Digitization / RESEARCH MAP 08
Cybersecurity
Does the customer buy another tool, or a better security outcome?
From security inputs to products and operational response.
Scope: Enterprise security products and services. The commercial layers below are DEX's map, not the NIST CSF functions or a compliance checklist.
Geography: Global enterprise lens; NIST provides the risk-management reference.
01 / HOW IT WORKS
Follow the value chain
DEX editorial map. Read left to right (top to bottom on mobile); companies may span several stages. Expand a stage to inspect its economics.
-
Signals & foundations
Telemetry, identity and intelligence providers
Supply the information and controls used by security teams.
Revenue & bottleneck — Signals & foundations
- Revenue models to investigate
- Data feeds, infrastructure or identity-service contracts.
- Bottleneck to test
- Are the signals relevant, complete and lawful to use?
-
Security products
Endpoint, cloud, network and identity vendors
Turn inputs into prevention, detection and investigation tools.
Revenue & bottleneck — Security products
- Revenue models to investigate
- Subscriptions, licenses or consumption-based fees.
- Bottleneck to test
- Can tools integrate without overwhelming operators?
-
Operations & response
Internal teams, managed providers and responders
Operate controls and coordinate incident handling and recovery.
Revenue & bottleneck — Operations & response
- Revenue models to investigate
- Managed-service contracts, retainers or response projects.
- Bottleneck to test
- Can the customer turn alerts into timely, effective action?
02 / FOLLOW THE MONEY · DEX INTERPRETATION
The business-model lens
Test renewal quality and delivery cost alongside product claims. Security spending is not itself evidence that customer risk has fallen.
03 / TEST THE THESIS · RESEARCH QUESTIONS
Signals to investigate. Risks to challenge.
Demand & adoption questions
- Which assets and workflows create an uncovered exposure?
- Would integration or managed delivery solve a staffing bottleneck?
What could weaken the thesis?
- Product overlap and tool consolidation may affect renewals.
- Failures in the vendor's own systems can undermine trust.
04 / BUILD A WATCHLIST
Metrics worth tracking
Suggested research metrics, not measured values. Collect primary data with a date, geography and definition before making comparisons.
- Net revenue retention
- Use a consistent cohort and vendor definition.
- Response effectiveness
- Define incident severity and measurement boundaries before comparing.
- Service delivery cost
- Include analyst time and infrastructure per customer.
05 / CHECK THE EVIDENCE
Evidence anchors & sources
These sources support the statements below. They do not validate every editorial hypothesis, imply endorsement, or refresh the explorer's market estimates.
- NIST CSF 2.0 organizes cybersecurity outcomes under Govern, Identify, Protect, Detect, Respond and Recover. These are outcomes, not six sequential commercial stages. [nist-csf]
- NIST SP 800-207 sets out zero-trust architectural principles; it is not a market-sizing or vendor-share study. [nist-zero-trust]
- Menlo Ventures' 2022 market map is an illustrative snapshot of product categories and vendors, not a current estimate of spending or company shares. [menlo-map]
- Government framework · PDF
The NIST Cybersecurity Framework (CSF) 2.0
Supports: Risk-management functions only; does not establish vendor revenue, effectiveness or market size.
- Government publication
SP 800-207: Zero Trust Architecture
Supports: Zero-trust architecture concepts; not an estimate of industry revenue.
- Investor research · PDF
Cybersecurity Market Map
Supports: Illustrative historical vendor categories; not a verified 2026 revenue dataset.
CONTINUE THE RESEARCH
Go from map to evidence.
The 50-industry dataset is a separate screening resource with different coverage and source limitations. Related reports retain their own dates and scope.
Educational research framework only. Not investment, legal or medical advice.