Report:
The Forrester Wave™: Cybersecurity Incident Response Services, Q2 2024
How does Forrester define the Cybersecurity Incident Response Services market in 2024?
Cybersecurity incident response service providers must balance defense with defensibility, delivering engagements across all stages of the IR lifecycle—from readiness to recovery—in a litigation-aware manner backed by top threat intelligence, digital forensics, and IR tools and talent. With over 1.5 billion records breached and $2.6 billion in regulatory fines in 2023, organizations must respond to evolving attacker tactics while ensuring compliance with regional regulations. New breach notification requirements from the SEC (4-day disclosure for material incidents), EU NIS2 (October 2024), and DORA (January 2025) are transforming incident handling. Providers must work rapidly with corporate and outside counsel, communicate clearly across all stakeholder levels (boards, executives, regulators, insurers, partners, employees, customers), and continuously create efficiencies through automation and innovation. Cyber insurance brokers and carriers require panel providers to attest to security posture through specific assessments and exercises.
Key Facts for The Forrester Wave™: Cybersecurity Incident Response Services, Q2 2024 in 2024
- Publication Date: 09-Jun-2024
- Document ID: RES180928
- Summary: In our 25-criterion evaluation of cybersecurity incident response service providers, we identified the most significant ones and researched, analyzed, and scored them. This report shows how each provider measures up and helps security and risk professionals select the right one for their needs.
- Authors: Jess Burn, Joseph Blankenship, Faith Born, Michael Belden
How did the Cybersecurity Incident Response Services market evolve in 2024?
- Analysis of top 35 global breaches found attackers made off with over 1.5 billion customer or citizen records
- Regulatory bodies levied over $2.6 billion in fines for incidents and privacy violations during or before 2023
- New SEC requirement mandates publicly traded companies disclose material cybersecurity incidents within four business days
- EU regulations NIS2 directive takes effect October 2024, DORA in January 2025
- Zero-day vulnerabilities, genAI-crafted phishing, and social engineering tactics are driving high-volume IR business
- Cyber insurance brokers and carriers require specific assessments and exercises from panel providers
- IR services must balance defense capabilities with regulatory defensibility and compliance
- Market trends show increased focus on breach notification, crisis communications, and executive-level engagement
What product features are required to be included in this year's evaluation?
- At least $100 million in IR services revenue. Each service provider offers cybersecurity IR services independent of other consulting services, managed services, or technology solutions and possesses global IR capabilities with established capabilities for multinational companies with presence in two or more regions.
- Participation in cyber insurance carrier panels or referrals. Cybersecurity IR service providers included in this evaluation participate in one or more cyber insurance carrier panels available to their policyholders or undertake work with negotiated rates from an insurance carrier referral.
- Significant mindshare with Forrester clients. To select the most relevant cybersecurity IR service providers to evaluate, Forrester considered the level of interest from our clients based on inquiries, advisory sessions, consulting engagements, and other interactions. Alternatively, the participating provider may, in Forrester's judgment, have warranted inclusion because of technical capabilities and market presence.
What are the common features of top products in the Cybersecurity Incident Response Services space?
No common features specified.
Scope Exclusions
- Vendors with less than $100 million in IR services revenue
- Vendors without global IR capabilities or presence in fewer than two regions
- Vendors not participating in cyber insurance carrier panels or referrals
- Vendors with insufficient mindshare among Forrester clients
- Managed security services providers without dedicated IR services
- Technology solution vendors without professional IR services
- Regional-only IR service providers
Inclusion Criteria
Vendors must, among other requirements:
- At least $100 million in IR services revenue with cybersecurity IR services independent of other consulting services, managed services, or technology solutions
- Global IR capabilities with established capabilities for multinational companies with presence in two or more regions
- Participation in cyber insurance carrier panels or referrals
- Significant mindshare with Forrester clients based on inquiries, advisory sessions, consulting engagements, and other interactions
Offering Strengths — Relative Weighting
- IR retainer or contract structure — 12%
- Metrics — 12%
- Onboarding — 4%
- Incident preparation — 4%
- Incident simulation — 4%
- Incident response — 10%
- Recovery — 4%
- Ecosystem collaboration — 4%
- Legal and regulatory compliance support — 3%
- Post-incident reporting and support — 3%
- Technology — 3%
- Threat intelligence — 3%
- Cloud environments — 3%
- OT/ICS environments — 3%
- IR leadership and team structure — 9%
- IR talent management — 9%
- Contribution to cybersecurity industry — 10%
Strategy Strength — Relative Weighting
- Vision — 20%
- Innovation — 20%
- Partner ecosystem — 15%
- Supporting services and offerings — 15%
- Talent strategy — 15%
- Global delivery strategy — 15%
FAQs
Q: What does this research cover?
A: This research provides a comprehensive evaluation of 14 cybersecurity incident response service providers based on 25 criteria across current offering, strategy, and market presence. It analyzes how providers deliver engagements at all stages of the IR lifecycle—from readiness to recovery—in a litigation-aware manner backed by threat intelligence, digital forensics, and IR tools and talent. The evaluation includes Leaders, Strong Performers, Contenders, and Challengers, with detailed vendor profiles highlighting strengths and weaknesses.
Q: Who should use this research?
A: Security and risk professionals should use this research to select the right cybersecurity incident response service provider for their needs. The report helps organizations identify providers that can closely collaborate on breach notification, clearly communicate at all stakeholder levels (boards, executives, regulatory bodies, insurance carriers), and continuously create efficiencies in responding to incidents. It's particularly valuable for organizations seeking providers with expertise in regional regulations, crisis communications, threat intelligence, and global delivery capabilities.
Q: What are the mandatory features of vendors included in this market?
A: To be included in this Forrester Wave evaluation, vendors must: 1) Generate at least $100 million in IR services revenue with cybersecurity IR services offered independently from other consulting, managed services, or technology solutions; 2) Possess global IR capabilities with established support for multinational companies in two or more regions; 3) Participate in one or more cyber insurance carrier panels or accept work with negotiated rates from insurance carrier referrals; 4) Demonstrate significant mindshare with Forrester clients through inquiries, advisory sessions, consulting engagements, and other interactions, or warrant inclusion based on technical capabilities and market presence.
Q: What are some reasons for not being included in this report?
A:
- IR services revenue below $100 million threshold
- Lack of global capabilities or presence in fewer than two regions
- No participation in cyber insurance carrier panels or referral programs
- Insufficient client mindshare or market presence
- IR services not offered independently from other services or products
- Decline to participate in the evaluation process
- Partial participation only in the evaluation process
Q: What should buyers consider when evaluating products in this market?
A:
- Providers that closely collaborate on breach notification with working knowledge of regional regulations and streamlined processes to operate under attorney-client privilege
- Providers that clearly communicate at all stakeholder levels including boards, executives, regulatory bodies, cyber insurance brokers/carriers, partners, employees, and customers
- Providers that continuously create efficiencies through innovation, automation of time-consuming processes like evidence collection, and training for smooth handoffs in follow-the-sun global delivery models
- In-house crisis communications practices or orchestrated support through trusted partners
- Rapid response times to meet retainer or contract-based guaranteed SLAs
- Litigation-aware approach working in lockstep with corporate and outside counsel to determine materiality and disclosure requirements
Q: How has the Cybersecurity Incident Response Services market evolved in 2024?
A:
- New stringent breach notification rules from regulatory bodies including SEC requirement for publicly traded companies to disclose material incidents within four business days
- EU regulations NIS2 (October 2024) and DORA (January 2025) affecting organizations within and outside the EU
- IR becoming a high-volume business driven by zero days, genAI-crafted phishing, social engineering tactics, and stolen credentials
- Cyber insurance brokers and carriers requiring panel providers to attest to security posture through specific assessments and exercises
- Multiple stakeholders requiring information at varying times, frequency, and privilege levels during incidents
- Providers investing in innovation and automation to speed all stages of IR lifecycle and improve efficiency
- Follow-the-sun global delivery models for consistent support across geographies
- Crisis communications becoming standard in-house capability or through trusted partners
Q: What differentiates Strength of Offering vs. Strength of Strategy?
A: Strength of Offering (Current Offering) evaluates vendors' current capabilities across the IR lifecycle including retainer structures, incident preparation, response, recovery, technology, threat intelligence, talent management, and industry contribution (50% weighting). Strength of Strategy evaluates vendors' future direction including vision, innovation, partner ecosystem, supporting services, talent strategy, and global delivery approach (50% weighting). Current offering focuses on what vendors deliver today, while strategy assesses their positioning for future market demands.
Reference
- Forrester, The Forrester Wave™: Cybersecurity Incident Response Services, Q2 2024, 09-Jun-2024, ID RES180928
View Leaders
View Vendor Movements