Picture a company in Pune that makes kitchen appliances. Its staff work in the office and from home. It sells online through its own website, and it runs a factory on the edge of the city. Every one of these connects to the internet, and every connection needs a gate that decides what may pass.
For thirty years, the gate was a device at the edge of the office network, called the firewall. It looked at every packet going in or out, and let it through or not. Then the office stopped being where the people and the applications were. Staff now work from home, and the applications live in someone else's cloud. A firewall at the edge of an empty office guards nothing. So the gate moved into the cloud too. The companies that sell it now sell a service that every laptop connects to first, wherever it is. That shift is the story of this Market Segment. It is why Zscaler, the largest company here, has never sold a hardware firewall.
The gate moved into the cloud. Then, staff and applications sat inside the office network, and a firewall at its edge guarded the way out to the internet. Now, staff work from home and from the office, the applications live in the cloud, and every laptop connects first to a security cloud such as Zscaler's or Netskope's, which checks who the user is.
Industry Vertical 1, Networking and telecom, covered the network itself. This Market Segment covers the gates on it. The buyers are the IT and security teams of companies. This is one of the Market Segments with the most job postings in Industry Vertical 4. Half of them are from companies whose India engineering is in Bengaluru.
Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.
This Market Segment has four sub-segments:
The firewall: still the biggest business, and the one most readers can picture.
The front door in the cloud: the newer companies, and the new names for the gate.
In front of the website: protecting the company's own website rather than its staff. Here the attack is a flood of traffic or a script, not an intruder.
OT and industrial security: the factory floor, where the network runs machines instead of laptops.
The firewall
Next-generation firewalls, VPN, intrusion prevention, network detection and response
Take the appliance maker from the start of this Market Segment. At its Pune office, every connection between the office network and the internet passes through the firewall. The first firewalls filtered traffic by port number. Today's firewalls, called next-generation firewalls, recognise the application, the user and any threat in the traffic. They also block known attack patterns, which is called intrusion prevention. And they run the VPN, the encrypted tunnel that lets staff at home reach the office network.
The companies that make firewalls are the established names of network security.
Palo Alto Networksis the largest of the firewall makers. On the reputation of its firewall, it now sells a whole security platform: cloud security, the cloud front door of the next sub-segment, and detection and response. It has owned CyberArk since February 2026, and has engineers in Bengaluru. (More on CyberArk in Market Segment 4.2, Identity and access management (IAM).)
Check Pointfrom Tel Aviv, made the stateful firewall the standard, and is still a major seller. A stateful firewall remembers each connection, so a reply from outside gets in only if someone inside asked for it.
Fortinetsells more firewalls than any other company in the world. It has only a few job postings in India, because most of its engineering is elsewhere.
SonicWallsells firewalls to small and mid-sized businesses through resellers, the IT firms that sell on its behalf. A large share of its product is engineered at its Pune centre.
SonicWall SLEDis SonicWall's own unit for schools and local government. SLED is short for state, local government and education.
WatchGuardis the other firewall maker for mid-sized businesses, with a small team in Delhi NCR.
Veherefrom Kolkata, sells network detection and response, full packet capture and a firewall. Network detection and response (NDR) watches the traffic inside a network for signs of an attacker. Full packet capture records every packet, so an attack can be studied later. Vehere began in lawful interception: systems that let government agencies, with legal permission, tap communications.
Five companies covered mainly in other Market Segments are here because they sell a firewall too:
Ciscothe largest network-equipment maker, and Juniper. (More on both in Market Segment 1.2, Enterprise networking, in Industry Vertical 1, Networking and telecom.)
Sophoswhose firewall comes in a bundle with its endpoint protection. (More on it in Market Segment 4.4, Endpoint security and device management.)
Barracudawhose firewall comes in a bundle with its email security. (More on it in Market Segment 4.1, Email security and anti-phishing.)
Rohde & Schwarzwhich makes network encryption and firewalls for European governments. (More on it in Market Segment 35.8, Chip manufacturing and test equipment, in Industry Vertical 35, Semiconductors and chip design.)
One company here works on the same wire for the state instead:
Pert Telecom Solutionssells lawful interception systems to telecom operators. That is monitoring, not defence, but it lives in the same equipment. (More on it in Market Segment 1.1, Telecom equipment and operators, in Industry Vertical 1, Networking and telecom.)
The front door in the cloud
Secure web gateway, zero-trust access, SASE and SSE, browser isolation, micro-segmentation
Back to the appliance maker from the start of this Market Segment. A sales manager works from home and opens the company's sales app, which runs in the cloud. The office firewall never sees this trip.
The new model has several names: secure access service edge (SASE), security service edge (SSE) and zero trust. They all share one idea:
- The user's laptop connects to the security company's cloud first, wherever the user is.
- The cloud checks who the user is.
- It connects the user only to the specific application they are allowed to use, never to the whole company network.
Zero trust in three steps. The laptop at home connects to the security company's cloud first, the cloud checks who the user is, and it connects the user only to the sales app, never to the whole company network. Nobody is trusted just for being on the company network.
Zero trust means nobody is trusted just for being on the company network. SSE is the security half of this model. SASE adds the networking half, called SD-WAN: software that links a company's offices over ordinary internet lines and steers the traffic between them. Part of the security half is a secure web gateway, which checks every website a user tries to open.
This is the largest change in network security in a generation. The companies that invented it were born in the cloud. They are now fighting over it with the firewall makers above, who sell the same thing.
Zscalerbuilt this category. Bengaluru is its main engineering site outside the United States.
Netskopeits closest rival, started by watching what staff do inside cloud applications. That product is called a cloud access security broker. Netskope then grew into the full front door. It also has engineers in Bengaluru.
Skyhigh Securityis in the same category, as an independent company again. It is the cloud business that McAfee's business for companies was split into, and it has a team in Bengaluru. (Trellix, in Market Segment 4.4, came from the same McAfee business.)
MEis McAfee Enterprise, now part of Skyhigh Security.
Menlo Securitytakes the idea one step further. It runs the user's browser in its own cloud, so nothing from the web ever runs on the laptop. This is called browser isolation. Menlo now also sells the browser itself.
Versa Networksis the SD-WAN company that turned into a SASE company.
Securlysells the same front door to schools: web filtering and student monitoring for the laptops a school district hands out. It is engineered in Pune.
One company here works inside the network instead of at the door:
ColorTokenswith its engineering centre in Bengaluru, divides the network into small segments, so an intruder who gets in cannot move around. This is called micro-segmentation.
Four companies covered mainly in other Market Segments mark where this market meets its neighbours:
Aryakadelivers SD-WAN and SASE as a managed service, run for the customer.
Arubasells network access control, which checks each device before letting it onto the network. It also sells the SD-WAN that the front door connects to.
Forcepointsells the gateway as the way to enforce its rules on company data. (More on it in Market Segment 4.8, Data security and privacy.)
Citrixis here for its secure private access, the door in front of virtual desktops. A virtual desktop runs in a data centre and appears on the user's screen. (More on it in Market Segment 16.2, Virtual desktops (VDI) and digital employee experience, in Industry Vertical 16, IT management and workplace tools.)
Versa, Aryaka and Aruba also appear in Market Segment 1.2, Enterprise networking (in Industry Vertical 1, Networking and telecom), where SD-WAN is covered. Zscaler, Netskope and Palo Alto Networks also appear in Market Segment 4.6, Cloud and SaaS security, for the cloud security in their platforms.
The browser as the front door.
If users only ever reach applications through a browser, then a browser the company controls becomes the whole security boundary. The companies are building exactly that, and it is called an enterprise browser. Menlo's is the one in this Market Segment, and Zscaler, Netskope and Palo Alto are all shipping one. This is where the next round of the contest will be fought.
You're reading as a guest. Sign in free to follow links for five minutes, once an hour.
Sign in
In front of the website
Web application firewall, DDoS protection, bot management, API security, DNS security
Back to the appliance maker from the start of this Market Segment. On a big sale day, its website has to stay up. Attackers may flood it with traffic, scrape its prices with scripts, or probe it for a flaw that lets them in.
The sub-segments above protect a company's people. This one protects what a company shows the world: its website and the APIs behind it. The defence sits in front of the site, in a network that the security company runs itself. That network absorbs the flood and inspects every request before it reaches the company's server. The defence has several parts:
DDoS protectionA distributed denial-of-service (DDoS) attack floods a site with traffic from thousands of hijacked machines, to knock it offline.
Web application firewallIt checks each web request for attacks, such as SQL injection.
Bot managementIt tells real shoppers apart from scripts. (More on bots in Market Segment 4.3, KYC, identity verification and fraud prevention.)
API securityIt protects the APIs that the website and the app call.
DNS securityIt filters the name lookups that turn a web address into a server address.
A shield in front of the website. Shoppers, floods of traffic and scripts all pass through a network run by a security company such as Akamai, Cloudflare, F5 or Radware. It absorbs the flood and checks every request with DDoS protection, a web application firewall, bot management, API security and DNS security, so only clean requests reach the company's website and its APIs.
The companies:
Akamairuns one of the two global networks that do this at the largest scale. It has engineers in Bengaluru, at one of its largest centres. Its security business, which protects websites and APIs, stops DDoS attacks and manages bots, is now bigger than the content delivery it was founded on. Content delivery means keeping copies of websites and videos on servers close to users, so they load fast.
Cloudflareruns the other one. It also has engineers in Bengaluru, in a smaller office.
F5made the hardware that sat in front of applications in the data centre. It now sells the same protection as a cloud service. Its main India centres are in Hyderabad and Bengaluru.
Radwarefrom Tel Aviv, is the specialist in DDoS and application protection, with a team in Bengaluru.
One company is here from the name lookup:
Infobloxalready runs DNS, the name lookup, for its customers. Every attack begins with a name lookup, so Infoblox's DNS security turns the lookup into a filter.
F5, Radware and Infoblox also appear in Market Segment 1.2, Enterprise networking (in Industry Vertical 1, Networking and telecom), which covers DNS and load balancing. Akamai and Cloudflare also appear in Market Segment 5.1, Cloud infrastructure and web hosting providers (in Industry Vertical 5, Cloud providers and OS makers).
OT and industrial security
Securing the networks that run machines: factories, ports, utilities, ships
Back to the appliance maker from the start of this Market Segment. Its factory also runs on a network, but that network runs machines, not laptops. The industry calls these systems operational technology, or OT, as against the IT of the office.
Each machine is run by a small industrial computer called a controller. Many controllers were designed decades ago to be reliable, not secure. They cannot run an agent, the security program from Market Segment 4.4, Endpoint security and device management. They cannot be patched on a regular schedule, and they cannot be taken offline to be fixed. So securing them means watching the network without touching them. It is a specialist trade with its own companies.
Forescoutwith engineering in Pune, is the established name. Its product needs no agent. It discovers every device on a network, whether a laptop, a camera, a controller or a pump, and controls what each device may reach. (More on it, and on the factory's control systems, in Market Segment 37.1, Industrial automation and control software, in Industry Vertical 37, Manufacturing tech.)
Cequraa New York start-up with engineers in Bengaluru, applies the same idea to ships and fleets. It compares signs of a cyber attack with the ship's physical signals. (More on it in Market Segment 30.6, Freight forwarding, customs and trade platforms, in Industry Vertical 30, Supply chain and logistics.)
So the appliance maker from the start of this Market Segment has four gates to guard. The firewall guards the office. The cloud front door guards staff wherever they work. A shield sits in front of the website, and a watch is kept over the factory floor.