Executive Strategy Paper · July 2026
How AI is reshaping the security services market.
For a decade, the managed security market evolved by adding capabilities. AI changes that trajectory — not by adding another category, but by changing what organizations are buying. This paper maps the four buying models in the market today, shows where the spending gravity is moving, and sets out what executives should plan around.
No form, no gate. Read it, share it, bring us your disagreements.
The argument
Who should read this
The four buying models
Each model reflects a different problem the customer is solving — and a different definition of value. The spending gravity is moving right.
"I need one platform." Buying technology. The objective is simplification — consolidating products into an integrated platform that reduces complexity and improves visibility.
"I need someone to run my SOC." Buying operational expertise through a managed SOC. Demand remains strong — but this is where AI compresses cost most directly.
"I need someone to run my security program." Buying judgment: which AI initiatives to approve, what governance to implement, how AI risk reaches the board.
"I need business transformation." Buying trustworthy innovation across the business. Here AI is not reducing cost — it is creating enterprise value.
These are not rungs on a ladder. Large enterprises routinely buy in all four models in the same fiscal year, and many organizations enter at Model 2 or 3 and stay there permanently. The models describe distinct problems and buying motions — not stages every organization passes through. What's directional is where the money and the executive attention are moving.
What the evidence shows
of surveyed organizations identified AI as the most significant driver of change in cybersecurity for the year ahead — and 87% named AI-related vulnerabilities as the fastest-growing cyber risk.
World Economic Forum with Accenture, Global Cybersecurity Outlook 2026
of directors say their boards do not know enough about AI — and 40% are rethinking board composition because of it.
Deloitte Global Boardroom Program, ~700 directors and executives
the share of organizations assessing the security of AI tools before deployment nearly doubled in a single year — while roughly a third still have no such process at all.
World Economic Forum, Global Cybersecurity Outlook 2026
increase since 2022 in public companies disclosing board-level AI oversight — up more than 84% year over year. AI risk is becoming a standing board obligation, not a technical footnote.
Analysis published via the Harvard Law School Forum on Corporate Governance
of organizations use AI in at least one business function — but only 39% attribute any EBIT impact to it, and just 7% report it fully scaled. Nearly everyone is adopting; almost no one has converted adoption into governed, scaled value.
McKinsey, State of AI 2025
projected worldwide end-user information security spending in 2026 — up 12.5% over 2025. The total grows; the composition shifts toward judgment and governance.
Gartner forecast, July 2025
The independence test
Ask who in the relationship loses money if the honest recommendation is to spend less, cancel an initiative, or leave an existing arrangement in place. If the answer is the party giving the advice, the advice is not independent — however competent and well-intentioned the people giving it are.
— From the paper's guidance on evaluating advisory relationships
The paper's guidance to buyers is to stop asking one relationship to both deliver the work and grade it: send the operational work to the best available operator, hold them to outcome-based commitments, and place the judgment about whether those commitments are being met somewhere that has no revenue riding on the answer.
It's a test we hold ourselves to. Realis doesn't resell tools, operate your SOC, or build the AI we assess — so "spend less," "wait," and "you're fine, here's what to maintain" are answers we're free to give. See how we work →
What executives should plan around
Five developments, offered with SOAR-era discipline: right directionally, uncertain in timing.
The strongest objection
What if AI collapses the models instead? The paper answers it directly.
The objection: if AI makes Tier-1 and Tier-2 operations nearly free, platform vendors absorb the managed-service model and the market bifurcates into products on one side and elite advisory on the other. Parts of that are likely right — pure labor-arbitrage services are structurally endangered. But the full collapse thesis fails on three points:
Security spent two decades being measured by what it prevented. The next decade will measure it by what it made possible.
— From the conclusion
Any question. 20 minutes. A real answer — no pitch. Tell us what you want to know when you book, and we'll come ready.