Spotlight

Report:

The Forrester Wave™: Cybersecurity Consulting Services In Asia Pacific, Q4 2023

How does Forrester define the Cybersecurity Consulting Services In Asia Pacific market in 2023?

In 2023, APAC CISOs face a collision of challenges including talent crunches (23.6% increase in cybersecurity workforce gap), evolving threats, emerging technologies like generative AI, and regulatory sprawl. One-third of the 55 most notable breaches in 2022 were from APAC, prompting regulatory responses across Australia, India, Singapore, and Japan. APAC CISOs now require consulting providers that obsess with customers first, attract and retain the right talent mix, and think proactively and strategically without sacrificing technology and tactics. The evaluation assessed 10 providers across 31 criteria, categorizing them as Leaders (Accenture, EY, PwC), Strong Performers (KPMG, TCS, Wipro), Contenders (Deloitte, Trustwave, IBM), and Challengers (Tech Mahindra).

Key Facts for The Forrester Wave™: Cybersecurity Consulting Services In Asia Pacific, Q4 2023 in 2023

How did the Cybersecurity Consulting Services In Asia Pacific market evolve in 2023?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the Cybersecurity Consulting Services In Asia Pacific space?

No common features specified.

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Offering Strengths — Relative Weighting

Strategy Strength — Relative Weighting

FAQs

Q: What does this research cover?

A: This research covers a 31-criterion evaluation of the 10 most significant cybersecurity consulting service providers operating in Asia Pacific. It evaluates providers across three main categories: Current Offering (50%), Strategy (50%), and Market Presence (0%). The evaluation focuses on how well providers align with APAC CISO needs, customer centricity, localization of services, vision, innovation, talent strategy, and partner ecosystems.

Q: Who should use this research?

A: This research should be used by security and risk (S&R) leaders and CISOs in Asia Pacific who are selecting cybersecurity consulting providers. It helps them understand which providers best match their specific needs based on factors like customer obsession, talent quality, strategic thinking capabilities, and ability to address challenges like regulatory compliance, generative AI risks, talent gaps, and Zero Trust implementation.

Q: What are the mandatory features of vendors included in this market?

A: To be included in this Forrester Wave evaluation, cybersecurity consulting providers must meet all of the following criteria: generate at least $30 million in APAC cybersecurity consulting revenue; maintain broad service coverage across multiple APAC countries with no single subregion representing more than 85% of revenue; derive at least 10% of global cybersecurity consulting revenue from APAC; serve at least 70 active enterprise clients (1,000+ employees) in the region; offer a comprehensive suite of cybersecurity consulting services covering a minimum of three core business scenarios and one extended business scenario; and demonstrate significant mindshare among Forrester clients through inquiries, advisories, and event interactions.

Q: What are some reasons for not being included in this report?

A:

  • Insufficient APAC revenue (less than $30 million in cybersecurity consulting)
  • Geographic concentration exceeding 85% in any single APAC subregion
  • APAC represents less than 10% of global cybersecurity consulting revenue
  • Fewer than 70 active enterprise clients in APAC
  • Incomplete cybersecurity consulting portfolio (not covering minimum three core and one extended business scenarios)
  • Lack of significant Forrester client mindshare and engagement
  • Primary focus on managed services rather than consulting
  • Technology product vendor without substantial consulting capability

Q: What should buyers consider when evaluating products in this market?

A:

  • Prioritize providers that obsess with customers first and business later, putting client needs above commercial gain
  • Seek providers with in-depth understanding of your specific business, geography, and industry
  • Evaluate providers on their ability to balance junior staff for cost efficiency with senior expertise where needed
  • Look for providers with gender parity on leadership teams and strong diversity, equity, and inclusion outcomes, not just programs
  • Assess providers' ability to deliver strategic vision while maintaining technical depth and tactical competence
  • Consider providers' customer retention rates and satisfaction measurement processes
  • Evaluate providers' approach to emerging technologies, particularly generative AI risks and opportunities
  • Review providers' talent retention strategies and attrition rates
  • Assess partnership ecosystems and how partnerships translate to client value
  • Verify provider stability and reputation through reference customers, particularly regarding 'A team sells, C team delivers' risk
  • Consider providers' investment in R&D and innovation specific to APAC market needs
  • Evaluate localization capabilities and understanding of regional regulatory requirements

Q: How has the Cybersecurity Consulting Services In Asia Pacific market evolved in 2023?

A:

  • One-third of the 55 most notable breaches in 2022 were from APAC, ending the region's relative immunity to headline-making incidents
  • Regulatory sprawl across APAC with Australia amending privacy legislation, India passing Digital Personal Data Protection bill, Singapore amending Personal Data Protection Act, and Japan strengthening its Act on the Protection of Personal Information
  • Emergence of generative AI creating new security challenges and opportunities
  • 23.6% increase in cybersecurity workforce gap creating significant resource constraints
  • Growing expectation for consulting providers to address interlinked challenges of talent, threats, technology, and regulation
  • Shift from PowerPoint strategies and maturity assessments to actionable, tactical consulting that translates technical matters into business insights
  • Movement toward Zero Trust and modern security architectures
  • Increased focus on faster, more consequential attack scenarios introduced by generative AI
  • Need for AI model defense capabilities

Q: What differentiates Strength of Offering vs. Strength of Strategy?

A: Current Offering (50% weighting) evaluates vendor capabilities in delivering cybersecurity consulting services today, focusing on customer centricity, engagement quality, service localization, strategic consulting capabilities, and breadth of services. It measures how well vendors meet current CISO needs across tactical, operational, and strategic dimensions. Strategy (50% weighting) assesses vendor forward-thinking capabilities including vision for the future of cybersecurity, innovation in IP and methodologies, talent development programs, partnership ecosystems, community contribution, and pricing approaches. It measures how well positioned vendors are for future market demands and their ability to lead clients into emerging security paradigms.

Reference

View Leaders
View Vendor Movements