Cybersecurity: players, trends, rules and cases
Who the players are by region, consolidation and AI from 2024 to 2026, the rules that drive spending, and typical case prompts.
Industry brief, with a one-minute summary: CybersecurityFirm processes and online tests change from year to year and differ by office. Use this to prepare, and confirm the exact current steps on the firm's own careers page.
Key takeaways
- Cybersecurity demand is steady because threats and rules keep rising.
- Common traps: Treating security as a pure IT cost instead of a risk decision with an expected loss.
- Breaches cost more. IBM's 2026 study puts the average cost of a breach at a record USD 4.99 million, up about 12 percent on the previous year's USD 4.44 million (IBM).
- Attackers moved to software flaws.
Key idea
Cybersecurity demand is steady because threats and rules keep rising. The fight among vendors is about becoming the customer's main platform, and the biggest deals of 2025 and 2026 were platforms buying the pieces they lacked.
| Region | Examples |
|---|---|
| United States | Palo Alto Networks, CrowdStrike, Fortinet, Zscaler, Microsoft, Cisco (with Splunk), Google (with Mandiant and Wiz), Okta, Cloudflare, SentinelOne |
| Israel | Check Point; birthplace of many security firms, including Wiz and CyberArk before they were bought |
| Europe | Thales (France), Sophos and Darktrace (UK, both owned by private equity), WithSecure (Finland, taken private in 2025), ESET (Slovakia) |
| Middle East | Help AG (part of e&, UAE), CPX (UAE), sirar by stc (Saudi Arabia); national regulators such as the UAE Cyber Security Council and Saudi Arabia's National Cybersecurity Authority |
| India | Quick Heal and its Seqrite brand; managed security from TCS, Infosys, Wipro and HCLTech; CERT-In as the national agency |
| Southeast Asia | Ensign InfoSecurity and ST Engineering (Singapore); Singapore's Cyber Security Agency as a regional reference |
So-what
Gartner expects information security spending of about USD 4 billion in the Middle East and North Africa and about USD 3.4 billion in India in 2026, both growing about 10 to 12 percent a year.
Trends from 2024 to 2026 (checked 30 September 2026)
- Spending keeps growing. Gartner forecast worldwide information security spending of about USD 213 billion in 2025 and about USD 240 billion in 2026, up about 12.5 percent, with later updates slightly higher (Gartner).
- Breaches cost more. IBM's 2026 study puts the average cost of a breach at a record USD 4.99 million, up about 12 percent on the previous year's USD 4.44 million (IBM).
- Attackers moved to software flaws. Verizon's 2026 report finds exploiting vulnerabilities is now the top way in, at about 31 percent of breaches, with ransomware in about 48 percent of breaches and generative AI used across a growing number of attack techniques (Verizon).
- Consolidation through big deals. Palo Alto Networks completed its roughly USD 25 billion purchase of CyberArk (identity security) in February 2026, and Google completed its USD 32 billion purchase of Wiz (cloud security) in March 2026, Google's largest acquisition (as reported).
- A reminder of concentration risk. A faulty CrowdStrike update in July 2024 crashed about 8.5 million Windows devices worldwide, stopping airlines, banks and hospitals (Microsoft). CrowdStrike kept its customers: it reported ARR of about USD 5.84 billion at the end of July 2026, up 25 percent, with a subscription gross margin of about 78 percent (81 percent on its adjusted measure) (CrowdStrike).
- AI on both sides. Vendors add AI assistants to help analysts; attackers use AI for more convincing phishing and faster attacks; and companies now buy security for their own AI systems and agents.
In the EU, the NIS2 directive widens cybersecurity duties to many more sectors and makes management responsible, and DORA sets digital resilience rules for banks, insurers and their technology suppliers, applying since January 2025. In the US, listed companies must disclose a material cyber incident within four business days under SEC rules adopted in 2023. India's CERT-In directions of 2022 require many organisations to report cyber incidents within 6 hours. Saudi Arabia's National Cybersecurity Authority sets controls for government and critical sectors, the UAE has a national Cyber Security Council, and Singapore updated its Cybersecurity Act in 2024. Data protection laws such as the GDPR add fines for leaking personal data.
| Case prompt | Structure hint | First driver to check |
|---|---|---|
| A security vendor's growth is slowing. Why? | ARR bridge: new, expansion, churn; by product and segment; competition from platforms | Whether new wins or expansion slowed, and in which product |
| Should a point-product vendor build a platform or sell itself? | Customer demand for bundles, product gaps, cost to build versus buy, likely buyers and price | How often it loses deals to bundled platform offers |
| A bank asks how much to spend on cybersecurity | Threats and regulation, current controls, expected loss by scenario, peers, insurance | The regulatory minimum and the largest expected-loss scenario |
| Should an IT services firm in India enter managed security in the Gulf? | Market size and growth, local rules and data residency, partners, skills, pricing | Whether local rules require in-country operations and staff |
| Due diligence on a cybersecurity SaaS target | Retention and expansion, gross margin, product strength, platform risk, team | Gross and net revenue retention by customer group |
So-what
For vendors, start with the ARR bridge and retention. For buyers, start with regulation and expected loss.
Treating security as a pure IT cost instead of a risk decision with an expected loss. Assuming more tools mean more safety: many breaches come from basic gaps such as unpatched software and missing multi-factor login. Forgetting people and process: tools need analysts to act on alerts. Ignoring regulation, which often sets the minimum spend and deadlines. In vendor cases, missing the threat of large platforms bundling a similar product at little extra cost.
IBM put the average cost of a data breach at USD 4.44 million in its 2025 study and USD 4.99 million in its 2026 study. By what percent did it rise? Round to one decimal place.
Related modules: "Software and SaaS" covers ARR, retention and the rule of 40 in more depth; "Data centres, cloud and AI compute" covers the cloud platforms security vendors protect; "Banking" and "Insurance" cover two of the largest buyers and cyber insurance. Case types that fit: "Unit economics and subscription businesses", "Mergers, acquisitions, and due diligence" and "Digital and AI transformation".
Why did Palo Alto Networks buy CyberArk and Google buy Wiz?
A company in India suffers a serious cyber incident. What does CERT-In require?
Sources for this lesson (16)
- Gartner: worldwide end-user spending on information security to total USD 213 billion in 2025, with a table by segment to 2026 (July 2025, official press release)
- Gartner: information security spending in India to total USD 3.4 billion in 2026 (March 2026, official press release)
- Gartner: MENA end-user spending on information security to total USD 4 billion in 2026 (October 2025, official press release)
- IBM: Cost of a Data Breach Report 2026 (official report page)
- eSecurity Planet: IBM 2026 Cost of a Data Breach Report, key findings including the US average
- IBM Middle East and Africa newsroom: Cost of a Data Breach 2026, Middle East findings, average USD 8 million (3 August 2026, official)
- Verizon: 2026 Data Breach Investigations Report (official report page)
- CrowdStrike: second quarter fiscal year 2027 financial results, quarter ended 31 July 2026 (official)
- Microsoft: helping our customers through the CrowdStrike outage, 8.5 million Windows devices affected (July 2024, official blog)
- Cleary Gottlieb: Google completes USD 32 billion acquisition of Wiz (March 2026)
- CRN Asia: Palo Alto Networks completes USD 25 billion acquisition of CyberArk (February 2026)
- EUR-Lex: Directive (EU) 2022/2555 (NIS2) on a high common level of cybersecurity across the Union (official)
- EUR-Lex: Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) (official)
- US Securities and Exchange Commission: SEC adopts rules on cybersecurity risk management and incident disclosure (July 2023, official)
- CERT-In, Government of India: directions of 28 April 2022 on reporting cyber incidents within 6 hours (official)
- Recognized public explanations of case-interview concepts and frameworks
My notes on this lesson
0 of 5,000 characters. Saves automatically.
Try the 3 remaining checks and drills above to complete this lesson (0 of 3 done).
Spotted something wrong or out of date? Report a mistake. We check every report and correct the page.