Forrester's 2019 evaluation of this market named fifteen providers. Twelve of them were global firms headquartered outside Europe.

By the 2021 edition, five names had dropped out and five had arrived. The arrivals were Atos, NCC Group, Orange Cyberdefense, Sopra Steria, and Tata Consultancy Services. Four of those five are European companies.

The European cybersecurity consulting market became measurably more European over two years, and it did so while the global firms were investing heavily in the region. That is the finding worth building a shortlist around, because it says something specific about what European buyers were selecting for that scale alone could not provide.

Why this is a separate evaluation

Forrester maintains a distinct Wave for this market rather than treating Europe as a region within the global one. Three reasons hold that separation in place.

Regulation is the obvious one, and it is more layered than GDPR alone. European security programmes now sit under overlapping regimes covering network and information security, operational resilience in financial services, critical entity resilience, and product cybersecurity, each with its own scope, timelines, and supervisory authority. A provider's value depends substantially on knowing which regime applies to which entity and how the requirements interact, which is jurisdictional knowledge rather than security knowledge.

Data sovereignty is the second, and it has hardened considerably. Where the data sits, who can access it, and under which legal jurisdiction that access could be compelled are now selection criteria rather than contractual footnotes. A provider whose delivery model routes European client data through non-European infrastructure is carrying a disadvantage that no amount of technical capability offsets.

The third is fragmentation. Europe is not one market. A programme spanning Germany, France, the Netherlands, and Poland encounters four regulators, four languages, four sets of works council expectations, and four rather different security cultures. Scale helps with this. Local presence helps more.

The arc across four editions

The Forrester Wave: European Cybersecurity Consulting Providers, Q4 2019 scored fifteen providers against twenty one criteria: Accenture, Boston Consulting Group, Capgemini, Cognizant, Deloitte, DXC, EY, F-Secure, Hewlett Packard Enterprise, IBM, KPMG, NTT, PwC, and Wipro, alongside Infosys.

The Forrester Wave: European Cybersecurity Consulting Providers, Q3 2021 also scored fifteen against twenty one criteria, with a changed roster: Accenture, Atos, BCG, Capgemini, Deloitte, DXC Technology, EY, IBM Security, KPMG, NCC Group, Orange Cyberdefense, PwC, Sopra Steria, Tata Consultancy Services, and Wipro.

Accenture placed as a Leader in that edition, with Forrester noting that it dominated the field with technology-driven offerings, and with top scores in European go-to-market strategy, European partnership ecosystems, European research and development initiatives, and technical consulting implementation. Deloitte also placed as a Leader, with clients citing knowledge, deliverable quality, and professional flexible interaction at all levels.

Notice what Accenture's winning criteria have in common. Three of the four are explicitly European. Not go-to-market strategy but European go-to-market strategy. Not R&D but European R&D. The criteria themselves encode the argument that regional investment is the differentiator.

The Q1 2024 edition raised the criteria count to thirty two, a substantial expansion from twenty one, with KPMG taking the highest strategy score of all providers and the highest possible market presence score, plus top marks across seventeen criteria. PwC also placed as a Leader.

The Forrester Wave: Cybersecurity Consulting Services In Europe, Q4 2025, authored by senior analyst Madelein van der Hout, scored thirteen providers. The category name changed too, dropping European Cybersecurity Consulting Providers in favour of a construction that matches the global evaluation with a regional qualifier.

Fifteen, fifteen, then thirteen. Criteria from twenty one to thirty two. A market consolidating at the top while the evaluation gets more demanding.

What Forrester found in Q4 2025

Van der Hout's framing describes European CISOs facing rising regulatory demands, geopolitical instability, and rapid technological shifts, and identifies two market trends buyers should weigh.

The first bundles resilience, innovation, and data governance. European CISOs now prioritise resilience, the security of emerging technologies, and transparency. They select providers offering tailored crisis simulations and operational technology recovery planning, providers that embed resilience capabilities into transformation programmes rather than relying on generic templates, and providers that treat resilience as a compliance requirement.

That last phrase is the one to sit with. Resilience as a compliance requirement is a different proposition from resilience as good practice. It means the recovery plan has to be documented, tested, and demonstrable to a supervisor, which changes what a crisis simulation is for. A tabletop exercise that makes executives think harder is valuable. A tabletop exercise that produces defensible evidence of tested recovery is a regulatory artefact.

Forrester also credits leading European providers with securing AI, operational technology, and quantum systems, and specifically with using AI to test and develop quantum-safe intellectual property. Post-quantum cryptography has moved from research topic to procurement question faster in Europe than most buyers expected, driven by regulatory attention to long-lived data and the harvest-now-decrypt-later problem.

The second trend is pricing, and Forrester's language is unusually prescriptive. Pricing models are shifting from effort to outcomes. AI is transforming service delivery, and the real opportunity lies in redefining value rather than in discounting cost. CISOs should demand pricing models linking fees directly to outcomes such as faster compliance closure, reduced risk exposure, or earlier threat detection. Providers must demonstrate value rather than assume it.

An analyst firm telling buyers to demand outcome-linked pricing, in the announcement of its own vendor evaluation, is a stronger position than these documents usually take.

The sentence that should shape your due diligence

Buried in the data governance trend is the most operationally useful line in the research: European CISOs now insist that providers disclose data flows, embed privacy by design, and offer safeguards for third-party risks, and exposing clients to cross-border compliance gaps is strongly discouraged.

Strongly discouraged is analyst language for something that will end an engagement badly.

The concrete version of this concern is straightforward. A consulting engagement generates artefacts: architecture documentation, vulnerability findings, incident details, personal data encountered during assessment. Those artefacts live in the provider's systems. If the provider's collaboration platform, ticketing system, or delivery centre routes that material outside the European Economic Area, or into infrastructure subject to foreign disclosure obligations, the client has created an exposure by hiring someone to reduce exposure.

This is the sovereignty question in its most practical form, and it is not answered by a data processing agreement alone. It is answered by knowing which delivery centres touch the work, which platforms hold the artefacts, and which jurisdictions those platforms sit in. That question distinguishes providers more sharply than any capability comparison, and it is a large part of why the European-headquartered firms gained ground.

Budget realities

Two of the three Leader citations from recent European editions contain the same unglamorous theme, and it does not appear in the global evaluation at all.

KPMG's assessment credits Cyber Risk Insights, a licensable product providing data-driven insights and vendor contract analysis to uncover overlaps, unused licences, and underperforming solutions, freeing funds for higher-priority initiatives. Forrester's positioning statement describes KPMG as translating complex technology risks into boardroom priorities tailored to local and industry contexts and aligned with budget realities.

Aligned with budget realities is doing real work in that sentence. European security budgets are generally tighter than American ones for organisations of comparable size, while the regulatory obligations are heavier. That combination produces a specific buyer who needs to satisfy more requirements with less money, and who values a provider that can find headroom inside existing spend rather than proposing new programmes.

PwC's citation points the same direction from a different angle, with Forrester crediting strategic workforce planning using predictive analytics to allocate talent dynamically, and board and executive coaching that equips CISOs to influence their boards effectively. Forrester positions the firm for organisations wanting a pan-European partner combining scale with adaptable, talent-led delivery aligned to regional needs, cultural context, and business objectives.

Coaching a CISO to influence a board is not a technical service. It is recognition that in many European organisations the constraint on security maturity is not knowledge or technology but the CISO's standing in the room where budget gets allocated.

What pan-European actually requires

The phrase appears in vendor marketing constantly and means less than it implies.

A provider can be pan-European in the sense of having entities in fourteen countries while operating as fourteen loosely connected practices with different methodologies, different tooling, and partners who have never worked together. A multinational buying a single programme across those markets discovers this during delivery rather than during procurement.

The alternative failure is the opposite. A provider with genuinely unified methodology and a single delivery hub can produce consistency at the cost of local fluency, arriving in Germany with an approach designed elsewhere and no working relationship with the regulator or the works council.

Forrester's language around cultural context and regional needs points at the tension without resolving it, and it cannot be resolved in general because the right answer depends on your footprint. An organisation concentrated in two countries needs depth in those two. One operating across a dozen needs consistency more than it needs local nuance in each.

What is worth extracting from the research is that this dimension is scored. European go-to-market strategy, European partnership ecosystems, and European R&D were criteria in 2021 precisely because Forrester considered regional investment measurable and material. When a provider claims pan-European capability, the checkable version of that claim is where its people are, which regulators it has appeared before, and which local partners it works with in the specific markets you operate in.

The market this describes

Set the global and European evaluations side by side and the difference is not capability. It is what the capability has to accommodate.

The global evaluation rewards depth, scale, and increasingly proprietary tooling that compresses delivery. The European one rewards those things too, and then adds a set of requirements that come from outside the security discipline entirely: which regulator supervises this entity, where the artefacts live, whether recovery is demonstrable to a supervisor, whether the budget conversation can be won.

That is why the vendor lists diverge, and why a Leader in one is not automatically a Leader in the other. The European market selects for providers who have made region-specific investments that would be difficult to justify on global economics alone.

The 2019 to 2021 shift toward European-headquartered firms was the market noticing this first. The expansion of the criteria set from twenty one to thirty two was Forrester catching up. Whether the consolidation to thirteen providers continues, and whether the European specialists hold their positions as the global firms industrialise delivery with proprietary tooling, is the open question in this category.

Analyst Source

Forrester Research

Category definition, provider inclusion, and evaluation findings in this article draw on Forrester's coverage of cybersecurity consulting services in Europe, evaluated as European Cybersecurity Consulting Providers in Q4 2019 and Q3 2021 against 21 criteria, expanded to 32 criteria in Q1 2024, and published as Cybersecurity Consulting Services In Europe, Q4 2025 covering 13 providers. The current edition is authored by senior analyst Madelein van der Hout. Forrester evaluates this market separately at global level and in Asia Pacific.

Source research

Forrester does not endorse any provider named here, and tier placement should not be read as a recommendation to buy.