Consulting and the Big Four
Cyber consulting has not consolidated through a single megadeal. The Big Four (Deloitte, PwC, EY, KPMG), Accenture, IBM, and the global system integrators run multi-billion-dollar cyber practices, yet the headline deals reshaping the industry — Wiz, CyberArk, Armis, Red Canary — are all product or product-adjacent. Advisory consolidates differently: through a steady churn of mid-market tuck-ins, and now under an existential question — whether a business that sells billable hours can survive a technology whose promise is to eliminate hours. That tension shapes both buy-side roll-ups and the AI thesis of The Agentic Edge.
What cyber consulting is, and how it makes money
"Cyber consulting" is not one business; it is a stack of four distinct economic models that buyers conflate and that capture value very differently:
1. Strategy & program advisory — the CISO-facing work: security strategy, target operating models, board reporting, risk quantification, maturity assessments against NIST CSF / ISO 27001. Sold as fixed-fee projects or retainers; high day-rates, partner-led, low headcount-leverage. This is where the Big Four and McKinsey/BCG/Bain compete, and where reputation and C-suite access are the moat.
2. Compliance & assurance — audit-adjacent work: SOC 2, PCI, HIPAA, ISO certification, and the regulatory-driven assessments (DORA, NIS2, CMMC, SEC disclosure readiness — see Regulation). This is the annuity of consulting: recurring, calendar-driven, mandated by regulators rather than chosen by buyers, and therefore the most defensible revenue in the stack. It is also where the Big Four's audit franchise gives them structural advantage.
3. Implementation & integration — architecting and standing up the tools (SIEM migrations, IAM rollouts, Zero-Trust programs, cloud-security buildouts). Headcount-heavy, partner-funnel-fed, and increasingly a channel play — the integrator earns margin on the product and the services wrapped around it (see Channel and MSSP where implementation flows into managed services).
4. Managed services — the recurring tail: once a firm builds it, it operates it (MSSP/MDR — see 04a/04b). This is the consulting industry's escape route from the billable-hours trap: convert a project into an annuity.
In economic terms, value migrates rightward and downward — from high-rate, low-leverage strategy work toward recurring compliance and managed services — because recurring revenue commands a higher multiple and is more defensible against AI. A pure strategy boutique is a lifestyle business; a firm with a compliance annuity and a managed-services tail is a platform.
The named-player map (four tiers)
| Tier | Who | What they sell | How they capture value | M&A relevance |
|---|---|---|---|---|
| Big Four | Deloitte, PwC, EY, KPMG | Strategy + compliance + implementation at enterprise/board level | Audit-franchise pull-through; global scale; trust | Acquirers of mid-market boutiques; rarely targets |
| Global SIs / IT services | Accenture (Security), IBM (X-Force/Consulting), Wipro, Infosys, TCS, Capgemini, DXC, NTT | Implementation + managed services at scale | Product pull-through + offshore labor arbitrage | Serial acquirers; Accenture is the most aggressive |
| Pure-play cyber consultancies | Optiv, GuidePoint, Coalfire, NCC Group, Bishop Fox, Booz Allen (federal), Leviathan, Kroll | Specialist depth: testing, IR, GRC, federal | Expertise scarcity; trusted-advisor relationships | The roll-up sweet spot — PE-backed platforms (Optiv/GuidePoint) tucking in regional shops |
| Elite strategy | McKinsey, BCG, Bain | Board-level cyber strategy, risk quantification | C-suite access; brand | Mostly organic; partner with vendors |
The differentiation that matters for M&A: the Big Four buy, the SIs buy, the pure-plays get bought, and the elite firms mostly abstain. A regional cyber consultancy doing $5–50M of revenue — strong local relationships, a compliance annuity, maybe a nascent managed-services practice — is the archetypal tuck-in target for a PE-backed platform like Optiv (KKR) or GuidePoint, or for a Big Four firm filling a capability or geographic gap.
AI compression of the billable hour
The strategic squeeze is now visible in the public numbers: Accenture's outlook has repeatedly flagged softening time-and-materials demand as clients pause discretionary consulting, even as the firm sells "AI transformation." The firms are caught selling the very technology that erodes the hours they bill. Two adaptations are underway:
First, co-opt the disruptor. Accenture's partnership with Anthropic to build AI-driven cyber operations is the template: rather than defend the billable hour, redeploy senior people to supervise AI agents and reprice toward outcomes. Even McKinsey — long the purest day-rate model — has moved a meaningful share of fees to outcome-based structures.
Second, buy the annuity. The defensible escape is to own recurring compliance and managed services. This is why the most acquisitive consultancies (Accenture, the Big Four, PE-backed pure-plays) are buying GRC, IR, and managed-services capability rather than more strategy headcount — they are buying the parts of the stack AI cannot easily eat and that carry a software-like multiple.
The segment's own security posture is part of its commercial profile. In July 2026, Accenture confirmed a data breach after a threat actor offered for sale on a hacker forum what it claimed were 35 gigabytes of internal data — including source code, Azure access keys and tokens, and RSA/SSH keys — exfiltrated from a private Azure DevOps repository; Accenture described the incident as isolated, remediated at its source, and without operational or service-delivery impact (SecurityWeek, Jul 8 2026). The incident illustrates a structural exposure: large consulting and services firms sit close to clients' cloud environments, identity tooling, and codebases, which makes them concentrated targets — one compromise can yield a playbook for attacks on many downstream clients. For acquirers and clients alike, a services firm's own security record is a diligence line item, a dynamic sharpened in Accenture's case by its pending majority acquisition of Dragos (announced Jun 18, 2026; see Deals).
The bear case
The bull case: cyber consulting rides a structural demand wave (regulation, breach frequency, the AI attack surface), it is deeply fragmented, and a disciplined acquirer can roll up regional shops at single-digit EBITDA multiples and re-rate them inside a platform. Three counterweights. First, AI may compress the industry faster than acquirers can roll it up — if agents do the assessment, the report, and even the remediation plan, the billable base shrinks under the very assets being acquired, and a roll-up of declining-revenue shops destroys value. Second, people are the asset and they walk — consulting equity is the partners and senior practitioners; a tuck-in that loses its rainmakers post-close is a goodwill write-down, which is why advisory M&A lives or dies on retention structuring (earn-outs, deferred equity). Third, the Big Four's audit-conflict and scale make the mid-market the only roll-up zone — the truly defensible compliance annuity sits with the audit franchises, leaving financial buyers to consolidate the more AI-exposed implementation tier. Falsifiable test: watch whether PE-backed consulting platforms (Optiv, GuidePoint) grow organic revenue and retain practitioners through an AI cycle (thesis holds — consulting is a durable roll-up), or whether their organic growth stalls and billable headcount shrinks faster than tuck-ins add (thesis weakens to "AI made advisory a melting-ice-cube that no amount of consolidation fixes"). One early reading arrived in June 2026: Optiv sold its project-based Advisory, Consulting and Transformation (ACT) business — roughly 500 consultants serving 800+ enterprise clients — to Vobis Ventures, retaining an exclusive services partnership rather than continuing to own the discretionary consulting tier outright (Optiv PR, Jun 2 2026; see Deals). The largest pure-play platform electing to shed, rather than roll up more of, the most AI-exposed revenue tier is a data point on the compression side of the test — though a single carve-out is portfolio shaping, not proof.
→ Cross-references: Service Providers, MSSP, MDR, The Agentic SOC, Incident Response, Channel & Distribution, Regulation, Operator Economics.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.