As AI adoption accelerates, many organizations are discovering that spending is rising faster than their ability to control it. Building the right cost management capabilities is becoming essential to scaling AI without sacrificing financial discipline.
SUSECON 2026 in Prague marked a clear advance on the platform pillars SUSE introduced a year earlier in Orlando — and a more forceful articulation of its choice narrative. SUSE argued that choice only matters if it can be operationalized: enabling sovereign workload control and resilience not just to technical failure but to economic and […]
Google Cloud Next 2026 opened with Thomas Kurian declaring the end of the AI pilot era and Sundar Pichai comparing the enterprise refrain of last year (“Can we build an agent?”) to today’s: “How do we manage thousands of them?” Google Cloud Next ’26 answers the second question with a single product story: Gemini Enterprise […]
The annual RSAC Conference in San Francisco is the cybersecurity industry’s biggest event of the year. For the analysts attending, RSAC Conference week provides an opportunity to learn about cybersecurity trends and topics, meet with vendors and clients, and share our insights and observations. It’s also an excellent opportunity to meet our daily step goals […]
We have seen this pattern before, even if the specifics look different. Think back to the day AWS introduced GuardDuty, when Microsoft folded Defender for Endpoint into its enterprise licensing commitments and launched Microsoft Sentinel, or when Google acquired Mandiant and eventually Wiz. Sure, the launch of fully autonomous AI agents that can ingest entire […]
Predictions are a tough sport to play. If you get them all right, you played it safe by recapping existing trends or gave wishy-washy statements that are hard to verify. If you got them all wrong, you likely went for the headlines with little accountability on those claims. Every year, we try to find that […]
A formidable challenge awaits security leaders as personal tools like Moltbot spread. AI butlers are the next shadow super-user.
The goal of this year’s event was to position AWS as a newly transformed, AI-native cloud that’s ready right now. Here’s a closer look at the key announcements and developments.
Some of the biggest online platforms in the world were recently knocked offline by an automatically generated configuration file that grew too large. In a world plagued by security threats, operational failures can still happen even in your favorite cloud service. Find out why and how to reduce your risk.
Cloud in 2026 will be defined by two major races: the hyperscaler race to build AI-native cloud infrastructure and the enterprise race to craft meaningful AI strategies. Our predictions break those down.
Despite the ongoing macroeconomic uncertainty in 2025, cybersecurity spending will rise by 13.1% this year to $174.8 billion, driven by ongoing concerns around cyberattacks and the need to secure new cloud-based deployments. Find out more in our cybersecurity spending forecast.
AI red teaming blends offensive security tactics with safety evaluations for bias, toxicity, and reputational harm. It’s messy, fragmented and, most of all, necessary. Get six tips to get started on an AI red team that actually works in this preview of our upcoming Security & Risk Summit.
Sovereignty is no longer optional. Geopolitical tensions, tariffs, and regulatory pressures have made digital sovereignty a permanent concern for tech leaders. But chasing full sovereignty across your IT stack can lead to decision paralysis, ballooning costs, and operational complexity. Instead, organizations should aim for what Forrester calls minimum viable sovereignty — a pragmatic, risk-based approach […]
CrowdStrike held its Fal.Con 2025 conference recently and not surprisingly for a cybersecurity vendor event in 2025, AI dominated. Get our highlights and key takeaways here.
Find out more about Tencent’s sovereign cloud solution, Tencent Cloud Enterprise, which it is using to pursue overseas business expansion.
The cybersecurity industry is in the middle of a land grab as AI security M&A heats up. In just 18 months, eight major vendors — including Check Point, Cisco, CrowdStrike, F5, and Palo Alto Networks — have spent upwards of $2.0 billion acquiring startups focused on securing enterprise AI. AI for security is already poised to disrupt […]
The 10th annual Splunk .conf took place in Boston recently. From the opening keynote to various new product releases and enhancements, get a full review of the event in this post.
2025 marks the 28th year of Black Hat, and although it remains on the edgier side of corporate-focused cybersecurity conferences, it sometimes feels like the event is considering completely ditching its hoodie in favor of a collared shirt.
What we’re now observing in Southeast Asia is a more nuanced and strategically driven “diverse cloud” approach that directly addresses concerns around US foreign policy uncertainty and the imperative for localized data control.
Learn how increased complexity and additional market factors led us to rethink the title of our upcoming Forrester Landscape report on digital sovereignty platforms
Cybersecurity platform provider CrowdStrike announced plans to acquire Adaptive Shield, a SaaS Security Posture Management (SSPM) vendor. Some sources reported the purchase price around $300 million. If that purchase price is accurate, based on Forrester’s estimates of Adaptive Shield’s current revenue, that price represents an approximately 12x-15x revenue multiplier and 6 times more than Adaptive […]
In 2025, public cloud AI offerings will continue to expand and mature, but private cloud will also thrive in the year ahead due to some complex industry dynamics. Get the details in our 2025 cloud predictions.
With cybercrime expected to cost $12 trillion in 2025, regulators will take a more active role in protecting consumer data while organizations pivot to adopt more proactive security measures to limit material impacts. Find out more in our 2025 predictions for cybersecurity, risk, and privacy.
Forrester is once again partnering with Women in Security and Privacy to provide free admission to our Security & Risk Summit for four women looking to break into cybersecurity. Learn the details and find out how to apply for the scholarship here.
Here are the top things you need to know coming out of CrowdStrike's recently held Fal.Con user conference, just two months after its config update took down 8.5 million Windows endpoints.
The Security & Risk Enterprise Leadership Award recognizes orgs that transformed the security, privacy, and risk management. Learn more about the award and find out how to apply.
Public cloud may be the major underpinning of enterprise infrastructure strategies, but it comes with risks. Learn the top three cloud trends that CISOs and security leaders need to be aware of in this preview of our upcoming Security & Risk Summit on December 9–11.
VMware Explore 2024 began with Broadcom CEO Hock Tan re-announcing a significant departure from the previous VMware direction (embrace hybrid cloud) to a singular focus on making private cloud a success. Much like hyperscalers deliver an integrated set of infrastructure services, Broadcom is targeting integrating compute, storage and network resources. It is aiming at making […]
Forrester just published the second edition of The Forrester Wave™: Microsegmentation Solutions. Just over two years separates this research from the previous report, and the technological advances over that short time are stunning. The previous evaluation, The Forrester New Wave™: Microsegmentation, Q1 2022, was all about layer 3 microsegmentation in a data center (or private […]
On August 15, Hewlett-Packard Enterprise (HPE) announced its intent to acquire Morpheus Data, a multicloud management solution “to make HPE GreenLake cloud the de facto platform for innovating IT.” The deal is expected to close early FY2024 Q4 of its fiscal year. Morpheus follows a string of HP acquisitions in recent years (OpsRamp (2023), Ampool […]
Forrester’s top ten cloud trends for 2024 report is out. No one will be surprised that AI figures prominently. Yet there are other fundamental shifts in play — the rise of the intelligent edge, increased cloud compliance complexity, and (finally!) mature multicloud networking offerings. Tracking these trends was a collective effort with all of my […]
At long last, the The Forrester Wave™: Cloud Cost Management And Optimization (CCMO), Q3 2024 is published! The process is incredibly long and thorough. We go through hours long briefings, customer calls, and perform multiple iterations on scoring. Vendors go through the same. They put in many hours setting up customer references, product demonstrations and […]
After the rumors that Wiz was going to acquire cloud workload security (CWS) specialist Lacework fell through, Fortinet has announced the acquisition of Lacework for an undisclosed amount. The sales price is expected to be higher than Wiz’s rumored offer but lower than what Lacework’s investors would have liked. Forrester estimates that Fortinet paid approximately $200M-230M […]
Cisco has announced a new network and cloud security platform, called Hypershield. Hypershield offers autonomous and automatic network segmentation based on understanding network traffic patterns with AI. Hypershield provides: A modified and proprietary version of the Extended Berkeley Packet Filter (eBPF)-based agent framework to act as not only a traditional observation point but also a […]
Cloud detection and response is not a market category — it is a feature of existing cloud tools. Get a formal definition and more in this post previewing a new report.
Wiz (founded in 2020) announced a new VC funding round of $1 billion at a post-money valuation of $12 billion. Wiz has cumulatively raised $1.8 billion in venture capital, is generating over $350 million in annual recurring revenue, and is on an upward trajectory toward a likely IPO in 2025. This signals high investor confidence […]
With Selipsky Out, What’s Next For AWS? On May 14, AWS announced Adam Selipsky’s departure as CEO and that Matt Garman, AWS senior VP of sales and marketing, would replace him in June. Selipsky’s reasoning for this move was to “spend more time with family for a while, recharge a bit, and create some mental […]
RSA Conference (RSAC) 2024 boasted 41,000 attendees, 600 exhibitors on the show floor, 425 sessions, and plenty of dashing around Moscone Center and its surrounding area for our analysts. The event, still the top dog of cybersecurity events, was packed with announcements and press releases galore. This blog contains some of the key themes we […]
Forrester announces the opening call for our annual Security & Risk Enterprise Leadership Award. This award recognizes organizations that have transformed the security, privacy, and risk management functions into capabilities that fuel the organization’s long-term success. Learn more about the award and how to apply here.
Recently, Wiz announced the acquisition of cloud detection and response vendor Gem Security. Learn how this move aligns with Wiz’s plan to build a comprehensive cloud security portfolio and accelerate product innovation.
As the cloud landscape adapts to new changes, there is a renewed interest in cloud governance programs. But implementation of cloud governance may prove to be more difficult than expected. Find out why.
Google recently held its Google Cloud Next conference four months early to unveil new AI offerings and upstage its rivals. Get a detailed review of all of the announcements at the event in this post.
A recent cybersecurity incident at Change Healthcare cause the pharmacy claims processors to take its systems offline. Learn the implication of this event and five things firms can do to prepare.
It's time to take a look back and score our 2023 cloud predictions. Find out where we accurately predicted cloud trends and where we missed the mark for cloud in 2023.
Last week, Amazon.com VP and CTO Werner Vogels closed out re:Invent 2023 with his keynote address on the “frugal architect.” This isn’t the first time that Vogels has introduced this topic. In fact, it was a theme he originally introduced in 2012 that revolves around architecting with cost in mind. To me, and likely to […]
With the VMware-Broadcom deal set for closing, what should you know? Learn five key things VMware customers can expect in the coming years.
Get an inside look at some of the highlights and findings from the new Forrester Wave™: Zero Trust Platform Providers, Q3 2023 report.
Should CISOs fend off Microsoft to keep their preferred products or embrace consolidation? Find out in this blog.
Find out what Cisco's $28 billion planned acquisition of Splunk could mean for both observability and security.
Curious about Zero Trust in the cloud? Learn more about it in this preview of our the upcoming Security & Risk forum.
The FBI’s Cyber Division issued an advisory which “strongly advises” that organizations still using Barracuda Networks Email Security Gateway (ESG) appliances affected by an exploit of CVE-2023-2868 remove those appliances “immediately.” This advisory builds on the vendor’s own recommendations to replace its ESG appliances. This is an extraordinary announcement as the vendor-provided patches have proven […]
Last month, Forrester announced its inaugural Security & Risk Enterprise Leadership Award. As former CISOs, my Forrester colleague Brian Wrozek and I are sharing our thoughts about why you should apply. There are tangible benefits to you, your team, your organization, and the greater security community. You should apply — and apply now — for […]
Black Hat USA 2023: Insights From Our Short Vegas Residency Black Hat has gone from being RSAC’s smaller tech and practitioner-focused cousin to being a commercial showcase for cybersecurity vendors. A tightly packed, noisy Business Hall included over 300 vendors and 400 organizations with booths, which was great for swag but bad for anyone with […]
Zero Trust advocates have been on a campaign to #KillTheVPN for years, largely because VPNs provide too much (implicit) access and can become the entry point for malicious activity. The replacement technology is Zero Trust Network Access (ZTNA) and it is how most organizations are getting into Zero Trust today. ZTNA was the darling of […]
On traditional infrastructure (laptops, servers, workstations, on-premises network infrastructure), the attack surface was the closest match to true perimeter-based defense we could get. The network infrastructure gave access to the systems within (crunchy outside, gooey, cubicle, khakis, and blue button-downs inside). As such, detection of attacker activity was relegated to network-based activity, endpoint-based activity, and […]
Kubernetes is the de facto standard for deploying and managing application workloads and containers. Lee has written quite a bit about the power of Kubernetes as an innovation platform, but while development and architecture teams are bullish on Kubernetes, security teams can find themselves scrambling to secure Kubernetes environments as they hurtle towards production. The […]
Forrester is thrilled to announce its inaugural Security & Risk Enterprise Leadership Award, which will recognize security organizations that have transformed the security, privacy, and risk management functions to fuel long-term success. Learn how to apply here.
Cloud Native Application Protection Platforms (CNAPP) solutions offer multiple capabilities rolled into one (marketing label) solution. CNAPP platforms claim to contain: Cloud security posture management (CSPM) Cloud infrastructure entitlement management (CIEM) Cloud workload protection (CWP), both agent-based and agentless Container security, application security API security Infrastructure-as-Code (IaC) build script scanning Serverless security and DevOps security […]
The Forrester Wave™: Managed Detection And Response (MDR), Q2 2023 is live! The MDR market continues to redefine what it means to offer a successful security service with high client satisfaction and retention rates and, as a result, extraordinary growth rates. For now, no single vendor dominates the MDR market, but providers bringing endpoint detection […]
Cybersecurity threats continue to plague organizations, multiplying like Mogwai in the 1984 hit movie “Gremlins” (just don’t feed them after midnight). Forrester data shows that almost three-quarters of organizations reported one or more data breaches in the past 12 months. Forrester’s recently published report, Top Cybersecurity Threats In 2023, examines five cybersecurity threats — established […]
Oracle has again changed licensing rules for its widely used Java product. On January 23, 2023, the company introduced a new license metric, the SE Universal Subscription. It offers all the benefits of the legacy Java SE subscription, plus universal use rights (desktop, server, and third-party cloud) and triage support for customers’ entire Java portfolio, […]
Forrester recently published Top Recommendations For Your Security Program, 2023 for CISOs and other senior cybersecurity and technology leaders. This year’s overarching theme involves protection (as you might expect) — but not exactly in the way you’d think in the context of security. In 2023, our recommendations fall into three major strategic themes for security […]
This blog outlines Forrester’s existing Security & Risk research to help organizations navigate, manage, and prepare their organizations for the implications of the National Cybersecurity Strategy.
I’ve been working with a long list of financial services companies from various subsectors on their cloud strategies. Each wants to know how to best take advantage of cloud while meeting stringent (and shifting) regulatory requirements. It’s been a long road for financial services and cloud. Here’s a little bit of history. Financial services have […]
CISOs must use this period of austerity to reinforce security as a core competency that drives growth and protects revenue.
Earlier this month, Apple announced several important new data protection features for general availability in 2023 that have numerous implications for security teams in all industries and geographies. Here is the Forrester security and risk team’s collective analysis of these new features. Quick Summary The announcement is not particularly noteworthy in terms of the newly […]
The four-way hyperscaler horse for market share matters as the leading players continue to invest up and down the stack for new capabilities that set the pace for the industry. Those efforts are reflected in the results of The Forrester Wave™: Public Cloud Development And Infrastructure Platforms, Global, Q4 2022, in which custom silicon and […]
This blog piggybacks off of my last post regarding the management evaluations I’ve been working on in 2022. As previously noted, they take a lot of effort but deliver high value — a lot of which can’t be captured in a single report. I already shared my tidbits of advice for the cost management evaluation. […]
The battle between hyperscalers and European cloud providers to conquer the European public cloud market is getting more contentious over the issue of data sovereignty. It now involves new actors, new concerns, and new weapons. Here a few of the main facts that will most probably influence the European cloud scenario moving forward. Growing Complexity […]
On top of the usual challenges, in 2023, security pros will see more risk coming from internal forces, such as enabling anywhere work and the future of the office. Learn more in our 2023 predictions.
How will economic headwinds impact spending on cloud native or security in the year ahead? Get a sneak peek at our 2023 cloud computing predictions.
In 2023, European banks and governments will accelerate their cloud plans while Kubernetes will see increased interest, as well. Learn more in our 2023 cloud predictions for EMEA.
As KubeCon North America 2022 gets underway, it’s useful to reflect on how far the cloud-native ecosystem has come, a focus of a new report by my colleague Charlie Dai and me. It wasn’t so long ago that IT enterprise architects began every project with a list of constraints: What can be built with a […]
Learn how to redefine data security in an age of multicloud, anywhere work, edge computing, and changing privacy regulations.
Which security technologies should be getting the investment in 2023, and which ones should you be scaling back on? Find out in Forrester’s Planning Guide 2023: Security & Risk.
On June 28, Google unveiled plans for a new Public Sector subsidiary aimed at helping US public institutions, such as state, local, and educational institutions, drive digital transformations into the cloud. The company also has US federal ambitions by partnering with the Defense Innovation Unit, the US Navy, and the Department of Veterans Affairs (VA). […]
Learn the seven data resilience strategies that every enterprise should consider as they transform their business.
Late Sunday evening, Bloomberg reported rumors of advanced Broadcom talks to acquire VMware, which has since been confirmed this morning. In light of Broadcom’s investment activities in the past few years, this news is unsurprising. It made a string of massively expensive enterprise software company acquisitions: Brocade Communications Systems in 2016 ($5.9 billion), CA Technologies […]