CiteWorks Studio

How AI Search Is Recommending Cybersecurity Services: Monthly Trends

Mark HuntleyBy Mark HuntleyFounder and CEO
10 minutes read

Key Takeaways

  • CrowdStrike led August 2026 valid recommendation coverage at 53.5%, ahead of Palo Alto Networks at 47.6%.
  • Most large month-over-month gains and declines were caused by a tracking change from product names to parent-company names, not by underlying recommendation shifts.
  • Arctic Wolf was the clearest organic mover, with valid recommendation coverage falling 8.1 points from July to August.
  • Recommendation-shaped answers increased from 33.9% to 40.8%, while the qualified benchmark set declined from 404 observations to 338.

Executive Summary

CrowdStrike is the category leader in AI search recommendations for cybersecurity services, with valid recommendation coverage of 53.5% in August 2026, 5.9 points ahead of Palo Alto Networks at 47.6%. This leadership picture reflects a benchmark instrument update: the tracked brand set shifted from product-specific names (CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos Intercept X, Rapid7 InsightIDR, Secureworks Taegis) to parent-company names (CrowdStrike, Palo Alto Networks, Sophos, Rapid7, Secureworks), with Google Chronicle giving way to Mandiant (Google).

The largest upward mover was CrowdStrike, rising from 0.0% baseline coverage in July 2026 to 53.5% in August 2026. Palo Alto Networks moved up 47.6 points from 0.0% to 47.6%, and Sophos rose 26.3 points from 0.0% to 26.3%. These moves track closely with the switch from measuring product lines to measuring parent companies, which redistributes recommendation credit across the full answer set under new tracked names.

The sharpest declines, including CrowdStrike Falcon (down 53.7 points, from 53.7% to 0.0%), Sophos Intercept X (down 34.4 points, from 34.4% to 0.0%), and Palo Alto Cortex XDR (down 25.0 points, from 25.0% to 0.0%), pair one-for-one with the naming change rather than a loss of recommendation credit. The underlying vendors remain strongly represented, under different tracked names.

Against July 2026, the category shows movement concentrated in the brand-identity shift. The two names that carried across the instrument change, Optiv (1.0% to 1.2%) and Trustwave (1.5% to 1.5%), illustrate the category's underlying quietness outside the renamed cluster. Arctic Wolf is the clearest organic mover in the dataset, falling 8.1 points from 17.3% to 9.2%, a change not explained by the naming shift.

Each monthly run begins with 750 prompt-surface observations (475 unique questions) in July 2026, and the August 2026 run began with a comparable prompt universe. Of the July prompts, 750 mentioned a tracked brand or competitor; 500 were relevant and 250 were irrelevant. The public metrics use the 404 observations that survived both qualification stages in July 2026, and 338 observations in August 2026.

AI recommendation trend

valid recommendation coverage, Jul 2026 to Aug 2026

  • CrowdStrike+53.5% · beyond normal variation
    Jul 20260.0%
    Aug 202653.5%
  • Palo Alto Networks+47.6% · beyond normal variation
    Jul 20260.0%
    Aug 202647.6%
  • Sophos+26.3% · beyond normal variation
    Jul 20260.0%
    Aug 202626.3%
  • Arctic Wolf-8.1% · beyond normal variation
    Jul 202617.3%
    Aug 20269.2%
  • Rapid7+8.6% · beyond normal variation
    Jul 20260.0%
    Aug 20268.6%
  • Mandiant (Google)+8.3% · beyond normal variation
    Jul 20260.0%
    Aug 20268.3%
  • Secureworks+4.7% · beyond normal variation
    Jul 20260.0%
    Aug 20264.7%
  • Trustwaveno change
    Jul 20261.5%
    Aug 20261.5%
  • Optiv+0.2%
    Jul 20261.0%
    Aug 20261.2%
  • CrowdStrike Falcon-53.7% · beyond normal variation
    Jul 202653.7%
    Aug 20260.0%
  • Deepwatch-1.2% · beyond normal variation
    Jul 20261.2%
    Aug 20260.0%
  • Google Chronicle-2.2% · beyond normal variation
    Jul 20262.2%
    Aug 20260.0%
  • Palo Alto Cortex XDR-25.0% · beyond normal variation
    Jul 202625.0%
    Aug 20260.0%
  • Rapid7 InsightIDR-9.9% · beyond normal variation
    Jul 20269.9%
    Aug 20260.0%
  • Secureworks Taegis-2.0% · beyond normal variation
    Jul 20262.0%
    Aug 20260.0%
  • Sophos Intercept X-34.4% · beyond normal variation
    Jul 202634.4%
    Aug 20260.0%

Key Findings

Signal

August 2026 finding

Category leader

CrowdStrike leads valid recommendation coverage at 53.5%, 5.9 points ahead of Palo Alto Networks

Strongest upward mover

CrowdStrike rose 53.5 points from 0.0% baseline to 53.5% current coverage

Sharpest decliner (instrument-linked)

CrowdStrike Falcon fell 53.7 points from 53.7% baseline to 0.0% current coverage

Brand identity shift

Product-line tracked names (CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos Intercept X, Rapid7 InsightIDR, Secureworks Taegis, Google Chronicle) moved to parent-company names in the August 2026 run

Stable names

Trustwave held at 1.5% coverage across both months; Optiv moved from 1.0% to 1.2%

Recommendation-shaped answers

40.8% of August 2026 observations were recommendation-shaped, up from 33.9% in July 2026

Benchmark Context

The benchmark separates the raw collection universe from the qualified analysis set. Brand-level recommendation percentages are calculated within the qualified benchmark set.

Research stage

Jul 2026

Aug 2026

What it represents

Source prompt-surface observations collected

750

750

Total prompt-surface observations across the defined AI/search surface universe

Unique questions

475

475

Distinct questions after de-duplication

Brand / competitor mentions

750

750

Prompts mentioning a tracked brand or competitor

Relevant prompts

500

500

Prompts relevant to the cybersecurity services category

Irrelevant prompts

250

250

Prompts outside the category scope

Qualified benchmark observations

404

338

Public denominator after both qualification stages

Qualified surface breadth

6

6

AI surface families with at least one qualified observation

The qualified denominator moved from 404 to 338 observations between the two months, and the two months also carry different tracked platform IDs (rolling up to the same six canonical AI surface families in both periods). The metrics below summarize category-wide movement across that qualified set, independent of the individual brand-naming changes covered later in this report.

Benchmark-Level Metrics

Metric

Jul 2026

Aug 2026

Change

Qualified observations

404

338

Down 66

Companies tracked

10

10

No change

Recommendation-shaped answer share

33.9%

40.8%

Up 6.9 points

Valid recommendation shortlist share

53.5%

60.7%

Up 7.2 points

Category leader by coverage

CrowdStrike Falcon

CrowdStrike

Leadership carried across the naming shift

AI Recommendation Trend

The top of the category is now a two-brand cluster with a single-digit gap, and the ranking changed because the benchmark tracks parent companies rather than product lines.

Brand

Jul 2026

Aug 2026

Movement

Aug 2026 rank

Arctic Wolf

17.3%

9.2%

Down 8.1 points

4th

CrowdStrike

0.0%

53.5%

Up 53.5 points

1st

CrowdStrike Falcon

53.7%

0.0%

Down 53.7 points

11th

Deepwatch

1.2%

0.0%

Down 1.2 points

10th

Google Chronicle

2.2%

0.0%

Down 2.2 points

11th

Mandiant (Google)

0.0%

8.3%

Up 8.3 points

6th

Optiv

1.0%

1.2%

Up 0.2 points

9th

Palo Alto Cortex XDR

25.0%

0.0%

Down 25.0 points

11th

Palo Alto Networks

0.0%

47.6%

Up 47.6 points

2nd

Rapid7

0.0%

8.6%

Up 8.6 points

5th

Rapid7 InsightIDR

9.9%

0.0%

Down 9.9 points

11th

Secureworks

0.0%

4.7%

Up 4.7 points

7th

Secureworks Taegis

2.0%

0.0%

Down 2.0 points

11th

Sophos

0.0%

26.3%

Up 26.3 points

3rd

Sophos Intercept X

34.4%

0.0%

Down 34.4 points

11th

Trustwave

1.5%

1.5%

No change

8th

The category-level change comes overwhelmingly from the instrument's brand-naming shift rather than from organic movement in recommendation behavior. Several brands moved beyond normal month-to-month variation, but those moves pair one-for-one with the switch from product-line names to parent-company names, which redistributes the same underlying recommendation credit across newly tracked entities. Arctic Wolf's decline is the one movement in this table that is not explained by the naming shift.

What Changed This Month

CrowdStrike: New Leader Under a Parent-Company Name

CrowdStrike's valid recommendation coverage moved from 0.0% in July 2026 to 53.5% in August 2026. The prior month's coverage for CrowdStrike Falcon was 53.7%, which means the parent-company name now captures essentially the same recommendation credit the product line held before. The brand was present in 82.2% of August 2026 observations, with a top-three recommendation rate of 47.9% and a rank-one rate of 27.5% across 162 top-three placements and 93 rank-one placements.

CrowdStrike was already the most recommended vendor in July under the Falcon product name, and it remains so in August under the corporate name. The current benchmark records this as a naming-driven leadership carryover rather than a new competitive gain.

Highest-priority diagnostic: whether the parent-company name captures recommendation credit in prompts where the product line was previously invisible, or whether the same set of prompts is now simply credited to the parent name.

Palo Alto Networks: Close Second, Not a Simple Rename

Palo Alto Networks rose from 0.0% baseline to 47.6% valid recommendation coverage in August 2026, while Palo Alto Cortex XDR fell from 25.0% to 0.0%. The gap between CrowdStrike and Palo Alto Networks is 5.9 points. Palo Alto Networks was present in 76.3% of August 2026 observations, with a top-three rate of 37.6% and a rank-one rate of 18.1% across 127 top-three placements and 61 rank-one placements.

Palo Alto Networks' parent-company coverage is higher than its product-line coverage was in July, which the data cannot fully attribute to the naming change alone since the corporate name appears to capture additional recommendation credit beyond the Cortex XDR product line.

Highest-priority diagnostic: which specific product names within Palo Alto Networks' portfolio are driving the parent-company credit, and which prompts route to the corporate name versus the product name.

Sophos: Third Place With a Lower Parent-Company Total

Sophos moved from 0.0% baseline to 26.3% valid recommendation coverage in August 2026, while Sophos Intercept X fell from 34.4% to 0.0%. The parent-company name captured less credit than the Intercept X product line did in July. Sophos was present in 36.7% of August observations, with a top-three rate of 10.7% and a rank-one rate of 1.5% across 36 top-three placements and 5 rank-one placements.

Unlike CrowdStrike and Palo Alto Networks, Sophos' parent-company coverage is lower than its flagship product's July coverage, meaning some recommendation credit that previously attached to Intercept X does not appear under the corporate name in this dataset.

Highest-priority diagnostic: whether the gap represents credit spread across the broader Sophos brand or credit attached to other Sophos products not tracked in July.

Arctic Wolf: The Clearest Organic Decliner

Arctic Wolf's valid recommendation coverage fell from 17.3% in July 2026 to 9.2% in August 2026, a drop of 8.1 points that exceeds the significance threshold applied to this brand. Its raw mention presence fell from 24.5% to 13.0%, and its top-three rate declined from 8.9% to 5.3%. Arctic Wolf held 31 valid recommendations in August 2026, down from 70 in July, with 18 top-three placements and 6 rank-one placements.

Arctic Wolf's decline is not explained by a naming shift, making it the clearest organic movement in the category this month. The brand remains present and positively framed, with a net sentiment score of 0.8 in August 2026, but both its visibility and its recommendation share contracted.

Highest-priority diagnostic: which prompt categories and AI surfaces drove the visibility loss, and whether the benchmark can distinguish that loss from measurement effects tied to the broader instrument change.

Instrument Note: The July-to-August Naming Shift

The benchmark's tracked brand set changed between July 2026 and August 2026. Six product-line names (CrowdStrike Falcon, Palo Alto Cortex XDR, Sophos Intercept X, Rapid7 InsightIDR, Secureworks Taegis, Google Chronicle) were replaced by parent-company names (CrowdStrike, Palo Alto Networks, Sophos, Rapid7, Secureworks, Mandiant (Google)). Pairwise movements between these paired names are best read as effects of the naming change rather than independent gains or losses. The two names that carried across the change, Optiv and Trustwave, were both stable.

Highest-priority diagnostic: whether future months hold the parent-company names as the stable tracking set, and whether the product-line names re-enter as separately tracked entities.

Buyer-Intent Interpretation

Buyer-intent cluster

What it captures

Strategic question

Brand Recommendation

Prompts asking which cybersecurity vendor to choose for a given need

Which brand does the AI surface recommend first, and how often does it appear in the top three?

Pricing & Value

Prompts asking about cost, pricing models, or value for money

Which brands are surfaced in pricing discussions, and in what frame?

Multi-Brand Comparison

Prompts asking to compare two or more vendors head-to-head

Which brand wins the comparison, and which attributes drive the recommendation?

In August 2026, the qualified observations fell entirely into the Brand Recommendation cluster, with no qualified observations in the Pricing & Value or Multi-Brand Comparison clusters. The public benchmark therefore answers the "which vendor" question well, but it cannot answer commercial questions about price positioning, value perception, or head-to-head competitive outcomes. Those questions require a company-level audit that goes beneath the aggregate benchmark.

Brand Opportunity Summary

Brand

Aug 2026 coverage

Current signal

Highest-priority diagnostic

Arctic Wolf

9.2%

Coverage down 8.1 points; still visible at 13.0% mention presence with 31 valid recommendations

Which prompt categories and surfaces drove the visibility loss

CrowdStrike

53.5%

Category leader; 82.2% presence; 27.5% rank-one rate

Whether the parent name captures credit the product line missed

CrowdStrike Falcon

0.0%

Name retired from tracked set; credit moved to CrowdStrike

Whether product-line credit is fully captured by the parent name

Deepwatch

0.0%

Zero valid recommendations in August 2026; 1 mention in 338 observations

Which prompts mention Deepwatch at all and why none convert to recommendations

Google Chronicle

0.0%

Name replaced by Mandiant (Google); no August observations

Whether Mandiant captures the Chronicle credit

Mandiant (Google)

8.3%

Newly tracked; 10.9% presence; no rank-one placements

Which threat-intelligence prompts drive Mandiant recommendations

Optiv

1.2%

Stable; 4 valid recommendations; no rank-one placements

Which niche prompts produce the small recommendation count

Palo Alto Cortex XDR

0.0%

Name retired from tracked set; credit moved to Palo Alto Networks

Whether parent-company credit exceeds product-line coverage

Palo Alto Networks

47.6%

Second place; 76.3% presence; 18.1% rank-one rate

Which product portfolio names drive the parent-company credit

Rapid7

8.6%

Newly tracked; 29 valid recommendations; 2 rank-one placements

Whether InsightIDR credit is fully captured under Rapid7

Rapid7 InsightIDR

0.0%

Name retired from tracked set; credit moved to Rapid7

Whether product-line recommendation patterns survive the rename

Secureworks

4.7%

Newly tracked; 16 valid recommendations; 5 rank-one placements

Why rank-one placements outpace top-three rate

Secureworks Taegis

0.0%

Name retired from tracked set; credit moved to Secureworks

Whether Taegis-specific prompts route to the parent name

Sophos

26.3%

Third place; 36.7% presence; 1.5% rank-one rate

Why parent-company credit trails the Intercept X product line

Sophos Intercept X

0.0%

Name retired from tracked set; credit moved to Sophos

Whether the parent name captures the full product-line credit

Trustwave

1.5%

Flat across both months; 5 valid recommendations; no rank-one placements

Which niche service prompts keep Trustwave visible

The benchmark identifies where attention is warranted across the tracked brand set; a company-level analysis is needed to explain why those patterns exist and what drives them.

Evidence Behind the Benchmark

The aggregate metrics are built from prompt-level observations capturing the query, the AI surface, the recommendation outcome, the rank, the sentiment, and the citations where exposed. Company-level analysis can go deeper into prompt, competitor, surface, and evidence patterns. Presence in a benchmark answer is not automatically evidence of causation.

About This Benchmark

This report is part of the CiteWorks Studio AI Industry Market Discovery research program.

Report-Specific Interpretation Notes

  • The August 2026 brand set changed from product-line names to parent-company names; pairwise movements between the old and new names track closely with that naming change rather than independent organic shifts.
  • The qualified denominator (338 observations in August 2026, 404 in July 2026) differs from the raw collection universe (750 prompt-surface observations); percentages are calculated within the qualified set.
  • With 16 tracked brand names across two months, several carry small observation counts; treat single-digit coverage figures as directional signals, not definitive rankings.
  • Movement between months identifies changes worth investigating; the data describes the output distribution, not its cause.

Next Step

The Public Benchmark Shows Where a Brand Is Winning or Losing. A Company-Level Audit Shows Why.

The aggregate percentage answers which brands AI systems recommend, but not why. Beneath CrowdStrike's 53.5% coverage sit questions about which high-intent prompts it wins, which competitor takes the recommendation when it loses, what attributes AI associates with each option, and which external sources shape those answers. The same questions apply to Arctic Wolf's 8.1-point decline and to the gap between Sophos' parent-company coverage and its product-line coverage.

A company-specific AI visibility audit maps those prompt, surface, competitor, ranking, sentiment, and evidence-source patterns into a prioritized visibility strategy. It identifies the highest-intent prompts where a brand is losing, the competitor that wins in its place, and the external sources that drive the AI's answer.

Request an AI visibility audit

/ Take the next step

Want to Understand Your AI Citation Footprint?

We start every engagement with a full audit of how AI systems reference your brand today.

Measurable, Repeatable Programme

Build a durable foundation of credible citations that compounds over time and continues to influence AI answers as new queries emerge

Citation Architecture Review

Identify which high-authority community sources are and aren't working in your favour across AI platforms.

AI Visibility Audit

Understand exactly how LLMs are referencing your brand today and which sources are shaping those answers.

/ Learn More

Understanding AI search visibility.

AI search experiences create answers by pulling information from many places online and summarizing it into a single response.

What Is AI Citation Intelligence?
AI citation intelligence is the process of measuring where AI platforms source their information and how frequently a brand is mentioned or referenced in AI-generated responses. Because LLMs synthesize across multiple sources, the sites and brands that appear repeatedly tend to influence how a topic or company is framed. This practice focuses on identifying which sources shape AI outputs and tracking brand visibility across different AI systems.
What Is Citation Architecture?
Citation architecture describes the set of sources that consistently inform how AI systems talk about a brand, product, or topic. LLMs draw from websites, articles, forums, and public discussion, and the sources they rely on most often become the backbone of their answers. Building strong citation architecture means ensuring that accurate, credible, high authority sources are the ones most likely to shape the way AI tools summarize and recommend a brand.
What Is Generative Engine Optimization?
Generative engine optimization (GEO) is the practice of improving the chances that AI systems use and cite your brand or content when generating answers. While traditional SEO is centered on ranking pages in search results, GEO focuses on how LLMs retrieve, interpret, and combine information when responding to a question. The objective is to strengthen the content and sources AI systems rely on, so your brand is treated as a trusted reference in AI responses.
What Is AI Share of Voice?
AI share of voice tracks how often a brand appears in AI-generated answers compared with competitors in the same category. It reflects visibility across AI platforms such as ChatGPT, Gemini, Claude, and Perplexity. Monitoring AI share of voice helps organizations see whether AI systems consistently include and recommend their brand for key queries or whether competitor brands are showing up more often.

About The Author

Mark Huntley

Mark Huntley

Founder and CEO

Mark Huntley, J.D. is founder of CiteWorks Studio, a strategic advisory focused on visibility, authority, and recommendation presence in AI-shaped search environments. His work centers on embedding-level GEO, vector optimization, and cosine gap engineering — helping brands align their digital presence with the retrieval systems that increasingly shape discovery, interpretation, and choice.

VIEW ALL CASE STUDIESREQUEST AN AI VISIBILITY AUDIT