从安全助手到数字员工,Agentic AI开启SOC建设运营新范式

过去几年,企业IT架构发生了深刻变化。混合云、多云、本地数据中心以及边缘计算等部署模式长期并存,业务系统和数据不断向云端迁移,安全边界逐渐模糊。与此同时,大模型、智能体以及AI原生应用开始快速进入企业生产环境,网络攻击也随之发生变化。攻击者借助生成式AI持续提升攻击效率,从自动生成钓鱼邮件、编写恶意代码,到利用智能体实施复杂攻击,攻击规模、速度和隐蔽性都在快速提升,传统SOC依赖规则、剧本和人工分析的运营模式正面临前所未有的挑战。

IDC观察到,Agentic AI(智能体)的快速成熟,正在推动安全运营进入新的发展阶段。不同于传统安全助手主要承担知识问答和辅助分析的角色,智能体具备自主规划、自主推理、自主执行和持续学习能力,能够直接参与威胁检测、事件调查、响应处置以及运营优化等完整流程,推动SOC由“人工驱动”向“智能体驱动”演进。Agentic SOC正在成为新一代安全运营范式。

市场进入高速增长期,Agentic AI成为安全运营的新引擎

国际数据公司(IDC)最新发布的《IDC MarketShare:中国基于大模型的安全运营平台市场份额,2025》(Doc# CHC53617226,2026年7月)报告数据显示,2025年,中国基于大模型的安全运营平台市场规模达到15亿元人民币,同比增长144%,成为近年来网络安全子市场增长最快的细分领域之一。这一增长表明,大模型技术正在从能力验证阶段迈向规模化应用,而安全运营已经成为AI技术在安全领域最先实现商业化落地、也是企业价值最明确的应用场景之一。其中,阿里巴巴、深信服科技、360数字安全集团、启明星辰集团、绿盟科技、安恒信息等厂商占据市场主导。

IDC预计,未来几年,随着智能体技术的持续成熟、多智能体协同能力的不断完善以及智能体治理体系的逐步建立,中国基于大模型的安全运营平台市场仍将保持高速增长,并逐步成为网络安全市场最具潜力的核心赛道之一。

Agentic AI正在重新定义SOC

过去几年,大模型开始进入SOC,但更多以AI助手(Copilot)的形式出现。这类能力虽然提升了分析效率,但本质上仍属于“辅助工具”,需要分析师主导整个运营流程。智能体则代表了另一种技术范式。与传统助手相比,安全运营智能体不仅能够理解用户意图,更能够围绕既定目标自主规划任务、自主调用工具、自主推理分析、自主执行操作,并根据执行结果持续优化后续行动,真正完成从威胁检测、事件调查到响应处置的完整安全运营任务。这意味着安全运营平台正从“工具自动化”迈向“智能体自主运营”。Agentic SOC并不是传统SOC增加一个聊天窗口,也不是SOAR叠加一个大模型,而是以安全运营智能体集群为核心,重构整个安全运营体系。更重要的是,智能体具备持续学习能力,能够在日常运营中不断积累企业知识、安全剧本和行业经验,逐步理解企业业务流程、安全策略和风险偏好,形成“运营即学习、学习即进化”的持续优化闭环。

IDC近日发布的《IDC MarketScape:中国安全运营智能体厂商评估,2026》(Doc #CHC54110626 ,2026年7月)报告指出,安全运营智能体的发展,不仅意味着AI能力的提升,更代表着安全运营模式的变革。传统SOC始终围绕“人”开展工作,分析师负责告警分析、事件调查、风险研判和响应处置。在Agentic SOC中,智能体开始承担越来越多重复性和标准化工作,可全天候自主完成告警分流、威胁调查、攻击溯源和事件响应,分析师的职责将逐步转向策略制定、复杂威胁研判和智能体管理等方向,实现从“人工处理告警、事件”到“管理智能体”的角色转变。

未来企业建设的不再只是一个SOC平台,而是一支能够7×24小时持续运行、由多个安全运营智能体组成的”数字安全团队”。安全分析师将逐步从告警处理者转变为智能体管理者和安全决策者,而安全运营平台也将从传统工具平台演进为企业AI原生安全运营的核心基础设施。

企业迈向Agentic SOC,仍需跨越五大门槛

尽管智能体为安全运营带来了新的可能,但从当前市场实践来看,安全运营智能体仍处于规模化落地的早期阶段。随着智能体逐步参与安全运营核心流程,企业关注点已从”智能体能不能用”转向“智能体能不能安全、可靠、持续地使用”。《IDC MarketScape:中国安全运营智能体厂商评估,2026》报告指出,企业部署Agentic SOC还需解决如下五大问题:

  • 系统集成复杂:智能体与现有安全平台、网络架构的融合涉及多系统对接和流程重构,落地门槛高。
  • 信任与可解释性不足:AI模型存在幻觉、决策过程不透明等问题,客户对智能体输出的结果和采取的行动的信任度有限,亟须增强可解释性。
  • 行业适配性问题:通用型智能体难以满足不同行业的专有安全需求,需要符合自身行业和场景要求的智能体。
  • 智能体自身安全风险:智能体本身可能成为新的攻击面,还需关注其自身安全防护和可控性。
  • 算力与数据合规挑战:智能体对算力资源消耗大,全部上云涉及数据安全、合规与算力成本的权衡,尤其在数据主权和行业监管严格的场景下更为突出。

IDC观察:Agentic SOC正沿七个方向持续演进

趋势一:从安全助手走向数字员工

安全运营智能体正由“辅助分析+建议输出”升级为“可执行主体”,不仅理解告警与威胁,还能直接调用工具链完成研判、响应与处置,形成从发现到修复的闭环。在一些标准化、低风险的场景中,安全运营智能体将逐步替代人工完成重复性工作,同时通过持续学习与策略优化提升处置质量与效率。未来衡量Agentic SOC成熟度的重要标准,不是智能体回答了多少问题,而是能够自主完成多少安全运营工作。

趋势二:从单一智能体走向多智能体协同

安全运营能力从单一智能体扩展为多智能体协作体系,不同角色(如检测、分析、溯源、响应、汇报等)分工协同完成复杂任务,通过编排与通信机制实现跨系统联动与全流程自动化。在某些成熟场景中可实现端到端自动响应与决策,推动安全运营向“无人值守”演进。与此同时,智能体集群协同机制将使得“超级智能体”成为用户安全运营的中枢和总管,进行任务调度与分配,帮助用户更好地完成安全运营任务。

趋势三:从GUI走向LUI,重塑安全运营交互方式

安全运营交互方式正由图形界面转向以自然语言与命令行为核心的对话式入口,用户通过与智能体交流即可完成查询、分析与处置操作,无需在复杂界面中反复切换。这种转变降低了使用门槛,提升了响应效率,并将安全运营入口从“系统界面”重塑为“对话即平台”的统一交互中心。

趋势四:走向智能体全生命周期管理

安全运营智能体是一系列智能体的集合,其工作流程中还会涉及调用诸多自有智能体、第三方智能体、工具、Skills等,智能体全生命周期管理至关重要。安全运营平台需覆盖智能体开发、编排、调优和监控的能力,实现智能体状态可视、动作可追溯、经验可沉淀、效果可量化,并通过数据反馈驱动能力持续进化。

趋势五:与用户共同成长,形成持续进化能力

智能体的真正价值来自与用户长期的协同进化,并深度结合具体业务场景与行业特性进行优化。一方面,为用户开放智能体、Skills等开发环境,并简化开发流程,降低使用门槛。另一方面,持续积累、整合知识库、Skills与剧本等能力资产,在真实运营中不断沉淀经验与优化策略,逐步形成可复用、可扩展且具备行业适配能力的安全运营体系。

趋势六:安全可信成为Agentic SOC规模化落地的基础

智能体自身的安全与可信问题是企业上线部署以及使用智能体的前提条件,安全运营智能体的技术服务提供商还需系统性解决模型幻觉、智能体身份与权限边界、决策可解释性等核心风险。同时引入“AI对抗AI、AI防护AI”的机制,通过智能体之间的交叉验证、对抗检测与自动审计提升防护能力,确保其行为可控、过程可追溯、结果可验证,从而支撑其在关键安全场景中的可靠落地。

趋势七:构建开放生态,推动安全运营平台化发展

安全运营智能体的发展不再依赖单一能力,而是需要构建涵盖模型生态、工具生态与行业生态的协同体系,通过多模型接入、工具链整合与行业伙伴共建,形成能力互补与持续扩展的生态格局。在此基础上,最终实现能力的快速集成与场景的灵活适配,推动安全运营从“单点能力”向“生态化能力平台”演进。

IDC中国网络安全领域研究经理王一汀表示,2026年,伴随智能体应用部署加快,安全运营智能体进入规模化落地与体系化演进的新阶段,Agentic SOC将成为企业AI原生安全运营体系的重要基础设施,也将成为未来几年网络安全市场最具活力和创新潜力的发展方向之一。从技术演进路径看,安全运营智能体正由“辅助工具”快速转向“数字员工”,在告警降噪、事件分析与威胁响应等高频场景中形成实用化能力,并逐步承担更多自动化处置职责。未来,Agentic SOC的发展将呈现集群化协同、平台化统一管理、全生命周期治理、安全可信增强以及开放生态融合等趋势,并通过持续的反馈与调优机制构建学习与优化的闭环体系,推动安全运营能力向更高效、更智能的方向迈进。

IDC更多相关研究:

进一步交流

IDC已于2026年启动AI安全技术系列研究,围绕AI原生安全架构、安全智能体成熟度评估、AI驱动DevSecOps实践路径以及企业级AI治理框架等方向展开持续跟踪与分析。对于希望进一步了解相关研究、评估自身AI安全能力或探讨落地路径的企业,欢迎与IDC分析师团队进行深入沟通(请点击此处),以获得更具针对性的洞察与建议。

Sophia Wang, CISSP

Sophia Wang, CISSP - Research Manager

Sophia Wang is a Research Manager in IDC China. She is responsible for the analysis and research of China's cybersecurity market. Her primary focus is on China's cybersecurity appliance and services market and operational technology (OT) security market. Additionally, she…

随着机器人技术持续成熟、应用场景不断拓展,全球配送机器人和商用清洁机器人市场进入快速发展阶段,商业化进程持续加快。为持续跟踪全球市场发展趋势,国际数据公司(IDC)最新发布了《全球配送机器人跟踪报告》《全球商用清洁机器人跟踪报告》显示,2025年全球商用服务机器人市场继续保持高速增长。全年市场规模达到13.7亿美元,同比增长35.7%;全年出货量约15.5万台,同比增长44.1%。

IDC预计,2026-2030年全球商用服务机器人市场仍将保持较快增长,2026—2030年货量复合增长率(CAGR)约15.1%。到2030年,全球商用服务机器人出货量将达45.4万台,市场规模将至31.7亿美元。

商用清洁机器人领跑市场增长,配送机器人保持规模优势

从产品品类来看,商业清洁机器人是2025年全球商用服务机器人市场增长最快的细分领域。2025年全球商业清洁机器人出货量约5.8万台,同比增长83.8%;市场规模超7.6亿美元,同比增长48.5%。中国市场规模化部署持续放量,欧美市场渗透率持续提升,日本、亚太市场更新换代需求稳步释放,共同推动商用清洁机器人快速增长。

配送机器人仍是全球商用服务机器人出货规模最大的细分市场,并继续保持稳健增长。2025年全球配送机器人全年出货量约8.4万台,同比增长30.2%;市场规模超3.8亿美元,同比增长25.4%。餐饮、酒店、医疗等场景需求持续增长,叠加劳动力短缺及智能化升级需求,推动配送机器人市场稳步发展。

全球化成为产业发展主线,中国厂商持续引领全球市场

全球商用服务机器人需求持续增长,全球市场进入多区域协同增长阶段,成熟市场持续扩容,新兴市场保持高速增长。2025年,中国、西欧、日本、美国及亚太(除中国、日本)位列全球前五大区域市场,合计贡献全球出货量约92.1%。其中,中国市场份额约38%,继续保持全球第一;拉丁美洲市场出货量同比增长84.4%,成为全球增长最快的区域市场。

中国企业正依托完善的制造体系、成熟的供应链能力以及人工智能技术创新,不断提升产品性能、智能化水平和成本竞争力,加快全球市场布局。2025年全球商用服务机器人出货量Top 10厂商中,中国厂商占据绝对优势,合计出货量占比超过90%。其中,擎朗智能、普渡机器人、高仙机器人位居全球出货量前三,三家厂商合计贡献全球出货量约53.2%,且海外收入占整体营收的比重均超过65%,全球化运营能力持续增强。

  • 擎朗智能连续保持全球商用服务机器人出货量第一,持续领跑全球配送机器人市场;同时积极布局商用清洁等新品类,商用清洁机器人业务出货量同比增长超过800%,第二增长曲线加速形成。
  • 普渡机器人持续推进配送与商用清洁双产品战略,两大产品线协同发展,商用清洁机器人业务增长更快。
  • 高仙机器人连续保持全球商用清洁机器人销售额、出货量双第一。作为商用清洁机器人赛道的开拓和定义者,高仙持续迭代的产品创新实力、深度适配多元场景的完整解决方案,持续巩固行业领先地位。

全球化竞争正从市场拓展迈向全球运营能力竞争。与此同时,欧美及新加坡等地区的厂商也在不断拓展国际市场。例如,LionsBot持续拓展西欧、美国及中东非市场;Bear Robotics依托LG全球合作网络,加快布局美国、西欧及亚太市场。未来,品牌建设、本地化运营、服务体系和生态合作能力将成为全球竞争的关键,具备全球运营能力的企业有望进一步巩固竞争优势。

应用场景持续拓展,机器人向更复杂环境延伸

随着自主导航、多传感器融合和环境感知能力不断提升,商用服务机器人的应用边界持续扩大,行业渗透率不断提升,应用场景正由室内向室外、由相对稳定环境向开放复杂环境持续延伸。

  • 配送机器人主要应用于餐饮、酒店、楼宇、文娱和零售行业,前五大行业占全球出货量92.8%;医疗、教育等行业需求持续增长
  • 商用清洁机器人主要应用于楼宇、零售、交通、酒店和餐饮行业,前五大行业占全球出货量72.9%;医疗、物流及工业等行业成为新的增长领域。
  • 室外服务机器人商业化进程明显提速。随着室外自主导航、环境感知和安全避障能力不断提升, 2025年全球室外服务机器人出货量同比增长62.2%,在外卖配送、园区配送、道路清扫、安防巡检等场景实现快速发展。

物理AI驱动升级,具身智能开启服务机器人新阶段

物理AI正推动商用服务机器人向具身智能体演进。随着具身智能模型、多模态感知、世界模型及机器人基础模型持续成熟,机器人将不断提升环境理解、任务规划、自主决策和持续学习能力,向自主完成复杂服务任务演进,产业竞争也将向AI模型、数据和场景能力迁移。

  • 具身智能推动机器人向自主服务演进。机器人将具备更强的环境感知、任务理解和自主执行和持续学习能力,实现从”被动执行任务”向”自主完成任务”转变。
  • 服务机器人形态持续丰富,人形机器人与服务机器人协同作业。配送、商用清洁等服务机器人将持续承担高频、标准化任务,人形机器人加快在酒店迎宾、零售导购、展馆讲解、物业服务、物品搬运等场景开展应用,二者协同满足复杂、多样化服务需求。
  • 竞争转向“AI+数据+运营”迁移。未来竞争将不再局限于机器人本体性能,而是围绕AI模型能力、数据闭环、软件平台、服务场景Know-how及运营服务能力展开,商业模式也将持续向RaaS、AI模型服务和机器人运营服务延伸。

全球服务机器人市场正迈入高质量发展阶段,来市场竞争将从单一产品能力转向产品、AI能力与场景化解决方案的综合竞争。——IDC中国机器人与具身智能领域研究经理李君兰

本文核心内容基于IDC相关研究成果:

本文数据来源于《全球配送机器人跟踪报告》《全球商用清洁机器人跟踪报告》及《中国具身智能服务机器人技术评估》(即将发布)等。机器人分类及定义请参考《IDC’s Worldwide Annual Delivery Robotics Tracker Taxonomy, 2026》与《IDC’s Worldwide Annual Commercial Cleaning Robotics Tracker Taxonomy, 2026》。

进一步交流

如需获取完整版报告《全球配送机器人跟踪报告》《全球商用清洁机器人跟踪报告》及即将发布的《中国具身智能服务机器人技术评估》,或希望就市场数据、竞争格局及AI应用趋势进行深入探讨,欢迎联系IDC中国机器人研究团队。

Lily Li

Lily Li - Research Manager

Lily is the Research Manager for China Robotics and Embodied Intelligence, specializing in market research on embodied intelligent robots. She has long focused on the development trends of China’s embodied intelligence robotics industry, systematically studying the evolution of robot hardware,…

Today we launched IDC Quanta. I led the strategy behind it, working closely with our product, research, and engineering teams to turn a point of view into something real. I want to share what building it taught me about the state of AI adoption, not just at IDC, but everywhere.

The number that started it

By 2029, there will be a billion AI agents running inside enterprises worldwide. That translates into an enterprise running thousands of agents. The investments to prepare for that future are already taking place. Hyperscalers are increasing AI infrastructure spend from $54 billion in 2023 to $800 billion by 2029 to create inference capacity at that scale. Enterprises are spending $400 billion on AI platforms, apps and services this year, headed toward a trillion by 2029.

Most enterprises can’t orchestrate at that scale today. Most vendors can’t fully support it yet either. A billion agents means the entire IT industry, vendors and enterprises together, has a massive amount of infrastructure, governance, and orchestration work still ahead of it before that number is something to be excited about instead of something to be worried about. We didn’t want IDC standing outside that work, measuring it from a distance. We wanted to build the intelligence layer that helps our clients get through it. That’s the thinking behind Quanta.

The gap we kept running into

Earlier this year, we ran our global AI maturity benchmark. In the U.S., the largest single group of organizations, 39%, sits at what we call the AI Pivot stage. They’ve moved past ad hoc experimentation. They have momentum and intent. But they’re still reacting to use cases as they surface instead of executing against one enterprise strategy.

That gap comes down to a problem our team designed against from the start: islands of AI. Fragmented experimentation across functions that makes enterprise-level orchestration nearly impossible. Half of organizations have an AI roadmap defined at the functional level. Finance has one. IT has one. Marketing has one. They don’t connect. There’s no shared prioritization and no way to see where one function’s work could accelerate another’s.

The reason this is more than a coordination problem is because agents don’t respect functional boundaries. A customer service agent needs data from CRM, from order management, from your knowledge base. An operations agent touches supply chain, finance, and procurement. The moment you deploy agents that work across functions, a fragmented roadmap becomes an architectural blocker. It’s why 42% of CEOs plan to hire a Chief AI Officer in the next year. They’re looking for someone who can see the whole board, not just their own function’s piece of it.

We had our own version of this problem to solve. For decades, IDC’s model was research in one place and data in another, and clients had to hunt across both to get a full picture. Quanta brings our research and our data together in a single platform, so that fragmentation stops being something you have to solve every time you come to us.

The curve nobody wants to admit they’re on

For the past three and a half years, enterprises have struggled to prove the ROI on their AI use cases. Now we have runaway token costs arriving at the exact moment everyone is lining up to deploy agents.

IDC recently published a report on effective agent cost management. In the report, the team showed cost per action spikes early in almost every deployment, before value catches up. We call that phase High Anxiety. Value climbs slowly the whole time, crossing cost at what we call the Strategic Alignment phase. Past that point, cost keeps falling and value keeps climbing. That’s the payoff phase.

Most organizations in this industry are still on the wrong side of that curve. The token economy conversation isn’t about whether AI is worth the spend. It’s about how long it takes you to get through the High Anxiety phase. The organizations pulling ahead are the ones treating ROI as a discipline, not a one-time calculation. A cost model that only counts inference will undercount true total cost of ownership by 30 to 60%. The shift that matters is treating tokens like a raw material, the way a factory tracks cost per unit, instead of like a technology bill.

That framework is one example of the kind of intelligence Quanta is built to deliver. Not a report waiting to be opened weeks after it would have mattered. Something you can reach directly at idc.com, or through connectors built into the platforms your team already uses, so the intelligence shows up where the decisions and execution happens instead of sitting in a document.

Why I’m telling you this today

Quanta didn’t come from spotting a market opportunity from a distance. It came from our team solving the exact problem I just described, for our own organization, alongside the people who build and research this every day.

For decades, our model was simple: we publish research, and you come find it. That worked when the pace of decisions making was slower. It doesn’t work anymore, not with a billion agents coming and the decisions being made this year that companies will live with for years. We built Quanta to work two ways. Come to idc.com directly for grounded, evidence-based answers. Or reach that same intelligence through connectors already built into the platforms your team uses, so you’re not switching context.

I’m proud of what we’re launching today. But the thing I actually want you to take from this is the reminder that the gap between where your organization is and where it needs to be closes the same way ours did: someone has to own the whole board, and go get the intelligence instead of waiting for it to come to you.

Meredith Whalen - Chief Research Officer - IDC

As IDC's Chief Product, Research & Delivery Officer, Meredith Whalen leads the company's global product, research and data, and delivery organizations. Under her leadership, IDC delivers cutting-edge intelligence to the world's leading technology vendors, enterprises, and investors as they navigate the evolving AI economy. Meredith sets the strategic direction for IDC's global analyst community, shaping research methodologies and agendas that generate industry-leading data and actionable insights to drive high-impact business decisions. With more than 20 years at IDC, Meredith has been a catalyst for some of the company's most transformative initiatives. She founded IDC's Industry Insights and Tech Buyer business units and pioneered the industry's first comprehensive business use case taxonomy. She also led the creation of IDC's DecisionScape methodology-a strategic framework that empowers organizations to better plan, implement, and optimize their technology investments. A recognized thought leader and sought-after speaker, Meredith regularly delivers keynotes at major global technology events and advises senior executives on the trends shaping the future of business and technology. Meredith holds a B.A. with honors from Wellesley College and an MBA with honors from Babson College's F.W. Olin Graduate School of Business.

I spent much of my career helping organizations operationalize customer and employee intelligence. During that time, I watched an entire industry emerge around dashboards.

Companies invested billions collecting customer feedback, employee sentiment, operational metrics, and business intelligence. Entire software categories were built around helping organizations visualize that information and drive action.

The model worked extraordinarily well.

Companies like Qualtrics, Medallia, Tableau, Salesforce, and many others helped define a generation of enterprise software. But over time, a pattern emerged.

The problem was never collecting the data; the problem was getting people to use it.

Organizations spent years trying to encourage executives, managers, and frontline employees to regularly log into dashboards, review reports, identify issues, and take action.

Adoption became a business problem unto itself. The intelligence existed, but the behavior did not.

The hidden cost of dashboards

The challenge with dashboards is simple: they require users to interrupt their workflow.

Every dashboard assumes a user will:

  1. Stop what they are doing.
  2. Open a separate application.
  3. Find the relevant information.
  4. Interpret it.
  5. Decide what to do next.

That process creates friction, and friction is the enemy of adoption.

Today, most professionals spend the majority of their time in a handful of environments:

  • Email
  • Teams
  • Slack
  • CRM platforms
  • ChatGPT
  • Claude
  • Productivity applications

These have become the operating systems for modern work. Every additional application competes for attention against those environments, and most lose.

AI changes the equation

Large language models have created a new interface for work, allowing users to interact with intelligence through natural language rather than reports, dashboards, and portals. For the first time, intelligence no longer needs to live in a separate destination. Instead, it can travel directly to the user.

An executive can ask a question inside ChatGPT.

A seller preparing for a customer meeting can instantly surface market trends, competitive threats, and analyst insights directly within Salesforce.

A product leader can receive market insights through Teams.

A strategist can query complex research through an AI assistant.

The user never leaves their workflow, because the intelligence comes to them. This represents more than a user experience improvement: It’s about introducing a fundamentally different operating model.

The goal isn’t simply better intelligence. It’s reducing the friction between intelligence and action.

Why proprietary data matters more than ever

Many organizations believe AI itself is the competitive advantage. I believe the opposite.

As models become increasingly accessible, the differentiator will be intelligence.

Organizations that possess unique, proprietary, trusted data will have a significant advantage because they can combine AI with insights that cannot be found on the open internet. That’s exactly what makes this moment so rich with potential.

At IDC, we have decades of proprietary market intelligence: market sizing data, competitive positioning, technology adoption trends, vendor performance data, industry forecasts, and strategic research.

These are the datasets organizations use to make billion-dollar decisions. Historically, customers accessed that intelligence through reports, portals, and analyst interactions.

Today, AI allows us to reimagine how that intelligence is consumed.

From intelligence systems to decision systems

The next evolution is bigger than dashboards, and it’s bigger than reports. It’s even bigger than AI assistants.

The real opportunity is creating a technology intelligence layer that connects:

  • Market intelligence
  • Customer intelligence
  • Operational intelligence
  • Financial intelligence
  • First-party enterprise data

When those signals come together, organizations gain a more complete view of their markets, customers, competitors, and business performance. At that point, we are no longer talking about a research platform, but a new decision system.

IDC Quanta was built around this idea: bringing trusted technology intelligence directly into the workflows where decisions are made.

The organizations that win in the next decade will not necessarily have the most data, but they will have the least friction between intelligence and action.

Dashboards are dead because intelligence no longer needs a destination. It can travel directly to the moment of decision.

Nick Mercurio - Chief Revenue Officer - IDC

Chief Revenue Officer As Chief Revenue Officer of IDC, Nick Mercurio leads the company’s global commercial organization, including Sales, Customer Success, and Revenue Operations. He is responsible for accelerating growth, expanding customer value, and advancing IDC’s position as the technology intelligence layer of the AI economy.

Right now, the world is generating more than seven petabytes of data every second. That’s roughly the equivalent of producing 17 billion books every second. By 2029, that number will more than double. And that’s before more than a billion AI agents come online, each one generating, consuming, and amplifying information at machine speed. [IDC Global DataSphere Forecast, 2025–2029]

We’re drowning in information.

But more data doesn’t mean more clarity. In fact, it’s quite the opposite. Most of what’s flooding in isn’t even original; it’s copies, reprints, and regurgitations. And AI can make even bad data look very convincing.

In a world where noise is growing and clarity is fading; the biggest challenge enterprises face is discerning what’s real from what’s just an echo.  The winners won’t be the organizations with the most data. They’ll be the ones with frictionless access to the truth — and the confidence to act on it.

Today, IDC is delivering that with IDC Quanta, the technology intelligence fabric of the AI-enabled enterprise. For more than 60 years, organizations around the world have trusted IDC to help them navigate technology decisions and deliver data-backed intelligence to sharpen business strategies.

IDC Quanta takes the same structured, sourced, defensible insights, pairs them with your data and context, and puts them inside the tools your teams already use. A process that previously required disjointed systems, manual synthesis, and endless hours is now relevant, citable, and frictionless.

Intelligence embedded where you work

IDC Quanta lives inside email, inside Anthropic’s Claude AI, and inside the custom AI tools and workflows enterprises are building right now. No portal or separate login required. No need to leave the tools or workflows you’re already in. Instead, IDC Quanta gives you the ability to call on its intelligence the moment you need it — whether that’s a competitive client deal on the line, a board presentation, a roadmap under review, or vetting a new software platform.

Intelligence built on your context

Upload your own data and documents, and IDC Quanta synthesizes and visualizes them alongside IDC’s research in a single session. Adding to that is an extensive memory layer that ensures every conversation deepens what IDC Quanta knows about your role and your priorities, making each answer it returns sharper than the last. Your business context, combined with IDC’s, gives you a fuller picture than either could produce on its own.

But there’s something else important to note when it comes to context, and that’s security. With more than 175 beta customers helping us shape IDC Quanta’s development, the questions we heard most were simple: is loading data and documents secure, and are those documents used to train the model? The answers are “yes” and “no, respectively. Every upload lives in a private workspace with AES-256 encryption, enterprise-grade compliance and privacy controls, is automatically deleted after 90 days, and is never used to train IDC’s models. That means the confidence IDC Quanta gives you never comes at the cost of what you shared to get it.

Intelligence you can defend

Every response IDC Quanta gives runs through a multi-agent system that validates it against IDC’s 15B proprietary data points and expert-led research before it ever reaches you. An expandable reasoning panel shows exactly how the answer was built and includes detailed citations for answers you can stand in the boardroom and defend.

Intelligence on your schedule

IDC Quanta doesn’t wait to be asked. Automated scheduling capabilities enable IDC Quanta to proactively deliver the intelligence you need to monitor with regularity and then goes a step further, surfacing anonymized peer signals and related follow-up questions you didn’t know to ask.

An exciting future

IDC Quanta is live today and available to all current and new IDC customers. It was Amarok CIO Ashley Spicer who said it best:

“We are getting ridiculous, previously unimaginable value from IDC Quanta.  If you had told me 20 years ago that I would have access to something like this in my lifetime, I would have said no way. Our team is creating massive value by fielding questions and guiding understanding for critical decisions and strategic programs.”

With more integrations, more use cases, and packages tailored specifically for CIOs and IT leaders arriving this August, we’re just getting started. Intelligence will never be the same.

Visit www.idc.com/quanta to see it for yourself.

 

Lorenzo Larini - Chief Executive Officer - IDC

Chief Executive Officer of IDC, responsible for leading the company’s global strategy, operations, and growth. Lorenzo brings more than two decades of experience across the Research, Advisory Services, Enterprise Software, and AI sectors, most recently serving as CEO of Mint.ai, where he led the development of AI-driven workflow solutions. Previously, he served as CEO of Ipsos North America, where he led transformative growth for one of the world’s top market research and data analytics firms. He has also held global senior executive roles in Gartner’s technology division, including SVP of Executive Programs, advising global CIOs and enterprise leaders on digital transformation and operational excellence.

随着AI和智能体在企业业务、生产和办公场景中的广泛应用,零信任网络访问(ZTNA)解决方案不仅要防护传统用户和设备,还需针对AI模型、自动化智能体、API调用等新型主体进行身份认证、访问控制和行为审计。AI和智能体已成为新的访问与攻击面,ZTNA架构必须扩展至“人+设备+AI Agent”统一治理,防范AI身份伪造、越权访问、提示注入等新型风险。

与此同时,AI技术正深度赋能ZTNA解决方案。通过行为分析、风险建模、自动化策略生成和智能响应,AI显著提升了ZTNA的动态风险感知、异常检测、自动化运营和复杂场景下的安全决策能力。AI不仅是防护对象,更是能力跃迁的驱动力,使ZTNA成为智能体时代企业安全治理的核心平台。

零信任理念已成市场普遍认知

在全球数字化转型、云化和远程办公常态化的推动下,企业IT架构正快速从传统集中式数据中心模式,演进为覆盖云、多云、SaaS、边缘计算与第三方生态的分布式体系。业务边界、访问边界和数据边界不断模糊,传统“内外网边界”安全模型逐渐失效。攻击面扩展至终端、API、云工作负载、供应链及AI应用生态,网络安全风险高度动态化和复杂化。身份滥用、会话劫持、权限滥用成为主流攻击路径,“身份即边界”成为行业共识。

零信任理念(ZTNA)以“永不信任、持续验证”为核心,通过身份、设备状态、行为上下文和风险态势的动态访问控制,替代静态信任模型,成为企业安全架构升级的主流方案。中国企业对零信任的认知度和接受度已广泛提升,ZTNA逐步成为企业现代安全访问控制的主流方案。

中国ZTNA市场规模与竞争格局

近日,国际数据公司(IDC)发布了针对中国零信任网络访问(ZTNA)解决方案市场的一系列报告:

  • IDC MarketScape:中国GenAI赋能的零信任网络访问解决方案2026年厂商评估
  • 中国零信任网络访问解决方案市场份额,2025
  • 中国零信任网络访问场景之软件定义边界市场份额,2025
  • 中国零信任网络访问场景之终端安全市场份额,2025

通过这些研究对中国ZTNA整体市场和主要细分市场的规模、产品发展现状和技术发展趋势,以及市场主要代表厂商的能力和特点进行了全面介绍。有如下洞察:

1. 中国ZTNA技术能力发展现状

  • 厂商ZTNA解决方案相关的各项基础能力建设已经趋于成熟。国内主流安全厂商已基本具备身份认证、终端可信接入、应用级访问控制、动态权限管理、细粒度审计以及持续风险评估等核心能力,并逐渐形成覆盖身份、终端、网络与应用的一体化零信任架构。
  • 中国ZTNA市场正加速向安全访问服务边缘(SASE)方向演进。随着企业业务环境向多云、SaaS与分布式办公架构发展,单一ZTNA能力已难以满足企业对统一安全接入与持续安全运营的需求。越来越多厂商开始将ZTNA与SWG、CASB、SD-WAN、数据安全、终端安全以及安全运营能力进行深度融合,构建统一SASE平台,实现跨网络、跨云、跨终端环境的一体化安全访问控制。
  • 中国ZTNA市场正在进入“AI赋能ZTNA”的新阶段。当前,基于机器学习、行为分析与GenAI能力的智能检测、动态风险评估、自动化策略生成以及安全事件分析,已经在众多安全场景中取得显著效果,推动安全体系从“人工驱动”向“智能驱动”加速演进。与此同时,AI正在显著提升安全产品的实时分析能力、自动化运营能力和复杂环境下的风险感知能力,逐渐成为安全产品竞争力的重要核心。
  • AI自身安全问题成为国内技术提供商重点关注的新方向。当前,行业已经开始围绕AI身份管理、提示注入防护、模型调用安全、敏感数据保护等领域持续加大研发投入,希望构建面向“人+设备+智能体”的新一代安全体系。从目前中国市场发展阶段来看,AI自身安全能力与ZTNA体系之间仍未实现充分融合,大部分厂商对于AI智能体身份治理、AI行为持续监测、模型调用链审计以及AI最小权限控制等能力支持仍相对有限。

2. 中国ZTNA市场规模发展现状

虽然近几年受到宏观环境的影响,中国整体网络安全市场承压明显,但ZTNA市场仍然凭借厂商不断完备的技术演进以及企业级客户的真实需求增长保持稳定增长态势。从市场规模来看,2025年中国零信任网络解决方案市场的整体规模达到27.6亿元,其中软件定义边界(SDP)依旧是最主要的ZTNA实现方式,市场规模为15.4亿元,零信任终端安全继续保持快速增长,市场规模为7.9亿元。深信服科技、奇安信、腾讯、启明星辰集团、亿格云、易安联、指掌易、华为等厂商在ZTNA市场占据重要的市场影响力。

IDC的调研发现,中国企业对零信任理念和ZTNA的认知度与接受度已广泛提升,ZTNA逐步成为新一代统一访问控制与身份安全体系的重要基础能力。主要技术提供商的ZTNA基础能力建设已经已覆盖远程办公、互联网暴露面治理、第三方接入、云原生、工业互联网及AI应用访问等复杂场景。同时,中国ZTNA市场正加速向SASE平台化演进,满足多云、分布式办公和AI应用生态下的统一安全接入与持续运营需求。IDC《中国智能安全访问服务边缘市场预测,2026—2030》报告数据显示,中国SASE市场在未来5年将保持快速增长,年均复合增长率为25.9%,市场规模在2030年将达到48.7亿元。

在另外一本《IDC MarketScape:中国GenAI赋能的零信任网络访问解决方案2026年厂商评估》报告中,IDC从能力、战略和营收等多个维度对国内市场主要的ZTNA解决方案技术提供商进行了全面评估,充分展现厂商各自的能力、优势和挑战,并最终选择阿里巴巴、持安科技、从云科技、缔盟云、华为、吉大正元、南凌科技、奇安信、启明星辰集团、山石网科、深信服科技、腾讯、网宿科技、易安联、亿格云、中国电信、竹云、指掌易入选本次报告(按拼音首字母顺序排列)。

ZTNA技术发展趋势:AI场景的双驱动

结合今年的市场研究,IDC对ZTNA解决方案的技术发展趋势有如下判断:

  • AI赋能ZTNA能力升级:国际与中国技术提供商普遍将AI/GenAI技术深度嵌入ZTNA体系。AI驱动行为基线建模、动态风险评估、自动化策略生成、智能事件分析与响应,显著提升安全事件分析、预测和处置的智能化水平,降低人工运维负担。
  • 智能体安全防护:随着大模型、智能体、MCP、API等新型主体广泛应用,ZTNA需扩展至“人+设备+智能体”统一治理。技术提供商需要加大AI身份管理、访问控制、提示注入防护、模型调用安全、敏感数据保护和行为审计等研发投入,防范AI身份伪造、越权访问、提示注入、敏感数据泄露等新型风险。
  • 平台化与生态化融合:ZTNA正加速与SASE、IAM、安全运营、数据安全等体系深度融合,向一体化安全访问与运营平台演进。技术提供商将强调开放集成能力,支持多云、SaaS、分布式办公、AI应用等复杂场景下的统一安全管控。
  • 行业场景化与持续运营:针对政府、金融、能源、制造等重点行业,技术提供商需要提供定制化ZTNA/SASE方案,强化与云服务、终端安全、身份安全、SaaS等生态伙伴协同。ZTNA/SASE产品从单点部署转向长期治理与持续运营,提供全生命周期服务。
  • 数据安全与合规:技术提供商普遍将数据安全能力原生嵌入ZTNA架构,支持敏感数据识别、分级管理、全流程追踪、动态脱敏、泄密溯源水印及多渠道外发管控。AI助力数据行为监测、异常识别和自动化响应,推动数据安全防护从被动防御向主动治理转型。

因此,AI既是防护对象,也是能力跃迁的驱动力。未来,ZTNA将逐步演进为AI时代统一安全控制平面的关键组成部分。技术提供商需积极拥抱AI赋能,强化平台能力和生态协同,持续提升产品智能化和运营服务能力,以应对高度动态化的业务与攻击环境。

IDC建议

IDC中国网络安全市场高级研究经理赵卫京认为,在企业数字化、云化与AI化持续深入的背景下,ZTNA正在与SASE、IAM、安全运营及数据安全等体系深度融合,向平台化、智能化方向发展。GenAI与智能体的快速普及,也在从‘AI赋能安全’和‘保护AI自身安全’两方面重塑ZTNA解决方案。当前,中国ZTNA市场整体已进入规模化落地阶段,厂商基础能力逐渐成熟,但在AI与安全的融合、统一运营以及复杂场景适配等方面仍面临挑战。未来,ZTNA将逐步演进为AI时代统一安全控制平面的关键组成部分。”

进一步交流

AI攻防规则已变。IDC深耕大模型安全与智能体治理研究,助您量化风险、重构防线。欢迎联系IDC,获取最新洞察与定制化咨询,共探破局之道。

Austin Zhao

Austin Zhao - Senior Research Manager

Austin Zhao, senior research manager of IDC China, focuses on research and analysis of the China network security market. He provides intelligence and consulting services to both local and multinational cybersecurity vendors. Austin has deep insights into the China network…