Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Gartner forecast worldwide end-user spending on information security at $213.025 billion in 2025, above the $200 billion mark. That was a forecast published on July 29, 2025—not a verified final tally. Gartner’s subsequent figure in the same forecast was about $239.759 billion for 2026.
What Gartner’s $213 billion figure measures
Gartner’s measure is worldwide end-user spending on information security: money organisations spend on security software, security services and network security. It is not the total cost of cybercrime, a tally of every government or military security budget, or all revenue associated with cybersecurity. The figures below are Gartner’s July 2025 forecasts for calendar years, not audited actual spending. Gartner’s July 29, 2025 announcement gives the category breakdown.
The headline’s “this year” meant 2025, the year of the original report. It should not be read as a current-year claim. Gartner’s figures were $193.408 billion for 2024, $213.025 billion for 2025 and $239.759 billion for 2026.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Where the forecast spending goes
| Category | 2024 | 2025 forecast | 2026 forecast |
|---|---|---|---|
| Network security | $21.317bn | $23.273bn | $25.825bn |
| Security services | $77.130bn | $83.812bn | $92.780bn |
| Security software | $94.960bn | $105.940bn | $121.154bn |
| Total | $193.408bn | $213.025bn | $239.759bn |
All values are Gartner’s July 2025 forecast snapshot. Security software was the largest category and had the largest projected dollar increase from 2024 to 2026. Gartner identified cloud security posture management and cloud access security broker capabilities as growth areas in that segment. Security services include external expertise and support such as managed services, implementation and consulting; they are not simply software licences.
#1 Best Overall
Why spending is expected to rise
Gartner pointed to a mix of expanding digital exposure, persistent threats and obligations on organisations—not one single cause. Cloud migration moves systems, identities, applications and data into environments that need ongoing security controls. Gartner also cited the increased use of AI and generative AI by employees and threat actors, regulatory pressure, higher defence budgets and stronger cybersecurity awareness among small and medium-sized businesses.
AI has two implications for budgets. Organisations may spend on AI-assisted detection, investigation and automation, while also needing to manage risks around data access, model use, agent permissions and sensitive information. Attackers’ use of AI adds pressure, but the forecast does not establish AI as the sole or dominant driver of market growth.
Does a larger security market mean organisations are safer?
No. A market-spending forecast says nothing by itself about whether breaches are falling or defences are working. Outcomes depend on whether tools cover the right assets, are configured and integrated properly, and are operated by people who can investigate and respond. More products can even add complexity if they generate overlapping alerts or leave monitoring queues unstaffed.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchNor does the forecast prove that organisations are overspending. Gartner’s commentary, reported by Computer Weekly on July 29, 2025, described continued spending on established security needs alongside caution about some new spending in an uncertain economy. The useful question for a buyer is whether a proposed expense closes a meaningful gap, meets a real obligation, or improves a measurable security or recovery outcome.
Rank #3
How to assess the next security purchase
Use a risk-and-operations case rather than a global market number to justify a purchase. Before committing, check:
- Risk exposure: Which important systems, data, identities, suppliers and cloud services would the purchase protect?
- Coverage and effectiveness: What assets are included, what existing control gap will close, and how will effectiveness be verified?
- Operational capacity: Who will configure the tool, review its alerts, investigate findings and act on escalations?
- Integration: Does it work with the organisation’s identity, endpoint, cloud, logging, ticketing and backup environments?
- Total cost and exit: Account for implementation, training, migration, retention and renewal costs; check whether data and policies can be exported if the supplier changes.
- Outcome measures: Define relevant measures such as multifactor-authentication coverage, time to patch critical flaws, time to detect and contain incidents, privileged-account exposure and tested backup recovery.
Common traps include buying overlapping tools because they advertise AI, counting licences instead of protected assets, deploying a detection platform without enough telemetry or analysts, treating compliance evidence as proof of security, and overlooking identity or configuration weaknesses while adding perimeter products. A cloud-security dashboard cannot replace clear ownership and timely remediation; a recovery plan should be tested rather than assumed to work.
Rank #4
For smaller organisations
Gartner cited increased cybersecurity awareness among small and medium-sized businesses as one source of longer-term spending growth. That is not a recommendation to buy enterprise-scale tooling. Smaller organisations can prioritise foundational controls and use outside help where internal expertise is limited:
- Secure accounts with strong identity controls and multifactor authentication.
- Maintain an inventory of devices and services, and patch them reliably.
- Protect endpoints and maintain backups that can be recovered after an incident.
- Apply email and web-threat protection, and make sure important activity is logged.
- Set an incident-response process, including who makes decisions and whom to contact.
- Provide security awareness appropriate to the organisation’s work and risks.
- Consider managed support if nobody internally can monitor, investigate and respond; define telemetry access, escalation expectations and decision authority before signing.
What the 2025 forecast says—and does not say—about growth
The displayed Gartner table moves from $193.408 billion in 2024 to $213.025 billion in 2025, an increase of about 10.1% when calculated from those rounded figures. Gartner’s underlying research abstract describes 2025 growth as 10.7%. Those percentages do not match exactly, so they should not be treated as interchangeable: the abstract and displayed table appear to use different precision or presentation conventions. The key point is that Gartner’s forecast remained above $200 billion despite a more cautious environment.
Best Value
Computer Weekly reported that the July 2025 estimate was slightly above Gartner’s August 2024 forecast of $212 billion. A one-billion-dollar revision is less important than the uncertainty inherent in forecasts: these estimates describe Gartner’s expectations at publication, not a final account of what organisations ultimately spent.
Gartner’s outlook beyond 2025
Gartner forecast approximately $239.759 billion in worldwide end-user information-security spending for 2026. Its longer-term research abstract projected approximately $323 billion by 2029. That 2029 figure is a forecast, not a certainty or a reported actual. Gartner’s forecast abstract provides the longer-range projection.
For organisations, these market totals are context, not budget targets. The case for spending rests on which risks matter to a particular business, whether a control can be operated effectively, and whether it improves prevention, detection, response or recovery.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

