Spotlight

Report:

Magic Quadrant for Endpoint Protection Platforms

How does Gartner define the Endpoint Protection Platforms market in 2023?

Gartner defines an endpoint protection platform (EPP) as security software designed to protect managed end-user endpoints — including desktop PCs, laptop PCs, and mobile devices — against known and unknown malicious attacks. Additionally, EPPs provide capabilities for security teams to investigate and remediate incidents that evade prevention controls. EPP products are delivered as software agents deployed to endpoints and connected to centralized security analytics and management interfaces.

Key Facts for Magic Quadrant for Endpoint Protection Platforms in 2023

Strategic Planning Assumptions

How was the Endpoint Protection Platforms market evolved in 2023?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the Endpoint Protection Platforms space?

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Ability to Execute — Relative Weighting

Completeness of Vision — Relative Weighting

FAQs

Q: What does this research cover?

A: This research evaluates 18 endpoint protection platform vendors based on their ability to execute and completeness of vision. It covers EPP products that provide prevention, protection, detection, and response capabilities for managed end-user endpoints including desktops, laptops, and mobile devices. The evaluation emphasizes integrated EDR functionality, XDR capabilities, managed services, identity threat detection, workspace security integration, and security configuration management as key differentiators beyond basic malware protection.

Q: Who should use this research?

A: This research should be used by security and risk management leaders, IT security teams, and CISOs evaluating endpoint protection solutions. It is particularly relevant for organizations seeking to: consolidate security vendors, deploy or enhance EDR capabilities, adopt managed detection and response services, integrate endpoint protection with broader workspace security initiatives, improve ransomware defense, and support remote workforce security requirements. The research helps buyers understand vendor positioning, strengths, and cautions to make informed purchasing decisions based on their specific organizational needs and maturity levels.

Q: What are the mandatory features of vendors included in this market?

A: Mandatory features for vendors included in this market include: (1) Prevention and protection against security threats including file-based and fileless malware, (2) Behavioral threat detection using device activity, application, identity and user telemetry, (3) Incident detection, investigation and remediation guidance capabilities, (4) Management and reporting of OS security controls like host firewall and device control, and (5) Integrated endpoint detection and response (EDR) functionality. Additionally, solutions must use a single agent, provide automatic response actions, include MITRE ATT&CK mapping, support major OS updates within 90 days, offer cloud-based SaaS management, store telemetry for at least 30 days, and integrate with other security controls.

Q: What are some reasons for not being included in this report?

A:

  • Not providing EPP software and licensing independently of other products or services
  • More than 60% of detection content coming from sources other than the vendor's own threat intelligence team
  • Protection techniques not designed, owned, and maintained by the vendor itself
  • Not participating in at least two enterprise-focused public tests for accuracy and effectiveness within 12 months before March 1, 2023
  • Having fewer than 7.5 million endpoints protected and actively under management, or fewer than 500,000 active production installations with accounts larger than 500 seats
  • Having more than 60% of enterprise customers concentrated in a single region outside North America or Europe
  • Being a Russian vendor (due to Gartner's pause in coverage)

Q: What differentiates Ability to Execute vs. Completeness of Vision?

A: Ability to Execute evaluates vendors on the quality and efficacy of their processes, systems, methods and procedures to be competitive, efficient and effective, and to improve their revenue, retention and reputation. This includes current product capabilities, financial viability, sales execution, market responsiveness, customer experience and operations. Completeness of Vision evaluates vendors on their ability to convincingly articulate logical statements relating to current and future market direction, innovation, customer needs, and competitive forces. This includes market understanding, marketing and sales strategies, product strategy, innovation, vertical/industry strategy, and geographic strategy.

Reference

View Leaders
View Vendor Movements