Mena information security spending to hit $3.3b by 2025

Need to address the evolving cybersecurity threat landscape becomes more critical
- PUBLISHED: Tue 8 Apr 2025, 6:31 PM
Enterprises in the Middle East and North Africa (Mena) region are expected to significantly increase their investments in information security, projecting a total expenditure of $3.3 billion by 2025. This represents a robust 14 per cent increase from 2024, according to the latest forecast from Gartner, Inc.
The largest portion of this spending will be dedicated to security software, anticipated to reach nearly $1.5 billion. “Enhancing cyber resilience, regulatory compliance, and securing digital transformation are pivotal drivers for Mena chief information security officers (CISOs) as they escalate their security investments,” stated Shailendra Upadhyay, senior principal at Gartner.
As organisations in the region increasingly integrate artificial intelligence (AI) and other advanced technologies, the need to address the evolving cybersecurity threat landscape becomes more critical. “Enterprises must protect their critical infrastructure and combat insider threats to fortify their systems and enhance resilience against cyber threats,” Upadhyay said.
Spending on security services is projected to soar by 16.6 per cent in 2025, the highest growth rate among all segments. This surge is largely attributed to the pressing need for cost efficiency, the ongoing skill shortages in cybersecurity, and the demand for advanced tools and technology. “The challenge of sourcing staff with specialised skills for threat hunting and intelligence in advanced security operations is considerable,” noted Upadhyay.
Managed services, particularly Managed Detection and Response (MDR), are becoming essential solutions to bridge this skill gap. This trend reflects a broader strategy where organisations are increasingly investing in security services to manage their cybersecurity needs effectively.
Gartner’s forecast also highlights that security software will account for nearly 45 per cent of total information security spending in the Menaregion, driven by an expanding threat landscape and the rising adoption of cloud technologies. “Mena CIOs are enhancing their investments in generative AI applications, cloud services, and cybersecurity software to accelerate innovation securely,” Upadhyay explained, emphasising the importance of infrastructure protection, identity access management, and cloud security.
Sam Olyaei, vice president at Gartner, warned that as AI becomes integral to operations, organizations must navigate both the opportunities it presents and the potential threats. “By 2027, we predict that 60 per cent of organisations will fail to embrace resilience principles, leaving them vulnerable to global technology threats. CISOs must proactively prepare for complex cyberthreats with a collaborative approach to resilience planning,” Olyaei added.
To foster a sustainable cybersecurity programme, Gartner recommends that Mena security leaders prioritise two emerging trends:
>> Generative AI driving data security programs: The rise of generative AI is shifting focus toward the security of unstructured data, prompting a preference for synthetic data over traditional anonymisation methods.
>> Gartner recommends investments in synthetic data generation tools to mitigate privacy risks and ensure compliance. “Organisations must leverage technologies such as Data Security Posture Management (DSPM) to effectively catalog, monitor, and govern both structured and unstructured data,” Olyaei suggested.
With the recognition that human behaviour is pivotal to cybersecurity, organisations are increasingly embedding security into their culture. Gartner forecasts that by 2026, enterprises integrating generative AI with a platform-based architecture in their Security Behaviour and Culture Programs (SBCPs) will experience 40 per cent fewer employee-driven cybersecurity incidents. “Well-designed SBCPs enhance employee engagement and satisfaction by involving them in security initiatives,” Olyaei noted, highlighting their role in ensuring compliance and cultivating a resilient security culture.



