Cloud security
– Getty Images

HCLTech, IBM, and Wipro topped IDC’s latest security service edge (SSE) report, with researchers suggesting today’s market expects vendors to orchestrate and manage a truly integrated service at global scale.

IDC's "Worldwide Managed Security Service Edge Services 2025 Vendor Assessment" placed the three providers on a pedestal in this regard, with an evaluation of 15 vendors in total for its survey.

India’s HCLTech was distinguished by researchers for its vendor-agnostic approach and deep integration capabilities with the likes of Palo Alto Networks, Fortinet, Cisco, Netskope, and Zscaler. The company’s Cyber Security Fusion Center was also praised for delivering SSE offerings at enterprise scale, combining advanced threat intelligence with operational expertise.

On the negative side, IDC noted that the firm is still developing automation for routine operational tasks.

In contrast, IBM leans heavily on automation while taking a similarly agnostic path. IDC noted that IBM’s strength lies in its ability to accelerate deployments and integrate with complex enterprise environments. The report also highlighted IBM’s plan to extend its offering to a fully managed secure access service edge (SASE) service by merging its SSE capabilities with managed SD-WAN and networking services.

IDC also underscored that many of IBM's service levels remain defined as service-level objectives (SLOs) rather than hard service-level agreements (SLAs), a difference that may give larger organizations pause for thought.

Finally, Wipro’s place in the leadership cluster was down to its globally distributed, multitiered SSE offering – and similar to HCLTech – built around partnerships with top vendors likeNetskope, Zscaler, Palo Alto, and Cisco. But, also similar to HCLTech, IDC noted that the automation maturity of Wipro’s service portal is variable.

IDC sse
IDC vendor matrix – IDC

The telecom tier

IDC’s "Major Players" segment is mainly populated by telecom firms, with communication providers praised for extending their capabilities beyond connectivity work.

These included British Telecom (BT), noted for its pragmatic approach with modular service tiers that scale from foundational protection to premium, AI-driven analytics. The company’s Eagle-i platform, for example, unifies visibility across SD-WAN, SSE, and endpoint telemetry, appealing to customers in need of consolidated insights.

“Expanding automation for policy management, provisioning, and routine incident handling could further streamline service delivery and reduce operational overhead for customers,” IDC recommended as an area for BT to improve upon.

Deutsche Telekom was commended for its ability to merge network and security operations, but IDC noted that unified security information and event management (SIEM) and automation capabilities remain a work in progress for the firm.

Orange Business earned a nod with its Evolution platform, combining SSE and SASE with SD-WAN and managed detection services. Its Orange Cyberdefense arm, meanwhile, adds proprietary threat intelligence into the offering, marked by the report as a valuable differentiator.

The IDC MarketScape report suggests, however, that Orange Business could improve commercial packaging and expand pre-sales pilots to help customers validate value earlier.

Tata Communications and Telefónica were both commended for their flexible vendor partnership and SSE/SASE/SD-WAN integrations. As a result, IDC suggested both are well positioned for global enterprises, but that Tata should continue investing in automation and Telefónica needed to improve on its user experience due to a lack of proprietary unified reporting and consolidated dashboard.

Verizon’s SSE deployments were noted for tying into its network-as-a-service (NaaS) platform and ServiceNow integration, enabling highly customized global deployments. But the provider, which was the sole U.S. vendor on the list, was knocked down a peg for not providing defined SLAs for incident resolution.

Vodafone, meanwhile, was recommended for delivering managed SSE alongside its global connectivity and how its network management services support cohesive SASE deployments, enabling unified operational oversight and consistent policy enforcement across network and security functions. But similar to Telefónica, it was noted as lacking on the customer portal side.

Deloitte, IT firm LevelBlue, and cybersec business Open Systems were also named as major players, while GTT and Comcast Business represented the "Contenders" section in IDC’s overview.

SSE market trajectory

Across all providers, IDC defined automation, integration, and transparency as shaping the next phase of the SSE market. In its view, enterprises are demanding clear visibility into what their provider is doing, measurable SLAs for detection and remediation, and confidence that policies are consistent wherever users connect.

The SSE managed-service model is fast becoming the favored framework for zero-trust and hybrid-work strategies, and vendors who can combine automation, identity integration, and global reach are those leading ahead.

Overall, the 2025 IDC MarketScape portrays a market shifting from product delivery to service orchestration. The SSE success stories will be those who can make security seamless, weaving together people, process, and platform into a continuously adaptive service.