security architecture

As businesses compete to win and retain customers concerned about the privacy of their data, more firms are learning the value of a robust and effective security architecture. Get benchmarks and technical guidance here.

Learn more about how Forrester supports IT professionals.

Insights

Blog

Announcing The Forrester Wave™ For Microsegmentation Solutions, Q3 2026: Not Your Parents’ Access Control Solution

James Plouffe 6 hours ago
For as long as I’ve been in cybersecurity, we’ve been trying to “adapt to the shifting threat landscape.” More recently, a number of vendors and security leaders alike have told me some version of a joke about how starting a microsegmentation project is a great way to get fired. But this is a market that […]
Blog

The Capital Connection: Exploring Washington, DC During Security & Risk Forum 2026

Forrester 10 hours ago
Security & Risk Forum 2026 brings security, risk, and resilience leaders to Washington, DC, a city where technology, governance, security, and public trust intersect every day. From iconic landmarks and Smithsonian museums to neighborhood cafes and networking-worthy restaurants, explore what to see and do while you’re in the nation’s capital.

Secure AI Agents Before You Scale

Scaling AI agents shouldn’t mean scaling exposure. Download Forrester’s AEGIS playbook to set guardrails on intent, authority, and access so that adoption stays accountable, auditable, and defensible.

Blog

The First Principles Of Cybersecurity Still Apply

Paddy Harrington 2 days ago
As cyberthreats evolve and AI accelerates attacker capabilities, the most effective defenses remain the foundational practices many organizations overlook. Learn why recent attacks on critical infrastructure reinforce the need to focus on basic security principles before investing in new technologies.
Blog

Bringing Crypto Agility And PQC Visibility To The Network With NAV

Jitin Shabadu August 12, 2026
The Q4 2025 Forrester Wave™ evaluation for network analysis and visibility (NAV) solutions was the first iteration of the research to evaluate vendors on their post-quantum cryptography (PQC) capabilities, a decision that has become more pronounced in 2026. The rationale was compelling then; it is unavoidable now. Most notably, the US federal government has moved […]
Blog

Introducing AEGIS — The Guardrails That CISOs Need For The Agentic Enterprise

Jeff Pollard August 12, 2026
AI agents aren’t coming — they’re already here, and they’re not waiting for your security architecture to catch up. Learn how Forrester’s new AEGIS framework can help CISOs secure, govern, and manage AI agents and agentic infrastructure.
Blog

Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI

Allie Mellen June 25, 2026
Last week, Forrester released The Forrester Wave™: Extended Detection And Response Platforms, Q2 2026. This is the third iteration of the extended detection and response (XDR) Wave, with prior versions published in 2021 and 2024. This Wave differs significantly from the past, especially because of: The number of vendors. This year, only seven vendors were […]
Blog

AI Is Moving Fast, But Trust Is Struggling To Keep Up: Why Security And Risk Leaders Can’t Miss Forrester’s AI Forum

Jinan Budge June 24, 2026
AI adoption is accelerating, but confidence in its outcomes isn’t. At Forrester’s AI Forum 2026, security and risk leaders will learn how to shift from traditional protection to a trust-and-assurance mandate — with practical frameworks, real-world perspectives, and strategies to secure an increasingly agentic enterprise while enabling innovation.
Blog

Total Recall: A Cautionary Fable Of Anthropic And The US Government

Jeff Pollard June 15, 2026
On Friday, June 12, the same model class covered by our previous blog post went dark. Anthropic suspended Fable 5 and Mythos 5 worldwide after the US Department of Commerce issued an export control directive, which led to requests from prominent cybersecurity pros to undo the action. The bypass that triggered the export controls, per […]
Blog

How Fable 5 And Mythos 5 Change AI Security, Data Retention, And Vendor Risk

Jeff Pollard June 10, 2026
Anthropic’s Fable 5 and Mythos 5 is the most 2026 product launch you’ll read this year. The same model can find nation-state zero days, design novel drug candidates, and play FireRed on a Gameboy Advance with nothing but screenshots. And for the gaming fans out there, yes, we got Fable 5 before Fable 4. These […]
Blog

Announcing The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026

Geoff Cairns May 21, 2026
Our latest evaluation of workforce identity security providers, The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026 is now available! Workforce identity security is now a strategic pillar of modern cybersecurity, driven by the expansion of nonhuman identities, increasingly sophisticated identity‑based attacks, and the operational demands of Zero Trust. Organizations already grappling with identity sprawl across […]
Blog

AI Is Turning Unified Storage Into A Strategic Decision

Brent Ellis May 4, 2026
Unified storage has long been treated as a pragmatic, commodity storage investment: Balance cost, simplify operations, move on. In a world of AI enablement and, consequently, downside AI risk, that mindset no longer holds. Agentic, autonomous AI use cases are making storage a strategic decision point to address capability needs, performance requirements, and GRC concerns. AI systems increasingly operate directly on live enterprise data, […]
Blog

Why Scaling Products Without Architecture Slows You Down

Stéphane Vanrechem May 4, 2026
Product-centric operating models are now the default aspiration for digital organizations. Agile adoption continues to rise. Our data shows that 55% of firms in North America and Europe now use agile or product-centric ways of working, up double digits since 2023, while APAC adoption is approaching 50%. The promise is compelling: faster value delivery, empowered […]
Blog

Project Glasswing Shows That AI Will Break The Vulnerability Management Playbook

Erik Nost April 8, 2026
Anthropic, along with 11 other companies, recently announced Project Glasswing — an initiative that aims to secure software in the wake of advances in AI capabilities, most notably Anthropic’s Claude Mythos Preview frontier model. Project Glasswing is made up of a who’s who of tech companies, cybersecurity vendors, and others: Amazon Web Services, Anthropic, Apple, […]
Blog

The Four EA Archetypes: A Story Of How EA Finds Its True Place

Stéphane Vanrechem March 27, 2026
In nearly every enterprise architecture (EA) leadership conversation I’ve had this year, the same tension surfaces: The practice is doing real work, but stakeholders can’t describe what it delivers. Expectations have surged, roles have expanded, and transformation pressures are multiplying. Yet the practice remains invisible where it matters most. EA leaders need a clear anchor: […]
Blog

When Every Enterprise Architecture Tool Looks The Same …

Stéphane Vanrechem March 17, 2026
The demos all blurred together — another week, another vendor pitch. Slide after slide promised a “single source of truth,” “360-degree visibility,” and “seamless collaboration across the enterprise.” The names and interfaces changed, but to the enterprise architecture (EA) leader in the room, it all felt like the same story with a different logo on […]
Blog

White House Announces The 2026 Cyber Strategy For America

Allie Mellen March 11, 2026
On Friday, March 6, the Trump administration released the latest US national cybersecurity strategy, President Trump’s Cyber Strategy for America, alongside an executive order on combating cybercrime and fraud. The document, focused on six core pillars, is the briefest cybersecurity strategy released by the US in the last decade. The biggest challenge with the document […]
Blog

Unified Financial Crime Management Is Not Just For Small And Regional Banks

Andras Cser March 11, 2026
Fraud management and anti-money laundering (AML) solutions share common traits and requirements: Both are about risk scoring of entities (names, phone numbers, email addresses, accounts) and routing and investigating alerts and cases to AI agents and human investigators. While smaller, regional financial institutions (FIs) and insurers have always been motivated to consolidate tools and resources […]
Blog

How Philip Morris International’s Outcome‑Driven EA Practice Won The 2025 Forrester EA Award In EMEA

Stéphane Vanrechem March 3, 2026
Philip Morris International (PMI) won Forrester’s 2025 Enterprise Architecture Award in the EMEA region by redesigning its operating model to make AI scalable, governed, and reusable from day one.
Blog

Claude Code Security Causes A SaaS-pocalypse In Cybersecurity

Jeff Pollard February 23, 2026
We have seen this pattern before, even if the specifics look different. Think back to the day AWS introduced GuardDuty, when Microsoft folded Defender for Endpoint into its enterprise licensing commitments and launched Microsoft Sentinel, or when Google acquired Mandiant and eventually Wiz. Sure, the launch of fully autonomous AI agents that can ingest entire […]
Blog

Enterprise Architects Have Stepped Out Of The Ivory Tower

Stéphane Vanrechem February 12, 2026
For years, many enterprise architecture (EA) teams operated in isolation, building elaborate frameworks that few understood and even fewer used. Then something shifted: Architects started solving actual business problems instead of perfecting abstract models. Our research captures this turnaround. In 2023, only 35% of digital and IT professionals said architects add value; by 2025, that figure […]
More posts