Spotlight

Report:

The Forrester Wave™: Cybersecurity Incident Response Services, Q2 2024

How does Forrester define the Cybersecurity Incident Response Services market in 2024?

Cybersecurity incident response service providers must balance defense with defensibility, delivering engagements across all stages of the IR lifecycle—from readiness to recovery—in a litigation-aware manner backed by top threat intelligence, digital forensics, and IR tools and talent. With over 1.5 billion records breached and $2.6 billion in regulatory fines in 2023, organizations must respond to evolving attacker tactics while ensuring compliance with regional regulations. New breach notification requirements from the SEC (4-day disclosure for material incidents), EU NIS2 (October 2024), and DORA (January 2025) are transforming incident handling. Providers must work rapidly with corporate and outside counsel, communicate clearly across all stakeholder levels (boards, executives, regulators, insurers, partners, employees, customers), and continuously create efficiencies through automation and innovation. Cyber insurance brokers and carriers require panel providers to attest to security posture through specific assessments and exercises.

Key Facts for The Forrester Wave™: Cybersecurity Incident Response Services, Q2 2024 in 2024

How did the Cybersecurity Incident Response Services market evolve in 2024?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the Cybersecurity Incident Response Services space?

No common features specified.

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Offering Strengths — Relative Weighting

Strategy Strength — Relative Weighting

FAQs

Q: What does this research cover?

A: This research provides a comprehensive evaluation of 14 cybersecurity incident response service providers based on 25 criteria across current offering, strategy, and market presence. It analyzes how providers deliver engagements at all stages of the IR lifecycle—from readiness to recovery—in a litigation-aware manner backed by threat intelligence, digital forensics, and IR tools and talent. The evaluation includes Leaders, Strong Performers, Contenders, and Challengers, with detailed vendor profiles highlighting strengths and weaknesses.

Q: Who should use this research?

A: Security and risk professionals should use this research to select the right cybersecurity incident response service provider for their needs. The report helps organizations identify providers that can closely collaborate on breach notification, clearly communicate at all stakeholder levels (boards, executives, regulatory bodies, insurance carriers), and continuously create efficiencies in responding to incidents. It's particularly valuable for organizations seeking providers with expertise in regional regulations, crisis communications, threat intelligence, and global delivery capabilities.

Q: What are the mandatory features of vendors included in this market?

A: To be included in this Forrester Wave evaluation, vendors must: 1) Generate at least $100 million in IR services revenue with cybersecurity IR services offered independently from other consulting, managed services, or technology solutions; 2) Possess global IR capabilities with established support for multinational companies in two or more regions; 3) Participate in one or more cyber insurance carrier panels or accept work with negotiated rates from insurance carrier referrals; 4) Demonstrate significant mindshare with Forrester clients through inquiries, advisory sessions, consulting engagements, and other interactions, or warrant inclusion based on technical capabilities and market presence.

Q: What are some reasons for not being included in this report?

A:

  • IR services revenue below $100 million threshold
  • Lack of global capabilities or presence in fewer than two regions
  • No participation in cyber insurance carrier panels or referral programs
  • Insufficient client mindshare or market presence
  • IR services not offered independently from other services or products
  • Decline to participate in the evaluation process
  • Partial participation only in the evaluation process

Q: What should buyers consider when evaluating products in this market?

A:

  • Providers that closely collaborate on breach notification with working knowledge of regional regulations and streamlined processes to operate under attorney-client privilege
  • Providers that clearly communicate at all stakeholder levels including boards, executives, regulatory bodies, cyber insurance brokers/carriers, partners, employees, and customers
  • Providers that continuously create efficiencies through innovation, automation of time-consuming processes like evidence collection, and training for smooth handoffs in follow-the-sun global delivery models
  • In-house crisis communications practices or orchestrated support through trusted partners
  • Rapid response times to meet retainer or contract-based guaranteed SLAs
  • Litigation-aware approach working in lockstep with corporate and outside counsel to determine materiality and disclosure requirements

Q: How has the Cybersecurity Incident Response Services market evolved in 2024?

A:

  • New stringent breach notification rules from regulatory bodies including SEC requirement for publicly traded companies to disclose material incidents within four business days
  • EU regulations NIS2 (October 2024) and DORA (January 2025) affecting organizations within and outside the EU
  • IR becoming a high-volume business driven by zero days, genAI-crafted phishing, social engineering tactics, and stolen credentials
  • Cyber insurance brokers and carriers requiring panel providers to attest to security posture through specific assessments and exercises
  • Multiple stakeholders requiring information at varying times, frequency, and privilege levels during incidents
  • Providers investing in innovation and automation to speed all stages of IR lifecycle and improve efficiency
  • Follow-the-sun global delivery models for consistent support across geographies
  • Crisis communications becoming standard in-house capability or through trusted partners

Q: What differentiates Strength of Offering vs. Strength of Strategy?

A: Strength of Offering (Current Offering) evaluates vendors' current capabilities across the IR lifecycle including retainer structures, incident preparation, response, recovery, technology, threat intelligence, talent management, and industry contribution (50% weighting). Strength of Strategy evaluates vendors' future direction including vision, innovation, partner ecosystem, supporting services, talent strategy, and global delivery approach (50% weighting). Current offering focuses on what vendors deliver today, while strategy assesses their positioning for future market demands.

Reference

View Leaders
View Vendor Movements