U.S. enterprises are increasingly adopting advanced cybersecurity services and solutions to counter sophisticated attacks and expanding regulations, with a notable shift towards automated, proactive, and AI-enabled capabilities, according to a new research report from Information Services Group (ISG).
The 2025 ISG Provider Lens® Cybersecurity — Services and Solutions report for the U.S. indicates that organizations are collaborating with service and solution providers to implement adaptive systems for enterprise resilience. This trend is driven by the growing complexity and frequency of threats, evidenced by the increasing impact of data breaches and ransomware attacks observed throughout 2024.
Doug Saylors, partner and leader of ISG Cybersecurity, noted that “Security threats are more complex than ever, and regulations continue to expand and evolve. Companies in the U.S. want automated, proactive cybersecurity solutions closely integrated with their business strategies and objectives.”
The report highlights the application of advanced analytics and automation to enhance the efficiency and effectiveness of security operations. These technologies streamline workflows by integrating various tools, automating repetitive tasks, and standardizing incident response processes. AI innovations further augment these capabilities, providing new methods for data interpretation, pattern identification, and real-time recommendations. This development is anticipated to persist through 2025, influencing the future of technical security services.
AI’s role in U.S. cybersecurity strategies is expanding as both threat actors and solution providers increasingly leverage AI-enabled technologies. While IT professionals express concern about attackers using AI to exploit vulnerabilities more rapidly and effectively, AI-powered defense systems are capable of processing vast amounts of data to detect threats that might elude manual detection. Additionally, the proliferation of AI tools is increasing demand for solutions designed to protect AI models, training data, and applications from attacks such as data poisoning.
Zero trust architecture is gaining significant adoption across the U.S. as enterprises strive to secure resources across widening security perimeters. The shift to cloud environments and distributed operations makes this approach more appealing. Zero trust systems incorporate components like identity and access management (IAM) for user verification and microsegmentation to isolate individual assets.
As U.S. companies accelerate digital transformation and prepare for future threats, strategic security services are concentrating on bolstering business resilience and utilizing real-time intelligence to assist enterprises in developing strategies aligned with their specific risk profiles. Concurrently, organizations are benefiting from significant advancements in security operations center/managed detection and response (SOC/MDR) services, which include enhanced proactive threat hunting and improved threat prioritization.
Gowtham Sampath, assistant director and principal analyst, ISG Provider Lens Research, and lead author of the report, stated, “Successful enterprises in the U.S. are integrating people, processes and technology into their security postures to meet AI-related risks. Partnering with service providers is crucial for augmenting internal teams with specialized skills and building up defenses.”
The report also examines global cybersecurity technology trends impacting U.S. enterprises, such as the increasing adoption of IAM, extended detection and response (XDR), and security service edge (SSE).
The 2025 ISG Provider Lens® Cybersecurity — Services and Solutions report for the U.S. assessed 116 providers across nine quadrants: Identity and Access Management (Global), Extended Detection and Response (Global), Security Service Edge (Global), Technical Security Services — Large Accounts, Technical Security Services — Midmarket, Strategic Security Services — Large Accounts, Strategic Security Services — Midmarket, Next-Gen SOC/MDR Services — Large Accounts, and Next-Gen SOC/MDR Services — Midmarket.
IBM was identified as a Leader in five quadrants. Accenture, Atos, Capgemini, CyberProof, Deloitte, EY, HCLTech, Infosys, Kudelski Security, NCC Group, Optiv, PwC, Rackspace Technology, TCS, Trustwave, Unisys, and Wipro were named Leaders in three quadrants each. Broadcom, Fortinet, Microland, Microsoft, Palo Alto Networks, and Persistent Systems were recognized as Leaders in two quadrants each. Cato Networks, Check Point Software, Cisco, Critical Start, CrowdStrike, CyberArk, Cyderes, Forcepoint, KPMG, Kroll, ManageEngine, Mphasis, Netskope, Okta, One Identity (OneLogin), Ping Identity, Proficio, SailPoint, Saviynt, SentinelOne, Trellix, Trend Micro, Versa Networks, and Zscaler were named Leaders in one quadrant each.
NTT DATA was named a Rising Star in three quadrants, indicating a “promising portfolio” and “high future potential.” BeyondTrust, HPE (Aruba), Microland, Mphasis, Persistent Systems, and Sophos were named Rising Stars in one quadrant each. PwC was recognized as the global ISG CX Star Performer for 2025 among cybersecurity service and solution providers, achieving the highest customer satisfaction scores in ISG’s Voice of the Customer survey.