Skip to content
The Cyber Security Place

Industry

The security market in 2026: the part nobody audits

An industry built on measuring things cannot say how large it is, how many products you own, or whether any of it works. Every other page here rests on figures. This one is about where the figures come from.

Last reviewed August 25, 2026

Published answers to how many security tools an organisation runs range from about 45 to over 130, and the spread is a definition problem, not a difference between organisations. The market's own size for 2026 is quoted between roughly $240bn and $288bn — a $48bn gap — with growth given as both 12.5% and 15.1% for overlapping periods. Around 75% of organisations say they are consolidating; far fewer finish, because buying is faster than removing. Venture funding reached $4.62bn in one quarter and $10.6bn across a half-year, and 159 vendor transactions were tracked in a single quarter, 31 of them acquisitions — so any supplier you pick today may well belong to somebody else within three years. Almost none of this is independently audited, and what separates a measurement from an assertion is whether anybody else could reproduce it.

How many security tools do you run?

The estate below does not change. Only the rule for counting it does — and the answer moves by a factor of nine.

Worked exampleOne estate. Now choose what counts.

36 security tools, on the definition you just chose No widely published figure sits near this one.
What each criterion adds, and what gets published
Counting ruleAddsRunning total
Consoles used weekly by the security team—14
Count each module of a suite separately+2640
Count capabilities you already own but never enabled+3171
Count free and open-source tooling+980
Count what other teams bought+22102
Count agents rather than consoles+18120
Count what is installed but no longer used+11131

The same organisation, counted honestly, is anywhere from 14 to 131. Published answers to this question include 45, 61, 76, 83, 130, all quoted as though they measured the same thing.

An illustrative estate, not a survey. What is not illustrative is the spread: those figures are published and cited interchangeably, and almost none of them states which of the rules above it used. A number nobody can reproduce is not a measurement, and this particular number decides budgets.

Every one of those counting rules is defensible. A suite of eleven consoles with separate policies is arguably eleven things to operate, and arguably one purchase. A capability bought and never enabled is either a tool you have or a tool you do not, depending on whether the question is about licences or about work. There is no correct answer, only an undeclared one.

What follows matters, because this figure is used. It appears in board papers as evidence of complexity, in consolidation proposals as the size of the problem, and in vendor material as the reason to buy a platform that will reduce it. Whoever chooses the counting rule chooses the conclusion, and the rule is essentially never stated.

There is a practical test worth applying whenever a number in this field is quoted at you. Ask what would have to be true for somebody else to reproduce it. For most figures on this page the honest answer is that nobody could, because the survey population, the question wording and the counting rule are all absent.

The market that cannot measure itself

One question — how much is spent on this worldwide in 2026 — and four published answers, plotted on the same axis.

$240bnone analyst house$244bntrade press$248.9bna market tracker$287.7bna research firm$47.7bn between the lowest and the highestsame year, same question, no way to check

Forty-eight billion dollars separates the lowest published figure from the highest, for the same year. That difference is not a rounding disagreement; it is larger than this entire industry's revenue two decades ago. And it is not resolvable, because no methodology is published in a form that would let anybody outside those four organisations check the work.

The growth rates behave the same way. One source gives twelve and a half per cent into 2026, another fifteen point one over an overlapping period. Both are quoted in planning documents as though interchangeable, and they cannot both describe the same measurement.

It would be easy and wrong to read this as dishonesty. The likelier explanation is that these organisations are measuring genuinely different things — one counts licence revenue, another includes services, a third adds internal staff costs — and none states which, because stating it would invite comparison and comparison is not what the figure is for. The number exists to establish that the market is large and growing, which every version of it does.

Where does the money actually go?

Three flows are worth separating, because they behave differently and get confused with one another constantly.

What organisations spend is the large number: somewhere in the region of a quarter of a trillion dollars a year, most of it on licences and services rather than on people. It grows at low double digits regardless of whether the previous year's spending achieved anything, because it is budgeted as a percentage of technology spend and technology spend grows.

What investors put in is smaller and far more volatile: roughly $4.6bn in a single recent quarter and $10.6bn across a half-year, after a period when the same figure had halved. This money is not buying security; it is buying options on future acquisition, and it determines which categories exist to be sold to you in three years.

What changes hands between vendors is the flow that most affects buyers and gets the least attention. One quarter alone saw a hundred and fifty-nine tracked transactions, thirty-one of them acquisitions, with several megadeals above a billion dollars in the preceding year. Every one of those is a product whose roadmap now belongs to somebody else.

The third flow is the one to watch when purchasing, and it is almost never in the evaluation criteria. A tool chosen on features is a tool chosen on the assumption that the company shipping it will still be shipping it, independently, in three years — an assumption the transaction volume above makes roughly a coin toss.

Why does consolidation keep not happening?

Around three quarters of organisations report pursuing it, in survey after survey, year after year, while the tool counts described above keep rising. Both things are true, and the gap between them is structural.

Buying is a decision one person can make. There is a budget line, a business case, a supplier who will help write it, and a visible outcome: a capability that did not exist now exists. The whole apparatus of procurement is built to make this transaction happen.

Removing is a project. Somebody must establish what depends on the thing being switched off, which requires knowing what it does, who consumes its output, which dashboards reference it and whether an auditor was shown it last year. Then somebody must accept the risk of being wrong, on a change whose best possible outcome is that nothing happens. Nobody is promoted for that.

So the asymmetry compounds. Each new platform arrives promising to replace four products, and it does replace their function, but the four remain installed because removing them was a separate piece of work that was never scheduled. The estate grows by addition and shrinks only when a contract lapses and nobody notices in time to renew it.

The organisations that genuinely reduce their count do one specific thing differently: they make removal a condition of the purchase. The business case for the new platform names the products it replaces and the date they are switched off, and the project is not closed until they are gone. It is not a clever technique. It is simply putting the hard half in the same document as the easy half.

The only section that kept growing

1,831 reports were filed here, more than any other section of this archive, and the shape of that curve is unlike all the others.

Reports in this section, by year
2015201620172018201920202021
134162176319319321361

Every technical subject in this archive peaks and declines. Application security crests in 2019, connected devices in 2019, mobile as early as 2015. This one rises through the whole period and finishes at its highest point, which is not the shape of a topic and is very much the shape of an output.

What fills it is surveys. The word appears in 146 of these reports — a research finding announced, a percentage in the headline, a supplier credited in the final line. Read fifty in sequence and the genre becomes unmistakable: a question was asked of an unstated population, a figure emerged, and the figure supports buying something.

Cyber security becomes a boardroom issue for retailers, November 26, 2014, is an ordinary example rather than an egregious one, which is the point. There is nothing wrong with any individual piece of it. The volume is the phenomenon.

That volume also explains something about the rest of this site. The evidence base everybody works from — how many organisations were breached, how long detection took, what a breach costs — comes overwhelmingly from this genre. It is not worthless; it is the only measurement anybody funds. But it is produced by parties with an interest in the answer, and almost none of it could be reproduced by somebody else.

Does buying more reduce risk?

Nobody can demonstrate it either way at the level of a whole portfolio, and the reason is worth stating precisely rather than treating as cynicism.

Individual controls have evidence. Phishing-resistant authentication removes a category of loss and this is demonstrable. Offsite backups change ransomware outcomes measurably. Reachability analysis shortens a queue without lowering a standard. Those claims can be tested against what happens, and several other pages on this site rest on exactly that kind of evidence.

What has no evidence behind it is the aggregate: that an organisation spending twice as much is meaningfully safer than one spending half. To establish that you would need an outcome measure comparable across organisations, and the field does not have one. Breach counts are dominated by what gets disclosed. Incident counts are dominated by what gets detected, which is a function of tooling — so buying more detection raises your incident count, which is the opposite of the direction the measure would need to run.

That absence is the deepest problem in this section, and it is not going to be solved by the parties currently producing the figures. It is why the useful question for a specific purchase is never whether it improves security in general, but what it does that you can observe: which class of event stops happening, which piece of work stops being manual, which question becomes answerable in minutes.

Reading a figure in this field

Four questions, in order, and most published statistics do not survive the first.

Who was asked, and how many? A finding drawn from three hundred respondents recruited through a supplier's own customer list describes that supplier's customers. The population is frequently absent from the write-up entirely.

What exactly was the question? The wording carries most of the result.Have you experienced a security incident and have you experienced a breach return figures that differ by a factor, and both get reported as breaches.

Who paid for it? Not disqualifying, and it should be on the page. Research commissioned by a company selling the remedy is worth reading with the same care as a clinical trial run by the manufacturer, which is to say carefully rather than not at all.

Could somebody else reproduce this? The decisive test. If the method is described well enough that another party could run it and get a comparable answer, the figure is a measurement. If not, it is an assertion with a decimal point, and it should be quoted as one.

Applying those four to the numbers on this page is instructive. The tool-count range fails the fourth outright. The market size fails the fourth. The transaction counts largely pass, because deals are public events that anybody can enumerate — which is why the least discussed figures in this section are the most solid.

What happens to a product after it is bought

With over a hundred and fifty tracked transactions in a single quarter, this is not an edge case to plan around. It is the base case for any supplier you choose today.

The pattern is consistent enough to be worth writing down. In the first year the product continues unchanged and both parties say the roadmap is safe. Around the eighteen-month mark the founders and much of the original engineering team reach the end of their retention and leave. Pricing moves into a bundle, which is presented as value and functions as a rise for anybody who wanted only this part. Integration work consumes the roadmap for a year, during which nothing the customer asked for ships. Sometimes the product is retired and customers are migrated to an adjacent one that does most of what they had.

None of that is misconduct. It is what acquisition is for, and the acquirer is buying a customer base and a capability to fold into a platform rather than a commitment to keep operating an independent product line.

The consequence for a buyer is that the evaluation should include a question that rarely appears in one. Not is this company stable, which invites a reassuring answer, but what do we do if this is acquired next year — and the answer has to be in terms of your data, your detections and your contract rather than in terms of trust.

Are analyst rankings worth anything?

As an input, genuinely yes. As a decision, genuinely no, and the distinction is where a great deal of money goes wrong.

What they do well is survey a category. Somebody has spoken to most of the suppliers, understood roughly what each does, and produced a map of a space you may be entering for the first time. Building that yourself would take weeks. Using it to assemble a shortlist is an efficient use of somebody else's work.

What they cannot do is know your estate. Position is assessed against a generic model of what a complete product in the category looks like, so a supplier that does one thing superbly and the other nine not at all scores badly while being exactly right for an organisation that needs the one thing. Inclusion also generally requires revenue and customer-count thresholds, which systematically excludes newer and smaller suppliers regardless of fit.

The failure mode to name is procurement by leader quadrant: a shortlist assembled from the top-right corner, a comparison of vendors that are similar because they were selected for similarity, and a purchase that satisfies the process without anybody having asked which specific problem it removes. Ranking is a map. The decision needs the destination.

Buying so that leaving is possible

Given the transaction volume, the only durable protection is arranging in advance that departure is affordable. Four clauses do most of the work.

Your data leaves in a documented format. Not an export button that produces something proprietary — a specified schema, retrievable in bulk, tested once during the first year rather than discovered during the last.

Detections and policies are expressible outside the product. Two years of tuning is the real switching cost, far more than the licence. If that work lives only inside the vendor's console, the renewal is not a negotiation.

Exit at renewal carries no engineered penalty. Multi-year terms with steep early-termination clauses and bundled pricing that collapses if one component is dropped are all mechanisms for making the second conversation easier than the first. They are negotiable at signature and not afterwards.

None of these four is unusual to ask for, and the reason they are rarely in contracts is that nobody raises them while the relationship is new and everybody is enthusiastic. That is precisely when they are cheap: a supplier competing for the business will concede terms that the same supplier, three years in and holding your detection library, has no reason to discuss.

Acquisition is addressed explicitly. Ask what happens to your terms if the company changes hands, and get the answer in the contract. It is a reasonable question, it is asked routinely in other industries, and the reaction to it tells you something on its own.

Where to start on a Monday

Three exercises, all internal, none requiring a supplier conversation.

Count your own tools twice. Once as consoles somebody signs into weekly, once as everything installed or licensed. Write both numbers down with their definitions attached. That pair is more useful in a board paper than any published average, and it is the only version of the figure you can defend.

Take the last statistic you cited and try the four questions on it. Who was asked, what exactly, who paid, could anybody reproduce it. Doing this once changes how the next one reads.

Pick your most critical supplier and ask how you would leave. Not as a threat — as an exercise. How does the data come out, where do the detections live, what does the contract say about a change of ownership. Most organisations discover they could not leave, which is worth knowing before the question is urgent.

After those three the harder work is prioritisable: making removal a condition of every purchase, building the one outcome measure you can actually observe, and renegotiating the terms that were signed when nobody was thinking about exit. An organisation that has done the first three can say what it owns and what it would cost to change its mind, which is more than the figures in this section can say about anything.

A closing note on tone, because a page like this invites the wrong conclusion. None of the above argues that the products do not work, that the people producing the research are acting badly, or that spending is wasted. Several controls this site recommends elsewhere are sold by the companies described here, and they work. The argument is narrower and harder to dismiss: an industry whose entire proposition is rigour about evidence has not applied that rigour to its own numbers, and until it does, every figure quoted about it — including the ones on this page — should be read as a claim rather than as a count.

Common questions

How many security tools does an organisation actually run?

Published answers range from about 45 to over 130 for the same question, and the spread is a definition problem rather than a difference between organisations. Almost none of those figures states whether it counts suite modules separately, includes capabilities bought and never enabled, or counts tools owned by other teams.

How large is the market?

Published estimates for 2026 sit between roughly $240bn and $288bn, a gap of about $48bn between sources describing the same year. Growth is quoted at 12.5% and at 15.1% for overlapping periods, which cannot both be measuring the same thing.

Why do the numbers disagree so much?

Because there is no agreed definition of what counts and no independent auditor. Most figures come from organisations with a commercial interest in the answer being large, and methodologies are rarely published in a form anybody could reproduce.

Is consolidation actually happening?

Intent is nearly universal — around three quarters of organisations report pursuing it — and completion is rare. Buying is faster than removing, because removing requires proving nothing depended on the thing you are switching off.

Does spending more reduce risk?

The honest answer is that nobody can demonstrate it either way at portfolio level, because the outcome measure does not exist. Individual controls have evidence behind them; total spend as a predictor of breach outcomes does not, and the industry has not built the measurement that would settle it.

What does a funding round mean for a buyer?

It is a signal about investor confidence and a commitment to grow at a rate that eventually requires an exit. For a customer it usually means the product will improve for two or three years and then be acquired, after which the roadmap belongs to somebody else.

What happens to a product after acquisition?

Typically it is integrated into a platform, its pricing moves into a bundle, its independent roadmap ends and the people who built it leave within about eighteen months. Sometimes the product is retired outright and customers are migrated to an adjacent one.

Are analyst rankings worth anything?

As a shortlist, yes. As a purchase decision, no. They measure vendor completeness against a generic model of the category rather than fit against your estate, and inclusion generally requires revenue thresholds that exclude smaller suppliers who may suit you better.

How should a vendor-published statistic be read?

Ask who was surveyed, how many, whether respondents were customers, what exactly was asked, and whether the methodology is published. A figure that survives those four questions is worth citing; most do not survive the first.

What is the skills gap figure about?

It is the industry's oldest recurring statistic and among its least reproducible. The number counts unfilled postings rather than unmet need, which conflates a shortage of people with a shortage of people willing to work at the offered terms.

How do you buy so that leaving is possible?

Insist that your data can be exported in a documented format, that detections and policies are expressible outside the product, and that the contract permits exit at renewal without a penalty designed to prevent it. Ask what happens if this vendor is acquired.

Is there any independently audited figure in this field?

Very few. Breach notification counts from regulators and court filings are among the small number produced by parties without a product to sell, which is why they are worth more than their sample sizes suggest.

Industry and market coverage

1,831 reports, newest first. Most cited sources: helpnetsecurity.com (352), infosecurity-magazine.com (107), itproportal.com (64), informationsecuritybuzz.com (43), forbes.com (42), cisomag.eccouncil.org (41).