Security management

Insights

Blog

Remove Ambiguity: Measure Human Risk Management Metrics That Matter

Jinan Budge 7 days ago
Our latest research — Five Steps To Better Human Risk Management Metrics and The Essential List Of Human Risk Management Metrics — provides security leaders the clarity they need to measure what truly matters. I see this not as just another comprehensive metrics framework (though it is that!) — I also see it as a foundation for turning human risk management from a conversation into a movement.
Blog

Secure Vibe Coding: I’ve Done It Myself, And It’s A Paradigm, Not A Paradox

Janet Worthington October 28, 2025
“There’s a new kind of coding I call ‘vibe coding,’ where you fully give in to the vibes, embrace exponentials, and forget that the code even exists,” said Andrej Karpathy in a post on X (formerly Twitter) back in February.

Predictions 2026: Your Planning Starts Here

2026 will demand proof, not promises. Explore Forrester’s Predictions resources — guides, webinars, and blogs — to plan smarter, lead with trust, and stay ahead of disruption.

Blog

Gold Rush Or Fool’s Gold? How To Evaluate Security Tools’ Generative AI Claims

Allie Mellen October 27, 2025
Generative AI features and products for security are gaining significant traction in the market. Knowing how to evaluate them, however, remains a mystery. What makes a good AI feature? How do we know if the AI is effective or not? These are just some of the questions I receive on a regular basis from Forrester […]
Blog

Announcing Forrester’s 2025 Security & Risk Enterprise Leadership Award Winners

Joseph Blankenship October 22, 2025
Learn more about the two enterprise security programs that won this year’s Security & Risk Enterprise Leadership Award.
Blog

Declaring Zero Trust Without Testing Is A Lie

Tope Olufon October 20, 2025
Zero Trust without real-world testing is a false sense of security. Learn how MITRE ATT&CK-driven adversarial trials turn Zero Trust from theory into proof.
Blog

How F5 And SonicWall Revealed The Fragility Of The Software Supply Chain

Carlos Rivera October 17, 2025
The recent breaches at F5 and SonicWall illustrate how attackers are targeting the very infrastructure that enterprises rely on to secure and deliver digital services.
Blog

UK Government Plans To Mandate Digital eID For All Legal UK Residents

Andras Cser October 16, 2025
The UK government plans to mandate an electronic digital identity scheme and credential to all legal residents and employees of the UK to prove immigration and employment eligibility status. Read our assessment of the benefits, challenges, and concerns.
Blog

Announcing The Forrester Wave™: Network Analysis And Visibility Solutions, Q4 2025

Jitin Shabadu October 15, 2025
Despite its criticality, network analysis and visibility solutions remain underrepresented in enterprises compared to technologies such as endpoint detection and response and security information and event management. Find out why in this preview of our new Wave report.
Blog

You Know Who’s In The Building — But Who’s In Your Network?

Paddy Harrington October 9, 2025
Strong physical security is standard in critical infrastructure — but OT networks often remain wide open. This blog explores how applying Zero Trust principles can help you control digital access with the same rigor you apply to physical visitors.
Blog

Global Cybersecurity Spending To Exceed $300B By 2029

Merritt Maxim October 3, 2025
Despite the ongoing macroeconomic uncertainty in 2025, cybersecurity spending will rise by 13.1% this year to $174.8 billion, driven by ongoing concerns around cyberattacks and the need to secure new cloud-based deployments. Find out more in our cybersecurity spending forecast.
Blog

CrowdStrike Fal.Con 2025: Flexing Into The Agentic AI Age

Jitin Shabadu September 24, 2025
CrowdStrike held its Fal.Con 2025 conference recently and not surprisingly for a cybersecurity vendor event in 2025, AI dominated. Get our highlights and key takeaways here.
Blog

Your Top Questions On Generative AI, AI Agents, And Agentic Systems For Security Tools Answered

Allie Mellen September 23, 2025
Many security professionals are still confused about which AI capabilities are real now and which will come down the road. Get answers to some of the most common questions about use of generative AI, agentic AI, and AI agents in security tools in this preview of our upcoming Security & Risk Summit.

2026 Predictions: What Tech And Security Leaders Must Know

Our 2026 tech and security predictions are out — now it’s time to go deeper. Join Forrester’s analysts to uncover what you must do to lead with trust and value.

Blog

Securing AI’s M&A Feeding Frenzy Is On

Jeff Pollard September 22, 2025
The cybersecurity industry is in the middle of a land grab as AI security M&A heats up. In just 18 months, eight major vendors — including Check Point, Cisco, CrowdStrike, F5, and Palo Alto Networks — have spent upwards of $2.0 billion acquiring startups focused on securing enterprise AI. AI for security is already poised to disrupt […]
Blog

Get Your Zero Trust Initiative Back On Track With Forrester’s Zero Trust RASCI Chart

Carlos Rivera September 17, 2025
One of the biggest challenges to a Zero Trust journey can be misalignment between teams. Learn how our Zero Trust RASCI Chart can help define roles and responsibilities across the core domains of Zero Trust.
Blog

Splunk .conf25: Cisco, AI, And Data

Allie Mellen September 15, 2025
The 10th annual Splunk .conf took place in Boston recently. From the opening keynote to various new product releases and enhancements, get a full review of the event in this post.
Blog

School Is In Session, And Attackers Are Grading Your Software Supply Chain Security

Janet Worthington September 12, 2025
Three recently revealed software supply chain attacks are a reminder of how attackers probe for any weakness in a supply chain, including smaller entities, to target larger enterprises. Find out how you can learn from these attacks to strengthen your supply chains.
Blog

The Abyss Of The Salesloft-Salesforce Breach May Reach The Challenger Deep

Paddy Harrington September 12, 2025
Details have been trickling out about a security issue in Salesloft’s Drift product. Find out what data was compromised and what actions you can take to reduce the threat to your business.

2026 Tech & Security Predictions You Can’t Afford To Miss

AI cleanup, budget shifts, neocloud, and quantum threats — what’s ahead could reshape your strategy. Get Forrester’s guide with five bold predictions to stay ahead and lead with trust and value.

Blog

Announcing The Forrester Wave™: IoT Security Solutions, Q3 2025

Paddy Harrington September 10, 2025
IoT devices are a normal part of business and personal life. In enterprises, it is estimated that there are between six and 10 IoT devices for each employee, ranging from long-standing devices, such as printers and cameras, and industry-specific devices like warehouse scanners and medical infusion pumps to modern air quality monitors and soil moisture […]
Blog

Introducing Forrester AI Access: Equipping Organizations With Trusted Insights To Act Fast

Carrie Johnson September 9, 2025
Forrester AI Access is an important milestone in our AI journey, beginning with our 2023 launch of Izola. With AI Access, organizations can validate ideas, innovate, and make smarter decisions faster.
Blog

Partner For Progress: Security And HR Must Team Up For Insider Risk Management

Joseph Blankenship September 8, 2025
Since insider risk is more about people than PCs, security and insider risk management pros must make an unlikely new ally: their colleagues in HR. Find out how HR can help reduce insider risk in this preview of our upcoming Security & Risk Summit.
More posts