Resource Regions: Western Europe
Cyber risk is no longer just a technical issue, it is a core business concern discussed at the highest levels of the organization. Across EMEA, boards are demanding clearer visibility into risk exposure, regulatory impact, and resilience. This blog explores the latest IDC insights on how CISOs can translate cyber risk into business language, align with board expectations, and strengthen decision-making in an increasingly complex threat and regulatory landscape.
How cyber risk became a board-level business risk
IDC research confirms that cyber risk has become a top board-level concern across EMEA and globally. Boards increasingly recognize that cyber risk is synonymous with business risk, prompting them to ask CISOs to translate the risk of cyber compromise into tangible business and compliance impacts.
As highlighted in IDC’s perspectives, board members are no longer satisfied with technical metrics alone they want to understand how cyber threats could affect organizational resilience, regulatory standing, and overall business continuity.
Cyber risk appetite vs. security investment: Key EMEA trends
Cybersecurity remains the primary barrier to CIO success in Europe, with 16–18% of organizations identifying it as their top challenge. Despite ongoing economic volatility, security budgets are generally protected, though not immune to cuts. IDC’s EMEA Security Tech and Strategies Survey reveals that 33% of financial services organizations kept their security budgets flat, 29% increased them by less than 10%, and 14% decreased them by more than 10%.
Boards are demanding greater clarity on risk acceptance, transfer, and mitigation strategies. A common pitfall is treating security metrics as mere program performance indicators rather than as expressions of risk and compliance management. Boards are now asking, “What is the risk cyber presents to the organization, and how well are we positioned to address it?”
CISO best practices for communicating cyber risk to the board
IDC recommends that CISOs translate cyber risk into financial terms, expressing exposure as realistic cost-of-breach scenarios rather than relying solely on severity labels. Structured exercises should identify which risks threaten financial stability and which are critical for certification or compliance. At the board level, metrics should focus on governance, risk, and compliance trends, answering questions such as: “What are our minimal viable operations? Are we cyber crisis ready? How resilient are we? How long will our business, systems, and production be offline in the event of a severe cyber compromise?”
A robust risk management framework can address 70% of board questions by identifying mission-essential assets, evaluating threats, monitoring controls, and clarifying risk ownership. While boards seek benchmarks and industry comparisons, they are cautioned against adopting a “do $1 more than our competitor” mentality.
IDC advocates for quarterly red teaming and realistic tabletop exercises to educate boards and executives, clarify escalation policies, and better identity and assess third party risk. Boards are also increasingly interested in the impact of AI and emerging technologies such as quantum key encryption and Model Context Protocol (MCP) deployment on organizational risk posture. CISOs should review use cases, implement human-in-the-loop controls, assess data security, and continuously audit AI assets.
Cyber risk and regulation in EMEA: Key insights for CISOs
Regulatory pressure is intensifying in Europe, with frameworks like NIS2, DORA, and the EU AI Act resulting in governance, risk, and compliance (GRC) as the top security technology priority for large organizations. Over 40% of these organizations now place GRC at the forefront, with liability for infringements increasingly assigned to senior management.
In European financial services, cyber security for clients (59%) and internal cyber security (57%) are the primary drivers of risk management investment. But only 43% of CISOs in large UK enterprises report having monthly board engagement, while 48% engage on an ad-hoc basis. IDC recommends establishing regular, structured communication to align risk appetite and investment decisions.
Practical steps to improve cyber risk management and board engagement
To enhance board engagement and risk management, IDC advises quantifying risk in business terms using financial impact, loss scenarios, and regulatory exposure. Cyber risk management should be continuous, using process automation where possible.
Boards must align security investment with risk appetite, and balance resilience, compliance, and operational priorities. Regular, meaningful engagement beyond ad-hoc updates is essential, as is benchmarking against peers while avoiding herd mentality. Integrating GRC platforms to automate reporting, audit, and compliance can support board-level visibility and informed decision-making.
Key takeaways for CISOs and boards in 2026
IDC’s EMEA and worldwide research underscores that effective cyber risk assessment and CISO-board communication require translating technical risk into business impact, quantifying risk appetite, and aligning security investment with strategic objectives.
Boards seek clarity, context, and actionable insights not operational minutiae. CISOs must become influential partners, guiding risk acceptance, transfer, and mitigation in a language the board understands. As regulatory and threat landscapes evolve, disciplined, data-driven communication is essential for resilient, compliant, and secure organizations.
Join the conversation: Deep dive in our upcoming webinar
Want to go beyond the headlines and understand what these shifts mean for your organization? Join our upcoming IDC webinar on May 12 to hear directly from our analysts as they break down the latest EMEA cybersecurity trends, evolving board expectations, and what it takes to translate cyber risk into business impact. Gain practical insights, benchmark your approach, and learn how leading organizations are aligning security strategy with business priorities.
Joel Stradling - Senior Research Director, European Security - IDC
David Clemente - Research Director, European Security - IDC
What is really shaping IT investment across EMEA in 2026?
Across EMEA, IT spending continues to grow, but the forces shaping that growth are becoming more complex. Geopolitical tensions, regulatory developments and economic uncertainty are increasing the pressure on organisations to prioritise resilience and operational stability, even as executive expectations around artificial intelligence continue to rise. Many enterprises are now moving beyond experimentation and beginning to explore how AI can be operationalised at scale. The question for 2026 is not simply whether AI investment will continue, but how organisations balance innovation ambitions with resilience priorities in a rapidly evolving market environment.
Growth remains stable but increasingly concentrated
IT spending across EMEA is expected to grow by 7% in 2026, driven primarily by the continued double‑digit expansion of the software market. While 2025 was marked by a surge in the Service Provider segment, 2026 shows a more balanced outlook, with both Enterprise and Service Provider spending following similar growth trajectories. The only exception is the Consumer market, which remains flat (Source: IDC Worldwide Black Book, March 2026).
Geopolitical tensions, supply chain disruptions and an increasingly complex regulatory landscape continue to reshape investment priorities across EMEA. As explored in our recent analysis of how ongoing conflicts are stress-testing the digital economy, organisations are placing greater emphasis on resilience, operational continuity and regional autonomy in their technology strategies. IT spending is therefore not slowing, but becoming more deliberate and selective, with investment increasingly directed toward capabilities that strengthen stability and long-term adaptability in an uncertain global environment.
Executive expectations are raising the bar
At the same time, executive ambition around AI continues to intensify. IDC research indicates that 50 percent of CEOs believe AI will offer their organisation the opportunity to reinvent its business model within the next three to five years.
This signals a shift in how AI is positioned within enterprise strategy. AI is no longer viewed primarily as a tool for experimentation or incremental efficiency gains. Instead, it is increasingly expected to deliver tangible transformation, automation and competitive differentiation.
However, survey data also shows that some organisations are reassessing elements of their AI programmes. Concerns around return on investment, governance, data readiness and skills availability are influencing decision-making across the region. The result is a more demanding environment in which expectations are rising but scrutiny is increasing as well.
From experimentation to operational AI
Across EMEA, AI maturity is evolving. The early phase of generative AI experimentation is giving way to a stronger focus on operational deployment.
Organisations are now moving beyond isolated pilots towards integrating AI capabilities into core workflows, enterprise applications and decision-making processes. This transition reflects a broader shift towards operational AI and the emergence of more agentic enterprise models.
At the same time, scaling AI requires far more than access to models. Infrastructure readiness, data management capabilities, governance frameworks and organisational skills are becoming decisive factors in determining whether organisations can move from experimentation to sustained operational impact.
Resilience, governance and execution will define the next phase
The evolving EMEA technology landscape is therefore shaped by a combination of innovation pressure and structural constraints. Geopolitical uncertainty, regulatory requirements and resilience priorities are increasingly influencing technology investment decisions.
For technology providers operating in the region, understanding these dynamics is critical. Growth opportunities remain significant, but they are tied more closely to execution readiness, operational maturity and the ability to support organisations as they scale AI responsibly.
Join the conversation
In our upcoming webcast on April 28, IDC analysts Andrea Siviero, Stephen Minton, and team will explore what these shifts mean for the EMEA IT market in 2026, including:
- How geopolitical developments and resilience priorities are influencing IT investment across the region
- Where growth is concentrated across EMEA markets and industries
- How organisations are moving from AI experimentation to operational deployment
- What the rise of more agentic enterprise models means for enterprise technology environments
Register for the webcast here.
Got a question? Drop it in here.
Andrea Siviero - Senior Research Director, MacroTech, Digital Business, and Future of Work - IDC
XR Market Grew 44.4% in 2025 as Smart Glasses Redefine the Category
Smart glasses drive XR growth while traditional headsets decline.
Read full releaseIn today’s technology market, certainty has become a luxury. AI adoption is accelerating, but unevenly. Partner ecosystems are fragmenting, consolidating, and recombining at speed. Go‑to‑market models are collapsing into customer‑led buying journeys, and leadership teams are being asked to make high‑stakes decisions with incomplete, fast‑aging information.
Broad market reports, benchmarks, and best practices retain significant intrinsic value as foundations for strategy. Yet decisions that are deeply contextual, ecosystem‑specific, and time‑sensitive often require additional layers of insight beyond these core inputs.
The reality is that strategy is no longer about understanding “the market” in the abstract. It is about understanding your market position, your partners, and your customers, right now. Increasingly, the most important questions leaders are asking sound like this:
- How is AI changing buying behavior and economics in our customer base?
- Which partners are actually driving growth, influence, and outcomes – and which no longer align with our direction?
- How does our ecosystem strategy compare to competitors in EMEA, not just globally?
- Where are customers genuinely willing to invest, and where are they experimenting, delaying, or pushing back?
These are not questions that generic insight can answer with confidence, because the answers depend on your installed base, your partner mix, your regional footprint, your commercial model, and your competitive posture. In short, strategy has become situational.
Faced with this uncertainty, many organizations default to gathering more data: more dashboards, more surveys, more internal analysis. But volume is rarely the issue. The real challenge is relevance. Internal data lacks external context. Global averages mask regional and sector nuance. Lagging indicators arrive after decisions have already been made. What leaders need instead is interpretation, synthesis, and external validation that is designed around the decisions they actually need to take.
This is why we see a growing shift toward custom insight. High‑performing organizations increasingly start with the decision, not the dataset. Whether the challenge is AI monetization, partner strategy, ecosystem prioritization, or route‑to‑market design, the work begins by asking what choice must be made in the next three to six months, and what evidence is required to make it with confidence. From there, insight is built backwards.
Critically, the most effective custom projects blend signals rather than relying on a single method. Partner surveys reveal capability gaps, investment priorities, and friction points across the ecosystem. Customer surveys surface willingness to pay, buying behavior, trust dynamics, and expectations around AI, services, and outcomes. Qualitative interviews add depth and context, while ecosystem and competitive analysis connects those findings to broader market forces. The value does not sit in any one input, but in how those inputs are connected and translated into strategic implications.
We consistently see customer and partner insight deliver the greatest impact when applied to a small number of high‑value areas:
- AI and agentic AI strategy, including pricing, packaging, economics, and partner roles
- Ecosystem and partner optimization, from role clarity to performance segmentation and investment focus
- Go‑to‑market and route‑to‑market evolution, particularly in EMEA’s fragmented markets
- Executive alignment, creating a shared, evidence‑based fact base for leadership teams
- External storytelling, using proprietary insight to support thought leadership and market influence
This is where insight turns into action. In many engagements, the report itself is not the most important output. The real value is decision confidence: knowing that a strategic move is anchored in how customers and partners are actually behaving, not how we assume they are behaving.
There is also a powerful dual role at play. Custom insight supports internal strategy and decision‑making, but it can simultaneously fuel external influence. Proprietary findings can shape executive narratives, strengthen partner and customer communications, and differentiate a company’s point of view in an increasingly noisy market. When insight is designed with this dual purpose in mind, it becomes a strategic asset rather than a one‑off deliverable.
This matters now more than ever. Across EMEA, partner ecosystems are being reshaped by a set of interlocking forces: AI economics, consolidation, shifting alliance hierarchies, collapsing route‑to‑market models, sovereignty pressures, and the rise of in‑product and marketplace‑led buying. Many of these shifts are subtle in isolation but powerful in combination.
Understanding which are leading indicators, which are mid‑cycle effects, and which are lagging consequences requires more than surface‑level analysis. It requires insight grounded in real partner and customer evidence, interpreted through an ecosystem lens.
The bottom line is simple. In a market defined by AI acceleration, ecosystem complexity, and regional divergence, generic insight is no longer enough. Organizations that are pulling ahead are those that ask better questions, invest in insight tailored to their context, and use research as a decision tool rather than a reference document.
If these questions resonate, you’re not alone. Most technology leaders we work with are already grappling with how AI, ecosystem change, and buyer behavior are reshaping their growth models – and are looking for concrete, evidence‑based answers they can act on. Through bespoke research and advisory projects, we help clients translate partner and customer insight into tangible business benefits: sharper internal intelligence for decision‑making, clearer ecosystem strategy, and insight‑led assets that can be used confidently with partners and customers alike.
This perspective is also captured in our 15 Key Trends Shaping EMEA Partnering Ecosystems report, often used as a starting point for bespoke client work. Contact us to learn more about our ecosystem research, custom solutions and advisory portfolio.
IDC’s ecosystem lens
IDC’s ecosystem research focuses on value creation, margin capture, and strategic influence. We analyze how partners orchestrate outcomes, how they align with customer buying journeys, and how they evolve their business models to stay relevant. You can find more information here.
If you have any further questions, drop them in the form here.