NEWS
AI Risk and Regulation Reshape Australia’s Cybersecurity Providers
ISG’s 2026 report names 11 providers leading all three Australian cybersecurity quadrants, with Brennan and Datacom as Rising Stars, and ties the shift to AI risk and local delivery.
Australian enterprises are rewriting what they want from cybersecurity providers, and the 2026 ISG Provider Lens report for Australia maps the new pecking order. The shift is driven by two forces that did not figure this way three years ago: AI risk, especially around generative and agentic systems, and tighter regulatory expectations across critical infrastructure, finance, healthcare, telecoms, and government. Local delivery has stopped being a nice-to-have and become a procurement filter.
Eleven global firms now lead all three of the report’s quadrants, while a small set of local players, including Brennan and Datacom, are tagged as Rising Stars. The report is published by Information Services Group, the Nasdaq-listed research and advisory firm that counts 75 of the world’s top 100 enterprises as clients. The signal for buyers is that the criteria for picking a security partner are no longer about catalogue breadth. They are about how much of the work happens inside Australia, and whether the partner can stand between the enterprise and a regulator.
The Mandate Driving the 2026 Market
Australian enterprises are no longer buying cybersecurity the way they did in 2022. Regulatory expectations have moved faster than the threat landscape, and the two now push in the same direction, toward providers that can demonstrate residency, accountability, and an audit trail. The 2026 ISG Provider Lens Australia report frames it bluntly, saying enterprises are seeking partners that can strengthen long-term resilience across cloud, identity, and critical infrastructure.
The local-delivery point is the most concrete break from the previous cycle. Michael Gale, partner and regional leader at ISG Asia Pacific, said Australian enterprises increasingly expect cybersecurity partners to combine proven local delivery with practical capabilities to address evolving regulatory expectations. The phrase “close to home” appears in his framing of how organizations now evaluate bids. It echoes a pattern that other regulated markets, including the EU and parts of the United States, have already moved through, with similar consequences for vendor selection.
The second shift is operational. Enterprises are consolidating overlapping security tools, which means fewer vendors in the stack and more weight on the few that remain.
Sectors under the heaviest regulatory load are doing the most consolidation. Organizations in critical infrastructure, financial services, healthcare, telecommunications, and government are increasing investments in incident response, recovery planning, and third-party risk management. The result, ISG says, is a market that rewards breadth and depth together, not catalogue size.
Eleven Firms Lead All Three Quadrants
The 2026 report evaluates 36 providers across three quadrants: Strategic Security Services, Technical Security Services, and Next-Gen SOC/MDR Services. A core group of eleven providers took the Leader designation in all three: Accenture, Deloitte, DXC Technology, EY, Fujitsu, HCLTech, IBM, NTT DATA, TCS, Thales, and Wipro. The list is heavy with the same names that lead similar reports in other regulated markets, which underlines how the Australian buying pattern is converging with the global one.
Two more firms, Infosys and PwC, are Leaders in two quadrants each. Three others, KPMG, Tech Mahindra, and Telstra, are Leaders in one quadrant each. The split signals how the global firms with the deepest Australian benches and the most regulated-sector references are pulling away from the rest of the field.
The full leader map looks like this.
| Position in the 2026 ranking | Providers |
|---|---|
| Leader in all three quadrants | Accenture, Deloitte, DXC Technology, EY, Fujitsu, HCLTech, IBM, NTT DATA, TCS, Thales, Wipro |
| Leader in two quadrants | Infosys, PwC |
| Leader in one quadrant | KPMG, Tech Mahindra, Telstra |
| Rising Star in two quadrants | Brennan |
| Rising Star in one quadrant | Datacom |
EY also collected the report’s customer-experience prize. The firm is named the global ISG CX Star Performer for 2026 among cybersecurity service and solution providers, on the strength of the highest customer satisfaction scores in ISG’s Voice of the Customer survey. The dual recognition, Leader in all three quadrants and top customer-experience mark, is the closest the report comes to naming a single front-runner.
Brennan and Datacom in the Rising Star Tier
Outside the global tier, the report flags two providers that Australian buyers should track. Brennan is named a Rising Star, which ISG defines as a company with a “promising portfolio” and “high future potential,” in two quadrants. Datacom, the largest locally owned IT services firm in Australia and New Zealand, takes the Rising Star tag in one quadrant. Neither cracks the Leader tier, but both are positioned for upward movement in the next cycle.
The Rising Star designation matters in a market that is rewarding local delivery. Both Brennan and Datacom run significant Australian-based security operations and bring the kind of regulatory familiarity that global firms often have to import. For buyers looking for a partner that can speak to a local auditor without translation, the Rising Star list is the place to start. Australian cyber risk shows up at every layer, from brokerages still relying on SMS authentication to enterprise SOCs, and the procurement patterns described in the report track all of them.
Generative and Agentic AI Force a Reset
The technology shift in the report is about AI as a new class of risk, with AI defending networks a secondary concern. ISG’s lead author Andrew Milroy said Australian companies are becoming much more disciplined in how they evaluate cybersecurity partners, and that providers combining practical AI expertise with strong execution and sector knowledge are best positioned to meet enterprise expectations. The framing puts AI risk management on the same procurement checklist as incident response.
The two AI categories driving the reset are generative AI and agentic AI. Enterprises are reinforcing data protection, access controls, and oversight to address the legal, operational, and reputational risks that come with embedding these systems into business processes. The operational picture is more crowded than the report’s framing suggests, with security teams already using AI to enhance threat detection, accelerate prioritization, and streamline case management, and a wave of new AI-powered cybersecurity tools arriving from major vendors.
Buyer behavior is bifurcated. Enterprises favor practical applications that strengthen day-to-day security operations, not broad technology narratives, and they want partners who can do the same. The report describes organizations using AI to enhance threat detection, accelerate prioritization, and streamline case management while reducing pressure on security teams. The regulatory pressure on this category is now international: NSA, ASD’s ACSC, and agencies in the UK, Canada, and New Zealand have co-sealed a joint Cybersecurity Information Sheet on carefully adopting agentic AI services, a sign that agentic risk has moved from an enterprise concern to a national-security one.
Where the New Dollars Are Going
The biggest spenders are not the biggest names. Critical infrastructure, financial services, healthcare, telecommunications, and government organizations are increasing investments in incident response, recovery planning, and third-party risk management. The report does not give a sector-by-sector dollar breakdown, but the priority list points to where the next wave of contract activity will land.
ISG’s list of priority investments shapes where the new dollars are going.
- Incident response for organizations with regulatory reporting duties
- Recovery planning tied to Australia’s Security of Critical Infrastructure Act and sector-level continuity rules
- Third-party risk management as supply-chain attacks extend the attack surface
- Threat-led assessments to rehearse response against realistic attack patterns
- Tabletop exercises to close the gap between policy and execution
Threat-led assessments and tabletop exercises are the two practices gaining the most traction. ISG describes a growing enterprise appetite for security evaluations that simulate realistic attack scenarios based on known criminal or hostile methods, alongside structured exercises that rehearse response. Both practices are designed to surface the gap between policy and execution, and both are easier to run with a partner that already knows the customer’s environment. Enterprise interest is also growing in commercial models that deliver greater flexibility and faster time to value, a signal that buyers are pushing back on multi-year lock-ins.
Gartner’s Numbers Behind the Spending Shift
The procurement reset is happening against a large and growing market. Gartner’s March 2026 forecast for Australian information security spending sets the 2026 number at more than AU$7.5 billion, an increase of 9.5% from 2025. Security software is growing faster than the overall market, with Gartner forecasting a 12.3% increase on security software spending in Australia to more than AU$3.3 billion in 2026. The largest single category is security services, which Gartner sizes at more than AU$3.7 billion in 2026, an increase of 6.9% from 2025.
Gartner VP Analyst Richard Addiscott said the talent shortage is the single biggest reason services is the largest bucket, calling it a growing and increasingly critical need for AI-literate security personnel. Security services includes consulting, professional, and managed security services, and managed security service providers are absorbing demand that enterprises cannot fill with in-house teams. The same dynamic shows up in ISG’s framing of the Australian market, where consolidation and resilience work both push buyers toward outside help.
AI is reshaping how that money gets spent. Gartner predicts over 75% of enterprises will be using AI-amplified cybersecurity products for most cybersecurity use cases by 2028, up from less than 25% in 2025. The same forecast points to application security, data security, privacy, and infrastructure protection as the fastest-growing software categories. Australian buyers, in other words, are spending more on the same areas where AI is moving fastest.
- AU$7.5 billion in Australian information security spending in 2026 (Gartner)
- 9.5% increase from 2025 (Gartner)
- 12.3% growth in Australian security software spending in 2026 (Gartner)
- AU$3.7 billion in Australian security services spend in 2026 (Gartner)
- Over 75% of enterprises using AI-amplified cybersecurity products by 2028 (Gartner)
What the 2026 Report Does Not Say
The 2026 report is a vendor ranking, and it shows its shape. It evaluates the capabilities of 36 providers, names leaders and rising stars, and frames the buyer behavior that the rankings reflect. It does not break out spend by sector, does not name which buyers are running threat-led assessments, and does not quantify how much of the local-delivery preference is regulatory versus preference-based.
Several practical questions remain for the buyers the report is built around. Australian enterprises have not said publicly how they are weighting the eleven global Leaders against the Rising Stars in procurement, or how much of the new spend is going to managed services and how much to project work. The breach data that boards are now asking CISOs about has not been tied back to generative or agentic AI risk in a way the report can cite. The 2026 ISG Provider Lens is a vendor map with a strong directional signal, not a spending forecast.
-
AI1 month agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
AI1 month agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
GAMING1 month agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
CRYPTO2 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
APPS2 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
