How AI Search Is Recommending Cybersecurity Services: Monthly Trends
This analysis is based on the source benchmark: Cybersecurity Services: 2026 AI Market Discovery Index
Key Takeaways
- CrowdStrike led August 2026 valid recommendation coverage at 53.5%, ahead of Palo Alto Networks at 47.6%.
- Most large month-over-month gains and declines were caused by a tracking change from product names to parent-company names, not by underlying recommendation shifts.
- Arctic Wolf was the clearest organic mover, with valid recommendation coverage falling 8.1 points from July to August.
- Recommendation-shaped answers increased from 33.9% to 40.8%, while the qualified benchmark set declined from 404 observations to 338.
Executive Summary
CrowdStrike is the category leader in AI search recommendations for cybersecurity services, with valid recommendation coverage of 53.5% in August 2026, 5.9 points ahead of Palo Alto Networks at 47.6%. This leadership picture reflects a benchmark instrument update: the tracked brand set shifted from product-specific names (CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos Intercept X, Rapid7 InsightIDR, Secureworks Taegis) to parent-company names (CrowdStrike, Palo Alto Networks, Sophos, Rapid7, Secureworks), with Google Chronicle giving way to Mandiant (Google).
The largest upward mover was CrowdStrike, rising from 0.0% baseline coverage in July 2026 to 53.5% in August 2026. Palo Alto Networks moved up 47.6 points from 0.0% to 47.6%, and Sophos rose 26.3 points from 0.0% to 26.3%. These moves track closely with the switch from measuring product lines to measuring parent companies, which redistributes recommendation credit across the full answer set under new tracked names.
The sharpest declines, including CrowdStrike Falcon (down 53.7 points, from 53.7% to 0.0%), Sophos Intercept X (down 34.4 points, from 34.4% to 0.0%), and Palo Alto Cortex XDR (down 25.0 points, from 25.0% to 0.0%), pair one-for-one with the naming change rather than a loss of recommendation credit. The underlying vendors remain strongly represented, under different tracked names.
Against July 2026, the category shows movement concentrated in the brand-identity shift. The two names that carried across the instrument change, Optiv (1.0% to 1.2%) and Trustwave (1.5% to 1.5%), illustrate the category's underlying quietness outside the renamed cluster. Arctic Wolf is the clearest organic mover in the dataset, falling 8.1 points from 17.3% to 9.2%, a change not explained by the naming shift.
Each monthly run begins with 750 prompt-surface observations (475 unique questions) in July 2026, and the August 2026 run began with a comparable prompt universe. Of the July prompts, 750 mentioned a tracked brand or competitor; 500 were relevant and 250 were irrelevant. The public metrics use the 404 observations that survived both qualification stages in July 2026, and 338 observations in August 2026.
AI recommendation trend
valid recommendation coverage, Jul 2026 to Aug 2026
- CrowdStrike+53.5% · beyond normal variationJul 20260.0%Aug 202653.5%
- Palo Alto Networks+47.6% · beyond normal variationJul 20260.0%Aug 202647.6%
- Sophos+26.3% · beyond normal variationJul 20260.0%Aug 202626.3%
- Arctic Wolf-8.1% · beyond normal variationJul 202617.3%Aug 20269.2%
- Rapid7+8.6% · beyond normal variationJul 20260.0%Aug 20268.6%
- Mandiant (Google)+8.3% · beyond normal variationJul 20260.0%Aug 20268.3%
- Secureworks+4.7% · beyond normal variationJul 20260.0%Aug 20264.7%
- Trustwaveno changeJul 20261.5%Aug 20261.5%
- Optiv+0.2%Jul 20261.0%Aug 20261.2%
- CrowdStrike Falcon-53.7% · beyond normal variationJul 202653.7%Aug 20260.0%
- Deepwatch-1.2% · beyond normal variationJul 20261.2%Aug 20260.0%
- Google Chronicle-2.2% · beyond normal variationJul 20262.2%Aug 20260.0%
- Palo Alto Cortex XDR-25.0% · beyond normal variationJul 202625.0%Aug 20260.0%
- Rapid7 InsightIDR-9.9% · beyond normal variationJul 20269.9%Aug 20260.0%
- Secureworks Taegis-2.0% · beyond normal variationJul 20262.0%Aug 20260.0%
- Sophos Intercept X-34.4% · beyond normal variationJul 202634.4%Aug 20260.0%
Key Findings
Signal | August 2026 finding |
|---|---|
Category leader | CrowdStrike leads valid recommendation coverage at 53.5%, 5.9 points ahead of Palo Alto Networks |
Strongest upward mover | CrowdStrike rose 53.5 points from 0.0% baseline to 53.5% current coverage |
Sharpest decliner (instrument-linked) | CrowdStrike Falcon fell 53.7 points from 53.7% baseline to 0.0% current coverage |
Brand identity shift | Product-line tracked names (CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos Intercept X, Rapid7 InsightIDR, Secureworks Taegis, Google Chronicle) moved to parent-company names in the August 2026 run |
Stable names | Trustwave held at 1.5% coverage across both months; Optiv moved from 1.0% to 1.2% |
Recommendation-shaped answers | 40.8% of August 2026 observations were recommendation-shaped, up from 33.9% in July 2026 |
Benchmark Context
The benchmark separates the raw collection universe from the qualified analysis set. Brand-level recommendation percentages are calculated within the qualified benchmark set.
Research stage | Jul 2026 | Aug 2026 | What it represents |
|---|---|---|---|
Source prompt-surface observations collected | 750 | 750 | Total prompt-surface observations across the defined AI/search surface universe |
Unique questions | 475 | 475 | Distinct questions after de-duplication |
Brand / competitor mentions | 750 | 750 | Prompts mentioning a tracked brand or competitor |
Relevant prompts | 500 | 500 | Prompts relevant to the cybersecurity services category |
Irrelevant prompts | 250 | 250 | Prompts outside the category scope |
Qualified benchmark observations | 404 | 338 | Public denominator after both qualification stages |
Qualified surface breadth | 6 | 6 | AI surface families with at least one qualified observation |
The qualified denominator moved from 404 to 338 observations between the two months, and the two months also carry different tracked platform IDs (rolling up to the same six canonical AI surface families in both periods). The metrics below summarize category-wide movement across that qualified set, independent of the individual brand-naming changes covered later in this report.
Benchmark-Level Metrics
Metric | Jul 2026 | Aug 2026 | Change |
|---|---|---|---|
Qualified observations | 404 | 338 | Down 66 |
Companies tracked | 10 | 10 | No change |
Recommendation-shaped answer share | 33.9% | 40.8% | Up 6.9 points |
Valid recommendation shortlist share | 53.5% | 60.7% | Up 7.2 points |
Category leader by coverage | CrowdStrike Falcon | CrowdStrike | Leadership carried across the naming shift |
AI Recommendation Trend
The top of the category is now a two-brand cluster with a single-digit gap, and the ranking changed because the benchmark tracks parent companies rather than product lines.
Brand | Jul 2026 | Aug 2026 | Movement | Aug 2026 rank |
|---|---|---|---|---|
Arctic Wolf | 17.3% | 9.2% | Down 8.1 points | 4th |
CrowdStrike | 0.0% | 53.5% | Up 53.5 points | 1st |
CrowdStrike Falcon | 53.7% | 0.0% | Down 53.7 points | 11th |
Deepwatch | 1.2% | 0.0% | Down 1.2 points | 10th |
Google Chronicle | 2.2% | 0.0% | Down 2.2 points | 11th |
Mandiant (Google) | 0.0% | 8.3% | Up 8.3 points | 6th |
Optiv | 1.0% | 1.2% | Up 0.2 points | 9th |
Palo Alto Cortex XDR | 25.0% | 0.0% | Down 25.0 points | 11th |
Palo Alto Networks | 0.0% | 47.6% | Up 47.6 points | 2nd |
Rapid7 | 0.0% | 8.6% | Up 8.6 points | 5th |
Rapid7 InsightIDR | 9.9% | 0.0% | Down 9.9 points | 11th |
Secureworks | 0.0% | 4.7% | Up 4.7 points | 7th |
Secureworks Taegis | 2.0% | 0.0% | Down 2.0 points | 11th |
Sophos | 0.0% | 26.3% | Up 26.3 points | 3rd |
Sophos Intercept X | 34.4% | 0.0% | Down 34.4 points | 11th |
Trustwave | 1.5% | 1.5% | No change | 8th |
The category-level change comes overwhelmingly from the instrument's brand-naming shift rather than from organic movement in recommendation behavior. Several brands moved beyond normal month-to-month variation, but those moves pair one-for-one with the switch from product-line names to parent-company names, which redistributes the same underlying recommendation credit across newly tracked entities. Arctic Wolf's decline is the one movement in this table that is not explained by the naming shift.
What Changed This Month
CrowdStrike: New Leader Under a Parent-Company Name
CrowdStrike's valid recommendation coverage moved from 0.0% in July 2026 to 53.5% in August 2026. The prior month's coverage for CrowdStrike Falcon was 53.7%, which means the parent-company name now captures essentially the same recommendation credit the product line held before. The brand was present in 82.2% of August 2026 observations, with a top-three recommendation rate of 47.9% and a rank-one rate of 27.5% across 162 top-three placements and 93 rank-one placements.
CrowdStrike was already the most recommended vendor in July under the Falcon product name, and it remains so in August under the corporate name. The current benchmark records this as a naming-driven leadership carryover rather than a new competitive gain.
Highest-priority diagnostic: whether the parent-company name captures recommendation credit in prompts where the product line was previously invisible, or whether the same set of prompts is now simply credited to the parent name.
Palo Alto Networks: Close Second, Not a Simple Rename
Palo Alto Networks rose from 0.0% baseline to 47.6% valid recommendation coverage in August 2026, while Palo Alto Cortex XDR fell from 25.0% to 0.0%. The gap between CrowdStrike and Palo Alto Networks is 5.9 points. Palo Alto Networks was present in 76.3% of August 2026 observations, with a top-three rate of 37.6% and a rank-one rate of 18.1% across 127 top-three placements and 61 rank-one placements.
Palo Alto Networks' parent-company coverage is higher than its product-line coverage was in July, which the data cannot fully attribute to the naming change alone since the corporate name appears to capture additional recommendation credit beyond the Cortex XDR product line.
Highest-priority diagnostic: which specific product names within Palo Alto Networks' portfolio are driving the parent-company credit, and which prompts route to the corporate name versus the product name.
Sophos: Third Place With a Lower Parent-Company Total
Sophos moved from 0.0% baseline to 26.3% valid recommendation coverage in August 2026, while Sophos Intercept X fell from 34.4% to 0.0%. The parent-company name captured less credit than the Intercept X product line did in July. Sophos was present in 36.7% of August observations, with a top-three rate of 10.7% and a rank-one rate of 1.5% across 36 top-three placements and 5 rank-one placements.
Unlike CrowdStrike and Palo Alto Networks, Sophos' parent-company coverage is lower than its flagship product's July coverage, meaning some recommendation credit that previously attached to Intercept X does not appear under the corporate name in this dataset.
Highest-priority diagnostic: whether the gap represents credit spread across the broader Sophos brand or credit attached to other Sophos products not tracked in July.
Arctic Wolf: The Clearest Organic Decliner
Arctic Wolf's valid recommendation coverage fell from 17.3% in July 2026 to 9.2% in August 2026, a drop of 8.1 points that exceeds the significance threshold applied to this brand. Its raw mention presence fell from 24.5% to 13.0%, and its top-three rate declined from 8.9% to 5.3%. Arctic Wolf held 31 valid recommendations in August 2026, down from 70 in July, with 18 top-three placements and 6 rank-one placements.
Arctic Wolf's decline is not explained by a naming shift, making it the clearest organic movement in the category this month. The brand remains present and positively framed, with a net sentiment score of 0.8 in August 2026, but both its visibility and its recommendation share contracted.
Highest-priority diagnostic: which prompt categories and AI surfaces drove the visibility loss, and whether the benchmark can distinguish that loss from measurement effects tied to the broader instrument change.
Instrument Note: The July-to-August Naming Shift
The benchmark's tracked brand set changed between July 2026 and August 2026. Six product-line names (CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos Intercept X, Rapid7 InsightIDR, Secureworks Taegis, Google Chronicle) were replaced by parent-company names (CrowdStrike, Palo Alto Networks, Sophos, Rapid7, Secureworks, Mandiant (Google)). Pairwise movements between these paired names are best read as effects of the naming change rather than independent gains or losses. The two names that carried across the change, Optiv and Trustwave, were both stable.
Highest-priority diagnostic: whether future months hold the parent-company names as the stable tracking set, and whether the product-line names re-enter as separately tracked entities.
Buyer-Intent Interpretation
Buyer-intent cluster | What it captures | Strategic question |
|---|---|---|
Brand Recommendation | Prompts asking which cybersecurity vendor to choose for a given need | Which brand does the AI surface recommend first, and how often does it appear in the top three? |
Pricing & Value | Prompts asking about cost, pricing models, or value for money | Which brands are surfaced in pricing discussions, and in what frame? |
Multi-Brand Comparison | Prompts asking to compare two or more vendors head-to-head | Which brand wins the comparison, and which attributes drive the recommendation? |
In August 2026, the qualified observations fell entirely into the Brand Recommendation cluster, with no qualified observations in the Pricing & Value or Multi-Brand Comparison clusters. The public benchmark therefore answers the "which vendor" question well, but it cannot answer commercial questions about price positioning, value perception, or head-to-head competitive outcomes. Those questions require a company-level audit that goes beneath the aggregate benchmark.
Brand Opportunity Summary
Brand | Aug 2026 coverage | Current signal | Highest-priority diagnostic |
|---|---|---|---|
Arctic Wolf | 9.2% | Coverage down 8.1 points; still visible at 13.0% mention presence with 31 valid recommendations | Which prompt categories and surfaces drove the visibility loss |
CrowdStrike | 53.5% | Category leader; 82.2% presence; 27.5% rank-one rate | Whether the parent name captures credit the product line missed |
CrowdStrike Falcon | 0.0% | Name retired from tracked set; credit moved to CrowdStrike | Whether product-line credit is fully captured by the parent name |
Deepwatch | 0.0% | Zero valid recommendations in August 2026; 1 mention in 338 observations | Which prompts mention Deepwatch at all and why none convert to recommendations |
Google Chronicle | 0.0% | Name replaced by Mandiant (Google); no August observations | Whether Mandiant captures the Chronicle credit |
Mandiant (Google) | 8.3% | Newly tracked; 10.9% presence; no rank-one placements | Which threat-intelligence prompts drive Mandiant recommendations |
Optiv | 1.2% | Stable; 4 valid recommendations; no rank-one placements | Which niche prompts produce the small recommendation count |
Palo Alto Cortex XDR | 0.0% | Name retired from tracked set; credit moved to Palo Alto Networks | Whether parent-company credit exceeds product-line coverage |
Palo Alto Networks | 47.6% | Second place; 76.3% presence; 18.1% rank-one rate | Which product portfolio names drive the parent-company credit |
Rapid7 | 8.6% | Newly tracked; 29 valid recommendations; 2 rank-one placements | Whether InsightIDR credit is fully captured under Rapid7 |
Rapid7 InsightIDR | 0.0% | Name retired from tracked set; credit moved to Rapid7 | Whether product-line recommendation patterns survive the rename |
Secureworks | 4.7% | Newly tracked; 16 valid recommendations; 5 rank-one placements | Why rank-one placements outpace top-three rate |
Secureworks Taegis | 0.0% | Name retired from tracked set; credit moved to Secureworks | Whether Taegis-specific prompts route to the parent name |
Sophos | 26.3% | Third place; 36.7% presence; 1.5% rank-one rate | Why parent-company credit trails the Intercept X product line |
Sophos Intercept X | 0.0% | Name retired from tracked set; credit moved to Sophos | Whether the parent name captures the full product-line credit |
Trustwave | 1.5% | Flat across both months; 5 valid recommendations; no rank-one placements | Which niche service prompts keep Trustwave visible |
The benchmark identifies where attention is warranted across the tracked brand set; a company-level analysis is needed to explain why those patterns exist and what drives them.
Evidence Behind the Benchmark
The aggregate metrics are built from prompt-level observations capturing the query, the AI surface, the recommendation outcome, the rank, the sentiment, and the citations where exposed. Company-level analysis can go deeper into prompt, competitor, surface, and evidence patterns. Presence in a benchmark answer is not automatically evidence of causation.
About This Benchmark
This report is part of the CiteWorks Studio AI Industry Market Discovery research program.
- AI Industry Market Discovery
- AI Industry Market Discovery Methodology
- AI Industry Market Discovery Metrics
- AI Industry Market Discovery Standards
Report-Specific Interpretation Notes
- The August 2026 brand set changed from product-line names to parent-company names; pairwise movements between the old and new names track closely with that naming change rather than independent organic shifts.
- The qualified denominator (338 observations in August 2026, 404 in July 2026) differs from the raw collection universe (750 prompt-surface observations); percentages are calculated within the qualified set.
- With 16 tracked brand names across two months, several carry small observation counts; treat single-digit coverage figures as directional signals, not definitive rankings.
- Movement between months identifies changes worth investigating; the data describes the output distribution, not its cause.
Next Step
The Public Benchmark Shows Where a Brand Is Winning or Losing. A Company-Level Audit Shows Why.
The aggregate percentage answers which brands AI systems recommend, but not why. Beneath CrowdStrike's 53.5% coverage sit questions about which high-intent prompts it wins, which competitor takes the recommendation when it loses, what attributes AI associates with each option, and which external sources shape those answers. The same questions apply to Arctic Wolf's 8.1-point decline and to the gap between Sophos' parent-company coverage and its product-line coverage.
A company-specific AI visibility audit maps those prompt, surface, competitor, ranking, sentiment, and evidence-source patterns into a prioritized visibility strategy. It identifies the highest-intent prompts where a brand is losing, the competitor that wins in its place, and the external sources that drive the AI's answer.
/ Take the next step
Want to Understand Your AI Citation Footprint?
We start every engagement with a full audit of how AI systems reference your brand today.
Measurable, Repeatable Programme
Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge
Citation Architecture Review
Identify which high-authority community sources are and aren't working in your favour across AI platforms.
AI Visibility Audit
Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.
/ Learn More
Understanding AI search visibility.
AI search experiences create answers by pulling information from many places online and summarizing it into a single response.


