Report:
The Forrester Wave™: Cybersecurity Consulting Services In Europe, Q1 2024
How does Forrester define the Cybersecurity Consulting Services In Europe market in 2024?
The European cybersecurity consulting services market faces persistent challenges including evolving threats, emerging technologies, regulatory complexities (NIS2, DORA), hybrid work transitions, talent costs, budget constraints, and generative AI adoption. The market shows limited innovation since 2021, with advancements primarily through acquisitions and hybrid delivery model shifts. Fully virtual projects have declined in favor of in-person collaboration. Reference customers report lack of innovation in pricing models and persistently high costs despite economic constraints. The evaluation assessed 12 providers using 32 criteria across current offering (50% weight) and strategy (50% weight), identifying Leaders, Strong Performers, Contenders, and Challengers in the European market.
Key Facts for The Forrester Wave™: Cybersecurity Consulting Services In Europe, Q1 2024 in 2024
- Publication Date: 05-Mar-2024
- Document ID: RES179986
- Summary: In our 32-criterion evaluation of cybersecurity consulting services providers in Europe, we identified the most significant ones and researched, analyzed, and scored them. This report shows how each provider measures up and helps security and risk leaders select the right one for their needs.
- Authors: Madelein van der Hout, Paul McKay, Jinan Budge, Laura Koetzle, Min Say, Demi Starks
How did the Cybersecurity Consulting Services In Europe market evolve in 2024?
- European cybersecurity consulting offerings haven't changed much since the last Forrester Wave in 2021
- No groundbreaking disruptions were observed in this market evaluation
- Advancements mainly occurred via acquisitions and notable shifts in delivery strategies
- Hybrid delivery models have replaced fully virtual projects as in-person collaboration has resurfaced
- Reference customers lament the lack of innovation in pricing models
- Persistently high costs continue despite constrained economic environment
- CISOs are navigating transitions to hybrid work, talent cost scrutiny, and budget constraints
- New regulations like NIS2 and DORA are creating compliance challenges
- Generative AI adoption is a daunting task for security leaders
- 12 providers were evaluated in this assessment
What product features are required to be included in this year's evaluation?
- Revenue of at least $150 million in Europe for cybersecurity consulting services
- Broad footprint of cybersecurity consulting customers and revenue across several European countries, demonstrating applicability beyond a single country or two
- At least 10% of global cybersecurity consulting revenue generated in Europe
- Complete suite of cybersecurity consulting services offered to clients across Europe, demonstrating minimum of three core business scenarios and an extended one in the region
- Significant interest from Forrester clients in the form of inquiries, advisories, interactions at events, and other conversations
What are the common features of top products in the Cybersecurity Consulting Services In Europe space?
No common features specified.
Scope Exclusions
- Vendors with less than $150 million revenue in European cybersecurity consulting services
- Providers with limited geographic coverage (single country or two countries only)
- Vendors generating less than 10% of global cybersecurity consulting revenue from Europe
- Providers offering incomplete cybersecurity consultancy portfolios (fewer than three core business scenarios)
- Vendors without significant Forrester client mindshare or engagement
Inclusion Criteria
Vendors must, among other requirements:
- Revenue of at least $150 million in Europe for cybersecurity consulting services
- Broad service coverage across several European countries
- At least 10% of global cybersecurity consulting revenue generated in Europe
- Comprehensive cybersecurity consultancy portfolio offering minimum of three core business scenarios
- Significant mindshare from Forrester clients through inquiries, advisories, and events
Offering Strengths — Relative Weighting
- Alignment with client CISO needs — 5%
- Customer retention and satisfaction — 5%
- Customer partnership and collaboration — 5%
- Customer centricity — 5%
- Engagement personnel and team allocation — 5%
- Localization of services — 5%
- Engagement delivery — 3%
- Cybersecurity training and literacy for clients — 3%
- Helping clients with emerging tech undertakings — 5%
- Use of emerging technology in client delivery — 5%
- Knowledge transfer to client teams — 3%
- Cybersecurity industry contribution — 3%
- Cybersecurity strategy and vision capabilities — 15%
- Governance, risk, and compliance capabilities — 5%
- Technology stack consolidation capabilities — 5%
- Threat and incident response capabilities — 5%
- Technical security assessment capabilities — 5%
- Zero Trust/architecture capabilities — 5%
- Security and risk culture capabilities — 8%
Strategy Strength — Relative Weighting
- Vision — 30%
- Innovation — 15%
- Talent strategy — 20%
- Partner ecosystem — 15%
- Community — 10%
- Pricing flexibility and transparency — 10%
FAQs
Q: What does this research cover?
A: This research covers a 32-criterion evaluation of the most significant cybersecurity consulting services providers operating in Europe. It evaluates 12 vendors across current offering (50% weight), strategy (50% weight), and market presence criteria. The evaluation assesses providers' abilities to navigate evolving CISO needs, harness collaborative ecosystems, demonstrate cultural adaptability, and deliver high-performing consultants. Key evaluation areas include alignment with client CISO needs, customer retention and satisfaction, partnership and collaboration, localization of services, vision, innovation, talent strategy, partner ecosystem, community engagement, and pricing flexibility.
Q: Who should use this research?
A: Security and risk leaders should use this research to select the right cybersecurity consulting services provider for their needs in Europe. The report helps organizations identify providers that can navigate evolving CISO challenges with forward-thinking roadmaps, harness collaborative ecosystems for differentiated results, and demonstrate both technical excellence and cultural adaptability. Decision-makers can use the vendor profiles, scoring methodology, and comparative analysis to evaluate which providers best align with their specific requirements, whether they need strategic expertise, technical implementation capabilities, boardroom communication skills, or innovative approaches to emerging challenges like AI and new regulations.
Q: What are the mandatory features of vendors included in this market?
A: All vendors included in this evaluation must demonstrate: (1) minimum annual revenue of $150 million for cybersecurity consulting services in Europe; (2) broad geographic service coverage across multiple European countries rather than just one or two; (3) Europe representing at least 10% of their global cybersecurity consulting revenue; (4) a comprehensive cybersecurity consultancy portfolio that includes at least three core business scenarios plus one extended scenario; and (5) significant engagement with Forrester clients demonstrated through inquiries, advisories, event interactions, and other client conversations.
Q: What are some reasons for not being included in this report?
A:
- Insufficient European revenue (below $150 million threshold)
- Limited geographic footprint (coverage in only one or two European countries)
- Europe not a key revenue hub (less than 10% of global cybersecurity consulting revenue)
- Incomplete service portfolio (fewer than three core business scenarios)
- Lack of significant Forrester client mindshare or engagement
- Vendor declined to participate in full evaluation process
- Vendor contributed only partially to the evaluation requirements
Q: What should buyers consider when evaluating products in this market?
A:
- Navigate evolving CISO needs with a forward-thinking roadmap that goes beyond maturity assessments and PowerPoint strategies
- Demand transparency regarding consulting firms' roadmaps and proof of benefits delivered for clients
- Harness a collaborative ecosystem for differentiated results, including co-creative ventures with competitors
- Ensure providers possess high-performing consultants with strong technical skills and outstanding soft skills
- Evaluate cultural adaptability and organizational fit of consultant teams
- Assess talent allocation approach, feedback mechanisms, and turnover mitigation strategies
- Consider providers' approach to talent attraction, development, and retention
- Evaluate client staff training and knowledge transfer capabilities
- Assess innovation in pricing models and cost transparency
- Verify understanding of emerging technologies (generative AI, Quantum, OT/IoT) and regulatory requirements
Q: How has the Cybersecurity Consulting Services In Europe market evolved in 2024?
A:
- Transitions to hybrid work models with resurgence of in-person project collaboration
- Preparation for new European regulations including NIS2 and DORA
- Adoption of generative AI in cybersecurity operations
- Scrutiny over talent costs and budget constraints
- Limited innovation in pricing models despite constrained economic environment
- Market advancements primarily through acquisitions rather than organic innovation
- Shift from fully virtual to hybrid engagement delivery models
- Evolution from maturity assessments to forward-thinking roadmaps addressing CISO needs
- Increased focus on collaborative ecosystems including co-creation with competitors
- Growing emphasis on cultural adaptability and soft skills alongside technical expertise
Q: What differentiates Strength of Offering vs. Strength of Strategy?
A: Current Offering (vertical axis) evaluates the strength of vendors' existing cybersecurity consulting capabilities, service delivery, customer satisfaction, technical expertise, and localization across Europe. It focuses on what vendors deliver today including their portfolio breadth, engagement quality, personnel allocation, and specific capabilities in areas like GRC, Zero Trust, incident response, and security strategy. Strategy (horizontal axis) evaluates vendors' future direction and strategic positioning through their vision, innovation initiatives, talent development programs, partner ecosystem approach, community engagement, and pricing models. It assesses how well-positioned vendors are for future market needs and their ability to anticipate and address evolving CISO challenges.
Reference
- Forrester, The Forrester Wave™: Cybersecurity Consulting Services In Europe, Q1 2024, 05-Mar-2024, ID RES179986
View Leaders
View Vendor Movements