CURVE(TM) Reports
Eight independent research reports covering the most critical enterprise security markets. Free for IT buyers - always.
AI Security
CURVE(TM) Report
“The attack surface of deployed AI - mapped, measured, and ranked.”
From prompt injection and model poisoning to agentic exploits and AI supply-chain compromise. We plot 14 vendors on the CURVE(TM) and identify who is building defenses at the speed the threat demands.
Key Findings
- Three vendors have achieved genuine frontier status
- Agentic AI security is the most underserved sub-category
- Supply-chain compromise is the highest-probability, lowest-visibility threat
SASE / SSE
CURVE(TM) Report
“The network perimeter is gone. Who rebuilt it - and who sold the illusion.”
The convergence of network and security is complete. Which vendors have built a genuine unified platform and which are assembling acquisitions under a shared brand.
Key Findings
- Only two vendors have achieved genuine platform convergence
- SD-WAN acquisitions have created hidden technical debt
- Zero-trust enforcement quality varies dramatically across the Frontier tier
AI Governance
CURVE(TM) Report
“Board-level accountability for AI risk. The regulatory wave is here.”
The EU AI Act, SEC AI disclosure guidance, and NIST AI RMF mandates are creating a compliance market faster than most enterprises can respond. Maps the governance platform landscape.
Key Findings
- EU AI Act compliance is 14 months closer than most programs are prepared for
- Board-level AI risk reporting required but absent in 73% of enterprises
- Governance tooling is consolidating fast - point solutions face acquisition
AI Infrastructure & Connectivity
CURVE(TM) Report
“The silicon-to-cloud layer powering the AI enterprise - and who is securing it.”
The AI infrastructure layer is simultaneously the most critical and the most exposed. Covers vendors securing the AI fabric from GPU clusters and inference endpoints to AI-optimized networks.
Key Findings
- Inference endpoint security is two years behind model security maturity
- Three hyperscalers dominate but differ materially in AI-native controls
- Edge AI deployment is outpacing enterprise security teams' ability to monitor it
CTEM / Exposure Management
CURVE(TM) Report
“From vulnerability management to continuous exposure reduction.”
Continuous Threat Exposure Management is reshaping how CISOs prioritize. Maps the vendors building the CTEM stack - from attack surface management and breach simulation to risk scoring engines.
Key Findings
- CTEM programs reduce exploited vulnerabilities by 4x vs. traditional VM
- Only 3 vendors have built a genuinely unified CTEM platform
- BAS and ASM are consolidating into CTEM platforms faster than expected
Data Security for AI
CURVE(TM) Report
“As AI consumes enterprise data, the attack surface on the data layer explodes.”
Bridges AI Security and AI Governance - mapping the vendors protecting the data pipelines that feed the models. Covers training data, RAG datastores, inference inputs, and output monitoring.
Key Findings
- Vector database security is the most underprotected layer in enterprise AI
- DSPM vendors with AI-native capabilities growing 3x faster than legacy DLP
- RAG pipeline exposure is the most common source of AI-related breaches
AI Enterprise Agent Platform
CURVE(TM) Report
“The orchestration layer powering the AI-native enterprise - and who will win the platform war.”
Above models and below enterprise systems sits the most contested layer in software: the agent platform. Microsoft, Salesforce, ServiceNow, OpenAI, Anthropic, LangChain, CrewAI, and more - plotted against the enterprise standard for autonomous digital workforce deployment.
Key Findings
- Agent platform layer will exceed CRM revenue by 2028
- Only two vendors meet enterprise-grade orchestration + governance today
- Developer frameworks face a structural governance gap buyers underestimate
Email Security
CURVE(TM) Report
“The most exploited attack vector in the enterprise - and the vendors finally getting ahead of it.”
Email remains the entry point for over 90% of enterprise breaches. AI-native threats have outpaced legacy secure email gateways. Maps the vendors moving from reactive filtering to behavioral AI, business email compromise prevention, and integrated cloud email protection.
Key Findings
- Legacy SEGs are failing against AI-generated phishing - replacement cycle has begun
- BEC losses exceed ransomware in total enterprise cost
- Cloud-native email platforms have fundamentally changed the protection architecture
Independent
No vendor pays to appear in a CURVE(TM) Report, influence a tier, or shape a finding. Full stop.
Free to IT Buyers
Every report is free to download. Enter your contact details once - the PDF is yours to keep.
Annual Cadence
Reports are refreshed annually. The 2026 editions reflect market state as of Q1 2026.