Security vendors face declining sales as SaaS customers rely on cloud providers for security controls

Dec 9, 2013 | Cloud, News, Security

SOURCE: TBR

HAMPTON, N.H. (Dec. 9, 2013) — Technology Business Research Inc. (TBR) recently identified a growing trend among organizations using Software as a Service (SaaS): Increasing use of cloud services is disrupting sales for security vendors. Security vendors that sell products or services directly to end-user organizations will experience a reduction in revenues in 2014 as more organizations move applications and data to the cloud.

In a 2013 TBR study of organizations using SaaS, 53% of respondents expect their security controls to be selected and integrated by their cloud service provider. Among organizations using SaaS, more than half will not purchase or deploy their own security products or services to protect the applications they moved to the cloud.

“As cloud adoption increases, security vendors will not be directly involved in as many organizations’ security purchasing decisions,” said Jane Wright, a TBR senior analyst focusing on information security. “Security vendors will be challenged to replace these lost sales opportunities through other initiatives, such as technology partnerships and marketplace alliances with cloud service providers.”

The SaaS study was part of a series of TBR research studies about the state of security in public, private and hybrid cloud environments. Highlights from the studies will be delivered in a TBR webinar, “Security Opportunities in the Cloud — IT Security Insights from TBR’s Cloud Customer Research” on Dec. 18, 2013. Wright and TBR Senior Analyst Allan Krans will discuss how security vendors can navigate the changing perceptions and role of security in the cloud to grow in 2014. To register for the webinar, visit tbrevents.webex.com.

Detailed findings from TBR research are also covered in a related TBR report, Security Opportunities Driven by Cloud Adoption. The report details the reasons that organizations perceive security as either a driver or a barrier to cloud adoption, and the types of workloads that are most commonly deployed in public, private and hybrid clouds by organizations that consider security as a driver for cloud services.

For more information about Security Opportunities Driven by Cloud Adoption or to purchase the report, please contact Alison Crawford, senior marketing manager, at 603.758.1838 or alison.crawford@tbri.com, or James McIlroy, vice president of sales, at 603.758.1813 or mcilroy@tbri.com.

ABOUT TBR

Technology Business Research, Inc. is a leading independent technology market research and consulting firm specializing in the business and financial analyses of hardware, software, professional services, telecom and enterprise network vendors, and operators. Serving a global clientele, TBR provides timely and actionable market research and business intelligence in a format that is uniquely tailored to clients’ needs. Our analysts are available to further address client-specific issues or information needs on an inquiry or proprietary consulting basis.

TBR has been empowering corporate decision makers since 1996. For more information please visit www.tbri.com.

 

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more