We sent 52 real buying questions to ChatGPT and Google AI Overviews – the questions IT and security teams actually ask. Then we counted which providers get named, and how often. The result is a ranking built from real AI answers, not opinion.
Proofpoint (3.8%) and Sophos (3.6%) dominate the answers – the remaining 163 named providers split what's left. If you're not here, you simply don't exist to AI users. That's exactly the gap BuzzView makes visible.
Share of all brand mentions across 52 prompts (Share of Voice). The longer the bar, the more often AI names the provider – across every question tested.
Behind the ranking — what the numbers actually mean for brands in this space.
Cybersecurity is one of the most fragmented categories in enterprise software when viewed through the lens of AI-generated recommendations. Our 52 prompts surfaced 163 distinct providers — an average of more than three new vendors per prompt — with no single brand dominating the conversation. Proofpoint leads the tracked set with only 16 mentions and a 3.8% share of voice. That number sounds modest because it is: in a category this crowded, reaching even 4% share of voice in AI responses represents a meaningful competitive position.
The 12 brands we tracked collectively earned 126 mentions — roughly 30% of the total 419. The remaining 70% — 293 mentions — flowed to 151 other providers that AI systems surface without prompting. This is not a sign of a healthy long tail of niche specialists. It reflects how immature AI-assisted discovery still is in cybersecurity: language models draw on an enormous corpus of security publications, vendor comparisons, analyst reports, and forum discussions, and they surface names accordingly, without the editorial curation that narrows results in more mature categories.
The cybersecurity market has historically bifurcated between legacy platform vendors — think Palo Alto Networks, Sophos, and Barracuda, all with roots in on-premise hardware and network security — and a wave of cloud-native challengers like CrowdStrike, SentinelOne, and Lakera that built their products entirely around software-defined architectures and AI-first threat detection. This structural divide shows up clearly in the data. Legacy vendors earn mentions in broad "best firewall" or "best email security" queries, while cloud-native entrants appear most prominently in prompts that mention AI risks, zero-trust architectures, or next-generation threat intelligence.
For any brand competing in this space, fragmentation is both a threat and an opportunity. The threat is that AI systems default to well-documented incumbents whenever a query lacks specificity. The opportunity is that precisely worded queries — the ones where buyers have already narrowed their problem — can surface best-fit specialists rather than household names. Brands that invest in documenting their specific use-case advantages in formats AI can readily ingest will consistently punch above their overall market-share weight in recommendation results.
In cybersecurity, no single brand owns the AI conversation — the market is too broad and too fast-moving. Winning share of voice requires ruthless focus on specific problem categories rather than trying to compete across the entire security landscape.
Among the 13 tracked cybersecurity firms in this dataset, the visibility range runs from a perfect 100% — Lakera appears as a recommendation in every single relevant prompt it was evaluated against — all the way down to 0% for sits Holding Germany GmbH, which earns no AI mentions whatsoever. SoSafe and Hornetsecurity share the second position at 87.5%, while Exeon, IT-Seal, and Link11 all sit at just 25%. This spread of 100 percentage points between the most and least visible tracked vendors is among the widest we have seen across any category we have measured.
What separates the visible from the invisible in cybersecurity is not simply budget or market share. Lakera's 100% visibility is directly tied to a very specific positioning: the company focuses entirely on AI security and protection against prompt injection attacks, a problem that has generated enormous editorial attention since the rise of generative AI systems in 2023 and 2024. When prompts mention AI application security or GenAI risk, Lakera is one of only a handful of brands that AI systems have enough contextual evidence to confidently recommend. Specificity of positioning, backed by a dense footprint of technical documentation, creates near-perfect recall.
Contrast that with SoSafe and Hornetsecurity, both at 87.5%. These two brands operate in well-documented sub-categories — security awareness training and Microsoft 365 email protection respectively — where the volume of independent reviews, analyst comparisons, and practitioner blog posts is high enough that AI systems have strong signal to draw on. The pattern is consistent: visibility in AI recommendations is almost entirely a function of how densely a brand's specific value proposition is documented across third-party sources that AI training corpora and live retrieval systems can access.
For vendors sitting at 25% or below — Exeon, IT-Seal, Link11, and Build38 among them — the data suggests a documentation deficit rather than a product quality problem. These are credible, operational cybersecurity businesses, but their footprint in the external content ecosystem that AI systems index is thin. Network detection and response, anti-DDoS, mobile app shielding: these are highly technical sub-categories where vendor-generated content dominates and independent coverage is sparse. Bridging that gap requires a deliberate content investment that targets the exact question formats AI systems encounter from buyers.
Visibility in AI recommendations is won through specificity and documentation density, not market size. Brands with a narrow, well-documented niche — like Lakera in AI security — consistently outperform larger but less precisely positioned competitors.
The four main prompt types we used — best-of questions, direct comparisons, alternative-seeking queries, and use-case or vertical-specific prompts — each produce a different winner landscape in cybersecurity. Best-of prompts ("What are the best email security tools for enterprises in Germany?") consistently surface Proofpoint, Sophos, and Barracuda. These are brands with decade-long track records, heavy analyst coverage in Gartner Magic Quadrants and Forrester Waves, and a massive secondary literature of reviews on platforms like G2, Capterra, and TrustRadius. AI systems use this extensive evidence base to confidently position them as category leaders in broad queries.
Comparison prompts produce a different dynamic. When a buyer asks "Compare Hornetsecurity, Proofpoint, and Barracuda for securing Microsoft 365," the AI system draws on structured comparison content — feature matrices, pricing breakdowns, migration guides — rather than on brand authority alone. Hornetsecurity performs particularly well here precisely because it has invested in comparison-oriented content and because its Microsoft 365 integration story is thoroughly documented in partner channels, IT-admin forums, and Microsoft's own partner ecosystem. Palo Alto Networks, despite its overall brand strength, appears less frequently in these direct three-way comparisons because its messaging tends toward enterprise-scale platform narratives rather than point-solution specifics.
Alternative-seeking prompts — "What alternatives exist to Snyk for protecting GenAI applications against prompt injection?" — are where the most strategically interesting results emerge. These prompts explicitly signal that the buyer has already evaluated an incumbent and is looking for something different. Lakera is the dominant beneficiary of this prompt type in the cybersecurity dataset, appearing as the primary recommended alternative in virtually every GenAI security comparison. SoSafe similarly benefits from alternative-seeking prompts in the security awareness training segment, positioned as the modern European alternative to the US-headquartered KnowBe4.
Use-case and vertical-specific prompts reveal the most nuanced picture. Prompts targeting specific buyer segments — MSPs, mid-market companies, enterprises in Germany — surface different brands depending on how well each vendor has documented its fit for that segment. CrowdStrike and SentinelOne appear prominently in enterprise-focused prompts, where their EDR and XDR capabilities are well-documented in the analyst community. KnowBe4 appears consistently in SMB and mid-market phishing training queries. The strategic implication is clear: the prompt type that most closely matches your target buyer's buying journey should determine your primary content investment.
Map your content strategy to the prompt types your buyers actually use. Alternative-seeking and use-case prompts are where challengers like Lakera and SoSafe consistently beat incumbents — because those prompts reward precise positioning over brand legacy.
Among the tracked providers, positive sentiment — instances where AI systems frame a brand's recommendation with clearly favorable language, citing outcomes, customer success, or differentiated capability — varies dramatically. SoSafe converts 6 of its 8 mentions into positively framed recommendations, a 75% positive rate. Proofpoint achieves 62.5% (10 of 16 mentions positive), while CrowdStrike and Palo Alto Networks both sit at around 63%. At the other end, AWS earns a positive framing in just 1 of its 8 mentions (12.5%), with the remaining 7 treated as neutral capability statements. Lakera, despite its perfect visibility score, converts only 25% of its mentions into positively framed recommendations.
The drivers of positive sentiment in cybersecurity AI recommendations follow a distinct pattern that differs from most other software categories. Third-party validation carries disproportionate weight: brands that appear in Gartner Peer Insights with high average scores, that win independent awards like SC Media's Best Endpoint Security, or that publish customer case studies with measurable security outcome metrics earn consistently higher positive framing. Proofpoint's strong positive rate reflects years of being cited in phishing prevention success stories, regulatory compliance outcomes, and zero-day threat response reports that became part of AI training data.
SoSafe's 75% positive rate is particularly notable given its relatively smaller brand footprint compared to US incumbents. The company has invested heavily in publishing phishing simulation outcome data, employee behaviour change statistics, and security culture research. This type of evidence-based content — where concrete outcomes are attached to the product name — is exactly what AI systems favour when constructing recommendation language. When there is data to cite, AI systems cite it enthusiastically. When there is only general capability description, the recommendation defaults to neutral.
AWS's low positive rate is instructive for large platform vendors in this space. Despite being a central component of many enterprise security architectures — through services like GuardDuty, Security Hub, and IAM — AWS is rarely the brand an AI system enthusiastically endorses in cybersecurity recommendation contexts. The platform's breadth is a liability here: it is too broad to be positioned as a specialist, so AI systems mention it as an infrastructure component rather than as a security solution. For Cloudflare and Barracuda, both sitting at 33% positive rates, a similar dynamic applies: they appear frequently but rarely generate the outcome-oriented framing that drives genuine recommendation value.
Positive AI sentiment is earned through published outcomes, third-party validation, and specificity — not brand size. SoSafe's 75% positive rate on just 8 mentions outperforms AWS's 12.5% positive rate on the same volume because outcome data beats platform breadth every time.
Across every category BuzzView has measured, AI-search maturity follows a recognisable arc. Immature categories show extreme fragmentation: many providers named, low maximum share of voice, frequent appearance of obscure or unexpected brands. Mature categories show consolidation: a handful of brands dominate AI mentions, share of voice is concentrated at the top, and challengers struggle to break through. By these measures, cybersecurity sits firmly at the immature end of the spectrum. The maximum share of voice in our dataset is just 3.8% (Proofpoint), and 70% of all AI mentions flow to the 151 providers outside our tracked set. This is an industry where AI-search opinion is still being formed.
Several structural factors drive this immaturity. First, cybersecurity is genuinely broad — it encompasses network security, endpoint protection, identity and access management, cloud security, email protection, security awareness training, AI security, and dozens of other distinct problem spaces, each with its own set of vendors and its own buyer vocabulary. A single set of 52 prompts spanning this breadth will inevitably surface a diverse provider landscape. Second, the category is moving fast: cloud-native players like CrowdStrike and SentinelOne have disrupted legacy endpoint security over the past decade, and a new wave of AI-native security vendors like Lakera is beginning to disrupt cloud-native players in turn. AI recommendation systems are still catching up with this rapid evolution.
The data also reveals that the German-language cybersecurity market — where several of these prompts were explicitly targeted — is at an even earlier stage of AI-search development than the global English-language market. Providers like Hornetsecurity, SoSafe, DataGuard, Perseus, and IT-Seal are well-known within the DACH enterprise IT community but have far thinner footprints in the global English-language content corpus that powers most AI systems. This creates a dual challenge: these brands must build AI visibility in German-language contexts where AI retrieval is less developed, while simultaneously increasing their English-language documentation to capture buyers who use English-language AI systems even when evaluating European vendors.
The strategic conclusion is that this fragmentation is temporary. Categories we have tracked over multiple quarters consistently show consolidation: early movers who invest in AI-optimised content establish durable share-of-voice advantages that compound over time. In cybersecurity, the window to claim a strong AI recommendation position — before the category consolidates around four or five dominant brand names per sub-category — is likely measured in months rather than years. The brands that are building structured, outcome-rich, prompt-optimised content ecosystems today are not just competing for next quarter's pipeline. They are competing for the category positions that AI systems will default to once the market matures and consolidation sets in.
Cybersecurity's AI recommendation landscape is still highly fragmented and fluid. Brands that act now — building dense, outcome-oriented content mapped to specific buyer queries — will claim durable category positions before the inevitable consolidation makes those positions much harder to win.
No wishful thinking: the ranking comes from exactly these prompt types – best-of questions, comparisons, alternatives and use cases.
Visibility score = share of prompts where the provider appears in the AI answer at all. 100% means: present for every relevant question.
See it in action
Track your brand across every AI — automatically. Here's how it works.
1. What is BuzzView?
2. Your Brand vs. Competition
3. From Data to Action
Lakera’s AI visibility across ChatGPT, Google AI Overviews & Perplexity — one of the brands tracked in this category, straight from the live tool.
We set the real search and buying questions of your industry – exactly how your customers actually ask AI.
Every prompt runs against all major AI models. We count mentions, position, sentiment and the cited sources.
You see your ranking, your share of voice and exactly the prompts where competitors win – and you don't.
Run your own industry comparison and see in minutes whether ChatGPT & co. recommend you – or your competitors.
Start Free Trial No credit card · Results in minutes · GDPR-compliant, hosted in Germany