So What Club
Start free
Cybersecurity
Lesson 1 of 3 Last reviewed 30 September 2026 10 min

How the cybersecurity industry works

The threats, the buyers, the product categories, the value chain from vendor to security team, and where the money goes.

Industry brief, with a one-minute summary: Cybersecurity

Firm processes and online tests change from year to year and differ by office. Use this to prepare, and confirm the exact current steps on the firm's own careers page.

Key takeaways

  • Cybersecurity is money spent to lower the chance and the cost of a very bad day: data stolen, systems locked, a factory or hospital stopped.
  • Exploiting vulnerabilities reached about 31 percent of breaches, overtaking stolen credentials.
  • Many companies cannot hire enough skilled analysts to run a security operations centre 24 hours a day, so they pay a provider that shares its team across many customers.

Key idea

Cybersecurity is money spent to lower the chance and the cost of a very bad day: data stolen, systems locked, a factory or hospital stopped. Buyers pay because the threat keeps growing, because regulators and insurers demand it, and because boards are now held responsible. Sellers are mostly software subscription businesses, plus the service firms that run security for customers who cannot.

The main threats: ransomware (criminals lock or steal a company's data and demand payment), phishing and stolen passwords (tricking people into handing over access), exploiting software vulnerabilities (flaws in software that attackers use before they are fixed), attacks through suppliers and partners, insiders, and espionage by state-backed groups. Verizon's 2026 Data Breach Investigations Report finds that exploiting vulnerabilities overtook stolen passwords as the top way attackers get in, at about 31 percent of breaches, and that ransomware was involved in about 48 percent of breaches. IBM's 2026 study puts the average cost of a data breach at about USD 4.99 million worldwide, a record.

Main cybersecurity product categories in plain words
Main cybersecurity product categories in plain words
CategoryWhat it protects or doesExamples of vendors
Endpoint security (EDR)Watches laptops, phones and servers for attacks and stops themCrowdStrike, Microsoft, SentinelOne, Sophos
Network security (firewalls)Controls traffic in and out of the company networkPalo Alto Networks, Fortinet, Check Point, Cisco
Identity and accessChecks who someone is and what they may reach (passwords, multi-factor login, privileged accounts)Microsoft, Okta, CyberArk (now part of Palo Alto Networks)
Cloud securityFinds risky settings and attacks in cloud accounts and softwareWiz (now part of Google), Palo Alto Networks, CrowdStrike
Security operations (SIEM)Collects alerts and logs from everywhere so analysts can spot and respond to attacksSplunk (Cisco), Microsoft, Google
Email and web securityBlocks phishing and harmful websitesProofpoint, Zscaler, Cloudflare
ServicesConsulting, managed security (a provider watches the customer's systems around the clock), incident responseAccenture, Deloitte, IBM, TCS, Help AG, Ensign InfoSecurity

So-what

Customers use dozens of tools from many vendors. Much of the industry's strategy since 2024 is about selling several categories as one platform.

The cybersecurity value chain
  • From threat research to a protected company
    • Threat research and detection dataVendors and specialists study attacks; more customers means more data to spot new ones.
    • Key: Security software vendorsBuild products, sold mostly as subscriptions per device, per user or per volume of data.
    • Distributors and resellersSell and bundle products to smaller customers in each country.
    • Key: Managed security and consultingRun security operations centres (SOCs) around the clock, advise, and respond to incidents.
    • The customer's security teamLed by a chief information security officer (CISO), who sets the budget and picks vendors.
    • Cyber insurance and incident responseInsurers pay for some breach costs and increasingly require basic controls before they cover a company.

Software vendors earn the highest margins; services firms earn from the shortage of skilled people.

Worldwide spending on information security (Gartner forecast, July 2025)
Worldwide spending on information security (Gartner forecast, July 2025)
Segment202420252026 forecast
Security softwareAbout USD 95 billionAbout USD 106 billionAbout USD 121 billion
Security servicesAbout USD 77 billionAbout USD 84 billionAbout USD 93 billion
Network securityAbout USD 21 billionAbout USD 23 billionAbout USD 26 billion
TotalAbout USD 193 billionAbout USD 213 billionAbout USD 240 billion

So-what

Spending grows about 10 to 13 percent a year, faster than IT spending as a whole, and software grows fastest as companies move to the cloud. Later Gartner updates raised the 2026 figure slightly.

Check your understanding

According to Verizon's 2026 report, what became the most common way attackers first get in?

Check your understanding

What does a managed security service provider do?

Sources for this lesson (4)
My notes on this lesson

0 of 5,000 characters. Saves automatically.

Try the 2 remaining checks and drills above to complete this lesson (0 of 2 done).

Spotted something wrong or out of date? Report a mistake. We check every report and correct the page.