When buyers ask AI which cybersecurity vendor to pick, who gets named?
We put 100 real security-buyer questions to ChatGPT and Gemini and Perplexity and checked which of 24 cybersecurity vendors each answer named. 1 of the 100 questions got no named vendor at all — spanning EDR/XDR, identity and access management, cloud security, SIEM, compliance and incident response, the everyday categories a CISO or security buyer actually shops in. Run the check for your platform →
Hover or tap a dot for the question.
Why we ran this
Security buying has quietly moved from "read an analyst report" to "ask an assistant and act on the shortlist it gives you." That shortlist is assembled from whatever content the assistant can find — vendor sites, analyst coverage, community forums, peer-review platforms — and it either names specific vendors or it doesn’t. This benchmark reads how visible cybersecurity vendors currently are across the categories a real security buyer shops in, engine by engine, and where the biggest content openings are.
How we measured it
We wrote 100 questions in the language a real CISO or security engineer actually uses — endpoint detection, identity and access management, cloud security posture, SIEM and security operations, compliance readiness, and incident response (all 100 are explorable in full below). Each question was sampled once per engine, and every answer was checked for a mention of any of 24 identifiable cybersecurity vendors — from diversified platform incumbents like CrowdStrike and Palo Alto Networks to focused security specialists like Wiz and Vanta — using the same name matcher a live Inserviss scan uses.
A single pass per engine establishes direction and priority; it is not a trend line. Citations are reported as measured; query volumes are labelled estimates, shown as ranges. Engines are never blended. This run covers ChatGPT and Gemini and Perplexity; Microsoft Copilot is not currently sampled.
The tracked list covers 24 vendors a real security buyer would plausibly shortlist across endpoint protection, identity, cloud security and compliance — a deliberately broad, category-spanning set rather than one narrow product line.
What we found, at a glance
- Visibility varies sharply by engine. ChatGPT named a tracked vendor in 87 of 100 answers, Gemini named a tracked vendor in 98 of 100 answers and Perplexity named a tracked vendor in 79 of 100 answers.
- 1 of 100 questions got no tracked vendor on any engine.
- Microsoft Defender is the most-named vendor, appearing in 109 of 300 answers. Only 23 of the 24 tracked vendors were named even once.
- Diversified platform incumbents and focused security specialists get named at very different rates. See the full breakdown, and which archetype AI actually favors, in the table below.
How often does AI name a vendor at all?
Below is the share of the 100 answers that named at least one tracked vendor, per engine — then the full table, every vendor against every engine, sortable by any column.
Share of 100 answers naming at least one of the 24 tracked vendors. Per engine, never blended.
| Vendor | ChatGPT | Gemini | Perplexity |
|---|---|---|---|
| Microsoft Defenderincumbent | 39 | 46 | 24 |
| CrowdStrikeincumbent | 33 | 45 | 23 |
| Palo Alto Networksincumbent | 20 | 41 | 11 |
| Oktaincumbent | 12 | 32 | 14 |
| Splunkincumbent | 18 | 26 | 8 |
| Wiz | 16 | 19 | 15 |
| SentinelOne | 10 | 28 | 11 |
| Vanta | 13 | 17 | 16 |
| Drata | 12 | 17 | 15 |
| Zscalerincumbent | 5 | 5 | 3 |
| Cloudflare | 4 | 5 | 4 |
| CyberArk | 3 | 6 | 4 |
| Arctic Wolf | 0 | 9 | 4 |
| Tenable | 2 | 5 | 5 |
| Ciscoincumbent | 4 | 4 | 3 |
| Rapid7 | 1 | 8 | 2 |
| Check Pointincumbent | 4 | 0 | 4 |
| Fortinetincumbent | 3 | 2 | 0 |
| Netskope | 2 | 2 | 0 |
| Proofpoint | 1 | 2 | 0 |
| Trellix | 2 | 0 | 1 |
| KnowBe4 | 0 | 0 | 1 |
| Mimecast | 0 | 1 | 0 |
| Darktrace | 0 | 0 | 0 |
Mentions across 100 answers per engine. Select a column heading to re-sort. Scroll the table sideways on a narrow screen.
Download this chart as an image →
Where the openings are
Coverage varies by question type. Below is the best engine’s coverage for each cluster, out of ~17 questions.
Answers naming a vendor on the strongest engine, per cluster (out of ~17).
How this is estimated
Estimate — a range, not a keyword-tool export. Illustrative estimate, not a keyword-tool export. Each cluster has ~16-17 seed buyer questions; cybersecurity is a broad, high-value commercial category — long-tail intent phrases run ~100–380 monthly searches each globally, one or two head terms (e.g. "best EDR platform") add ~2,000–7,500/mo, and an AI-assistant reformulation multiplier of ×2–4 accounts for the wider phrasing people use with an assistant. Ranges are rounded and widened. For a specific vendor, the real number comes from the check, not this table.
| Cluster | Best-engine coverage | Est. questions / mo |
|---|---|---|
| Endpoint Detection & Response | 17/17 | 12,000–44,000 |
| Identity & Access Management | 17/17 | 9,500–36,000 |
| Cloud Security Posture Management | 17/17 | 6,500–24,000 |
| SIEM & Security Operations | 17/17 | 7,000–26,000 |
| Compliance & Audit Readiness | 16/16 | 5,500–21,000 |
| Incident Response & Breach Readiness | 14/16 | 3,000–11,500 |
Volumes are an estimate, shown as a range. Illustrative estimate, not a keyword-tool export. Each cluster has ~16-17 seed buyer questions; cybersecurity is a broad, high-value commercial category — long-tail intent phrases run ~100–380 monthly searches each globally, one or two head terms (e.g. "best EDR platform") add ~2,000–7,500/mo, and an AI-assistant reformulation multiplier of ×2–4 accounts for the wider phrasing people use with an assistant. Ranges are rounded and widened. For a specific vendor, the real number comes from the check, not this table.
The check runs this same 100-question universe against your vendor’s name, per engine, and returns your AI Visibility Score plus the exact questions where a competitor — or no one — is being named.
Check your vendor’s AI visibility →Explore the 100 questions
Every question, and exactly what each engine did with it — which vendors it named, and which sources it pulled from. Filter by cluster, search for your own name, or show only the questions no vendor has claimed.
The 1 questions no tracked vendor owns on any engine, with the sources AI cites instead — a ready-made content brief.
One email. No list-selling. Unsubscribe any time.
Where each engine gets its answers
The domains each engine actually pulled from, per engine — never blended. ChatGPT leans on Microsoft’s own documentation (learn.microsoft.com, 36 citations) and Gartner (27), with vendor-owned pages (CrowdStrike, Vanta, Okta, Splunk) filling out the rest. Perplexity draws almost entirely on independent research and review content — expertinsights.com, cybersecuritynews.com, Reddit, G2 and Gartner — rarely a vendor’s own site. Gemini names a vendor in 98 of 100 answers but, as in our other studies, its citations are thin and scattered — no domain cited more than 4 times across all 100 answers.
Times a domain was cited across the 100 answers. Blue = a tracked vendor’s own site.
About this study
- Single pass per engine. One sample per question per engine establishes direction; it does not average out run-to-run answer variance.
- Snapshot in time. Collected September 14, 2026. AI engines change their answers week to week; this is not a trend line.
- Conservative name matching. Short one-token vendor names (Wiz, Okta, Vanta…) require an exact whole-word match, so a slight undercount is possible — but it cannot explain a 1-of-100 gap.
- ChatGPT and Gemini and Perplexity this run. Microsoft Copilot is not currently sampled; the measurement is identical when it is.
How to cite this study
To request the underlying data or discuss a vendor-specific analysis, contact igor@inserviss.app.
The same measurement, run against your vendor’s name — per engine, question by question — with your score and the questions to claim first.
Run my free scan →