decryptingtech

Technology. Business models. Market debates.

Browse this section

Specialist Cybersecurity Domains

Cybersecurity is often organised around the main enforcement surfaces: endpoint, identity, network, cloud, email, web and data. A second group of domains cuts across those surfaces. These capabilities secure software before it runs, find weaknesses before they are exploited, supply specialist operating capacity, restore the business after an attack and govern the entire control system.

Summary

The eight specialist domains are Application Security, Vulnerability and Exposure Management, Managed Detection and Response, Cyber Resilience and Recovery, Threat Intelligence, Governance Risk and Compliance, OT and IoT Security, and Human Risk Management. They are separate markets because each requires distinct data, workflows and expertise. They are also converging because their findings become far more valuable when connected to Security Operations and the major enforcement platforms.

DomainPrimary questionPrincipal connection
Application SecurityIs the software safe to release and run?Development, cloud and runtime controls
Exposure ManagementWhich weaknesses are most likely to matter?Assets, identities, cloud and remediation
MDRWho will operate detection and response continuously?XDR, SIEM and incident response
Cyber ResilienceCan the business restore trusted operations?Data, identity and business continuity
Threat IntelligenceWhich adversaries and campaigns are relevant?Detection, prioritisation and response
GRCAre risks, controls and obligations being managed?Governance, audit and board oversight
OT and IoT SecurityAre unmanaged and physical systems visible and safe?Network, asset and operational safety
Human RiskWhich behaviours create or reduce exposure?Email, identity and data protection
Summary

Application Security

Application Security protects software across design, code, build, deployment and runtime. The toolchain includes static and dynamic testing, software-composition analysis, secrets detection, container and infrastructure-as-code scanning, API security, web application firewalls and runtime protection. The strategic aim is to find exploitable weaknesses early without turning development security into a release bottleneck.

Major players span several camps. Snyk, Checkmarx and Veracode are code-security specialists. GitHub and GitLab embed controls inside the developer workflow. Palo Alto Networks and Wiz connect application findings to cloud posture and runtime context. Cloudflare, Akamai, F5 and Salt Security protect applications and APIs in production.

The competitive fault line is developer adoption versus security breadth. Specialists can deliver deeper testing and remediation guidance; development platforms own the workflow; cloud platforms can show whether vulnerable code is reachable in production; runtime vendors see live attacks. The winning architecture connects code ownership, exploitability and runtime exposure so developers fix the small number of issues that can materially change risk.

Vulnerability and Exposure Management

Traditional vulnerability management discovers assets, identifies known weaknesses and tracks remediation. Exposure management broadens the task to include cloud misconfigurations, identities, external attack surfaces, application flaws and attack paths. Its purpose is prioritisation: not every weakness is reachable, exploitable or attached to an important asset.

Qualys, Tenable and Rapid7 retain deep scanning and vulnerability-management estates. CrowdStrike, Palo Alto Networks, Microsoft and Wiz approach exposure through endpoint or cloud platforms. Armis and Axonius contribute asset intelligence, while validation vendors test whether suspected attack paths can actually be used.

The market is moving from lists to graphs and from scoring to remediation. Incumbent scanners benefit from coverage, history and workflow integration; platform vendors benefit from live telemetry and direct control of endpoints, identities or cloud workloads. Durable advantage comes from authoritative asset identity, broad exposure data and the ability to close the loop through patching, configuration changes, compensating controls or owner workflows.

Managed Detection and Response

MDR provides continuous monitoring, investigation and response as a service. It is not simply outsourced alert handling. A credible provider combines technology, detection engineering, threat hunting, incident expertise and authority to contain attacks. MDR matters because many organisations cannot recruit and retain a fully staffed SOC or operate complex tools continuously.

The market divides into product-attached services such as CrowdStrike Falcon Complete, Microsoft Defender Experts, Palo Alto Networks Unit 42 and Sophos MDR; security-operations specialists such as Arctic Wolf, Expel, Red Canary and eSentire; and large service providers that operate broader customer estates.

Product-attached MDR has better access to native telemetry and response controls. Vendor-neutral providers can work across heterogeneous environments and may deliver stronger human relationships and process ownership. The key competitive measures are detection quality, response authority, service consistency, coverage beyond endpoints and whether the provider improves the customer’s security programme rather than merely forwarding incidents.

Cyber Resilience and Recovery

Cyber resilience assumes prevention will sometimes fail. It protects recovery infrastructure, identifies clean restore points and coordinates the return of critical applications, data and identities. The domain extends backup into immutability, anomaly detection, sensitive-data visibility, isolated recovery environments and rehearsed business restoration.

Rubrik, Cohesity, Commvault and Veeam are the principal modern platforms, with Dell, IBM and cloud providers serving large installed bases. Competition centres on workload coverage, simplicity, isolation from production credentials, recovery speed and confidence that restored data is both clean and usable.

This domain joins Data Security to incident response and business continuity. Backup success is not the same as business recovery: organisations must restore identity, configuration, applications and dependencies in the right order. The most strategic platforms are moving from storing copies to orchestrating trusted recovery and proving readiness before an attack.

Threat Intelligence

Threat Intelligence converts evidence about adversaries, infrastructure, malware and campaigns into decisions. It helps defenders prioritise vulnerabilities, enrich alerts, write detections, block malicious infrastructure and understand whether activity belongs to a broader operation. Intelligence has value only when it is timely, relevant and connected to an action.

Google Mandiant, CrowdStrike, Microsoft and Palo Alto Networks Unit 42 combine intelligence with large security telemetry estates and incident-response work. Recorded Future, Flashpoint, Intel 471 and Group-IB specialise in external, underground or geopolitical collection. Threat-intelligence platforms such as Anomali and ThreatConnect aggregate feeds and manage workflows.

Scale of collection is useful, but raw indicators commoditise quickly. Differentiation comes from unique visibility, attribution expertise, speed, regional access and integration into security controls. The domain fits upstream of SecOps and Exposure Management: it tells detection systems what to look for and helps exposure platforms distinguish theoretical weaknesses from those being actively used.

Governance Risk and Compliance

GRC translates technical security into accountable business governance. It maintains policies, maps obligations to controls, records evidence, manages exceptions, assesses suppliers and reports risk to executives, auditors and boards. It does not prevent attacks directly; it determines what must be protected, who owns the decision and whether controls operate as intended.

ServiceNow competes through enterprise workflow and IT integration. Archer and MetricStream serve complex risk and compliance programmes. AuditBoard links audit, risk and control evidence. OneTrust is strong where privacy, data governance and third-party risk overlap. LogicGate and other cloud-native specialists compete on deployment speed and usability.

The competitive challenge is turning a system of record into a system of action. Static questionnaires and periodic evidence collection create administrative work but weak risk visibility. Stronger platforms ingest technical control data automatically, maintain a common control framework and route remediation to operational teams. AI can accelerate evidence mapping and policy work, but final accountability cannot be automated away.

OT and IoT Security

Operational Technology controls physical processes in manufacturing, energy, transport, buildings and healthcare. IoT adds large populations of specialised connected devices. These environments often use proprietary protocols, remain in service for long periods and cannot tolerate the scanning, agents or automatic containment common in IT. Availability and human safety can matter more than confidentiality.

Claroty, Nozomi Networks and Dragos bring specialised asset discovery, protocol knowledge, monitoring and industrial expertise. Armis spans unmanaged IT, IoT, medical and OT assets. Microsoft, Palo Alto Networks, Fortinet, Cisco and Tenable connect OT visibility to broader security platforms.

Specialists differentiate through passive discovery, device intelligence, industrial detections and incident knowledge. Broad platforms offer distribution and integration with network security, exposure management and the SOC. The domain fits beside Network Security, but response must respect operational context: automatically isolating a compromised laptop is routine; stopping an industrial controller may create a larger hazard than the cyber event.

Human Risk Management

Human Risk Management extends security-awareness training into continuous measurement and intervention. It combines simulations, education, real attack data, identity risk and user behaviour to identify where mistakes or malicious actions are most likely to create loss. The goal is not course completion; it is safer behaviour and faster reporting.

KnowBe4 has broad awareness and simulation distribution. Proofpoint and Mimecast connect human risk to email and collaboration telemetry. Hoxhunt focuses on adaptive training and behaviour change. Cofense is closely associated with phishing reporting and response, while CybSafe emphasises behavioural measurement.

Standalone providers can remain neutral across the security stack and focus deeply on engagement. Email and identity platforms can use richer live-risk signals and enforce controls around high-risk users. The domain connects Email and Web Security, Identity Security and Data Security. Its future is adaptive: stronger authentication, warnings, access restrictions or coaching should change with observed risk rather than follow the same annual schedule for every employee.

How the domains fit together

These markets form three operating loops. Application Security, Exposure Management and Human Risk reduce the probability of compromise. Threat Intelligence, OT monitoring and MDR improve detection and response. Cyber Resilience restores trusted operations when containment is not enough. GRC sits across all three, assigning ownership and testing whether the controls match business obligations.

The unifying layer is Security Operations. Application findings, vulnerable assets, threat context, human signals and OT alerts become incident evidence; endpoint, identity, network, cloud and data platforms provide enforcement. Recovery then closes the loop by restoring what the attack damaged. This explains both the persistence of specialists and the push toward platforms: expertise remains domain-specific, but outcomes depend on cross-domain context and action.

Competitive and investment lens

Across all eight domains, the same contest repeats. Specialists win through depth, proprietary data and expert workflows. Large platforms win through distribution, shared telemetry, bundled pricing and control of adjacent enforcement points. A feature becomes a durable business when it owns an authoritative dataset, an embedded workflow or a response action that customers cannot easily reproduce elsewhere.

The strongest businesses should move beyond visibility into verified outcomes: vulnerabilities remediated, incidents contained, recovery tested, risky access removed or behaviour changed. Products that only create another dashboard are vulnerable to consolidation. Products that become part of how an enterprise develops software, operates incidents, proves controls or restores the business can retain strategic value even as broader platforms expand.

Bottom line

These specialist domains are not peripheral. They cover the parts of cybersecurity that the core enforcement layers cannot solve alone: secure creation, prioritised prevention, expert operations, adversary context, accountable governance, physical-system protection, human behaviour and recovery. The architecture is converging, but the winning platform will still need credible depth in each domain and a clean connection to the controls that can change the outcome.