Cybersecurity Services: AI Market Discovery Index

Tracking how AI platforms recommend cybersecurity services. This public AI Market Discovery Index is updated monthly since July 2026.

Mark Huntley, J.D.
By Mark Huntley, J.D.Growth Strategist & AI Discovery Analyst
7 minutes read

Benchmark Summary

CrowdStrike Falcon leads the September 2026 benchmark with 50.7% valid recommendation coverage, ahead of Sophos Intercept X at 32.5%: a gap of 18.2 percentage points. CrowdStrike Falcon also led the July 2026 baseline, when it measured 53.7% coverage. Across the full baseline-to-current series, no brand registered a significant rise or decline in valid recommendation coverage; all 16 tracked brands are classified as stable.

Month-over-month, several brands showed sharp swings between August 2026 and September 2026. That pattern reflects a change in how tracked brands were identified and named that month, not organic movement in recommendation behavior. Parent-brand names used in August 2026 (CrowdStrike, Palo Alto Networks, Rapid7, Secureworks, Sophos, Mandiant (Google)) were not tracked in September 2026, while the product-line names tracked in July 2026 and September 2026 (CrowdStrike Falcon, Palo Alto Cortex XDR, Rapid7 InsightIDR, Secureworks Taegis, Sophos Intercept X, Arctic Wolf, Google Chronicle, Deepwatch) registered 0.0% in August 2026 because they were not part of that month's tracking list. Read against the July 2026 baseline rather than the August 2026 reading, all of these brands sit within normal month-to-month variation.

The benchmark began with 764 prompt-surface observations in September 2026 and produced 416 qualified observations after qualification.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Sep 2026

0%15%30%45%60%Jul 2026Aug 2026Sep 2026
  • CrowdStrike Falcon50.7%
  • Sophos Intercept X32.5%
  • Palo Alto Cortex XDR25.7%
  • Arctic Wolf16.6%
  • Rapid7 InsightIDR10.8%
  • Secureworks Taegis3.6%
  • Google Chronicle3.1%
  • Optiv2.6%
  • Trustwave2.2%
  • Deepwatch1.7%
  • CrowdStrike0.0%
  • Mandiant (Google)0.0%
  • Palo Alto Networks0.0%
  • Rapid70.0%
  • Secureworks0.0%
  • Sophos0.0%

Current Benchmark at a Glance

Measure

Jul 2026

Sep 2026

Movement

Qualified benchmark observations

404

416

Up 12

Tracked brands

10

10

No change

Qualified surface breadth

6

6

No change

Recommendation-shaped answer share

33.9%

31.3%

Down 2.6 points

Valid recommendation shortlist share

53.5%

53.1%

Down 0.4 points

Leader by valid recommendation coverage

CrowdStrike Falcon

CrowdStrike Falcon

No change

Qualified surface breadth counts the number of canonical AI surface families with at least one qualified observation. The six canonical families are ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode. In August 2026 the surface breadth also measured six; the tracked brands that month were identified under parent-brand names before reverting to product-line names in September 2026.

For the strategic interpretation of this benchmark, read CiteWorks Studio's analysis of How AI Search Is Recommending Cybersecurity Services

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Research Scope and Qualification

The public benchmark is narrower than the raw collection universe by design. In July 2026 the benchmark began with 750 source prompt-surface observations, of which 404 qualified for the public benchmark. In September 2026 the benchmark began with 764 source prompt-surface observations, of which 416 qualified. The table below details each stage.

Research stage

Jul 2026

Sep 2026

What it represents

Source prompt-surface observations

750

764

Total prompts collected across AI surfaces

Unique questions

475

531

Distinct questions after removing duplicates

Brand / competitor mentions

750

764

Prompts mentioning a tracked brand or competitor

Relevant observations

500

594

Prompts relevant to the cybersecurity services vertical

Irrelevant observations

250

170

Prompts not relevant to the vertical

Qualified benchmark observations

404

416

Public denominator for brand-level metrics

Brand-level percentages use the qualified observations as the public denominator, not the raw collection. Link: AI Market Discovery Methodology.

Current Brand Standings

This table is the primary current-month benchmark view. Standings are sorted by valid recommendation coverage.

Brand

Presence rate

Valid recommendation coverage

Top-three rate

Rank-one rate

Net sentiment

CrowdStrike Falcon

88.0%

50.7%

45.9%

30.0%

0.8

Sophos Intercept X

47.4%

32.5%

14.7%

1.7%

0.9

Palo Alto Cortex XDR

46.6%

25.7%

11.3%

2.2%

0.8

Arctic Wolf

26.2%

16.6%

13.0%

6.7%

0.8

Rapid7 InsightIDR

20.0%

10.8%

3.9%

0.2%

0.8

Secureworks Taegis

8.2%

3.6%

2.4%

0.7%

0.8

Google Chronicle

7.0%

3.1%

1.4%

0.0%

0.8

Optiv

5.8%

2.6%

1.4%

0.2%

0.9

Trustwave

5.8%

2.2%

1.2%

0.0%

0.6

Deepwatch

1.9%

1.7%

1.0%

0.0%

1.0

How to Read the Standings

  • Presence rate: the share of qualified observations in which the brand is mentioned.
  • Valid recommendation coverage: the share of qualified observations in which the brand receives a valid recommendation.
  • Top-three rate: the share of qualified observations in which the brand appears in the top three recommended positions.
  • Rank-one rate: the share of qualified observations in which the brand is the first recommended.
  • Net sentiment: the balance of positive over negative mentions among observations where sentiment is detected.

For formulas and denominator rules, see AI Market Discovery Metric Definitions.

Recommendation Coverage Movement

The table below shows movement from the July 2026 baseline to September 2026. Tracked brand naming shifted between months, so several brands enter, exit, and re-enter the series.

Brand

Jul 2026

Sep 2026

Movement since baseline

Arctic Wolf

17.3%

16.6%

Down 0.7 points

CrowdStrike

0.0%

0.0%

No change

CrowdStrike Falcon

53.7%

50.7%

Down 3.0 points

Deepwatch

1.2%

1.7%

Up 0.5 points

Google Chronicle

2.2%

3.1%

Up 0.9 points

Mandiant (Google)

0.0%

0.0%

No change

Optiv

1.0%

2.6%

Up 1.6 points

Palo Alto Cortex XDR

25.0%

25.7%

Up 0.7 points

Palo Alto Networks

0.0%

0.0%

No change

Rapid7

0.0%

0.0%

No change

Rapid7 InsightIDR

9.9%

10.8%

Up 0.9 points

Secureworks

0.0%

0.0%

No change

Secureworks Taegis

2.0%

3.6%

Up 1.6 points

Sophos

0.0%

0.0%

No change

Sophos Intercept X

34.4%

32.5%

Down 1.9 points

Trustwave

1.5%

2.2%

Up 0.7 points

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Every brand's baseline-to-current movement falls within normal month-to-month variation; none is classified as a significant riser or decliner. Versus the immediate prior month, the August 2026 readings for CrowdStrike Falcon, Palo Alto Cortex XDR, Rapid7 InsightIDR, Secureworks Taegis, Sophos Intercept X, Arctic Wolf, Google Chronicle, and Deepwatch were all 0.0% because those product-line names were not part of the August 2026 tracking list; the parent-brand names that tracked that month (CrowdStrike, Palo Alto Networks, Rapid7, Secureworks, Sophos, Mandiant (Google)) were not tracked in September 2026. This naming shift, rather than organic change in recommendation behavior, drives the large month-over-month swings.

Category Leader: CrowdStrike Falcon

CrowdStrike Falcon leads the September 2026 benchmark with 50.7% valid recommendation coverage, the same leader as the July 2026 baseline, when the brand measured 53.7%. The brand appears in 88.0% of qualified observations in September 2026. Its top-three rate came in at 45.9% and its rank-one rate at 30.0%. Coverage sits slightly below the July 2026 reading but within normal month-to-month variation, and the brand's presence rate of 88.0% in September 2026 is down 4.6 points from 92.6% in July 2026.

Recommendation Placement Snapshot

Coverage alone does not show how prominently a brand is recommended. For the leading brands, the top-three and rank-one rates show placement strength within those recommendations.

Brand

Sep 2026 top-three rate

Sep 2026 rank-one rate

Jul 2026 top-three rate

Jul 2026 rank-one rate

CrowdStrike Falcon

45.9%

30.0%

41.8%

27.7%

Sophos Intercept X

14.7%

1.7%

14.8%

4.7%

Palo Alto Cortex XDR

11.3%

2.2%

8.2%

2.2%

Close coverage can still hide different first-position rates. CrowdStrike Falcon pairs the highest coverage with the highest rank-one rate at 30.0% in September 2026, while Sophos Intercept X carries a 32.5% coverage rate but reaches the first position only 1.7% of the time. Palo Alto Cortex XDR, at 25.7% coverage, places first in 2.2% of observations.

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.

Buyer-Intent Distribution

The qualified observations in September 2026 fell into the Brand Recommendation class. The current public series measures this class of discovery.

Buyer-intent class

Jul 2026

Sep 2026

Brand Recommendation

404

416

Pricing & Value

0

0

Multi-Brand Comparison

0

0

Total qualified observations

404

416

All qualified observations sit in the Brand Recommendation class, so the current public series measures that class of discovery and does not yet contain qualified observations in the Pricing & Value or Multi-Brand Comparison classes. Pricing, value, and head-to-head comparison have no public signal in this data.

Historical Measurement Record

This is an evergreen benchmark URL. New measurements are added to the same report.

Measurement

Qualified observations

Coverage leader

Leader coverage

Largest coverage movement

Jul 2026

404

CrowdStrike Falcon

53.7%

Baseline month (no prior period for comparison)

Aug 2026

338

CrowdStrike

53.5%

CrowdStrike up 53.5 points since baseline

Sep 2026

416

CrowdStrike Falcon

50.7%

CrowdStrike Falcon down 3.0 points since baseline

Evidence and Source Layer

The benchmark is built from prompt-level observations that retain the query, AI/search surface, answer, brand outcome, recommendation placement, sentiment, and, where exposed, citations or attributable evidence sources. Source presence is evidence about the information environment. It is not automatically proof that the source caused the recommendation.

Scope Boundaries

This public benchmark does not measure market share, attributable sales, every possible AI response, organic-search ranking, social mention volume, private or sponsored channels, or causality from a metric movement alone. Movement between months reflects changes in recommendation patterns across the tracked AI surfaces; the benchmark records the change and does not, by itself, establish why the change occurred.

About This Benchmark

The LLM Authority Index AI Market Discovery Index is a neutral industry benchmark that measures how brands appear in AI-generated responses across six canonical AI search and assistant surfaces. The benchmark tracks presence, recommendation coverage, placement, and sentiment for each brand on a monthly basis.

Get a Company-Level Authority Index

The public industry benchmark shows category-level standings. A company-level Authority Index can go deeper, examining a specific brand's AI presence across surfaces, queries, and placement patterns in more detail.

Get my free AI Company Index

Want the full Authority Index

The paid deep-dive adds competitor threat profiles, the gap matrix, citation failure map, platform-by-platform recovery roadmap, and client-specific economic modeling.