The global network of KPMG firms has been recognized as a Leader in the IDC MarketScape: European Cybersecurity Governance, Risk, and Compliance Consulting and Professional Services 2026 Vendor Assessment. The assessment evaluates providers of cybersecurity governance, risk and compliance consulting and professional services, also known as cybersecurity GRC.

As noted in the IDC MarketScape report, KPMG’s European cybersecurity practice spans GRC advisory, regulatory compliance, cyber transformation and managed security services. KPMG’s approach includes strategy development, target operating model alignment, quantitative risk management and operational implementation.

KPMG’s strengths recognized by IDC MarketScape also include:

- Integrated risk and audit methodology. KPMG unifies risk management, internal controls and assurance workflows within a cohesive governance model.

- European regulatory compliance breadth. KPMG firms advise clients on NIS2, DORA, GDPR and the Cyber Resilience Act.

- Proprietary risk quantification tooling. The Cyber Risk Insights platform enables clients to quantify and benchmark cyber exposure, supporting data-driven investment decisions and executive reporting.