No Forrester Wave has published for this category. The Proactive Security Platforms Landscape, Q1 2026 maps 42 vendors without scoring them, and a scored evaluation is expected to follow. What follows draws on that report and on Forrester's adjacent coverage of attack surface management, exposure management, and unified vulnerability management.

In 2024 Forrester published its inaugural Wave evaluating attack surface management solutions, covering eleven vendors in what it described as a rapidly evolving market.

Roughly eighteen months later it published a piece headed ASM is a feature, no longer a market.

That is the fastest category death I have come across in this series. An analyst firm creating a scored evaluation for a market and then declaring the market dissolved within two years is unusual enough to be worth understanding, because the reason explains what proactive security platforms are.

Three principles, three markets

Forrester organises proactive security around three principles: visibility, prioritisation, and remediation.

Visibility means knowing what you have. Every asset, internal and external, cloud and on-premises, including the ones nobody registered. Attack surface management was built for this, combining the internal defender view and the external attacker view into a single inventory.

Prioritisation means deciding what matters. An enterprise inventory produces exposures in the tens or hundreds of thousands, and the overwhelming majority are not worth acting on. Exposure management and exposure assessment platforms exist to rank them by genuine risk rather than by severity score.

Remediation means fixing things. Forrester's assessment is that the best remediation capabilities sit in unified vulnerability management solutions.

Three principles, three separate product markets, each solving one third of a problem that only makes sense as a whole.

Why the pieces could not stand alone

Forrester's own reasoning for collapsing them is the useful part.

On visibility, its observation is that external asset discovery and third-party asset attribute ingestion are becoming increasingly commoditised, and that the ubiquity of visibility options cannot alone solve proactive security. The question it poses is direct: once an organisation has a comprehensive asset inventory, what is it supposed to do about it?

An inventory is a precondition, not an outcome. Knowing you have forty thousand assets tells you nothing about which of them will be the entry point.

On prioritisation, the same logic applies one step further. Relying solely on assessment creates the same problem as relying solely on visibility, because organisations still need to remediate the weaknesses that were prioritised. A ranked list of ten thousand exposures with the worst two hundred at the top is progress and it is not a fix.

The market recognised this before the research did. Forrester notes that since the 2024 ASM Wave, several vendors rebranded their proactive security offerings into exposure management, and that one vendor went as far as declaring attack surface management dead outright.

ASM survives as a feature. Asset discovery and hardening remain prerequisites, and Forrester says so. What it does not survive as is a category worth buying separately, because a product that finds problems and cannot help you fix them creates work.

That is a pattern this series has encountered repeatedly. Cloud cost tools produce recommendations nobody acts on. Journey maps document problems that go unaddressed. Conversation intelligence records calls that nobody reviews. Security has arrived at the same discovery, and the market restructured faster than most because the consequences are sharper.

The Landscape, and what 42 vendors means

The Proactive Security Platforms Landscape, Q1 2026, published on 6 March 2026, maps forty two vendors.

Forrester's framing of what these platforms do covers all three principles: collecting a complete inventory of assets and their exposures, rationalising why to prioritise a breadth and depth of exposures, and improving security posture through response actions.

Forty two vendors is a large field, and it reflects convergence rather than growth. Companies arriving from attack surface management, from vulnerability management, from cloud security posture, from asset management, and from security operations platforms are all now describing themselves as proactive security platforms, because that is where the category boundary settled.

Convergence at that scale is normally followed by consolidation, and a scored evaluation will accelerate it by making the gap between the credible and the aspirational visible.

Forrester's caution in the Landscape is the standard one and it applies with force here: vendors vary by size, offering type, geography, and use case, and buyers should investigate based on size and market focus rather than against a single ranking.

The problem underneath the data

The Landscape identifies fragmentation across attack surface management, traditional vulnerability management, and application and cloud security among other sources, and names a deeper problem beneath it: a lack of trustworthy visibility into all assets and their ownership.

Ownership is the word doing the work, and it is the one that turns a technical problem into an organisational one.

Knowing that a server has a critical vulnerability is useful only if you know who can patch it. In most enterprises that mapping is incomplete, stale, or maintained in a configuration management database nobody trusts. The asset exists, the exposure is real, and the ticket has nowhere to go.

Vendor research in this space puts numbers on the resulting friction. Axonius, included among the notable vendors in the Landscape, reports from its own research that a majority of organisations still track remediation progress in spreadsheets, and that fewer than half successfully consolidate assets and exposures. Those figures come from an interested party and they are consistent with what the category's existence implies.

The customer testimony Axonius cites is more informative than the statistics. A security leader describing the shift from telling remediators to worry about everything to focusing on a small fraction of that volume is describing the actual value proposition: not finding more, but credibly telling people to ignore most of it.

Remediation is where this gets hard

The three principles are not equally difficult, and the third is where proactive security programmes fail.

Visibility is an engineering problem. Connect to the sources, deduplicate, resolve identities, maintain the inventory. Hard, tractable, and increasingly commoditised as Forrester notes.

Prioritisation is an analytical problem. Combine exploitability, reachability, asset criticality, and business context into a ranking. Genuinely difficult and improving quickly, and it is where most vendor differentiation currently sits.

Remediation is an organisational problem, and no platform solves organisational problems.

The security team identifies the exposure. The people who can fix it are in infrastructure, application development, or a business unit, and they have their own backlogs, their own priorities, and no reporting line to security. A prioritised list arriving from a function with no authority over the fixer is a request, not an instruction.

Which is why platforms in this space compete on things that look peripheral: ticketing integration, ownership resolution, automated routing, remediation workflow, and progress tracking. Those capabilities exist because the gap between knowing and fixing is where the value is lost, and closing it requires making the fix easy for someone who did not ask for the work.

The honest limit is that a platform can reduce friction and cannot create accountability. An organisation where remediation service levels are unenforced will have a very well-instrumented view of exposures that persist.

What a scored evaluation would need to settle

When Forrester publishes a Wave here, three choices will define what the category actually is.

Whether remediation is weighted proportionally. If the criteria emphasise discovery and scoring, the evaluation describes an assessment market and the incumbents from visibility and vulnerability management will do well. If remediation, ownership resolution, and workflow carry real weight, a different set of vendors will surface, and it will be a more useful evaluation.

How context is assessed. Every vendor claims business context. The meaningful question is where it comes from: whether the platform derives asset criticality from an authoritative source, infers it, or asks the customer to maintain it manually, which is a capability that decays.

And whether it addresses the AI-era exposure surface. Model endpoints, agent identities, and the tooling connected to them are assets with exposures, and most of the criteria in adjacent evaluations were written before they existed at scale.

Where this leaves a buyer

Without a scored evaluation the useful preparation is internal, and it maps onto the three principles.

Establish which principle is actually your constraint. Organisations reflexively buy visibility because it is the first step and the easiest to demonstrate. If you already know what you have and the problem is that nothing gets fixed, another discovery tool will produce a more precise account of the same backlog.

Test ownership resolution against your own estate rather than in a demonstration. Ask a vendor to identify the responsible owner for a sample of your assets. The result will be uncomfortable and it predicts whether the platform can route anything.

And decide what happens to the output before buying it. If there is no remediation service level, no escalation path, and no accountability for exposures that persist past a threshold, the platform will produce excellent evidence of a problem nobody is empowered to solve.

That is the same conclusion this series has reached in cloud cost management, in conversation intelligence, and in process intelligence. The analysis has not been the constraint for some time. Security is simply the domain where the consequences of that gap are least theoretical.

Analyst Source

Forrester Research

No Forrester Wave has published for proactive security platforms. The Proactive Security Platforms Landscape, Q1 2026 maps 42 vendors without scoring them. Forrester's adjacent coverage includes an inaugural attack surface management Wave in Q3 2024 covering 11 vendors, and a unified vulnerability management Wave in Q3 2025. Forrester has since stated that attack surface management is a feature rather than a standalone market.

Source research

Forrester does not endorse any vendor named here, and inclusion in a Landscape report is not a rating or a recommendation to buy.