Cybersecurity Services: AI Market Discovery Index

Tracking how AI platforms recommend cybersecurity services. This public AI Market Discovery Index is updated monthly since July 2026.

Mark Huntley, J.D.
By Mark Huntley, J.D.Growth Strategist & AI Discovery Analyst
6 minutes read

Benchmark Summary

CrowdStrike leads the August 2026 benchmark with 53.5% valid recommendation coverage, ahead of Palo Alto Networks at 47.6% — a gap of 5.9 percentage points. The category recorded a mixed month: six brands (CrowdStrike, Mandiant (Google), Palo Alto Networks, Rapid7, Secureworks, and Sophos) posted significant increases in valid recommendation coverage, eight brands (Arctic Wolf, CrowdStrike Falcon, Deepwatch, Google Chronicle, Palo Alto Cortex XDR, Rapid7 InsightIDR, Secureworks Taegis, and Sophos Intercept X) posted significant declines, and Optiv and Trustwave held stable.

The largest increase came from CrowdStrike, which moved from 0.0% valid recommendation coverage in July 2026 to 53.5% in August 2026. The largest decline was CrowdStrike Falcon, which moved from 53.7% in July 2026 to 0.0% in August 2026. Much of this movement reflects a change in how tracked brands are identified and named between the two months, with several product-line names used in July no longer present in August and several parent-brand names entering the tracked list for the first time (see Recommendation Coverage Movement below).

The benchmark began with 750 prompt-surface observations in each month and produced 338 qualified observations in August 2026.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Aug 2026

  • CrowdStrike+53.5% · beyond normal variation
    Jul 20260.0%
    Aug 202653.5%
  • Palo Alto Networks+47.6% · beyond normal variation
    Jul 20260.0%
    Aug 202647.6%
  • Sophos+26.3% · beyond normal variation
    Jul 20260.0%
    Aug 202626.3%
  • Arctic Wolf-8.1% · beyond normal variation
    Jul 202617.3%
    Aug 20269.2%
  • Rapid7+8.6% · beyond normal variation
    Jul 20260.0%
    Aug 20268.6%
  • Mandiant (Google)+8.3% · beyond normal variation
    Jul 20260.0%
    Aug 20268.3%
  • Secureworks+4.7% · beyond normal variation
    Jul 20260.0%
    Aug 20264.7%
  • Trustwaveno change
    Jul 20261.5%
    Aug 20261.5%
  • Optiv+0.2%
    Jul 20261.0%
    Aug 20261.2%
  • CrowdStrike Falcon-53.7% · beyond normal variation
    Jul 202653.7%
    Aug 20260.0%
  • Deepwatch-1.2% · beyond normal variation
    Jul 20261.2%
    Aug 20260.0%
  • Google Chronicle-2.2% · beyond normal variation
    Jul 20262.2%
    Aug 20260.0%
  • Palo Alto Cortex XDR-25.0% · beyond normal variation
    Jul 202625.0%
    Aug 20260.0%
  • Rapid7 InsightIDR-9.9% · beyond normal variation
    Jul 20269.9%
    Aug 20260.0%
  • Secureworks Taegis-2.0% · beyond normal variation
    Jul 20262.0%
    Aug 20260.0%
  • Sophos Intercept X-34.4% · beyond normal variation
    Jul 202634.4%
    Aug 20260.0%

Current Benchmark at a Glance

Measure

Jul 2026

Aug 2026

Movement

Qualified benchmark observations

404

338

Down 66

Tracked brands

10

10

No change

Qualified surface breadth

6

6

No change

Recommendation-shaped answer share

33.9%

40.8%

Up 6.9 points

Valid recommendation shortlist share

53.5%

60.7%

Up 7.2 points

Leader by valid recommendation coverage

CrowdStrike Falcon

CrowdStrike

Changed

Qualified surface breadth counts the number of canonical AI surface families with at least one qualified observation. The six canonical families are ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode.

For the strategic interpretation of this benchmark, read CiteWorks Studio's analysis of How AI Search Is Recommending Cybersecurity Services

Research Scope and Qualification

The public benchmark is narrower than the raw collection universe by design. In July 2026 the benchmark began with 750 source prompt-surface observations, of which 404 qualified for the public benchmark. In August 2026 the benchmark began with 750 source prompt-surface observations, of which 338 qualified. The table below details each stage.

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Research stage

Jul 2026

Aug 2026

What it represents

Source prompt-surface observations

750

750

Total prompts collected across AI surfaces

Unique questions

475

475

Distinct questions after removing duplicates

Brand / competitor mentions

750

750

Prompts mentioning a tracked brand or competitor

Relevant observations

500

500

Prompts relevant to the cybersecurity services vertical

Irrelevant observations

250

250

Prompts not relevant to the vertical

Qualified benchmark observations

404

338

Public denominator for brand-level metrics

Brand-level percentages use the qualified observations as the public denominator, not the raw collection. Link: AI Market Discovery Methodology.

Current Brand Standings

This table is the primary current-month benchmark view. Standings are sorted by valid recommendation coverage.

Brand

Presence rate

Valid recommendation coverage

Top-three rate

Rank-one rate

Net sentiment

CrowdStrike

82.2%

53.5%

47.9%

27.5%

0.7

Palo Alto Networks

76.3%

47.6%

37.6%

18.1%

0.7

Sophos

36.7%

26.3%

10.7%

1.5%

0.8

Arctic Wolf

13.0%

9.2%

5.3%

1.8%

0.8

Rapid7

17.5%

8.6%

4.1%

0.6%

0.6

Mandiant (Google)

10.9%

8.3%

4.7%

0.0%

0.8

Secureworks

8.3%

4.7%

1.8%

1.5%

0.7

Trustwave

2.7%

1.5%

0.3%

0.0%

0.8

Optiv

1.8%

1.2%

0.6%

0.0%

0.8

Deepwatch

0.3%

0.0%

0.0%

0.0%

0.0

How to Read the Standings

  • Presence rate: the share of qualified observations in which the brand is mentioned.
  • Valid recommendation coverage: the share of qualified observations in which the brand receives a valid recommendation.
  • Top-three rate: the share of qualified observations in which the brand appears in the top three recommended positions.
  • Rank-one rate: the share of qualified observations in which the brand is the first recommended.
  • Net sentiment: the balance of positive over negative mentions among observations where sentiment is detected.

For formulas and denominator rules, see AI Market Discovery Metric Definitions.

Recommendation Coverage Movement

The table below shows movement from the July 2026 baseline to August 2026. Tracked brand naming shifted between months, so several brands enter or exit the series.

Brand

Jul 2026

Aug 2026

Movement since baseline

Arctic Wolf

17.3%

9.2%

Down 8.1 points

CrowdStrike

0.0%

53.5%

Up 53.5 points

CrowdStrike Falcon

53.7%

0.0%

Down 53.7 points

Deepwatch

1.2%

0.0%

Down 1.2 points

Google Chronicle

2.2%

0.0%

Down 2.2 points

Mandiant (Google)

0.0%

8.3%

Up 8.3 points

Optiv

1.0%

1.2%

Up 0.2 points

Palo Alto Cortex XDR

25.0%

0.0%

Down 25.0 points

Palo Alto Networks

0.0%

47.6%

Up 47.6 points

Rapid7

0.0%

8.6%

Up 8.6 points

Rapid7 InsightIDR

9.9%

0.0%

Down 9.9 points

Secureworks

0.0%

4.7%

Up 4.7 points

Secureworks Taegis

2.0%

0.0%

Down 2.0 points

Sophos

0.0%

26.3%

Up 26.3 points

Sophos Intercept X

34.4%

0.0%

Down 34.4 points

Trustwave

1.5%

1.5%

No change

Largest Increase: CrowdStrike

CrowdStrike rose from 0.0% valid recommendation coverage in July 2026 to 53.5% in August 2026, a move of 53.5 points. The brand appeared in 82.2% of qualified observations in August 2026. The movement should not be treated as organic growth; it reflects the parent-brand entering the tracked list.

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Largest Decline: CrowdStrike Falcon

CrowdStrike Falcon fell from 53.7% valid recommendation coverage in July 2026 to 0.0% in August 2026, a move of 53.7 points. This brand did not appear in the August 2026 tracking list, reflecting a change in brand identification.

Category Leader: CrowdStrike

CrowdStrike leads the current benchmark with 53.5% valid recommendation coverage in August 2026, ahead of Palo Alto Networks at 47.6%. The leader changed from July 2026, when CrowdStrike Falcon led with 53.7%.

Recommendation Placement Snapshot

Coverage alone does not show how prominently a brand is recommended. For the leading brands, the top-three and rank-one rates show placement strength within those recommendations.

Brand

Aug 2026 top-three rate

Aug 2026 rank-one rate

Jul 2026 top-three rate

Jul 2026 rank-one rate

CrowdStrike

47.9%

27.5%

0.0%

0.0%

Palo Alto Networks

37.6%

18.1%

0.0%

0.0%

Sophos

10.7%

1.5%

0.0%

0.0%

Close coverage can still hide different first-position rates. CrowdStrike's 27.5% rank-one rate is notably higher than Palo Alto Networks' 18.1% in August 2026, even though both brands have high coverage and top-three rates. The July 2026 columns read as 0.0% because these three brand names were not part of the July tracking list; the equivalent product lines tracked that month appear in the Recommendation Coverage Movement table above.

Buyer-Intent Distribution

The qualified observations in August 2026 fell into the Brand Recommendation class. The current public series measures this class of discovery.

Buyer-intent class

Jul 2026

Aug 2026

Brand Recommendation

404

338

Pricing & Value

0

0

Multi-Brand Comparison

0

0

Total qualified observations

404

338

All qualified observations sit in the Brand Recommendation class, so the current public series measures that class of discovery and does not yet contain qualified observations in the Pricing & Value or Multi-Brand Comparison classes.

Historical Measurement Record

This is an evergreen benchmark URL. New measurements are added to the same report.

Measurement

Qualified observations

Coverage leader

Leader coverage

Largest coverage movement

Jul 2026

404

CrowdStrike Falcon

53.7%

Baseline month (no prior period for comparison)

Aug 2026

338

CrowdStrike

53.5%

CrowdStrike up 53.5 points since baseline

Evidence and Source Layer

The benchmark is built from prompt-level observations that retain the query, AI/search surface, answer, brand outcome, recommendation placement, sentiment, and, where exposed, citations or attributable evidence sources. Source presence is evidence about the information environment. It is not automatically proof that the source caused the recommendation.

Scope Boundaries

This public benchmark does not measure market share, attributable sales, every possible AI response, organic-search ranking, social mention volume, private or sponsored channels, or causality from a metric movement alone. Movement between months reflects changes in recommendation patterns; the benchmark does not, by itself, establish why the change occurred. Movement between months reflects changes in recommendation patterns across the tracked AI surfaces; the benchmark records the change and does not, by itself, establish why the change occurred.

About This Benchmark

The LLM Authority Index AI Market Discovery Index is a neutral industry benchmark that measures how brands appear in AI-generated responses across six canonical AI search and assistant surfaces. The benchmark tracks presence, recommendation coverage, placement, and sentiment for each brand on a monthly basis.

Get a Company-Level Authority Index

The public industry benchmark shows category-level standings. The public percentage cannot identify the prompts, competitors, or sources causing the result. A company-level Authority Index can go deeper, examining a specific brand's AI presence across surfaces, queries, and placement patterns in more detail.

Get my free AI Company Index

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.