RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2
2023/10/26 18:36:01

TAdviser and Positive Technologies study: SIEM market in Russia will grow dynamically in the coming years

As a study by TAdviser and Positive Technologies showed, the SIEM market in Russia remains positive and will continue to grow until 2027. Its drivers remain growing cyber threats, increasing cyber attacks on Russian organizations, as well as the need for import substitution of foreign systems.

According to a study by TAdviser and Positive Technologies, the size of the SIEM systems market in Russia in 2022 amounted to 13.2 billion rubles. (growth + 30%). Experts expect that this year its high dynamics will continue (projected growth + 47%). By 2026, the domestic market may grow to 48.8 billion [1]

The results of the TAdviser and Positive Technologies study were presented at a press conference on October 26 "(photo from the event)"

Most Russian companies (97%) today already use systems of this class. At the same time, more than half of the surveyed organizations (56%) have already implemented domestic solutions by 2023. 4% of respondents reported migration plans for the Russian SIEM system in 2023-2024, almost a third of respondents planned to do this after 2024 according to the formed road maps for import substitution of IT (in large organizations such initiatives are implemented in stages and are designed for an average of 3-4 years).

SIEM market development forecast in Russia, RUB bln
Source: TAdviser, 2023
File:Aquote1.png
The Russian market for SIEM systems is already quite mature - both in terms of maturity of products of this class and in terms of their penetration into Russian companies. At the same time, in 2022, the market showed dynamic growth (above the global one), spurred by the requirements of regulators to switch to Russian solutions and the general need for import substitution, including due to the departure of foreign vendors. These factors remain relevant this year, and even greater pressure is added to them from the regulatory side, to which many need to switch to domestic products, as well as the need to update previously implemented systems due to the trend towards the continued growth of cyber threats. Therefore, at the end of 2023, we can expect even higher dynamics in the segment of SIEM systems, - comments Natalya Lavrentieva, deputy editor-in-chief of TAdviser.
File:Aquote2.png

As a result of the implementation of SIEM solutions, 97% of the surveyed companies expect to receive timely detection of attempts to violate cyber resistance and incidents that can lead to unacceptable consequences for business, and survey participants also note the need to obtain an up-to-date updated expertise to protect their infrastructure (59%).

Expected Results from SIEM Implementation
Source: TAdviser, 2023

When choosing a product of this class, companies focus primarily on constantly updated rules for detecting current threats (83%), the ability to respond to security events directly from the SIEM system (65%), as well as the convenience of the interface for the operator or information security analyst (64%).

The study also considered promising directions for the development of SIEM systems. In the next 2-3 years, Positive Technologies experts included automatic adaptation of boxed expertise to the infrastructure features of companies, synergy of event analysis from the level of endpoints, applications, traffic and information protection tools, behavioral analysis based on ML, AI technologies (Handling events with context and knowledge of attacker behavior patterns), SIEM in the cloud and for the cloud (using clouds as a data source and service delivery format, including the development of MSSP functionality), automation of interaction with adjacent information security systems.

As the study showed, the previously cautious attitude of Russian organizations to the clouds can be revised due to the need to solve problems related to the shortage of equipment and personnel against the background of the need to provide high-quality technical support. More than a third of respondents who do not yet consume information security products according to the service model plan to switch to it in the near future. Almost all of them indicate the absence of the need for hardware and software support in-house as the main factor in the choice of the SaaS model.

SaaS Model Selection Factors for Information Services Consumption
Source: TAdviser, 2023

Full version of the study by reference.

Notes

  1. rubles. During the study, two methods were used. To study the demand for SIEM systems and determine user requirements, 100 Russian organizations representing a large (from 3 thousand employees or more) and medium (from 250 to 3000 employees) business were interviewed. The survey was attended by leaders of IT and information security (CIO, CTO, CISO and other specialists responsible for the development of cybersecurity) from the fields of IT, finance, fuel and energy complex, industry, telecom, retail, as well as state, educational and medical institutions. The calculation of the market volume, vendor shares and SIEM growth forecasts was carried out on the basis of expert assessments of the authors of the study, analysis of data from well-known analytical agencies, including information on shipments of open tenders of trading platforms.