Skip to content
    Back to overview
    Data as of June 2026

    Market Intelligence

    Security Operations (SecOps)

    Autonomous Threat Detection, Investigation & Response

    2025 Market Size
    $21.0B
    2030 Projection
    $54B
    CAGR
    21.0%

    Market growth trajectory

    $B / year

    Established Vendors

    54 companies tracked, ranked by market prominence.

    Top 5 spotlight

    1

    CrowdStrike

    Unified AI-native cybersecurity from endpoint to SIEM and SOAR

    Falcon Platform
    Mkt Cap
    $96B
    Revenue
    $5.5B ARR
    Growth
    +24% YoY
    Jun 2026: Q1 FY27 record net-new ARR $256M (+32%); 4-for-1 stock split
    View profile
    2

    Palo Alto Networks (XSOAR)

    Most deployed SOAR platform with XDR and AI-native SOC capabilities

    SOAR + XDR Leader
    Mkt Cap
    $228B
    Revenue
    $9.2B Rev
    Growth
    +15% YoY
    Jun 2026: Q3 FY26 rev $3.0B +31%; NGS ARR $8.13B +60% (CyberArk/Chronosphere)
    View profile
    3

    Microsoft Sentinel

    Cloud-native SIEM with Copilot for Security and deep M365 integration

    Fastest Cloud SIEM
    Mkt Cap
    Div. of $3.1T
    Revenue
    Growth
    +52% YoY
    Apr 2026: Launched Security Copilot agents for autonomous threat triage
    View profile
    4

    Splunk SOAR (Cisco)

    Market-leading SOAR playbook automation with 300+ integrations

    Playbook Leader
    Mkt Cap
    Div. of Cisco
    Revenue
    Growth
    +18% YoY
    View profile
    5

    IBM QRadar SOAR

    Watson AI-integrated SOC platform for detection and investigation

    AI-Powered SOC
    Mkt Cap
    Div. of IBM
    Revenue
    Growth
    View profile

    Full list

    #CompanyDescription
    1CrowdStrike
    Jun 2026: Q1 FY27 record net-new ARR $256M (+32%); 4-for-1 stock split
    Unified AI-native cybersecurity from endpoint to SIEM and SOAR
    2Palo Alto Networks (XSOAR)
    Jun 2026: Q3 FY26 rev $3.0B +31%; NGS ARR $8.13B +60% (CyberArk/Chronosphere)
    Most deployed SOAR platform with XDR and AI-native SOC capabilities
    3Microsoft Sentinel
    Apr 2026: Launched Security Copilot agents for autonomous threat triage
    Cloud-native SIEM with Copilot for Security and deep M365 integration
    4Splunk SOAR (Cisco)
    Market-leading SOAR playbook automation with 300+ integrations
    5IBM QRadar SOAR
    Watson AI-integrated SOC platform for detection and investigation
    6ServiceNow SecOps
    Apr 2026: Closed $7.75B Armis deal; SecOps + asset discovery now unified
    Security incident, vulnerability, and change management in one platform
    7Exabeam (LogRhythm)
    Jan 2026: Launched Nova SIEM with AI-native UEBA, completing the LogRhythm integration
    Cloud-native SIEM with advanced user and entity behavior analytics
    8Securonix
    Cloud-native SIEM and open XDR platform for enterprise SOCs
    9Google Chronicle (SIEM)
    Cloud-native SIEM on Google infrastructure with Chronicle Security Ops
    10Elastic Security
    Search-powered security analytics combining SIEM and SOAR

    Startups & Emerging Players

    50 emerging vendors, ranked by momentum.

    Top 5 to watch

    1

    Halcyon

    AI-native anti-ransomware platform that detects, prevents, and recovers from ransomware attacks — purpose-built with autonomous response to stop encryption before data loss

    Anti-Ransomware AI
    Mkt Cap
    Private $1B
    Revenue
    Est. $50M ARR
    Growth
    +200% YoY
    Jan 2026: Raised $100M Series C; expanded to cover Linux and cloud workloads
    View profile
    2

    Tines

    No-code security automation platform replacing legacy SOAR workflows

    No-Code SecOps
    Mkt Cap
    Private $1B+
    Revenue
    Est. $60M ARR
    Growth
    +110% YoY
    Dec 2025: Series C $50M; expanded no-code SOAR with AI action suggestions
    View profile
    3

    Torq

    AI-powered security hyperautomation with autonomous investigation

    AI Hyperautomation
    Mkt Cap
    Private $500M
    Revenue
    Est. $40M ARR
    Growth
    +120% YoY
    May 2026: Acquired Jit to fuse AI Context Graphs into the Torq AI SOC platform
    View profile
    4

    Radiant Security

    Fully autonomous AI SOC analyst for alert triage and investigation

    Autonomous SOC
    Mkt Cap
    Private
    Revenue
    Early Stage
    Growth
    +100% YoY
    View profile
    5

    Stairwell

    Continuous threat detection using malware fingerprinting and file analysis

    Malware Intel
    Mkt Cap
    Private
    Revenue
    Est. $10M ARR
    Growth
    +60% YoY
    View profile

    Full list

    #CompanyDescription
    1Halcyon
    Jan 2026: Raised $100M Series C; expanded to cover Linux and cloud workloads
    AI-native anti-ransomware platform that detects, prevents, and recovers from ransomware attacks — purpose-built with autonomous response to stop encryption before data loss
    2Tines
    Dec 2025: Series C $50M; expanded no-code SOAR with AI action suggestions
    No-code security automation platform replacing legacy SOAR workflows
    3Torq
    May 2026: Acquired Jit to fuse AI Context Graphs into the Torq AI SOC platform
    AI-powered security hyperautomation with autonomous investigation
    4Radiant Security
    Fully autonomous AI SOC analyst for alert triage and investigation
    5Stairwell
    Continuous threat detection using malware fingerprinting and file analysis
    6Sublime Security
    Open email security detection platform for phishing and BEC attacks
    7Armorblox (Cisco)
    NLU-powered email security acquired by Cisco for AI-driven threat defense
    8Revelstoke
    Oct 2023: Acquired by Arctic Wolf; SOAR folded into Aurora
    Next-generation SOAR platform built for speed and analyst efficiency
    9Mindflow (SecOps)
    No-code SecOps orchestration with GenAI-assisted playbook creation
    10Shuffle Automation
    Open-source SOAR platform with drag-and-drop workflow builder

    Top Use Cases

    Where this market delivers measurable value today.

    1

    Automated Threat Detection & Triage

    AI models classify and prioritize alerts at machine speed, reducing analyst fatigue by 80%+

    2

    AI-Powered Incident Investigation

    Autonomous correlation of IOCs, threat intel, and user behavior across hybrid environments

    3

    SOAR Playbook Automation

    Pre-built and AI-generated playbooks automate containment, enrichment, and escalation workflows

    4

    Threat Intelligence Enrichment

    Real-time integration of external threat feeds to contextualize and prioritize active incidents

    5

    Compliance & Audit Automation

    Continuous evidence collection and policy enforcement for SOC 2, ISO 27001, and NIST frameworks

    Growth Opportunities

    AI SOC analyst augmentation (reduces analyst headcount gap)
    Cloud-native SIEM/SOAR platform consolidation
    Identity threat detection & response (ITDR) expansion
    OT/ICS security automation for critical infrastructure
    Multi-cloud security operations center unification
    Autonomous threat hunting and proactive exposure management
    Data sources & market scope

    Scope: SecOps tooling composite — SIEM + XDR + SOAR + Threat Intelligence platforms. Excludes vulnerability management (~$16B separate market) and managed security services (MDR/MSSP). XDR is the fastest-growing sub-segment at 31.2% CAGR; threat intel at 14.7%.

    MarketsandMarkets — XDR Market (Aug 2025)MarketsandMarkets — Threat Intelligence Market (2025)Grand View Research — SOAR Market (2025)Grand View Research — SIEM Market (2025)Gartner Worldwide Infosec Spending Forecast (2025)