The security tooling market in 2026 is, by spend, the largest it has ever been. By number of distinct problems it actually solves, it is about where it was in 2022. The growth has been in price per seat, in vendor consolidation, and in the number of dashboards the buyer pays for without reading them. The market has not grown in the way the marketing decks suggest.
What has changed serves as the shape of the market. Five years ago, a security team evaluating a new category would put eight vendors in the spreadsheet. Today, in most categories, they put three or four. The long tail has been acquired, has gone under, or has been pushed to niches. The result is fewer choices, higher prices, and a set of vendors that have learned they can raise prices because the buyer has nowhere else to go.
Where the consolidation has landed
The major categories have settled into a stable shortlist, and the shortlist is worth knowing if you are buying, building, or selling against it.
SIEM. Splunk (now Cisco), Google Chronicle, Microsoft Sentinel, and Sumo Logic own the bulk of the new logos. Splunk remains the enterprise default. Sentinel has eaten the mid market by being bundled with the E5 licence most enterprises already own. Chronicle wins on the data retention and the price per ingested gigabyte. Sumo Logic holds the cloud native shops.
EDR. CrowdStrike, SentinelOne, and Microsoft Defender. CrowdStrike still leads on mindshare and on the post incident forensic record. SentinelOne wins the technical evaluations on autonomous response. Defender wins on price, because Defender is already in the bundle. The “Defender is good enough” question is now settled in most enterprises, and the answer is yes, for most enterprises.
CSPM. Wiz, Palo Alto Prisma Cloud, Orca, and the cloud provider native offerings (AWS Security Hub, Microsoft Defender for Cloud, Google Security Command Center). Wiz dominated the category for three years, then was acquired by Google. The acquisition closed in 2025 and the market is still digesting what that means for the buyers who preferred Wiz as a neutral third party.
CDR. A newer category, with CrowdStrike Falcon LogScale, Palo Alto XSIAM, and Sumo Logic Cloud SIEM as the early leaders. The category exists because EDR is not enough on its own; the breach that mattered happened because nobody correlated the cloud control plane event with the endpoint event, and CDR sits as the category that promises to do that correlation natively.
IAM. Okta, Microsoft Entra ID, and the cloud provider native IAM. Okta is still the buy for best of breed identity in enterprises that want identity separate from the cloud directory. Entra ID stands as the default for everyone who is already a Microsoft shop, which is most enterprises.
The categories that are over funded
Four categories have been absorbing security budget for the last decade, and the four categories are still the easiest line items to defend in a budget meeting. They are also the four categories where the marginal dollar buys the least additional safety.
SAST. Static analysis has been the silver bullet on the security roadmap since 2005. The vendors are competent. The integrations are mature. The noise to signal ratio has not meaningfully improved in ten years, because the fundamental problem (a million findings, of which fifty matter) is a research problem, not a tooling problem.
DAST. Same story. The tools find what they have always found, the scanners are well understood by attackers, and the deployment model (scheduled scans against staging) misses the production endpoints that move every week.
Vulnerability management. The databases (NVD, GHSA, the vendor advisories) are good. The scanners are good. The dashboards are good. The act of triaging the finding, getting the patch prioritised, and getting the patch deployed stands as the bottleneck, and the bottleneck is not a tooling problem.
Threat intelligence. The feeds are valuable, but the marginal value of the fifth feed is much lower than the marginal value of the first feed, and most enterprises have already paid for the first three.
The categories that are under funded
Four categories get a fraction of the budget, and the four categories are where the actual incident response happens.
Detection engineering. The work of writing, testing, and maintaining the detection rules that fire on the things that matter. Almost no enterprise funds this as a programme. It gets done by a senior analyst in the hours they have left after the meetings, and the quality of the rules reflects the hours that have been left.
Incident response. Tabletop exercises are fun and they do not change the outcome. What changes the outcome amounts to the on call rotation, the runbooks that match the production environment, the forensic tooling that works against modern cloud workloads, and the relationships with outside counsel, the insurer, and law enforcement that have to be in place before the breach. None of that ships in a vendor licence.
Threat hunting. The proactive search for the adversary that is already inside the environment and is not yet firing alerts. The closest you can buy is a managed detection and response engagement, and even then the hunt is only as good as the hunter.
Security operations. The unglamorous work of keeping the SIEM tuned, keeping the integrations current, keeping the on call rotation staffed, keeping the playbooks updated. This is where the breach is prevented or where the breach is detected, and it is chronically understaffed in most enterprises because it is hard to put on a slide for the board.
The dashboard problem
Every vendor ships a dashboard. The board wants a dashboard. The CISO needs a dashboard for the board. The dashboard stands as the artefact the security team gets asked about in the quarterly review. The dashboard is, in most enterprises, the security programme’s biggest liability and its smallest asset.
The dashboard shows the number of alerts last quarter. It shows the number of incidents closed. It shows the mean time to detect and the mean time to respond. None of these numbers, on their own, tell the board anything useful. The number of alerts last quarter is a function of the detection rules, not a function of the security of the enterprise. The mean time to detect is a function of the rules plus the on call coverage, not a function of the security of the enterprise.
What the board actually wants to know is whether the enterprise is more or less likely to have a material breach in the next twelve months. The dashboard does not answer that question, because no dashboard can answer that question. The honest CISO tells the board that. The careful CISO shows a different dashboard every quarter and hopes nobody asks the hard question.
What to do about it
The teams that are doing this well are the ones that have made peace with the consolidation, that have stopped expecting the silver bullet from the next vendor, and that have shifted spend from the over funded categories into the under funded ones. Not by replacing the SAST licence; by adding a detection engineer headcount alongside it. Not by cutting the threat intelligence feeds; by adding a threat hunting engagement that uses the feeds.
The teams that are doing this poorly are the ones that are still buying the next silver bullet. The next silver bullet serves as the same silver bullet the last one was, just with a different logo and a higher price.

The bottom line
The patterns the post covers have been showing up in production for long enough that the patterns have names, the failures, the mitigations, the gaps. The work the security team and the engineering team and the operations team are quietly doing today sits as the work that decides whether the practice the post names sits as a tool the team uses or a liability the team is paying for.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.


