartner's 3Q25 Information Security Forecast

The 15 categories reshaping security architecture

1. Cloud Security Posture Management (CSPM) | 31.23% CAGR | $2.5B → $13.0B

CSPM tools continuously scan infrastructure across AWS, Azure, and Google Cloud. With 82% of misconfigurations caused by human error and organizations managing 100+ cloud accounts, CSPM automates what’s mathematically impossible to do manually. The market will reach $15.6 billion by 2032.

2. Cloud Access Security Brokers (CASB) | 25.82% CAGR | $1.5B → $5.8B

Here’s a reality check. Enterprises average 112 SaaS applications, but shadow IT, or unauthorized apps, accounts for 42% of all applications. IT remains unaware of one-third of the apps on its networks. The damage? 65% of shadow IT companies suffer data loss, and 52% experience breaches. CASBs transform this chaos into visibility and control.

3. Zero Trust Network Access (ZTNA) | 23.25% CAGR | $1.6B → $5.6B

ZTNA kills the VPN model. Instead of network access, it provides application-specific connections verified for every request. Gartner predicts 70% of new remote access deployments will use ZTNA by 2025. With 65% of companies planning to replace VPNs, this shift represents a wholesale rethinking of secure access. The perimeter-based model is dying. Good riddance.

4. Cloud Workload Protection Platforms (CWPP) | 22.78% CAGR | $3.9B → $13.5B

CWPP platforms secure everything from traditional VMs to containers that exist for milliseconds. Legacy endpoint security can’t protect ephemeral containers or serverless functions—it wasn’t designed for workloads that appear and disappear in seconds. The shift to microservices demands purpose-built security.

5. Consent and Preference Management | 22.39% CAGR | $0.5B → $1.7B

GDPR fines reached €5.88 billion by January 2025, according to the DLA Piper GDPR Fines and Data Breach Survey. California’s CCPA penalties continue climbing; the California Privacy Protection Agency fined Todd Snyder $345,178 for inadequate opt-out and privacy request processes. Manual handling can’t meet regulatory deadlines. Automation prevents massive fines.

6. Threat Intelligence | 22.17% CAGR | $1.8B → $5.8B

IBM data shows threat intelligence reduces detection and escalation costs by $1.63 million while cutting incidents by 30%. Modern platforms aggregate data about bad actors and vulnerabilities, transforming raw threat data into automated responses across security stacks. The days of threat feeds sitting in dashboards, unused, are over.

7. Subject Rights Request Automation | 16.53% CAGR | $0.8B → $2.1B

When users demand “delete my data,” these platforms automate the process across all systems. Manual handling doesn’t scale, not when you’re managing requests across multiple jurisdictions with different requirements and tight deadlines.

8. Tokenization | 14.26% CAGR | $1.0B → $2.2B

Tokenization replaces sensitive data with meaningless tokens that can’t be mathematically reversed. Why the urgency now? NIST standardized quantum-resistant algorithms, including ML-KEM (formerly CRYSTALS-Kyber), in August 2024. Organizations are preparing for quantum threats expected within five to ten years.

9. Network Detection and Response (NDR) | 14.05% CAGR | $1.6B → $3.5B

NDR platforms use AI to establish behavioral baselines and detect anomalies signaling compromise. Here’s the mindset shift: rather than hoping to prevent all attacks, innovative organizations invest in rapid detection that minimizes damage when sophisticated attackers inevitably get through. Prevention isn’t enough anymore.

10. Vulnerability Assessment | 13.98% CAGR | $2.6B → $5.7B

Cloud infrastructure changes constantly. Quarterly scans are obsolete before they finish. Modern platforms provide continuous scanning in CI/CD pipelines, prioritizing based on real-world exploit data. DevOps teams deploying daily need vulnerability detection that keeps pace. Anything less is theater.

11. Endpoint Protection Platform (EPP) | 13.61% CAGR | $13.5B → $29.1B

The largest category doubles to $29.1 billion as ransomware attacks surge. According to Cyble analysis cited by TechTarget, U.S. ransomware attacks increased by 149% year-over-year in the first five weeks of 2025. Manufacturing led targets with 638 attacks in 2023, per Statista data compiled by Fortinet. Next-gen EPP uses behavioral analytics to stop ransomware before encryption begins—catching what traditional antivirus misses.

12. Secure Web Gateway (SWG) | 13.26% CAGR | $3.3B → $7.0B

Malicious sites appear and disappear in hours. Cloud-delivered SWGs update threat intelligence in real-time, protecting remote workers wherever they connect. Integration with ZTNA creates comprehensive security that follows users across devices and locations. The old perimeter? It no longer exists.

13. Web Application Firewalls (WAF) | 11.93% CAGR | $2.0B → $3.8B

Organizations expose hundreds of APIs, each a potential attack vector. Traditional network firewalls can’t inspect application-layer attacks. Modern WAFs use machine learning to distinguish legitimate users from attackers without blocking customers. Getting that balance right is harder than it sounds.

14. Encryption | 11.90% CAGR | $1.0B → $2.0B

NIST’s standardization of quantum-resistant algorithms signals urgency. Attackers already practice “harvest now, decrypt later”—collecting encrypted data for future quantum decryption. Organizations must transition to post-quantum cryptography now, as full integration takes years. This isn’t theoretical risk anymore.

15. Security Information and Event Management (SIEM) | 11.74% CAGR | $5.8B → $11.3B

AI transforms SIEM from reactive to proactive. Organizations using AI-powered automation save $1.9 million per breach, according to IBM’s newsroom. Machine learning models identify attack patterns and detect zero-day threats before signatures exist, turning security operations into a competitive advantage.

The Investment Thesis behind the numbers

These growth rates reflect three converging realities:

  • Cloud Complexity Is Exponential. With 79% of organizations using multiple cloud providers and managing hundreds of accounts, manual security is mathematically impossible. The 31.23% CAGR for CSPM isn’t optimism, it’s survival.
  • AI Changes Everything. Shadow AI breaches cost $4.63 million, $670,000 more than standard incidents. But AI also powers the defense, with automated security tools reducing breach lifecycles by 80 days. The same technology that creates vulnerabilities offers the best defense.
  • Compliance Costs Are Skyrocketing. Between GDPR, CCPA, and emerging regulations, manual compliance is a liability that grows daily. Automation platforms turn regulatory requirements into competitive advantages.

The Bottom Line

The organizations winning this race aren’t those with the most significant security budgets; they’re those investing in the right categories at the right time. These fifteen segments aren’t just growing fast; they’re defining what modern security architecture looks like.

The message from Gartner’s data is unambiguous: security spending is shifting from reactive to proactive, from manual to automated, from perimeter-based to zero-trust. Organizations still relying on legacy approaches aren’t just falling behind; they’re accepting risks that the market has already priced as unacceptable.

Source: Gartner Information Security Forecast 3Q25 Update (Document G00839334), showing overall market growth from $215.8B (2025) to $322.2B (2029) at 10.55% CAGR

2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth

2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth

Demand for TensorFlow expertise is one of the leading indicators of machine learning and AI adoption globally. Kaggle’s State of Data Science and Machine Learning 2020 Survey found that TensorFlow is the second most used machine learning framework today, with 50.5% of respondents currently using it.

TensorFlow expertise continues to be one of the most marketable machine learning and AI skills in 2021, making it a reliable leading indicator of technology adoption. In 2020, there were on average 4,134 LinkedIn open positions that required TensorFlow expertise soaring to 8,414 open LinkedIn positions this year in the U.S. alone. Globally, demand for TensorFlow expertise has doubled from 12,172 open positions in 2020 to 26,958 available jobs on LinkedIn today.  

Demand for machine learning expertise, as reflected in LinkedIn open positions, also shows strong growth. Increasing from 44,864 available jobs in 2020 to 78,372 in 2021 in the U.S. alone, organizations continue to staff up to support new initiatives quickly. Globally, LinkedIn’s open positions requiring machine-learning expertise grew from 98,371 in 2020 to 191,749 in 2021.

Market forecasts and projections also reflect strong growth for AI and machine learning spending globally for the long term. The following are key takeaways from the machine learning market forecasts from the last year include the following:

  • Forrester says the AI market will be defined and grow within four software segments, with AI maker platforms growing the fastest, reaching $13 billion by 2025, helping drive the market to $37 billion by 2025. Forrester is defining the four AI software segments as follows: AI maker platforms for general-purpose AI algorithms and data sets; AI facilitator platforms for specific AI functions like computer vision; AI-centric applications and middleware tools built around AI for specialized tasks like medical diagnosis; and AI-infused applications and middleware tools that differentiate through advanced use of AI in an existing app or tool category.  New AI-centric apps built on AI functions such as medical diagnosis and risk detection solutions will be the second-largest market, valued at nearly $10 billion by 2025. Source: Sizing The AI Software Market: Not As Big As Investors Expect But Still $37 Billion By 2025, December 10, 2020.
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • IDC predicts worldwide revenues for the artificial intelligence (AI) market, including software, hardware, and services, will grow from $327.5 billion in 2021 to $554.3 billion in 2024, attaining a five-year compound annual growth rate (CAGR) of 17.5%. IDC further predicts that the AI Software Platforms market will be the strongest, with a five-year CAGR of 32.7%. The slowest will be AI System Infrastructure Software, with a five-year CAGR of 13.7% while accounting for roughly 36% of AI software revenues. IDC found that among the three technology categories, software represented 88% of the total AI market revenues in 2020. It’s the slowest growing category with a five-year CAGR of 17.3%. AI Applications took the largest share of revenue within the AI software category at 50% in 2020. Source: IDC Forecasts Improved Growth for Global AI Market in 2021, February 23, 2021
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • AI projects continued to accelerate in 2020 in the healthcare, bioscience, manufacturing, financial services, and supply chain sectors despite economic & social uncertainty. Two dominant themes emerge from the combination of 30 diverse AI technologies in this year’s Hype Cycle. The first theme is the democratization or broader adoption of AI across organizations. The greater the democratization of AI, the greater the importance of developers and DevOps to create enterprise-grade applications. The second theme is the industrialization of AI platforms. Reusability, scalability, safety, and responsible use of AI and AI governance are the catalysts contributing to the second theme.  The Gartner Hype Cycle for Artificial Intelligence, 2020, is shown below: Source: Software Strategies Blog, What’s New In Gartner’s Hype Cycle For AI, 2020, October 20, 2020.
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • Capgemini finds that Life Sciences, Retail, Consumer Products, and Automotive industries lead in the percentage of successfully deployed AI use cases today. Life Sciences leads all interviewed industries to AI maturity, with 27% of companies saying they have deployed use cases in production and at scale. Retail is also above the industry average of 13% of companies that have deployed AI in production at scale, with 21% of companies in the industry has adopted AI successfully.  17% of companies in the Consumer Products and Automotive industries now have AI in production, running at scale. Source: Capgemini, Making AI Work For You, (The AI-powered enterprise: Unlocking the potential of AI at scale) 2021
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • Between 2018 and 2020, there’s been a 76% increase in sales professionals using AI-based apps and tools. Salesforce’s latest State of Sales survey found that 57% of high-performance sales organizations use AI today. High-performing sales organizations are 2.8x more likely to use AI than their peers. High-performing sales organizations rely on AI to gain new insights into customer needs, improve forecast accuracy, gain more significant visibility of rep activity, improve competitive analysis, and more. Source: Salesforce Research, 4th Edition, State of Sales, June 2020
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • While 24% of companies are currently using AI for recruitment, that number is expected to grow, with 56% reporting they plan to adopt AI next year. In addition, Sage’s recent survey of 500 senior HR and people leaders finds adoption of AI as an enabling technology for talent management increasing. AI is proving effective for evaluating job candidates for potential, improving virtual recruiting events, and reducing biased language in job descriptions. It’s also proving effective in helping to improve career planning and mobility. Josh Bersin, a noted HR industry analyst, educator, and technologist, recently published an interesting report on this area titled The Rise of the Talent Intelligence Platform. Leaders in the field of Talent Intelligence Platforms include Eightfold.ai. Grounded in Equal Opportunity Algorithms, the Eightfold® Talent Intelligence Platform uses deep-learning AI to help each person understand their career potential, and each enterprise understands the potential of their workforce.Sources: VentureBeat, 8 ways AI is transforming talent management in 2021, March 25, 2021, and Eightfold.ai.
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • 84% of marketers are using AI-based apps and platforms today, up from 28% in 2018. Salesforce Research’s latest State of Marketing survey finds that high-performing marketers use an average of seven different applications or use cases. The familiarity high-performing marketers have with AI is a primary factor in 52% of them predicting they will increase their use of AI-based apps in the future. Source: Salesforce Research, 6th Edition, State of Marketing, June 2020
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • Marketing and Sales lead revenue increases due to AI adoption, yet lag behind other departments on cost savings.  40% of the organizations McKinsey interviewed see between a 6 and 10% increase in revenue from adopting AI in their marketing and sales departments. Adopting Ai to reduce costs delivers the best manufacturing and supply chain management results based on the McKinsey survey results. Revenue increases and cost reductions based on AI adoption are shown in the graphic below. Source: McKinsey & Company, The state of AI in 2020, November 17, 2020
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • AI sees the most significant adoption by marketers working in $500M to $1B companies, with conversational AI for customer service as the most dominant. Businesses with between $500M to $1B lead all other revenue categories in the number and depth of AI adoption cases. Just over 52% of small businesses with sales of $25M or less use AI for predictive analytics for customer insights. It’s interesting to note that small companies are the leaders in AI spending, at 38.1%, to improve marketing ROI by optimizing marketing content and timing. Source: The CMO Survey: Highlights and Insights Report, February 2019. Duke University, Deloitte, and American Marketing Association. (71 pp., PDF, free, no opt-in).
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • Three out of four companies are fast-tracking automation initiatives, including AI.  Bain & Company found that executives would like to use AI to reduce costs and acquire new customers, but they’re uncertain about the ROI and cannot find the talent or solutions they need. Bain research conducted in 2019 found that 90% of tech executives view AI and machine learning as priorities that they should be incorporating into their product lines and businesses. But nearly as many (87%) also said they were not satisfied with their Company’s current approach to AI. Source: Bain & Company, Will the Pandemic Accelerate Adoption of Artificial Intelligence? May 26, 2020
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • Gartner’s Magic Quadrant for Data Science and Machine Learning Platforms predicts a continued glut of exciting innovations and visionary roadmaps from competing vendors. Competitors in the Data Science and Machine Learning (DSML) market focus on innovation and rapid product innovation over pure execution. Gartner said key areas of differentiation include UI, augmented DSML (AutoML), MLOps, performance and scalability, hybrid and multicloud support, XAI, and cutting-edge use cases and techniques (such as deep learning, large-scale IoT, and reinforcement learning). Please see my recent article on VentureBeat, Gartner’s 2021 Magic Quadrant cites ‘glut of innovation’ in data science and ML, March 14, 2021.
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
  • 76% of enterprises are prioritizing AI & machine Learning In 2021 IT Budgets. Algorithmia’s survey finds that six in ten (64%) organizations say AI and ML initiatives’ priorities have increased relative to other IT priorities in the last twelve months. Algorithmia’s survey from last summer found that enterprises began doubling down on AI & ML spending last year. The pandemic created a new sense of urgency regarding getting AI and ML projects completed, a key point made by CIOs across the financial services and tech sectors last year during interviews for comparable research studies. Source: Algorithmia’s Third Annual Survey, 2021 Enterprise Trends in Machine Learning.
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth
2021 Roundup Of AI And Machine Learning Market Forecasts Show Strong Growth

Sources of Market Data on Machine Learning:

What’s New In Gartner’s Hype Cycle For AI, 2020

What's New In Gartner's Hype Cycle For AI, 2020
AI is starting to deliver on its potential and its benefits for businesses are becoming a reality.

  • 47% of artificial intelligence (AI) investments were unchanged since the start of the pandemic and 30% of organizations plan to increase their AI investments, according to a recent Gartner poll.
  • 30% of CEOs own AI initiatives in their organizations and regularly redefine resources, reporting structures and systems to ensure success.
  • AI projects continue to accelerate this year in healthcare, bioscience, manufacturing, financial services and supply chain sectors despite greater economic & social uncertainty.
  • Five new technology categories are included in this year’s Hype Cycle for AI, including small data, generative AI, composite AI, responsible AI and things as customers.

These and many other new insights are from the Gartner Hype Cycle for Artificial Intelligence, 2020, published on July 27th of this year and provided in the recent article, 2 Megatrends Dominate the Gartner Hype Cycle for Artificial Intelligence, 2020.  Two dominant themes emerge from the combination of 30 diverse AI technologies in this year’s Hype Cycle. The first theme is the democratization or broader adoption of AI across organizations. The greater the democratization of AI, the greater the importance of developers and DevOps to create enterprise-grade applications. The second theme is the industrialization of AI platforms. Reusability, scalability, safety and responsible use of AI and AI governance are the catalysts contributing to the second theme.  The Gartner Hype Cycle for Artificial Intelligence, 2020, is shown below:

What's New In Gartner's Hype Cycle For AI, 2020
Smarter with Gartner, 2 Megatrends Dominate the Gartner Hype Cycle for Artificial Intelligence, 2020.

Details Of What’s New In Gartner’s Hype Cycle for Artificial Intelligence, 2020

  • Chatbots are projected to see over a 100% increase in their adoption rates in the next two to five years and are the leading AI use cases in enterprises today.  Gartner revised the bots’ penetration rate from a range of 5% to 20% last year to 20% to 50% this year. Gartner points to chatbot’s successful adoption as the face of AI today and the technology’s contributions to streamlining automated, touchless customer interactions aimed at keeping customers and employees safe. Bot vendors to watch include Amazon Web Services (AWS), Cognigy, Google, IBM, Microsoft, NTT DOCOMO, Oracle, Rasa and Rulai.
  • GPU Accelerators are the nearest-term technology to mainstream adoption and are predicted to deliver a high level of benefit according to Gartner’s’ Priority Matrix for AI, 2020. Gartner predicts GPU Accelerators will see a 100% improvement in adoption in two to five years, increasing from 5% to 20% adoption last year to 20% to 50% this year. Gartner advises its clients that GPU-accelerated Computing can deliver extreme performance for highly parallel compute-intensive workloads in HPC, DNN training and inferencing. GPU computing is also available as a cloud service. According to the Hype Cycle, it may be economical for applications where utilization is low, but the urgency of completion is high.
  • AI-based minimum viable products and accelerated AI development cycles are replacing pilot projects due to the pandemic across Gartner’s client base. Before the pandemic, pilot projects’ success or failure was, for the most part, dependent on if a project had an executive sponsor and how much influence they had. Gartner clients are wisely moving to minimum viable product and accelerating AI development to get results quickly in the pandemic. Gartner recommends projects involving Natural Language Processing (NLP), machine learning, chatbots and computer vision to be prioritized above other AI initiatives. They’re also recommending organizations look at insight engines’ potential to deliver value across a business.
  • Artificial General Intelligence (AGI) lacks commercial viability today and organizations need to focus instead on more narrowly focused AI use cases to get results for their business. Gartner warns there’s a lot of hype surrounding AGI and organizations would be best to ignore vendors’ claims of having commercial-grade products or platforms ready today with this technology. A better AI deployment strategy is to consider the full scope of technologies on the Hype Cycle and choose those delivering proven financial value to the organizations adopting them.
  • Small Data is now a category in the Hype Cycle for AI for the first time. Gartner defines this technology as a series of techniques that enable organizations to manage production models that are more resilient and adapt to major world events like the pandemic or future disruptions. These techniques are ideal for AI problems where there are no big datasets available.
  • Generative AI is the second new technology category added to this year’s Hype Cycle for the first time. It’s defined as various machine learning (ML) methods that learn a representation of artifacts from the data and generate brand-new, completely original, realistic artifacts that preserve a likeness to the training data, not repeat it.
  • Gartner sees potential for Composite AI helping its enterprise clients and has included it as the third new category in this year’s Hype Cycle. Composite AI refers to the combined application of different AI techniques to improve learning efficiency, increase the level of “common sense,” and ultimately to much more efficiently solve a wider range of business problems.
  • Concentrating on the ethical and social aspects of AI, Gartner recently defined the category Responsible AI as an umbrella term that’s included as the fourth category in the Hype Cycle for AI. Responsible AI is defined as a strategic term that encompasses the many aspects of making the right business and ethical choices when adopting AI that organizations often address independently. These include business and societal value, risk, trust, transparency, fairness, bias mitigation, explainability, accountability, safety, privacy and regulatory compliance.
  • The exponential gains in accuracy, price/performance, low power consumption and Internet of Things sensors that collect AI model data have to lead to a new category called Things as Customers, as the fifth new category this year.  Gartner defines things as Customers as a smart device or machine or that obtains goods or services in exchange for payment. Examples include virtual personal assistants, smart appliances, connected cars and IoT-enabled factory equipment.
  • Thirteen technologies have either been removed, re-classified, or moved to other Hype Cycles compared to last year.  Gartner has chosen to remove VPA-enabled wireless speakers from all Hype Cycles this year. AI developer toolkits are now part of the AI developer and teaching kits category. AI PaaS is now part of AI cloud services. Gartner chose to move AI-related C&SI services, AutoML, Explainable AI (also now part of the Responsible AI category in 2020), graph analytics and Reinforcement Learning to the Hype Cycle for Data Science and Machine Learning, 2020. Conversational User Interfaces, Speech Recognition and Virtual Assistants are now part of the Hype Cycle for Natural Language Technologies, 2020. Gartner has also chosen to move Quantum computing to the Hype Cycle for Compute Infrastructure, 2020. Robotic process automation software is now removed from the Hype Cycle for AI, as Gartner mentions the technology in several other Hype Cycles.

Why Cybersecurity Needs To Focus More On Customer Endpoints

Why Cybersecurity Needs To Focus More On Customer Endpoints

  • Cloud-based endpoint protection platforms (EPP) are proliferating across enterprises today as CIOs and CISOs prioritize greater resiliency in their endpoint security strategies going into 2020.
  • Gartner predicts that Global Information Security and Risk Management end-user spending is forecast to grow at a five-year CAGR of 9.2% to reach $174.5 billion in 2022, with approximately $50B spent on endpoint security.
  • Endpoint security tools are 24% of all IT security spending, and by 2020 global IT security spending will reach $128B according to Morgan Stanley Research.
  • 70% of all breaches still originate at endpoints, despite the increased IT spending on this threat surface, according to IDC.

There’s a surge of activity happening right now in enterprises that are prioritizing more resiliency in their endpoint security strategies going into 2020. The factors motivating CIOs, CISOs, IT, and Practice Directors to prioritize endpoint resiliency include more effective asset management based on real-time data while securing and ensuring every endpoint can heal itself using designed-in regenerative software at the BIOS level of every device. CIOs say the real-time monitoring helps reduce asset management operating expense, a big plus many of them appreciate give their tight budgets. Sean Maxwell, Chief Commercial Officer at Absolute, says, “Trust is at the center of every endpoint discussion today as CIOs, CISOs and their teams want the assurance every endpoint will be able to heal itself and keep functioning.”

The Endpoint Market Is Heating Up Going Into 2020

Over thirty vendors are competing in the endpoint security market right now. A few of the most interesting are Absolute Software, Microsoft, Palo Alto Networks, and others who are seeing a surge of activity from enterprises based on discussions with CIOs and CISOs. Absolute Software’s Persistence self-healing endpoint security technology is embedded in the firmware of more than 500 million devices and gives CIOs, CISOs and their team’s complete visibility and control over devices and data. Absolute is the leading visibility and control platform that provides enterprises with tamper-proof resilience and protection of all devices, data, and applications.

Like Absolute, Microsoft is unique in how they are the only vendor to provide built-in endpoint protection at the device level, with the core focus being on the OS. Windows 10 has Windows Defender Antivirus now integrated at the OS level, the same System Center Endpoint Protection delivers in Windows 7 and 8 OS. Microsoft Defender Advanced Threat Protection (ATP) incident response console aggregates alerts and incident response activities across Microsoft Defender ATP, Office 365 ATP, Azure ATP, and Active Directory, in addition to Azure.

Further evidence of how enterprise customers are placing a high priority on endpoint security is the increase in valuations of key providers in this market, including Absolute Software (TSE: ABT) and others. Absolute’s stock price has jumped 13% in just a month, following their latest earnings announcement on November 12th with a transcript of their earnings call here. Absolute’s CEO Christy Wyatt commented during the company’s most recent earnings call that, “The ability to utilize near real-time data from the endpoint to… to deliver actionable insights to IT about where controls are failing and the ability to apply resilience to self-heal and reinforce those security controls will become a critical skill for every one of our customers. This is the essence of Absolute’s platform, which adds resiliency to our customer’s operations.” It’s evident from what CIOs and CISOs are saying that resiliency is transforming endpoint security today and will accelerate in 2020.

Key Takeaways From Conversations With Enterprise Cybersecurity Leaders

The conversations with CIOs, CISOs, and IT Directors provided valuable insights into why resiliency is becoming a high priority for endpoint security strategies today. The following are key takeaways from the conversations:

  • Known humorously as the “fun button” cybersecurity teams enjoy being able to brick any device any time while monitoring the activity happening on it in real-time. One CIO told the story of how their laptops had been given to a service provider who was supposed to destroy them to stay in compliance with the Health Insurance Portability and Accountability Act (HIPAA), and one had been resold on the back market, ending up in a 3rd world nation. As the hacker attempted to rebuild the machine, the security team watched as each new image was loaded, at which time they would promptly brick the machine. After 19 tries, the hacker gave up and called the image re-build “brick me.”
  • IT budgets for 2020 are flat or slightly up, with many CIOs being given the goal of reducing asset management operating expenses, making resiliency ideal for better managing device costs. The more effectively assets are managed, the more secure an organization becomes. That’s another motivating factor motivating enterprises to adopt resiliency as a core part of the endpoint security strategies.
  • One CIO was adamant they had nine software agents on every endpoint, but Absolute’s Resilience platform found 16, saving the enterprise from potential security gaps. The gold image an enterprise IT team was using had inadvertently captured only a subset of the total number of software endpoints active on their networks. Absolute’s Resilience offering and Persistence technology enabled the CIO to discover gaps in endpoint security the team didn’t know existed before.
  • Endpoints enabled with Resiliency have proven their ability to autonomously self-heal themselves, earning the trust of CIOs and CISOs, who are adopting Absolute to alleviate costly network interruptions and potential breaches in the process. 19% of endpoints across a typical IT network require at least one client or patch management repair monthly, according to Absolute’s 2019 Endpoint Security Trends Report. The report also found that increasing security spending on protecting endpoints doesn’t increase an organizations’ safety – and in some instances, reduces it. Having a systematic, design-in solution to these challenges gives CIOs, CISO, and their teams greater peace of mind and reduces expensive interruptions and potential breaches that impede their organizations’ growth.

 

Machine Learning Is Helping To Stop Security Breaches With Threat Analytics

Bottom Line: Machine learning is enabling threat analytics to deliver greater precision regarding the risk context of privileged users’ behavior, creating notifications of risky activity in real time, while also being able to actively respond to incidents by cutting off sessions, adding additional monitoring, or flagging for forensic follow-up.

Separating Security Hacks Fact from Fiction

It’s time to demystify the scale and severity of breaches happening globally today. A commonly-held misconception or fiction is that millions of hackers have gone to the dark side and are orchestrating massive attacks on any and every business that is vulnerable. The facts are far different and reflect a much more brutal truth, which is that businesses make themselves easy to hack into by not protecting their privileged access credentials. Cybercriminals aren’t expending the time and effort to hack into systems; they’re looking for ingenious ways to steal privileged access credentials and walk in the front door. According to Verizon’s 2019 Data Breach Investigations Report, ‘Phishing’ (as a pre-cursor to credential misuse), ‘Stolen Credentials’, and ‘Privilege Abuse’ account for the majority of threat actions in breaches (see page 9 of the report).

It only really takes one compromised credential to potentially impact millions — whether it’s millions of individuals or millions of dollars. Undeniably, identities and the trust we place in them are being used against us. They have become the Achilles heel of our cybersecurity practices. According to a recent study by Centrify among 1,000 IT decision makers, 74% of respondents whose organizations have been breached acknowledged that it involved access to a privileged account. This number closely aligns with Forrester Research’s estimate “that at least 80% of data breaches . . . [involved] compromised privileged credentials, such as passwords, tokens, keys, and certificates.”

While the threat actors might vary according to Verizon’s 2019 Data Breach Investigations Report, the cyber adversaries’ tactics, techniques, and procedures are the same across the board. Verizon found that the fastest growing source of threats are from internal actors, as the graphic from the study illustrates below:


Internal actors are the fastest growing source of breaches because they’re able to obtain privileged access credentials with minimal effort, often obtaining them through legitimate access requests to internal systems or harvesting their co-workers’ credentials by going through the sticky notes in their cubicles. Privileged credential abuse is a challenge to detect as legacy approaches to cybersecurity trust the identity of the person using the privileged credentials. In effect, the hacker is camouflaged by the trust assigned to the privileged credentials they have and can roam internal systems undetected, exfiltrating sensitive data in the process.

The reality is that many breaches can be prevented by some of the most basic Privileged Access Management (PAM) tactics and solutions, coupled with a Zero Trust approach. Most organizations are investing the largest chunk of their security budget on protecting their network perimeter rather than focusing on security controls, which can affect positive change to protect against the leading attack vector: privileged access abuse.

The bottom line is that investing in securing perimeters leaves the most popular attack vector of all unprotected, which are privileged credentials. Making PAM a top priority is crucial to protect any business’ most valuable asset; it’s systems, data, and the intelligence they provide. Gartner has listed PAM on its Top 10 Security Projects for the past two years for a good reason.

Part of a cohesive PAM strategy should include machine learning-based threat analytics to provide an extra layer of security that goes beyond a password vault, multi-factor authentication (MFA), or privilege elevation.

How Machine Learning and Threat Analytics Stop Privileged Credential Abuse 

Machine learning algorithms enable threat analytics to immediately detect anomalies and non-normal behavior by tracking login behavioral patterns, geolocation, and time of login, and many more variables to calculate a risk score. Risk scores are calculated in real-time and define if access is approved, if additional authentication is needed, or if the request is blocked entirely.

Machine learning-based threat analytics also provide the following benefits:

  • New insights into privileged user access activity based on real-time data related to unusual recent privilege change, the command runs, target accessed, and privilege elevation.
  • Gain greater understanding and insights into the specific risk nature of specific events, computing a risk score in real time for every event expressed as high, medium, or low level for any anomalous activity.
  •  Isolate, identify, and track which security factors triggered an anomaly alert.
  • Capture, play, and analyze video sessions of anomalous events within the same dashboard used for tracking overall security activity.
  • Create customizable alerts that provide context-relevant visibility and session recording and can also deliver notifications of anomalies, all leading to quicker, more informed investigative action.

What to Look for In Threat Analytics 
Threat analytics providers are capitalizing on machine learning to improve the predictive accuracy and usability of their applications continually. What’s most important is for any threat analytics application or solution you’re considering to provide context-aware access decisions in real time. The best threat analytics applications on the market today are using machine learning as the foundation of their threat analytics engine. These machine learning-based engines are very effective at profiling the normal behavior pattern for any user on any login attempt, or any privileged activity including commands, identifying anomalies in real time to enable risk-based access control. High-risk events are immediately flagged, alerted, notified, and elevated to IT’s attention, speeding analysis, and greatly minimizing the effort required to assess risk across today’s hybrid IT environments.

The following is the minimum set of features to look for in any privilege threat analytics solution:

  • Immediate visibility with a flexible, holistic view of access activity across an enterprise-wide IT network and extended partner ecosystem. Look for threat analytics applications that provide dashboards and interactive widgets to better understand the context of IT risk and access patterns across your IT infrastructure. Threat analytics applications that give you the flexibility of tailoring security policies to every user’s behavior and automatically flagging risky actions or access attempts, so that you’ll gain immediate visibility into account risk, eliminating the overhead of sifting through millions of log files and massive amounts of historical data.
  • They have intuitively designed and customizable threat monitoring and investigation screens, workflows, and modules. Machine learning is enabling threat analytics applications to deliver more contextually-relevant and data-rich insights than has ever been possible in the past. Look for threat analytics vendors who offer intuitively designed and customizable threat monitoring features that provide insights into anomalous activity with a detailed timeline view. The best threat analytics vendors can identify the specific factors contributing to an anomaly for a comprehensive understanding of a potential threat, all from a single console. Security teams can then view system access, anomaly detection in high resolutions with analytics tools such as dashboards, explorer views, and investigation tools.
  • Must provide support for easy integration to Security Information and Event Management (SIEM) tools. Privileged access data is captured and stored to enable querying by log management and SIEM reporting tools. Make sure any threat analytics application you’re considering has installed, and working integrations with SIEM tools and platforms such as Micro Focus® ArcSight™, IBM® QRadar™, and Splunk® to identify risks or suspicious activity quickly.
  • Must Support Alert Notification by Integration with Webhook-Enabled Endpoints. Businesses getting the most value out of their threat analytics applications are integrating with Slack or existing onboard incident response systems such as PagerDuty to enable real-time alert delivery, eliminating the need for multiple alert touch points and improving time to respond. When an alert event occurs, the threat analytics engine allows the user to send alerts into third-party applications via Webhook. This capability enables the user to respond to a threat alert and contain the impact of a breach attempt.

Conclusion 
Centrify, Forrester, Gartner, and Verizon each have used different methodologies and reached the same conclusion from their research: privileged access abuse is the most commonly used tactic for hackers to exfiltrate sensitive data. Breaches based on privileged credential abuse are extremely difficult to stop, as these credentials often have the greatest levels of trust and access rights associated with them. Leveraging threat analytics applications using machine learning that is adept at finding anomalies in behavioral data and thwarting a breach by denying access is proving very effective against privileged credential abuse.

Companies, including Centrify, use risk scoring combined with adaptive MFA to empower a least-privilege access approach based on Zero Trust. This Zero Trust Privilege approach verifies who or what is requesting privileged access, the context behind the request, and the risk of the access environment to enforce least privilege. These are the foundations of Zero Trust Privilege and are reflected in how threat analytics apps are being created and improved today.