So What Club
Start free
Cybersecurity
Lesson 3 of 3 Math checked Last reviewed 30 September 2026 11 min

Cybersecurity: players, trends, rules and cases

Who the players are by region, consolidation and AI from 2024 to 2026, the rules that drive spending, and typical case prompts.

Industry brief, with a one-minute summary: Cybersecurity

Firm processes and online tests change from year to year and differ by office. Use this to prepare, and confirm the exact current steps on the firm's own careers page.

Key takeaways

  • Cybersecurity demand is steady because threats and rules keep rising.
  • Common traps: Treating security as a pure IT cost instead of a risk decision with an expected loss.
  • Breaches cost more. IBM's 2026 study puts the average cost of a breach at a record USD 4.99 million, up about 12 percent on the previous year's USD 4.44 million (IBM).
  • Attackers moved to software flaws.

Key idea

Cybersecurity demand is steady because threats and rules keep rising. The fight among vendors is about becoming the customer's main platform, and the biggest deals of 2025 and 2026 were platforms buying the pieces they lacked.

Examples of cybersecurity players by region (not a ranking)
Examples of cybersecurity players by region (not a ranking)
RegionExamples
United StatesPalo Alto Networks, CrowdStrike, Fortinet, Zscaler, Microsoft, Cisco (with Splunk), Google (with Mandiant and Wiz), Okta, Cloudflare, SentinelOne
IsraelCheck Point; birthplace of many security firms, including Wiz and CyberArk before they were bought
EuropeThales (France), Sophos and Darktrace (UK, both owned by private equity), WithSecure (Finland, taken private in 2025), ESET (Slovakia)
Middle EastHelp AG (part of e&, UAE), CPX (UAE), sirar by stc (Saudi Arabia); national regulators such as the UAE Cyber Security Council and Saudi Arabia's National Cybersecurity Authority
IndiaQuick Heal and its Seqrite brand; managed security from TCS, Infosys, Wipro and HCLTech; CERT-In as the national agency
Southeast AsiaEnsign InfoSecurity and ST Engineering (Singapore); Singapore's Cyber Security Agency as a regional reference

So-what

Gartner expects information security spending of about USD 4 billion in the Middle East and North Africa and about USD 3.4 billion in India in 2026, both growing about 10 to 12 percent a year.

Trends from 2024 to 2026 (checked 30 September 2026)

  • Spending keeps growing. Gartner forecast worldwide information security spending of about USD 213 billion in 2025 and about USD 240 billion in 2026, up about 12.5 percent, with later updates slightly higher (Gartner).
  • Breaches cost more. IBM's 2026 study puts the average cost of a breach at a record USD 4.99 million, up about 12 percent on the previous year's USD 4.44 million (IBM).
  • Attackers moved to software flaws. Verizon's 2026 report finds exploiting vulnerabilities is now the top way in, at about 31 percent of breaches, with ransomware in about 48 percent of breaches and generative AI used across a growing number of attack techniques (Verizon).
  • Consolidation through big deals. Palo Alto Networks completed its roughly USD 25 billion purchase of CyberArk (identity security) in February 2026, and Google completed its USD 32 billion purchase of Wiz (cloud security) in March 2026, Google's largest acquisition (as reported).
  • A reminder of concentration risk. A faulty CrowdStrike update in July 2024 crashed about 8.5 million Windows devices worldwide, stopping airlines, banks and hospitals (Microsoft). CrowdStrike kept its customers: it reported ARR of about USD 5.84 billion at the end of July 2026, up 25 percent, with a subscription gross margin of about 78 percent (81 percent on its adjusted measure) (CrowdStrike).
  • AI on both sides. Vendors add AI assistants to help analysts; attackers use AI for more convincing phishing and faster attacks; and companies now buy security for their own AI systems and agents.
Rules that drive spending (general, not legal advice)

In the EU, the NIS2 directive widens cybersecurity duties to many more sectors and makes management responsible, and DORA sets digital resilience rules for banks, insurers and their technology suppliers, applying since January 2025. In the US, listed companies must disclose a material cyber incident within four business days under SEC rules adopted in 2023. India's CERT-In directions of 2022 require many organisations to report cyber incidents within 6 hours. Saudi Arabia's National Cybersecurity Authority sets controls for government and critical sectors, the UAE has a national Cyber Security Council, and Singapore updated its Cybersecurity Act in 2024. Data protection laws such as the GDPR add fines for leaking personal data.

Typical cybersecurity case prompts and how to crack them
Typical cybersecurity case prompts and how to crack them
Case promptStructure hintFirst driver to check
A security vendor's growth is slowing. Why?ARR bridge: new, expansion, churn; by product and segment; competition from platformsWhether new wins or expansion slowed, and in which product
Should a point-product vendor build a platform or sell itself?Customer demand for bundles, product gaps, cost to build versus buy, likely buyers and priceHow often it loses deals to bundled platform offers
A bank asks how much to spend on cybersecurityThreats and regulation, current controls, expected loss by scenario, peers, insuranceThe regulatory minimum and the largest expected-loss scenario
Should an IT services firm in India enter managed security in the Gulf?Market size and growth, local rules and data residency, partners, skills, pricingWhether local rules require in-country operations and staff
Due diligence on a cybersecurity SaaS targetRetention and expansion, gross margin, product strength, platform risk, teamGross and net revenue retention by customer group

So-what

For vendors, start with the ARR bridge and retention. For buyers, start with regulation and expected loss.

Common traps

Treating security as a pure IT cost instead of a risk decision with an expected loss. Assuming more tools mean more safety: many breaches come from basic gaps such as unpatched software and missing multi-factor login. Forgetting people and process: tools need analysts to act on alerts. Ignoring regulation, which often sets the minimum spend and deadlines. In vendor cases, missing the threat of large platforms bundling a similar product at little extra cost.

Timed math drill

IBM put the average cost of a data breach at USD 4.44 million in its 2025 study and USD 4.99 million in its 2026 study. By what percent did it rise? Round to one decimal place.

Related modules: "Software and SaaS" covers ARR, retention and the rule of 40 in more depth; "Data centres, cloud and AI compute" covers the cloud platforms security vendors protect; "Banking" and "Insurance" cover two of the largest buyers and cyber insurance. Case types that fit: "Unit economics and subscription businesses", "Mergers, acquisitions, and due diligence" and "Digital and AI transformation".

Check your understanding

Why did Palo Alto Networks buy CyberArk and Google buy Wiz?

Check your understanding

A company in India suffers a serious cyber incident. What does CERT-In require?

Sources for this lesson (16)
My notes on this lesson

0 of 5,000 characters. Saves automatically.

Try the 3 remaining checks and drills above to complete this lesson (0 of 3 done).

Spotted something wrong or out of date? Report a mistake. We check every report and correct the page.