Inserviss Labs
Insights · Directional Study

When buyers ask AI which cybersecurity vendor to pick, who gets named?

We put 100 real security-buyer questions to ChatGPT and Gemini and Perplexity and checked which of 24 cybersecurity vendors each answer named. 1 of the 100 questions got no named vendor at all — spanning EDR/XDR, identity and access management, cloud security, SIEM, compliance and incident response, the everyday categories a CISO or security buyer actually shops in. Run the check for your platform →

By Inserviss Labs·September 14, 2026·~6 min read
100 buyer questions6 clusters · 24 tracked vendorsGlobalChatGPT and Gemini and Perplexity
99%
Any engine cites
100
Buyer questions tracked
99 / 100
Claimed → total
This categoryEndpoint Detection & ResponseIdentity & Access ManagementCloud Security Posture ManagementSIEM & Security OperationsCompliance & Audit ReadinessIncident Response & Breach Readiness
No tracked firm namedNamed by at least one engine

Hover or tap a dot for the question.

Why we ran this

Security buying has quietly moved from "read an analyst report" to "ask an assistant and act on the shortlist it gives you." That shortlist is assembled from whatever content the assistant can find — vendor sites, analyst coverage, community forums, peer-review platforms — and it either names specific vendors or it doesn’t. This benchmark reads how visible cybersecurity vendors currently are across the categories a real security buyer shops in, engine by engine, and where the biggest content openings are.

How we measured it

We wrote 100 questions in the language a real CISO or security engineer actually uses — endpoint detection, identity and access management, cloud security posture, SIEM and security operations, compliance readiness, and incident response (all 100 are explorable in full below). Each question was sampled once per engine, and every answer was checked for a mention of any of 24 identifiable cybersecurity vendors — from diversified platform incumbents like CrowdStrike and Palo Alto Networks to focused security specialists like Wiz and Vanta — using the same name matcher a live Inserviss scan uses.

A single pass per engine establishes direction and priority; it is not a trend line. Citations are reported as measured; query volumes are labelled estimates, shown as ranges. Engines are never blended. This run covers ChatGPT and Gemini and Perplexity; Microsoft Copilot is not currently sampled.

The tracked list covers 24 vendors a real security buyer would plausibly shortlist across endpoint protection, identity, cloud security and compliance — a deliberately broad, category-spanning set rather than one narrow product line.

What we found, at a glance

  • Visibility varies sharply by engine. ChatGPT named a tracked vendor in 87 of 100 answers, Gemini named a tracked vendor in 98 of 100 answers and Perplexity named a tracked vendor in 79 of 100 answers.
  • 1 of 100 questions got no tracked vendor on any engine.
  • Microsoft Defender is the most-named vendor, appearing in 109 of 300 answers. Only 23 of the 24 tracked vendors were named even once.
  • Diversified platform incumbents and focused security specialists get named at very different rates. See the full breakdown, and which archetype AI actually favors, in the table below.

How often does AI name a vendor at all?

Below is the share of the 100 answers that named at least one tracked vendor, per engine — then the full table, every vendor against every engine, sortable by any column.

ChatGPT
87%
Gemini
98%
Perplexity
79%

Share of 100 answers naming at least one of the 24 tracked vendors. Per engine, never blended.

ValueSort
VendorChatGPT Gemini Perplexity
Microsoft Defenderincumbent
39
46
24
CrowdStrikeincumbent
33
45
23
Palo Alto Networksincumbent
20
41
11
Oktaincumbent
12
32
14
Splunkincumbent
18
26
8
Wiz
16
19
15
SentinelOne
10
28
11
Vanta
13
17
16
Drata
12
17
15
Zscalerincumbent
5
5
3
Cloudflare
4
5
4
CyberArk
3
6
4
Arctic Wolf
0
9
4
Tenable
2
5
5
Ciscoincumbent
4
4
3
Rapid7
1
8
2
Check Pointincumbent
4
0
4
Fortinetincumbent
3
2
0
Netskope
2
2
0
Proofpoint
1
2
0
Trellix
2
0
1
KnowBe4
0
0
1
Mimecast
0
1
0
Darktrace
0
0
0

Mentions across 100 answers per engine. Select a column heading to re-sort. Scroll the table sideways on a narrow screen.

Download this chart as an image →

Where the openings are

Coverage varies by question type. Below is the best engine’s coverage for each cluster, out of ~17 questions.

Incident Response & Breach Readiness
14
Compliance & Audit Readiness
16
Endpoint Detection & Response
17
Identity & Access Management
17
Cloud Security Posture Management
17
SIEM & Security Operations
17

Answers naming a vendor on the strongest engine, per cluster (out of ~17).

Estimated demand · Incident Response & Breach Readiness
43,500–162,500
high-intent questions a month, across the under-owned clusters, that don’t currently point to a named vendor.
How this is estimated

Estimate — a range, not a keyword-tool export. Illustrative estimate, not a keyword-tool export. Each cluster has ~16-17 seed buyer questions; cybersecurity is a broad, high-value commercial category — long-tail intent phrases run ~100–380 monthly searches each globally, one or two head terms (e.g. "best EDR platform") add ~2,000–7,500/mo, and an AI-assistant reformulation multiplier of ×2–4 accounts for the wider phrasing people use with an assistant. Ranges are rounded and widened. For a specific vendor, the real number comes from the check, not this table.

ClusterBest-engine coverageEst. questions / mo
Endpoint Detection & Response17/1712,000–44,000
Identity & Access Management17/179,500–36,000
Cloud Security Posture Management17/176,500–24,000
SIEM & Security Operations17/177,000–26,000
Compliance & Audit Readiness16/165,500–21,000
Incident Response & Breach Readiness14/163,000–11,500

Volumes are an estimate, shown as a range. Illustrative estimate, not a keyword-tool export. Each cluster has ~16-17 seed buyer questions; cybersecurity is a broad, high-value commercial category — long-tail intent phrases run ~100–380 monthly searches each globally, one or two head terms (e.g. "best EDR platform") add ~2,000–7,500/mo, and an AI-assistant reformulation multiplier of ×2–4 accounts for the wider phrasing people use with an assistant. Ranges are rounded and widened. For a specific vendor, the real number comes from the check, not this table.

An open category is the easiest to win.

The check runs this same 100-question universe against your vendor’s name, per engine, and returns your AI Visibility Score plus the exact questions where a competitor — or no one — is being named.

Check your vendor’s AI visibility →

Explore the 100 questions

Every question, and exactly what each engine did with it — which vendors it named, and which sources it pulled from. Filter by cluster, search for your own name, or show only the questions no vendor has claimed.

100 of 100 questions·ChatGPTGeminiPerplexitynamed no tracked vendor
Get the unclaimed-questions list

The 1 questions no tracked vendor owns on any engine, with the sources AI cites instead — a ready-made content brief.

One email. No list-selling. Unsubscribe any time.

Where each engine gets its answers

The domains each engine actually pulled from, per engine — never blended. ChatGPT leans on Microsoft’s own documentation (learn.microsoft.com, 36 citations) and Gartner (27), with vendor-owned pages (CrowdStrike, Vanta, Okta, Splunk) filling out the rest. Perplexity draws almost entirely on independent research and review content — expertinsights.com, cybersecuritynews.com, Reddit, G2 and Gartner — rarely a vendor’s own site. Gemini names a vendor in 98 of 100 answers but, as in our other studies, its citations are thin and scattered — no domain cited more than 4 times across all 100 answers.

ChatGPT
learn.microsoft.com
36
gartner.com
27
crowdstrike.com
16
vanta.com
11
g2.com
9
microsoft.com
9
okta.com
5
splunk.com
5
Gemini
paloaltonetworks.com
4
gartner.com
4
crowdstrike.com
2
sentinelone.com
2
cynet.com
2
netwrix.com
2
safeguard.sh
2
sprinto.com
2
Perplexity
expertinsights.com
50
cybersecuritynews.com
38
reddit.com
37
sentinelone.com
36
learn.g2.com
35
gartner.com
33
worldmetrics.org
30
paloaltonetworks.com
27

Times a domain was cited across the 100 answers. Blue = a tracked vendor’s own site.

About this study

  • Single pass per engine. One sample per question per engine establishes direction; it does not average out run-to-run answer variance.
  • Snapshot in time. Collected September 14, 2026. AI engines change their answers week to week; this is not a trend line.
  • Conservative name matching. Short one-token vendor names (Wiz, Okta, Vanta…) require an exact whole-word match, so a slight undercount is possible — but it cannot explain a 1-of-100 gap.
  • ChatGPT and Gemini and Perplexity this run. Microsoft Copilot is not currently sampled; the measurement is identical when it is.

How to cite this study

Inserviss Labs, “Cybersecurity Vendors in AI Answers”, 2026. https://inserviss.app/insights/cybersecurity-vendor

To request the underlying data or discuss a vendor-specific analysis, contact igor@inserviss.app.

Be the vendor AI names.

The same measurement, run against your vendor’s name — per engine, question by question — with your score and the questions to claim first.

Run my free scan →
← More Inserviss research