DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Blog

Gartner Forecast Cybersecurity-Service Spending Would Reach $86 Billion in 2025—But Later Estimates Shifted

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Gartner’s August 28, 2024 forecast projected worldwide spending on security services would rise from $74.478 billion in 2024 to $86.073 billion in 2025. The forecast was part of a broader prediction that total information-security spending would reach $211.552 billion, or roughly $212 billion, in 2025.

That headline remains useful as a snapshot of the market’s direction—but it should not be treated as Gartner’s final view. A July 2025 update put 2025 security-services spending at $83.812 billion and total information-security spending at $213.025 billion. In other words, security budgets remained strong, while the services estimate was revised lower.

What Gartner originally forecast

Gartner’s original forecast covered worldwide end-user spending, not vendor revenue, bookings or contract value. Its August 2024 release projected the following 2025 spending:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Category 2023 2024 2025 forecast 2025 growth
Security software $76.574 billion $87.481 billion $100.692 billion 15.1%
Security services $65.556 billion $74.478 billion $86.073 billion 15.6%*
Network security $19.985 billion $21.912 billion $24.787 billion 13.1%
Total information security $162.115 billion $183.872 billion $211.552 billion 15.1%

*Gartner’s table shows 15.6% growth for security services. A contemporaneous CRN report cited 13.8%. The accessible Gartner table is the primary source, but the discrepancy may reflect a different forecast version, rounding or a reporting error.

The original Gartner release described security software as the fastest-growing segment. Services were therefore not the largest category: software was forecast to generate about $100.7 billion, compared with $86.1 billion for services. The important point was that external expertise was expected to remain a major growth engine alongside software purchases.

What “security services” includes

Gartner’s security-services category is broader than managed detection and response, or MDR. It includes:

  • Managed security services: outsourced or co-managed monitoring and security operations.
  • Security consulting services: advice on risk, architecture, compliance, strategy and program design.
  • Security professional services: implementation, integration, incident response, assessments and other hands-on work.

That distinction matters when interpreting the $86.073 billion estimate. It does not mean organizations were collectively spending that amount on outsourced security operations or 24/7 SOC coverage. The category can include a short-term cloud-security assessment, a major identity implementation, a compliance engagement, a breach-response retainer or an ongoing MDR subscription.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why security-services demand was expected to rise

Cybersecurity talent shortages

Many organizations cannot recruit or retain enough experienced security engineers, threat hunters, incident responders and cloud-security specialists. Even companies with internal security teams may lack round-the-clock coverage or expertise in every technology they operate.

External providers can spread specialized analysts, threat intelligence, tooling and operating processes across multiple customers. That can give an organization access to capabilities it would struggle to build internally, although it does not automatically make outsourcing cheaper or better.

Cloud migration and expanding attack surfaces

Cloud adoption creates security work that is easy to underestimate: identity and access design, permissions, workload protection, logging, configuration monitoring, SaaS governance and incident response across providers. Gartner separately forecast worldwide public-cloud end-user spending would reach $723.421 billion in 2025, up from $595.652 billion in 2024.

As more applications and data move into cloud environments, buyers may need consulting to redesign controls, professional services to implement them and managed services to operate them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More complex and automated attacks

Attackers can use automation, identity abuse, cloud infrastructure and generative AI to increase the scale and speed of phishing, impersonation, reconnaissance, malware assistance and social engineering. Defenders must respond with better telemetry, faster investigation and more practiced containment procedures.

Gartner also predicted that by 2027, 17% of total cyberattacks and data leaks would involve generative AI. That wording does not mean 17% of attacks would be fully autonomous, nor that generative AI alone would cause that share. It means Gartner expected attacks or data leaks to involve generative-AI technologies.

Organizations are also securing their own AI use

AI expands the security-services market in two directions. Security teams need to defend against AI-assisted attacks, but they also need to secure their own AI systems, data, models, prompts, applications and employee usage.

That may require AI-security governance, access controls, data-loss prevention, monitoring, model-risk assessments and defenses against prompt injection. An MDR provider may help monitor activity, but conventional endpoint monitoring alone will not resolve every AI-governance or model-security problem.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Incident response and operational resilience

The July 2024 CrowdStrike outage also encouraged organizations to review endpoint-protection dependencies, recovery procedures, vendor concentration, detection-and-response arrangements and operational resilience. A managed provider can support detection and response, but resilience also depends on tested backups, identity recovery, communications plans and business-continuity procedures.

How the later forecast changed the picture

Gartner revised its outlook during 2025. Its July 29, 2025 forecast reported:

Category 2024 2025 forecast 2026 forecast
Network security $21.317 billion $23.273 billion $25.825 billion
Security services $77.130 billion $83.812 billion $92.780 billion
Security software $94.960 billion $105.940 billion $121.154 billion
Total information security $193.408 billion $213.025 billion $239.759 billion

Compared with the August 2024 forecast, the later estimate reduced projected 2025 security-services spending from $86.073 billion to $83.812 billion—about 2.6% lower—while increasing projected total security spending from $211.552 billion to $213.025 billion.

The revised figures also used a different 2024 baseline, so they are not a simple measurement of what happened between two identical forecasts. They show why dated market forecasts should be identified by publication date.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Gartner’s later research abstracts continued to show strong spending, but lower overall growth expectations: 12.4% in a first-quarter 2025 outlook, 10.7% in a third-quarter outlook and 10.4% in a fourth-quarter outlook. Gartner’s December 2024 abstract had cited approximately $211 billion in current dollars for 2025 and $294 billion by 2028, with 13.3% constant-currency growth in 2025.

Which security service fits which problem?

Managed detection and response

Consider MDR when: you need continuous monitoring, alert triage, threat hunting, investigation support and guided response without building a complete SOC.

Watch for: “24/7 monitoring” may not mean 24/7 hands-on remediation. Detection quality depends on endpoint, identity, email, cloud and network telemetry. Also clarify whether the provider can isolate endpoints or disable accounts, or whether it can only recommend action.

Managed security operations

This broader model may include SIEM administration, vulnerability management, endpoint and identity monitoring, cloud-security operations, policy maintenance and tool integration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The principal risk is unclear responsibility. A provider may operate the tools without owning business-risk decisions, risk acceptance or final remediation approval. Service-level agreements may promise alert acknowledgment rather than resolution.

Consulting

Consulting is generally appropriate for security-program design, risk assessments, compliance preparation, architecture reviews, cloud or zero-trust strategy, AI-security planning and executive reporting.

A strategy document does not create operational capacity. Buyers should also examine whether the consultant resells products and whether recommendations include implementation support, measurable outcomes and internal knowledge transfer.

Professional and implementation services

Professional services can help deploy a SIEM or XDR platform, modernize identity, configure cloud controls, segment networks, consolidate tools, prepare for incidents or improve data-security controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Projects can create expensive rework when permissions, data schemas, integrations or retention policies are incomplete. The customer should retain architecture documentation, administrative access and ownership of security configurations.

Incident-response and recovery retainers

A retainer can be valuable for organizations with high downtime or regulatory exposure, or those lacking forensic and crisis-management expertise. It is not cyber insurance, and it does not guarantee immediate availability unless the agreement specifies activation procedures, staffing and response commitments.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What cybersecurity services will not fix

  • Weak identity controls, missing multifactor authentication or excessive privileges.
  • Incomplete asset inventories and unmanaged endpoints.
  • Unpatched systems and poorly configured cloud resources.
  • Untested backups or an inability to recover identities and critical applications.
  • Unclear executive ownership of risk acceptance and business decisions.
  • A lack of internal documentation and dependence on one provider’s platform.

For a small business, a full SIEM or MDR program may be less urgent than securing identity, email, endpoints, patching and backups. An organization with an existing SOC may benefit more from co-managed operations than a fully outsourced model. A cloud-native company should verify that a provider understands cloud, identity, Kubernetes and SaaS environments rather than relying mainly on traditional network monitoring.

Buyer checklist for evaluating a provider

  1. Define the job: monitoring, investigation, containment, remediation, compliance, architecture, implementation or emergency response.
  2. Map coverage: confirm support for endpoints, identity, email, cloud workloads, SaaS applications, network devices and OT or IoT where relevant.
  3. Confirm telemetry requirements: identify required agents, SIEM ingestion, retention periods, API permissions and cloud-account access.
  4. Set response authority: determine whether the provider may isolate endpoints, disable accounts, block indicators or change firewall rules.
  5. Read the SLA definitions: distinguish alert acknowledgment, escalation, investigation, containment, reporting and critical-incident activation.
  6. Review staffing: ask about human analysts, automated triage, follow-the-sun coverage, delivery locations and named escalation contacts.
  7. Protect data: examine log location, subprocessors, cross-border transfers, retention, deletion and regulatory obligations.
  8. Measure outcomes: request definitions for response-time metrics, false-positive handling, detection coverage and customer references.
  9. Plan the exit: confirm whether you can export cases, detections, logs, playbooks and configurations, and who owns the tools and incident records.

How to interpret the spending surge

Rising spending is a market signal, not proof that every organization should buy more services or that every provider delivers equivalent value. Spending can rise because of staffing costs, compliance requirements, cloud complexity, incident recovery, tool consolidation or poorly integrated products.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Outsourcing can reduce the burden of hiring and operating specialized teams, but it introduces provider dependency, data-access concerns and contractual limits. The right purchase depends on the capability gap:

  • Continuous monitoring needed: evaluate MDR or co-managed SOC services.
  • Strategy or compliance gap: evaluate consulting.
  • Deployment or migration problem: evaluate professional services.
  • Emergency expertise needed: evaluate an incident-response retainer.
  • Basic controls are weak: prioritize identity, endpoint coverage, patching, backups, asset inventory and cloud configuration first.

Potential buyers may review offerings from Microsoft, CrowdStrike, Palo Alto Networks, Okta, Cloudflare, Kyndryl and Arctic Wolf, but these companies do not offer interchangeable products. Some primarily sell software, some emphasize managed operations, and others focus on consulting or implementation. Enterprise pricing is generally quote-based and varies with endpoints, users, telemetry, retention, geography, response authority and contract scope.

The Bottom Line

Bottom line: Gartner’s August 2024 forecast genuinely projected a sharp rise in worldwide security-services spending, to $86.073 billion in 2025. The category includes managed, consulting and professional services—not just MDR. Gartner later lowered the services estimate to $83.812 billion, so the original “surge” should be presented as a dated forecast, not a final result. For buyers, the priority is matching the service to a specific capability gap while retaining clear authority, data ownership and exit rights.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.