CiteWorks Studio

Expel AI Market Strategy Report - Managed Detection and Response

Mark HuntleyBy Mark HuntleyFounder and CEO
10 minutes read

Key Takeaways

  • Expel appeared in 10.06% of qualified observations but converted that visibility into only 6.64% valid recommendation coverage.
  • The brand had 39 positive mentions, 8 neutral mentions, and no negative mentions, producing a net sentiment score of 0.8298.
  • Google AI Overviews was Expel's strongest platform, while Perplexity showed no visibility and Gemini showed mentions without recommendation conversion.
  • Expel's main gap is recommendation placement, with a 2.36% top-three rate that trails category leaders such as CrowdStrike Falcon and SentinelOne.

Answer Capsule

Expel holds meaningful presence in AI-generated recommendations for Managed Detection and Response but converts only a fraction of that visibility into actual recommendations. The benchmark shows Expel with 10.06% raw mention presence yet just 6.64% valid recommendation coverage in September 2026, a conversion gap that leaves the brand visible but rarely chosen. Its clearest strength is a positive framing profile with no negative mentions across 467 qualified observations. The clearest weakness is recommendation placement, with a 2.36% top-three rate that trails the category leaders by a wide margin. The biggest opportunity lies in converting existing positive references into shortlist positions by strengthening the evidence layer that AI systems draw on when forming recommendations.

Who This Report Is For

This report is for Expel's marketing, demand generation, and competitive intelligence leadership evaluating AI recommendation visibility in the managed detection and response category.

Report Card

Field

Value

Report type

AI Company Market Strategy Report

Target company

Expel

Category / market studied

Managed Detection and Response

Reporting month

September 2026

AI platforms tracked

6 (ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, AI Mode)

Public high-intent clusters

1

AI observations analyzed

467

Competitors tracked

10

Executive Summary

Expel's September 2026 benchmark profile shows a brand that is present in AI answers but not yet winning recommendation placement. The brand appeared in 10.06% of qualified observations, yet earned valid recommendations in only 6.64% of them. That gap between presence and recommendation conversion is the central finding of this report: Expel is being mentioned, but AI systems are not consistently choosing it when buyers ask for managed detection and response recommendations.

The sentiment picture is more encouraging. Expel recorded 39 positive mentions, 8 neutral mentions, and zero negative mentions across 467 qualified observations, producing a net sentiment score of 0.8298. No tracked brand in the category recorded negative framing, but Expel's positive-to-neutral ratio is healthy and suggests the brand is referenced favorably when it does appear.

Expel's strongest cluster is the only one with qualified observations in this public dataset: Best MDR Services, Discovery and Evaluation. All 467 qualified observations fell into this brand recommendation cluster, meaning the benchmark captures how AI systems recommend providers in direct answer contexts. The weakest area is recommendation placement, where Expel's 2.36% top-three rate and 0.21% rank-one rate place it in the lower tier of the tracked field.

The strongest platform signal for Expel is Google AI Overviews, where the brand achieved its highest positive visibility rate at 17.00% and its only rank-one recommendation in the dataset. The clearest platform gap is Perplexity, where Expel recorded zero mentions across 26 observations despite competitors appearing regularly. ChatGPT and Copilot show modest presence, while Gemini shows presence without any valid recommendation conversion.

The benchmark evidence suggests Expel has a narrow but real recommendation pocket in Google AI Overviews. The challenge is that this strength does not yet translate into competitive visibility at the decision moment, where CrowdStrike Falcon and SentinelOne dominate top-three placement.

What Expel Is Winning

Questions This Section Answers

  • What are Expel's strongest evidence-backed results in AI recommendations?
  • Where does Expel's positive framing profile place it relative to competitors?
  • On which platform does Expel show its strongest recommendation pocket?

Expel's clearest evidence-backed win is its positive framing profile. The brand recorded zero negative mentions across all platforms and clusters in September 2026, with a net sentiment score of 0.8298. This places Expel above several competitors, including Red Canary at 0.7170 and eSentire at 0.7368, and indicates that when AI systems reference Expel, they do so favorably.

A second win is Expel's performance in Google AI Overviews. The brand achieved a 16.00% valid recommendation coverage rate on that platform, its strongest platform-level result, with a 6.00% top-three rate and a 1.00% rank-one rate. This is the only platform where Expel secured a rank-one recommendation in the dataset, suggesting the brand's evidence layer is at least partially effective in AI Overviews contexts.

Expel also shows a narrow but meaningful recommendation pocket in Google AI Mode, where it reached 9.82% valid recommendation coverage. While below the category leaders, this indicates Expel can convert presence into recommendations on Google surfaces more effectively than on other platforms.

Where Expel Has the Clearest AI Visibility Gaps

Questions This Section Answers

  • How does Expel's presence-to-recommendation conversion compare with category leaders?
  • What platform-level absence or non-conversion gaps does Expel show?

Expel's most significant gap is the conversion of presence into recommendation placement. The brand's 10.06% raw mention presence rate drops to 6.64% valid recommendation coverage, and then falls further to 2.36% top-three placement. This pattern shows Expel is being referenced in AI answers but is not being positioned as a recommended option when buyers ask for managed detection and response providers.

The comparison to category leaders makes the gap concrete. CrowdStrike Falcon holds a 48.82% top-three rate and a 36.19% rank-one rate, while SentinelOne holds a 37.26% top-three rate. Expel's 2.36% top-three rate places it alongside Red Canary and Rapid7 InsightIDR in the lower tier, far below the brands that dominate recommendation placement.

Perplexity represents a complete absence gap. Expel recorded zero mentions across 26 Perplexity observations in September 2026, while SentinelOne appeared in 100% of those observations and CrowdStrike Falcon in 96.15%. This platform-level absence suggests Expel's public evidence layer is not retrievable or not being synthesized on Perplexity.

Gemini shows a different gap pattern: presence without recommendation conversion. Expel appeared in 5.95% of Gemini observations but earned zero valid recommendations. The brand is visible on Gemini but is not being recommended, indicating a framing or evidence problem rather than a discoverability problem.

Biggest Opportunity

Questions This Section Answers

  • Where should Expel focus to convert positive references into recommendation placement?

Expel's clearest opportunity is converting its positive reference profile into recommendation placement on Google surfaces. The brand already achieves its strongest recommendation outcomes in Google AI Overviews and Google AI Mode, and its zero-negative sentiment profile provides a foundation that AI systems can draw on favorably. The path forward is to strengthen the specific evidence sources that support recommendation-stage answers on these platforms, particularly for prompts where Expel is currently mentioned but not shortlisted. If Expel can move from being referenced to being recommended in even a modest share of the prompts where it already appears, the brand's top-three rate would improve meaningfully without requiring a broad increase in raw visibility.

Competitive Landscape

Questions This Section Answers

  • Where does Expel sit in the competitive table for top-three and rank-one placement?
  • How does Expel's sentiment profile compare with brands at the same recommendation tier?

CrowdStrike Falcon and SentinelOne hold dominant recommendation-stage strength in the managed detection and response category, with CrowdStrike Falcon leading on both top-three and rank-one placement. Expel sits in the lower tier alongside Red Canary and Rapid7 InsightIDR, with meaningful presence but limited recommendation conversion.

Brand

Top-3 rate

Rank-1 rate

Avg recommended rank

Sentiment

CrowdStrike Falcon

48.82%

36.19%

1.4979

0.8231

SentinelOne

37.26%

2.78%

2.5122

0.8015

Sophos Intercept X

14.78%

1.28%

3.694

0.8952

Arctic Wolf

13.06%

7.07%

1.9104

0.8

Rapid7 InsightIDR

2.36%

0.21%

4.3056

0.7538

Red Canary

2.36%

0.21%

3.9667

0.717

Expel

2.36%

0.21%

3.92

0.8298

eSentire

2.14%

0.00%

3.8667

0.7368

Secureworks Taegis

0.43%

0.00%

5.3333

0.7391

Deepwatch

0.00%

0.00%

5.1667

0.875

Average recommended rank covers rank-eligible recommendations only.

Expel's position in the table shows a brand with the same top-three rate as Rapid7 InsightIDR and Red Canary but a stronger sentiment profile than either. The brand's average recommended rank of 3.92 indicates that when Expel does earn a recommendation, it tends to appear outside the top three, limiting its visibility at the decision moment.

Prompt Evidence

Google AI Overviews / Best MDR Services Discovery Prompt: "managed security solutions" Result: Expel appeared in the response with positive framing and earned a recommendation, one of the brand's strongest outcomes in the dataset.

Perplexity / Best MDR Services Discovery Prompt: "managed detection and response" Result: Expel was absent from the response entirely, while competitors including SentinelOne and CrowdStrike Falcon were recommended.

Gemini / Best MDR Services Discovery Prompt: "cybersecurity companies" Result: Expel was mentioned in a positive context but received no valid recommendation, showing presence without recommendation conversion.

ChatGPT / Best MDR Services Discovery Prompt: "managed security solutions" Result: Expel appeared in a limited number of responses with mixed framing, earning a small number of recommendations but no rank-one placement.

What CiteWorks Studio Would Do Next

Phase 1: AI Market Discovery Audit Map the specific prompts where Expel appears but is not recommended, identifying which competitors capture the recommendations Expel loses.

Phase 2: Recommendation Readiness Plan Prioritize the Google surfaces where Expel already shows recommendation strength and build a plan to extend that pattern to ChatGPT, Gemini, and Perplexity.

Phase 3: Owned Answer Layer Buildout Develop owned content that answers the specific discovery and evaluation prompts where Expel is currently mentioned but not shortlisted.

Phase 4: Citation / Authority Layer Development Strengthen the external evidence sources that AI systems can retrieve and synthesize, focusing on the platforms where Expel has presence gaps.

Phase 5: Monthly AI Visibility and Recommendation Tracking Track Expel's presence-to-recommendation conversion monthly to measure whether the gap between mentions and recommendations is closing.

Why This Matters

Questions This Section Answers

  • Why does recommendation placement matter more than mere visibility for Expel?
  • What kind of correction should Expel pursue instead of broader visibility?

For buyers researching managed detection and response providers, AI-generated answers increasingly shape which brands enter the consideration set. Expel's current profile shows a brand that is known and referenced favorably but is not being positioned as a recommended option when buyers ask for provider suggestions. That distinction matters because recommendation placement, not mere presence, is what puts a brand on the buyer's shortlist.

The next move for Expel is not broader visibility. It is targeted correction of the prompt, page, and citation layers that determine whether AI systems recommend the brand or mention it only as context. Closing the gap between Expel's 10.06% presence rate and its 2.36% top-three rate would represent a meaningful shift in how AI systems position the brand at the decision moment.

Core Metrics

Metric

Value

Mentions

47

Valid recommendations

31

Top 3 recommendation count

11

Rank #1 recommendation count

1

Average recommended rank

3.92

Positive mentions

39

Neutral mentions

8

Negative mentions

0

Raw mention presence rate

10.06%

Valid recommendation coverage

6.64%

Top 3 recommendation rate

2.36%

Rank #1 recommendation rate

0.21%

Net sentiment score

0.8298

Strongest cluster by recommendation behavior

Best MDR Services, Discovery and Evaluation

Strongest platform by recommendation behavior

Google AI Overviews

Sentiment Score

Sentiment Score = (positive mentions x 1 + neutral mentions x 0 + negative mentions x -1) / total mentions

For Expel, this calculation is (39 x 1 + 8 x 0 + 0 x -1) / 47, producing a net sentiment score of 0.8298.

This score matters because unclassified mention counts are misleading. Expel's 47 total mentions look modest on their own, but the classification reveals that 83% of those mentions are positive and none are negative. Share of voice is a diagnostic metric, not a business KPI; knowing that Expel appears in 10.06% of observations is less useful than knowing how it appears. A positive recommendation, neutral reference, cautionary mention, and competitor-displaced mention are not equal, and counting all mentions as wins is bad measurement. Classified sentiment is required before interpreting AI visibility, because the same presence rate can reflect very different competitive positions depending on how the brand is framed.

Sentiment by Platform

Platform

Mentions

Positive

Neutral

Negative

Sentiment Score

Readout

ChatGPT

8

4

4

0

0.5

Present, but not recommendation-led

Copilot

3

2

1

0

0.6667

Positive, but sample too small

Gemini

5

4

1

0

0.8

Present as context, not recommendation

Perplexity

0

0

0

0

N/A

No public presence in this packet

AI Overviews

18

17

1

0

0.9444

Strongest public recommendation signal

AI Mode

13

12

1

0

0.9231

Positive, but sample too small

Methodology

  1. This report is a benchmark-based analysis of Expel's AI recommendation visibility in the Managed Detection and Response category, produced from the LLM Authority Index AI Market Discovery Index and supporting metrics aggregation. It is not a client implementation case study.
  2. The reporting window is September 2026, with baseline comparisons drawn from July 2026 and August 2026 where relevant.
  3. Six AI/search surface families were tracked: ChatGPT, Copilot, Gemini, Perplexity, AI Overviews, and AI Mode.
  4. The September 2026 run began from 800 prompt-surface observations, of which 593 were unique questions and 569 were relevant to the vertical.
  5. After relevance filtering and qualification, 467 qualified observations formed the public benchmark denominator for brand-level metrics.
  6. The competitor universe included 10 tracked brands: Arctic Wolf, CrowdStrike Falcon, Deepwatch, eSentire, Expel, Rapid7 InsightIDR, Red Canary, Secureworks Taegis, SentinelOne, and Sophos Intercept X.
  7. All qualified observations fell into the Brand Recommendation buyer-intent class, representing discovery and consideration intent. No qualified observations were recorded in Pricing & Value or Multi-Brand Comparison classes.
  8. Stage 0 extraction retained the query, AI/search surface, answer, brand outcome, recommendation placement, sentiment, and, where exposed, citations or attributable evidence sources.
  9. A mention is defined as any appearance of a tracked brand within a qualified observation, regardless of whether the brand is recommended.
  10. A valid recommendation is defined as a positive recommendation of a tracked brand within a qualified observation, with rank-eligible recommendations receiving position credit from 1 to 10.
  11. The public benchmark does not measure market share, sales attribution, organic-search ranking positions, social mention volume, private channels, or causality from metric movement alone.
  12. Small-count brands, including Expel at 31 valid recommendations, warrant careful interpretation of platform-level movement. One month of movement should not yet be treated as a trend until additional measurements confirm the direction.

See How AI Is Recommending Your Brand

The public benchmark shows where Expel stands in AI-generated recommendations, but the aggregate percentages cannot identify the specific prompts, competitors, or sources driving the gap between presence and recommendation. A company-level AI visibility audit maps those patterns into a prioritized strategy for converting Expel's positive references into shortlist positions.

/ Take the next step

Want to Understand Your AI Citation Footprint?

We start every engagement with a full audit of how AI systems reference your brand today.

Measurable, Repeatable Programme

Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge

Citation Architecture Review

Identify which high-authority community sources are and aren't working in your favour across AI platforms.

AI Visibility Audit

Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.

/ Learn More

Understanding AI search visibility.

AI search experiences create answers by pulling information from many places online and summarizing it into a single response.

What Is AI Citation Intelligence?
AI citation intelligence is the process of measuring where AI platforms source their information and how frequently a brand is mentioned or referenced in AI-generated responses. Because LLMs synthesize across multiple sources, the sites and brands that appear repeatedly tend to influence how a topic or company is framed. This practice focuses on identifying which sources shape AI outputs and tracking brand visibility across different AI systems.
What Is Citation Architecture?
Citation architecture describes the set of sources that consistently inform how AI systems talk about a brand, product, or topic. LLMs draw from websites, articles, forums, and public discussion, and the sources they rely on most often become the backbone of their answers. Building strong citation architecture means ensuring that accurate, credible, high authority sources are the ones most likely to shape the way AI tools summarize and recommend a brand.
What Is Generative Engine Optimization?
Generative engine optimization (GEO) is the practice of improving the chances that AI systems use and cite your brand or content when generating answers. While traditional SEO is centered on ranking pages in search results, GEO focuses on how LLMs retrieve, interpret, and combine information when responding to a question. The objective is to strengthen the content and sources AI systems rely on, so your brand is treated as a trusted reference in AI responses.
What Is AI Share of Voice?
AI share of voice tracks how often a brand appears in AI-generated answers compared with competitors in the same category. It reflects visibility across AI platforms such as ChatGPT, Gemini, Claude, and Perplexity. Monitoring AI share of voice helps organizations see whether AI systems consistently include and recommend their brand for key queries or whether competitor brands are showing up more often.

About The Author

Mark Huntley

Mark Huntley

Founder and CEO

Mark Huntley, J.D. is founder of CiteWorks Studio, a strategic advisory focused on visibility, authority, and recommendation presence in AI-shaped search environments. His work centers on embedding-level GEO, vector optimization, and cosine gap engineering — helping brands align their digital presence with the retrieval systems that increasingly shape discovery, interpretation, and choice.

VIEW ALL CASE STUDIESREQUEST AN AI VISIBILITY AUDIT