How the cybersecurity industry works
The threats, the buyers, the product categories, the value chain from vendor to security team, and where the money goes.
Industry brief, with a one-minute summary: CybersecurityFirm processes and online tests change from year to year and differ by office. Use this to prepare, and confirm the exact current steps on the firm's own careers page.
Key takeaways
- Cybersecurity is money spent to lower the chance and the cost of a very bad day: data stolen, systems locked, a factory or hospital stopped.
- Exploiting vulnerabilities reached about 31 percent of breaches, overtaking stolen credentials.
- Many companies cannot hire enough skilled analysts to run a security operations centre 24 hours a day, so they pay a provider that shares its team across many customers.
Key idea
Cybersecurity is money spent to lower the chance and the cost of a very bad day: data stolen, systems locked, a factory or hospital stopped. Buyers pay because the threat keeps growing, because regulators and insurers demand it, and because boards are now held responsible. Sellers are mostly software subscription businesses, plus the service firms that run security for customers who cannot.
The main threats: ransomware (criminals lock or steal a company's data and demand payment), phishing and stolen passwords (tricking people into handing over access), exploiting software vulnerabilities (flaws in software that attackers use before they are fixed), attacks through suppliers and partners, insiders, and espionage by state-backed groups. Verizon's 2026 Data Breach Investigations Report finds that exploiting vulnerabilities overtook stolen passwords as the top way attackers get in, at about 31 percent of breaches, and that ransomware was involved in about 48 percent of breaches. IBM's 2026 study puts the average cost of a data breach at about USD 4.99 million worldwide, a record.
| Category | What it protects or does | Examples of vendors |
|---|---|---|
| Endpoint security (EDR) | Watches laptops, phones and servers for attacks and stops them | CrowdStrike, Microsoft, SentinelOne, Sophos |
| Network security (firewalls) | Controls traffic in and out of the company network | Palo Alto Networks, Fortinet, Check Point, Cisco |
| Identity and access | Checks who someone is and what they may reach (passwords, multi-factor login, privileged accounts) | Microsoft, Okta, CyberArk (now part of Palo Alto Networks) |
| Cloud security | Finds risky settings and attacks in cloud accounts and software | Wiz (now part of Google), Palo Alto Networks, CrowdStrike |
| Security operations (SIEM) | Collects alerts and logs from everywhere so analysts can spot and respond to attacks | Splunk (Cisco), Microsoft, Google |
| Email and web security | Blocks phishing and harmful websites | Proofpoint, Zscaler, Cloudflare |
| Services | Consulting, managed security (a provider watches the customer's systems around the clock), incident response | Accenture, Deloitte, IBM, TCS, Help AG, Ensign InfoSecurity |
So-what
Customers use dozens of tools from many vendors. Much of the industry's strategy since 2024 is about selling several categories as one platform.
- From threat research to a protected company
- Threat research and detection dataVendors and specialists study attacks; more customers means more data to spot new ones.
- Key: Security software vendorsBuild products, sold mostly as subscriptions per device, per user or per volume of data.
- Distributors and resellersSell and bundle products to smaller customers in each country.
- Key: Managed security and consultingRun security operations centres (SOCs) around the clock, advise, and respond to incidents.
- The customer's security teamLed by a chief information security officer (CISO), who sets the budget and picks vendors.
- Cyber insurance and incident responseInsurers pay for some breach costs and increasingly require basic controls before they cover a company.
Software vendors earn the highest margins; services firms earn from the shortage of skilled people.
| Segment | 2024 | 2025 | 2026 forecast |
|---|---|---|---|
| Security software | About USD 95 billion | About USD 106 billion | About USD 121 billion |
| Security services | About USD 77 billion | About USD 84 billion | About USD 93 billion |
| Network security | About USD 21 billion | About USD 23 billion | About USD 26 billion |
| Total | About USD 193 billion | About USD 213 billion | About USD 240 billion |
So-what
Spending grows about 10 to 13 percent a year, faster than IT spending as a whole, and software grows fastest as companies move to the cloud. Later Gartner updates raised the 2026 figure slightly.
According to Verizon's 2026 report, what became the most common way attackers first get in?
What does a managed security service provider do?
Sources for this lesson (4)
- Gartner: worldwide end-user spending on information security to total USD 213 billion in 2025, with a table by segment to 2026 (July 2025, official press release)
- Verizon: 2026 Data Breach Investigations Report (official report page)
- IBM: Cost of a Data Breach Report 2026 (official report page)
- Recognized public explanations of case-interview concepts and frameworks
My notes on this lesson
0 of 5,000 characters. Saves automatically.
Try the 2 remaining checks and drills above to complete this lesson (0 of 2 done).
Spotted something wrong or out of date? Report a mistake. We check every report and correct the page.