The laptop you were handed on your first day has something running on it that you did not install and cannot remove. It is a small program called an agent. It watches every program that starts, every file that is written and every network connection that is opened. If it sees the pattern of ransomware, software that locks your files and demands money to unlock them, it kills the program and alerts the security team. The same agent, or a related one, decides which apps may be on your phone and whether the phone may open the company's mail.
The industry calls the laptop, the phone and the server "endpoints", because they are where the network ends and the person begins. The endpoint is where most attacks are finally stopped, or finally succeed.
This Market Segment is about the companies that make this software. Most of their buyers are the security and IT teams of other companies. The last sub-segment is different: its products are sold to you.
Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.
This Market Segment has four sub-segments:
The agent that detects and responds: the program that grew out of antivirus, and is now the centre of company security.
Managing the device: the software that enrols, configures and wipes the device. It is half security and half IT.
The phone as its own problem: protecting a device the company usually does not own.
Security for the person: the consumer version, from the antivirus on a home PC to the app that tells you which calls not to answer.
The agent that detects and responds
Endpoint protection, endpoint detection and response (EDR), and the platforms that grew from them
Take the laptop from the start of this Market Segment. Say an email attachment you opened starts locking your files. Old-style antivirus might have missed it. Antivirus matched each file against a list of known bad files, called signatures. A new attack is on no list yet.
The product that replaced antivirus is called endpoint detection and response, or EDR. It records everything a machine does, and looks for suspicious behaviour instead of known files. So an attack nobody has seen before is caught by what it does. A security analyst can also replay the attack afterwards, step by step.
Why endpoint detection and response replaced antivirus. Old-style antivirus asks whether a file is on a list of known bad files, so a new attack that is on no list is missed. Endpoint detection and response records every program, file and connection, catches the attack by what it does, and lets an analyst replay it later. SentinelOne, CrowdStrike, Trellix and Sophos all sell it.
Almost every company in this sub-segment began with EDR. Since then, they have spread into protecting cloud servers, identity, and the security operations centre (SOC), the team that watches security alerts all day. The reason is simple: whoever has an agent on every machine has the data everyone else wants. (More on the SOC in Market Segment 4.9, SIEM and security operations (SOC).)
SentinelOneis a newer company that built a version of EDR around AI from the start. It has engineers in Bengaluru.
Trellixis what became of McAfee's business for companies when it was merged with FireEye. It sells an endpoint platform with SOC tools attached, and has engineering in Bengaluru.
Sophosfrom Oxford, sells endpoint protection, a firewall and a managed detection service, mostly to mid-sized companies. In a managed detection service, the seller's own team watches the alerts for the customer. Sophos has engineers in Bengaluru. Its firewall comes partly from Cyberoam, an Ahmedabad company Sophos bought in 2014. (More on its firewall in Market Segment 4.5, Network security, firewalls and SASE.)
CrowdStrikeone of the largest companies in this category, opened a development centre in Pune in 2024.
N-ablesells an endpoint and detection suite, but not to companies. It sells to managed service providers: firms that run the IT of small businesses, thousands of them at once.
Fortinetis here for FortiEDR, the endpoint agent it sells alongside its network equipment. (More on it in Market Segment 4.5, Network security, firewalls and SASE.)
The agent that acts.
Detection has become response. The agent no longer waits for a person. It cuts the machine off from the network, restores the locked files, and hunts for the same attack across every device the company owns. The companies compete on how much of a security analyst's shift this saves. This is where SentinelOne and CrowdStrike built their names, and where Trellix and Sophos are heading.
Managing the device
Unified endpoint management (UEM), mobile device management (MDM), cloud directories, patching
Back to your laptop from the start of this Market Segment. Before IT handed it to you, it had to be set up. It was enrolled, meaning registered with the company. Then it was configured with the company's settings. From then on, it has to be patched: kept up to date with software fixes. When you leave, it will be wiped.
The life of a work laptop: enrolled with the company, configured with its settings, patched with fixes, and wiped when you leave. This is unified endpoint management, or mobile device management for phones alone, sold by companies such as 42Gears, Hexnode, Jamf, NinjaOne, Ivanti and JumpCloud.
Before a device can be protected, all of this has to happen, and the software that does it is a market of its own. The industry calls it unified endpoint management, or UEM. For phones alone, it is called mobile device management, or MDM. The IT department buys it as often as the security team does.
The desktop and the digital workplace are covered in Market Segment 16.2, Virtual desktops (VDI) and digital employee experience (in Industry Vertical 16, IT management and workplace tools). Six companies here also appear there: JumpCloud, 42Gears, Hexnode, Jamf, NinjaOne and N-able. The companies in this sub-segment are the ones whose product is control of the device.
42Gearsfrom Bengaluru, is the Indian company in this category. Its product, SureMDM, manages rugged and single-purpose devices, like the scanners in a warehouse and the tablets in a restaurant, for customers around the world.
Hexnodefrom Kochi, is the other Indian one. It sells a unified endpoint management product to mid-sized companies.
Jamfmanages Apple devices. In a company full of MacBooks, that is the whole job.
NinjaOneis an IT operations platform, sold to managed service providers and to companies' own IT teams. Its security role is patching.
Ivantiis here for its endpoint management and its risk-based patching, which fixes the most dangerous gaps first. It has more job postings in India than any company covered mainly in this Market Segment. (More on it in Market Segment 16.1, IT service management (ITSM) and IT operations software, in Industry Vertical 16, IT management and workplace tools.)
One company here starts from the directory instead:
JumpCloudsells a cloud directory, the master list of users and devices, with single sign-on and device management built in. It replaces Microsoft's directory for companies that never had a Windows server. It has engineering teams in several Indian cities. (More on directories in Market Segment 4.2, Identity and access management (IAM).)
You're reading as a guest. Sign in free to follow links for five minutes, once an hour.
Sign in
The phone as its own problem
Mobile threat defence and mobile app security
Back to you. The phone in your pocket is probably your own, not the company's, and you install whatever you like on it. It also carries the code for every login, from Market Segment 4.2, Identity and access management (IAM). So it is the most exposed device, and the one the security team is least allowed to touch.
Mobile threat defence is the small industry that protects it anyway. It sells an app that spots three things:
- malicious apps
- fake Wi-Fi networks set up to spy on the traffic
- phishing over SMS
It does this without reading the user's messages.
Zimperiumwith engineering in Bengaluru and Kolkata, is the specialist. It also sells tools that protect a company's own mobile apps against tampering. (More on those tools in Market Segment 4.7, Application and API security.)
Lookoutdoes the same for the phone. It built a business on top that gives staff secure access to company systems from the phone, and sold that business to Fortra in 2025.
Security for the person
Consumer antivirus, identity protection, scam-call blocking
Back to you, at home this time. Everything above is sold to companies. This sub-segment is sold to you. It is bigger than its few names suggest, because two of the largest consumer security companies in the world have engineers in India.
Genwas formed when NortonLifeLock bought Avast. It owns Norton, Avast, AVG and LifeLock, and has engineers in Chennai.
McAfeesold its business for companies, which became Trellix in the first sub-segment. Now it sells only to consumers: antivirus, a VPN that encrypts your internet connection, and monitoring for identity theft. It has a centre in Bengaluru.
F-Securefrom Finland, sells the same protection through telecom operators, bundled with home broadband.
Truecalleris the Indian consumer's security product, whether or not anyone calls it that. The app names the unknown caller and blocks the scam call. It was built in Stockholm, but India is its largest market and its engineering is in Bengaluru. It now also sells the verification and number-lookup APIs behind the app to businesses. It sits on the phone network, so it also appears in the telecom Market Segment. (More on it in Market Segment 1.1, Telecom equipment and operators, in Industry Vertical 1, Networking and telecom.)
So endpoint security runs from the agent on your company laptop to the phone in your pocket. At home, it is the app that warns you about a scam call.