"Security leaders are striving to help their organizations securely use technology platforms to become more competitive and drive growth for the business," said Siddharth Deshpande, research director at Gartner. "Persisting skills shortages and regulatory changes like the EU’s Global Data Protection Regulation (GDPR) are driving continued growth in the security services market."
A 2017 Gartner survey* revealed that the top three drivers for security spending are (1) security risks; (2) business needs; and (3) industry changes. Privacy concerns are also becoming a key factor. Gartner believes privacy concerns will drive at least 10 percent of market demand for security services through 2019 and will impact a variety of segments, such as identity and access management (IAM), identity governance and administration (IGA) and data loss prevention (DLP).
Deshpande said highly publicized data breaches, like the recent attack on SingHealth that compromised the personal health records of 1.5 million patients in Singapore, reinforce the need to view sensitive data and IT systems as critical infrastructure.
"Security and risk management has to be a critical part of any digital business initiative," he said.
An increased focus on building detection and response capabilities, privacy regulations such as GDPR, and the need to address digital business risks are the main drivers for global security spending through 2019 (see Table 1).
Worldwide Security Spending by Segment, 2017-2019 (Millions of U.S. Dollars):
Identity Access Management
Integrated Risk Management
Network Security Equipment
Other Information Security Software
Consumer Security Software
Source: Gartner (August 2018)
Gartner has identified key trends affecting information security spending in 2018-2019, including:
At least 30 percent of organizations will spend on GDPR-related consulting and implementation services through 2019.
Organizations are continuing their journey toward compliance with the GDPR that has been in effect since 25 May 2018. Implementing, assessing and auditing the business processes related to the GDPR are expected to be the core focus of security service spending for EU-based organizations, and for those whose customers and employees reside there.
Risk management and privacy concerns within digital transformation initiatives will drive additional security service spending through 2020 for more than 40 percent of organizations.
Consulting and implementation service providers have retooled their service offerings over the past several years to support customers on their digital transformation journey. Security is a key factor in the uptake of that transformation process for regulated data, critical operations and intellectual property protection spanning public cloud, SaaS and the use of Internet of Things (IoT) devices.