Read EY's Leader citation from the current evaluation and notice what Forrester is actually praising. A private large language model. An automated evidence validation tool. A privileged-access risk scoring engine.
Three products. Named, proprietary, and built in-house. Forrester's assessment is that these accelerators compress compliance timelines and elevate reporting quality.
That is a consulting firm being evaluated on its software. Which is either a curiosity or the most important thing happening in this market, depending on how seriously you take the implication for what you are buying and how you pay for it.
What cybersecurity consulting covers
The scope is broad because the buyer's problem is broad. A CISO arrives with some combination of a regulatory deadline, a board that has started asking questions, an architecture assembled over fifteen years, and a team that is understaffed relative to the threat.
The work sorts into a few recognisable engagements. Strategy and programme design, meaning what the security function should be and how it gets there. Risk assessment and maturity benchmarking. Compliance and regulatory readiness, which is frequently the thing that actually releases budget. Architecture work, particularly around identity, cloud, and network segmentation. Incident response readiness and crisis simulation. And increasingly the security of specific emerging technologies, meaning AI systems, operational technology, and post-quantum cryptography planning.
What separates this from adjacent categories is the presence of an adversary. Most consulting improves a process against a static benchmark. Security consulting improves a posture against an opponent who adapts to whatever you implement, which means recommendations decay in a way that operating model advice does not.
Why this consulting market behaves differently
Three structural features make cybersecurity consulting unlike the general advisory market, and they explain most of what shows up in the evaluations.
The failure is public and permanent. A poorly executed transformation programme is embarrassing internally. A breach is a disclosure obligation, a regulatory event, and frequently a news story. That asymmetry pushes buyers toward providers whose brand carries weight with boards and regulators, which is why the Big Four and the strategy houses compete strongly here despite the work being deeply technical.
The regulator is a participant. Much of the demand is created by rules rather than by ambition, and a firm's ability to produce documentation that satisfies an examiner is a real capability rather than a formality. EY's positioning around integrated compliance solutions is a direct response to that.
And the technical depth requirement is unusually high for consulting. Forrester's assessment of the 2024 evaluation put it plainly: deep technology expertise matters most right now in this market. That is not a phrase you see attached to strategy consulting categories, and it sets the bar that produced the accelerator arms race described below.
Inside The Forrester Wave: Cybersecurity Consulting Services, Q2 2024
The evaluation scored fifteen providers against twenty four criteria.
McKinsey placed as a Leader with the highest possible score in eleven criteria, including cybersecurity strategy and vision delivery and customer retention and satisfaction, and ranked among the highest in use of emerging technologies in client delivery.
That last criterion is worth pausing on. Use of emerging technologies in client delivery is not a measure of what a firm knows about security. It is a measure of what the firm uses to do the work. A strategy house scoring well on it, in a market where Forrester says deep technology expertise matters most, is an early signal of where the competition was heading.
The criteria set at twenty four is also notably lean for a services evaluation. Compare it to the thirty two criteria Forrester applied in its European edition of this market, and the difference suggests the global evaluation is testing a narrower set of things that discriminate between very large firms.
Inside The Forrester Wave: Cybersecurity Consulting Services, Q1 2026
Published in February 2026 and authored by Jeff Pollard with Caroline Provost, Joseph Blankenship, and Michael Belden, the current evaluation continues the direction the 2024 edition pointed at.
EY placed as a Leader, and its citation is the clearest statement of what now differentiates in this market. Forrester singled out an AI-enabled delivery ecosystem comprising EYQ, a private large language model, IsecMapper for automated evidence validation, and PARIS for privileged-access risk scoring, describing these accelerators as compressing compliance timelines and improving reporting quality. Forrester positioned the firm for organisations seeking AI-driven transformation and integrated compliance solutions.
Read that alongside the 2024 finding and the arc is clear. In 2024 the market rewarded firms that knew the most. By 2026 it rewards firms that have built the most, because knowing things has become less scarce than being able to apply that knowledge at speed across a large estate.
Automated evidence validation is the specific capability worth understanding. Compliance work in security consulting is overwhelmingly evidence gathering: proving that a control exists, that it operates, and that someone reviewed it. That work has historically consumed enormous quantities of junior consultant time at senior consultant rates. A tool that validates evidence automatically removes the single largest cost line in a compliance engagement.
The pricing question this creates
Here is the consequence nobody selling into this market volunteers.
If a firm's accelerators compress compliance timelines, the engagement takes fewer hours. If the engagement is priced per hour, the fee falls. If the fee does not fall, the productivity gain has been captured entirely by the provider.
Forrester has noticed. Its commentary on this market has flagged that pricing models are shifting from effort to outcomes, with the observation that the real opportunity in AI-enabled delivery lies in redefining value rather than in discounting cost, and that CISOs should demand pricing linked to outcomes such as faster compliance closure and reduced risk.
That is unusually direct advice, and it converts into a concrete negotiating position. When a provider leads with its accelerators, the reasonable response is to ask what proportion of the engagement they now perform and how that is reflected in the price. A firm confident in its tooling should be comfortable pricing against the outcome rather than the hours, because it expects to deliver the outcome faster.
The firms that resist this are telling you the accelerators are a marketing asset rather than a delivery one.
There is a second-order effect worth anticipating. The consulting pyramid depends on leveraged junior staff, and evidence validation is exactly the work junior staff did. A firm that automates it improves margin in the short term and hollows out its own training pipeline in the medium term, which is a problem the whole professional services industry is currently pretending is a decade away.
The independence problem
Cybersecurity consulting has a conflict that its practitioners discuss less than they should.
The same firms that assess your security posture frequently also implement the remediation, operate managed security services, resell the products they recommended, and in the case of the Big Four, may audit the financial statements of the organisation whose controls they are evaluating.
None of that is illegitimate and the firms maintain separation where regulation requires it. But the incentive structure is worth seeing clearly. An assessment that identifies substantial gaps generates remediation work. An assessment that finds you are in good shape generates a report and an invoice.
This is not an argument for assuming bad faith. It is an argument for reading recommendations with the same scepticism you would apply to any advice from someone positioned to sell the solution, and for asking directly what the firm's revenue mix looks like across assessment, implementation, and managed services.
The same applies to technology partnerships. A provider with a deep alliance to one security vendor will produce competent recommendations that tend toward that vendor's architecture. Ask which alliances fund the practice.
Resilience replaced prevention
The most consequential change in this market is conceptual rather than commercial, and it has quietly rewritten what these engagements are for.
The older model treated security as prevention. Build the perimeter, harden the systems, keep the adversary out, and success is measured by the absence of incidents.
That model lost. Not because prevention stopped mattering, but because sufficiently motivated adversaries get in, supply chains create exposure you do not control, and the assumption of a defensible perimeter stopped matching how organisations actually operate.
Resilience assumes compromise and asks a different question: how quickly do you detect it, how much damage occurs before you contain it, how fast do you recover, and does the business keep running while you do. Forrester's current framing of this market puts resilience at the centre, alongside the security of emerging technologies and transparency about data handling.
That shift changes what a good engagement produces. A prevention-era deliverable was a gap assessment against a control framework. A resilience-era deliverable includes tested recovery, crisis simulation with the actual executives who would be in the room, and scenario planning for operational technology environments where recovery is genuinely hard.
Forrester's own commentary is pointed about the difference between real and performative work here, noting that leading providers embed resilience into transformation programmes rather than relying on generic templates. A crisis simulation run from a standard scenario deck is a training exercise. One built from your actual architecture, your actual dependencies, and your actual executives is a stress test, and the two cost roughly the same to buy.
What the arc suggests
Forrester also runs regional evaluations of this market, including a European edition with a broader criteria set and a first-ever Asia Pacific edition covering ten providers, which tells you the buying requirements diverge enough by geography to warrant separate research.
But the global arc is the one that matters for understanding where this is going. In 2024, deep technology expertise was the differentiator. In 2026, the differentiator is proprietary tooling that applies expertise at scale, and the Leader citations read like product announcements.
Follow that trajectory and cybersecurity consulting starts to look less like a professional services market and more like a software market with a services wrapper. The firms are building platforms. They are describing them in analyst evaluations. They are using them to compress delivery timelines.
What has not changed is the commercial model, which still mostly prices people and time. That gap between how the work is done and how it is billed is the largest unresolved question in this category, and it is one buyers are currently better positioned to exploit than they realise.
Analyst Source
Forrester Research
Category definition, provider inclusion, and evaluation findings in this article draw on Forrester's coverage of cybersecurity consulting services. The Q2 2024 Wave scored 15 providers against 24 criteria; the Q1 2026 edition was authored by Jeff Pollard with Caroline Provost, Joseph Blankenship, and Michael Belden. Forrester evaluates this market separately in Europe and Asia Pacific.
Source research
- The Forrester Wave: Cybersecurity Consulting Services, Q1 2026
- The Forrester Wave: Cybersecurity Consulting Services, Q2 2024
- Research Announcement: The First-Ever Forrester Wave On Cybersecurity Consulting Services In Asia Pacific
Forrester does not endorse any provider named here, and tier placement should not be read as a recommendation to buy.