Analytics and business intelligence (ABI) platforms prepare, model, analyze and visualize data to support decision making. They deliver insights through AI-powered conversational experiences, interactive dashboards and classic reporting. They support collaboration between business and technical users for defining the dimensions, measures and business rules used to create and maintain semantic models. The platforms provide functionality for agentic analytics, where AI agents coordinate tasks across the data-to-insight workflow to automate insight delivery under governance and audit controls. Analytics and business intelligence platforms integrate data from multiple sources, such as databases, spreadsheets, cloud services and external data feeds, to provide a unified view of data, breaking down silos and transforming raw data into meaningful insights. They also allow users to clean, transform and prepare data for analysis, in addition to creating data models that define relationships between different data entities.
Cyber asset attack surface management (CAASM) is focused on enabling security teams to overcome asset visibility and exposure challenges. It enables organizations to see all assets (internal and external), primarily through API integrations with existing tools, query consolidated data, identify the scope of vulnerabilities and gaps in security controls. These tools then continuously monitor and analyze detected vulnerabilities to drill down the most critical threats to the business and prioritize necessary remediation and mitigation actions for improved cyber security.
Data and Analytics refers to products and services that enable organizations to collect, integrate, analyze, and act on data to drive informed decision-making and business outcomes. This category includes markets that focus on empowering enterprises to manage data pipelines, ensure data quality and governance, extract insights through advanced analytics, and machine learning across structured and unstructured data environments.
Gartner defines decision intelligence platforms (DIPs) as software to create decision-centric solutions that support, augment and automate decision making of humans or machines, powered by the composition of data, analytics, knowledge and AI. DIPs enable enterprises to collaboratively design and explicitly model decisions, orchestrate decision flow during execution at scale, and enable monitoring and governance of decision quality, while learning from actions and outcomes. Features can include a combination of rule- and logic-based techniques, machine learning, real-time event stream processing, business intelligence, multimodal data and analytics preparation, natural language, graph technology, optimization, simulation or AI agents for decision intelligence. DIPs provide a solution to enhance how organizations make decisions, whether by humans or machines, individually or collectively. They address the growing challenge of making timely and accurate decisions in volatile, uncertain, complex and ambiguous ecosystems, for more demanding customers in disruptive, competitive and regulated markets. DIPs help by creating executable decision models that improve decision service composition and all-source intelligence to achieve better situational awareness, better recommendations or autonomous actions, tailored to specific decisions and outcomes. They can reduce the risk of poor decisions, allow organizations to anticipate change and respond more swiftly to opportunities at scale.
Gartner defines digital experience monitoring (DEM) as the measurement of the availability, performance and quality of the user experience of applications. This can include internal users (employees), external users (customers and partners) or a digital agent connecting to an API. In addition to performance, DEM enables observability of user behavior and journeys based on their interaction with applications. DEM tools allow I&O leaders to understand the availability, performance and reliability of business applications, networks and infrastructure by focusing on understanding the user experience. This is in contrast to other performance monitoring approaches, such as observability platforms, that understand the inner workings of applications.
Gartner defines event intelligence solutions (EIS) as tools that apply artificial intelligence (AI) and data analytics to augment, accelerate and automate responses to signals or events detected from digital services. The key characteristics of event intelligence solutions include cross-domain event ingestion, topology assembly, event correlation and enrichment, pattern recognition, and accelerated remediation. These solutions are designed to process event streams into actionable insights and enable proactive responses that reduce toil and improve performance and availability. They are delivered as software as a service or self-managed software.
IT Infrastructure and IoT refers to the products and services that support the deployment, management, and optimization of core technology systems and connected devices across enterprise environments. This category includes markets that focus on enabling organizations to build and operate resilient, scalable, and intelligent infrastructure. It encompasses solutions for data center management, network infrastructure, and IoT connectivity—spanning on-premises, cloud, edge, and hybrid models.
Infrastructure monitoring tools capture the health and resource utilization of IT infrastructure components wherever they reside (e.g., in a data center, at the edge, or IaaS or PaaS in the cloud). This enables I&O teams to monitor the availability and resource utilization data of physical, virtual, software entities, and AI systems — including servers, containers, network devices, database instances, hypervisors, storage, and basic application monitoring. These tools collect data in near real time and perform historical data analysis or trending of the elements they monitor.
Gartner defines the insider risk management (IRM) market as solutions that use advanced analytics, monitoring, and behavior-based risk models to detect, analyze and mitigate risks posed by trusted insiders within an organization. These solutions monitor the activities of employees, service partners and key suppliers to ensure their behavior aligns with corporate policies and risk tolerance levels. IRM platforms can be delivered as cloud-based services or on-premises solutions, or in hybrid forms. When effectively implemented alongside proper governance, they provide comprehensive visibility, real-time detection, and proactive intervention to safeguard against data theft, fraud and other malicious or unintentional insider threat activities.
Network-based sandboxing is a proven technique for detecting malware and targeted attacks. Network sandboxes monitor network traffic for suspicious objects and automatically submit them to the sandbox environment, where they are analyzed and assigned malware probability scores and severity ratings. Sandboxing technology has been used for years by malware researchers at security companies and even in some large enterprises that are highly security conscious. Traditionally, using a sandbox has been an intensive effort requiring advanced skills. The malware researcher manually submits a suspicious object into the sandbox and analyzes it before flagging it as malware or not. By adding automated features to sandboxing technology (automatically submitting suspicious objects and automatically generating alerts). (Retired as of Mar-12-2026).
Gartner defines observability platforms as products that help organizations understand and optimize the health, performance and behavior of applications, services, infrastructure and AI agents, as well as user experience. They ingest and analyze telemetry such as logs, metrics, events and traces to detect issues that affect end users, enabling early remediation. These platforms are used by IT operations, SRE, platform engineering, developers, security teams and product owners. Modern businesses rely on critical digital applications and services that directly influence revenue, client satisfaction and brand reputation. Outages, latency and degraded performance harm these outcomes. Observability platforms address this by ingesting, correlating and analyzing telemetry from applications, infrastructure and AI systems to detect anomalies, identify the root cause of issues and quantify user‑experience impact. These capabilities enable organizations to improve the availability, performance and resilience of digital services. As a result, observability platforms support revenue‑loss avoidance through early detection, faster mean time to resolution and prevention of customer‑impacting failures. They also accelerate development and platform engineering workflows by providing continuous feedback on code changes, deployments and model behavior. This allows teams to deliver new features and AI capabilities faster while maintaining reliability and improving customer experience.
Security information and event management (SIEM) is a configurable system of record that collects, aggregates and analyzes security event data from on-premises and cloud environments. SIEM processes security event data for the purposes of threat detection, investigation and response. It natively supports data normalization and offers user-configurable detection content and reporting to orchestrate threat mitigation and satisfy compliance requirements. These solutions are delivered via a SaaS platform or client-hosted on-premises or private cloud. The security information and event management (SIEM) system must assist with: 1. Aggregating and normalizing data from various IT and operational technology (OT) environments. 2. Designing and executing near real-time monitoring and alerting content. 3. Enriching and investigating security events of interest. 4. Supporting manual and automated response actions. 5. Maintaining and reporting on current and historical event data.
Security orchestration, automation and response (SOAR) solutions combine incident response, orchestration and automation, and threat intelligence (TI) management capabilities in a single platform. SOAR tools are also used to document and implement processes (aka playbooks, workflows and processes); support security incident management; and apply machine-based assistance to human security analysts and operators. SOAR solutions must provide: - Highly customizable workflow process management that enables repeatable automated tasks to be turned into playbooks that run in isolation or joined together into more sophisticated workflows. - The ability to store (locally or in a third-party system) incident management data to support SecOps investigations. - Manually instigated and automated triggers that augment human security analyst operators to carry out operational tasks consistently. - A mechanism to collate and better operationalize the use of threat intelligence. - Support for a broad range of existing security technologies that supports improved analyst efficiency and acts as an abstraction layer between the desired outcomes and the custom-made set of solutions in place in your environment.