Spotlight

Report:

The Forrester Wave™: Cybersecurity Consulting Services, Q2 2024

How does Forrester define the Cybersecurity Consulting Services market in 2024?

The cybersecurity consulting services market is experiencing a fundamental shift where deep technical expertise and innovation now matter more than traditional strategic consulting capabilities. CISOs face unprecedented technology advances including generative AI adoption by threat actors, massive attack surface expansion through marketplaces and plug-ins, and enterprise-wide genAI implementation efforts. This has elevated the value of providers with specialized technical knowledge, research-driven innovation, and ability to contribute to the broader cybersecurity community over traditional consultancies offering repeatable engagement methodologies. The market now prioritizes providers who can instill board-level confidence, possess genuine technical depth in emerging technologies, and openly share intellectual property rather than hoarding expertise behind client paywalls.

Key Facts for The Forrester Wave™: Cybersecurity Consulting Services, Q2 2024 in 2024

How did the Cybersecurity Consulting Services market evolve in 2024?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the Cybersecurity Consulting Services space?

No common features specified.

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Offering Strengths — Relative Weighting

Strategy Strength — Relative Weighting

FAQs

Q: What does this research cover?

A: This research evaluates 15 cybersecurity consulting service providers across 24 criteria, assessing their current offerings, strategy, and market presence. The evaluation focuses on providers' ability to deliver deep technical expertise, innovation and research capabilities, board-level credibility, and community contributions. It covers engagement types including technical assessments, security strategy development, budget optimization, technology stack consolidation, staff augmentation, and governance/risk/compliance services.

Q: Who should use this research?

A: Security and risk professionals, particularly CISOs, should use this research to select the right cybersecurity consulting provider for their needs. The research helps buyers identify providers best suited for specific engagement types—whether they need deep technical expertise for emerging technologies, strategic board-level advisory services, cost optimization support, or staff augmentation. The customizable Excel-based vendor comparison tool allows readers to adapt criteria weightings to their individual requirements.

Q: What are the mandatory features of vendors included in this market?

A: To be included in this Forrester Wave evaluation, vendors must meet three core requirements: 1) Offer comprehensive cybersecurity consulting service delivery capabilities across extended business scenarios, demonstrating breadth beyond narrow specialization; 2) Generate at least $500 million in cybersecurity consulting services revenue annually and serve clients globally, ensuring scale and international reach; 3) Demonstrate significant Forrester mindshare through client inquiries, advisories, consulting engagements, and other interactions, confirming relevance to Forrester's client base and ensuring quality reference availability.

Q: What are some reasons for not being included in this report?

A:

  • Cybersecurity consulting services revenue below $500 million threshold
  • Lack of global service delivery capabilities
  • Limited service portfolio not covering extended business scenarios comprehensively
  • Insufficient Forrester client mindshare and engagement
  • Primary focus on managed services rather than consulting
  • Narrow specialization in only product implementation without broader consulting capabilities
  • Vendor declined to participate in the evaluation process
  • Vendor provided only partial participation in the evaluation
  • New market entrant without established track record

Q: What should buyers consider when evaluating products in this market?

A:

  • Seek providers with deep technical expertise focused on innovation and research, not just repeatable methodologies
  • Prioritize providers who can instill confidence and credibility with boards and senior leaders
  • Evaluate providers' contributions to the broader cybersecurity community through conferences, open-source projects, and published frameworks
  • Consider whether you need strategic board-level advisory or tactical deployment and implementation work
  • Assess providers' expertise with emerging technologies like generative AI, machine learning, and blockchain
  • Evaluate the provider's ability to help with technology stack consolidation and budget optimization
  • Determine if the provider focuses on business enablement versus cost reduction only
  • Consider the provider's approach to risk versus business alignment
  • Assess the depth of technical talent versus presentation polish
  • Evaluate pricing transparency and flexibility for your specific needs
  • Consider global delivery capabilities if you operate internationally
  • Assess the provider's willingness to share intellectual property versus restricting it to clients only

Q: How has the Cybersecurity Consulting Services market evolved in 2024?

A:

  • Migration to cloud computing has reduced the value of deployment and implementation specialists
  • Generative AI adoption is transforming threat actor tools, tactics, and procedures
  • Massive increase in attack surface due to marketplaces and plug-ins
  • Enterprise-wide efforts to adopt and embed generative AI technologies
  • Shift from strategic consulting hierarchy to deep technical expertise being most valuable
  • Growing importance of innovation and research over repeatable engagement methodologies
  • Niche and boutique providers with specialized expertise becoming more valuable than traditional consultancies
  • Increased need for board-level credibility and C-suite alignment
  • Community contribution and open intellectual property sharing differentiating leading providers
  • Vendor consolidation forcing technology stack optimization decisions

Q: What differentiates Strength of Offering vs. Strength of Strategy?

A: Current Offering (vertical axis) measures the strength of a vendor's present capabilities and service delivery across 16 criteria including CISO alignment, customer satisfaction, engagement management, technical assessments, and various specialized delivery capabilities. Strategy (horizontal axis) evaluates the vendor's future direction and competitive positioning through 6 criteria focusing on vision, innovation, talent development, partnerships, community engagement, and pricing models. Offering emphasizes what vendors deliver today, while Strategy assesses their ability to adapt and lead in the evolving cybersecurity landscape.

Reference

View Leaders
View Vendor Movements