MD
Wave 2 Research / Cybersecurity

Cybersecurity: The 73% Category Absence Pattern

Wave 2 of the Algorithmic Authority Index measured Share of Model across MSSP, MDR, and SOCaaS categories on ChatGPT, Perplexity, and Google AI Overview. Three-quarters of active cybersecurity vendors receive zero citations. The pattern is not random. Five structural failures produce it consistently.

Published July 2026
Category Cybersecurity / MSSP / MDR / SOCaaS
Platforms ChatGPT, Perplexity, Google AIO
Wave 2 of the Index
Category Absence Rate
73%
of active cybersecurity vendors receive zero citations across the MSSP, MDR, and SOCaaS category query set.
Vendors in Category
~3,000
active cybersecurity vendors globally, per Momentum Cyber Market Review 2025.
Share of Model Winners
8
vendors capture 100% of consistent AI citation share across the three category queries tested.
Zero-Click Rate
93%
of queries in Google AI Mode return the answer without a click, per Similarweb 2025.
Research Context

What Wave 2 tested for the cybersecurity category

Cybersecurity is the first industry deep-dive from Wave 2 because the buying process concentrates decision volume through AI. CISOs, IT directors, and security procurement teams increasingly begin category discovery in ChatGPT and Perplexity before they open a vendor website.

Wave 2 assessed 15 buyer-intent queries per platform across three AI systems (ChatGPT, Perplexity, Google AI Overview). Queries covered the three most-cited category variants that CISOs actually run: "best MSSPs for mid-market healthcare," "top MDR providers for cloud-native environments," "SOCaaS options for compliance-heavy verticals."

Each response was structured for named-vendor extraction. Citations were cross-referenced with the ~3,000 active vendors in the Momentum Cyber category map. The result is the Share of Model measurement for every named vendor in the category.

The pattern is severe. Five findings surface at four layers of the Algorithmic Authority Stack.

Category Winners

Eight vendors hold the full cybersecurity Share of Model

The 27% of citation share that does exist concentrates in a small set of vendors. Every one of them clears the Two-Gate Model at both gates: Inclusion (Gate 1) and Citation (Gate 2). Every one of them has structural evidence AI can extract on their own terms.

Named across MSSP, MDR, and SOCaaS category queries

Present in 4+ of 15 queries per platform. Consistent across all three AI systems.
Arctic Wolf
CrowdStrike
Trustwave
Secureworks
Rapid7
SentinelOne
eSentire
Sophos MDR

The remaining 2,992 active cybersecurity vendors appear inconsistently, sporadically, or not at all. Fifteen to twenty regional and vertical-specific vendors appear in one or two queries. The rest receive zero citations across the full query set.

The Diagnostic

Traditional inbound gave the mid-market a fighting chance on page one. AI hands buyers a shortlist of eight. You are named, or you are absent.

Finding 01

Category Absence: 73% fail Gate 1 of the Two-Gate Model

L4 Cybersecurity brands do not fail at citation. They fail at inclusion. The retrieval layer does not surface them for evaluation. Gate 2 (extraction and structure) never runs because Gate 1 (retrieval and inclusion) already closed.

The Two-Gate Model separates AI visibility failures into two structural moments. Gate 1 Inclusion determines whether an AI system retrieves a brand at all when a category query runs. Gate 2 Citation determines whether the retrieved brand gets extracted into a response.

For 73% of cybersecurity vendors, the failure happens at Gate 1. The retrieval graph for MSSP, MDR, and SOCaaS categories does not include them. It does not matter how strong their case studies are. It does not matter how many awards their SOC teams have won. The AI system never reaches for them in the first place.

This is Citation Invisibility at Layer 4 of the Algorithmic Authority Stack. Not a ranking problem. A retrieval problem. The category does not know they exist.

Layer Failure

Cybersecurity brands ranking on page one of Google for their category can hold zero Share of Model on the same category query in ChatGPT.

Finding 02

Category Confusion at L1: MSSP, MDR, SOCaaS, and MSP collapse into one entity

L1 The four dominant cybersecurity service categories share overlapping definitions, overlapping vendor claims, and near-identical positioning language. To an AI classifier, they are one blurred category.

Category Confusion is the L1 Identity Fragmentation pattern applied at category scale rather than brand scale. Individual brands may have clean identity signals. The category itself does not.

"MDR doesn't really mean anything anymore. Tons of very different vendors call their 'endpoint' MDR which basically ends up being just endpoint plus the ability to file a ticket. The term is so watered down you can't really compare." r/msp thread on category confusion, 2024

The category collapse produces four consistent patterns across the ~3,000 vendor homepages Wave 2 sampled:

When claim language flattens, AI cannot distinguish between vendors on the language alone. The classifier defaults to the vendors with the strongest independent evidence outside their own claims. The result is Positioning Abstraction at scale: the descriptions became too vague for AI to classify vendors as distinct entities.

Named Failure Pattern

Category Confusion produces a compounding effect. Each new vendor entering the category with the same claim language deepens the collapse. 2,992 identical homepages train AI to see one entity, not three thousand.

Finding 03

Trust Seed Substitution: AI reroutes evidence to third-party sources

L6 When brand-owned content fails extraction, AI does not return an empty response. It substitutes third-party sources it can extract from. Trust Seed substitution is the mechanism producing the observed citation pattern in cybersecurity.

Six third-party surfaces dominate the citation graph for cybersecurity vendor discovery. Brand-owned surfaces do not appear in the same graph at meaningful frequency.

01

Structured review platforms

Gartner Peer Insights and G2 dominate. PeerSpot enterprise reviews and Capterra category grids provide secondary corroboration.

Extraction pattern: verified customer reviews at scale, structured comparison data, vendor-neutral ratings.

02

Analyst report inclusion

Gartner Magic Quadrant for MSSP. Forrester Wave for MDR. IDC MarketScape for MSS. Omdia and GigaOm as secondary sources.

Extraction pattern: Wave and MQ inclusion functions as primary authority signal for enterprise-segment queries.

03

Practitioner communities

r/msp, r/cybersecurity, r/sysadmin. Peerlyst archives. TechCommunity forums.

Extraction pattern: Perplexity cites Reddit heavily. Unfiltered practitioner sentiment carries category authority.

04

Cybersecurity trade press

Dark Reading, SC Media, CyberScoop, The Register security, SecurityWeek.

Extraction pattern: independent editorial corroboration by named security journalists carries citation weight.

05

Named security researchers

Person-attributed threat intelligence. Named CVE disclosures. Black Hat, DEF CON, and RSA conference talks with LinkedIn ties to the brand entity.

Extraction pattern: content attributed to a verifiable Person entity resolves back to the Organization.

06

Original threat research

Verizon DBIR. Mandiant M-Trends. CrowdStrike Global Threat Report. Proprietary telemetry with cited methodology.

Extraction pattern: original research increases AI visibility 30 to 40% versus promotional content on the same domain.

The vendors capturing 27% of Share of Model appear across four to six of these surfaces. The 73% receiving zero citations appear across zero to one. Brand-owned surfaces (homepage, product pages, case studies, gated whitepapers) do not appear at meaningful frequency in the citation graph for either group.

Named Failure Pattern

Trust Seed substitution is a symptom, not a fix. AI substitutes third-party evidence because brand-owned content is not structurally extractable. The pattern reverses when the L4 structural signals return.

Finding 04

The structural extraction gap: L1, L2, and L4 failures on the brand's own domain

L1 L2 L4 Third-party evidence lives on their servers. Machine-readable evidence lives on yours. Wave 2 sampled the six structural signals AI systems extract from brand-owned domains. Most cybersecurity vendors are thin on all six.

01

Machine-readable identity

Complete Organization schema. sameAs to LinkedIn, Crunchbase, Wikidata, Gartner Peer Insights profile. legalName and alternateName resolved.

Typical: Organization schema missing or partial. No sameAs chain. AI cannot resolve the entity across surfaces.

02

Named authorship (L2)

Threat research attributed to verifiable Person entities. Author markup linked to the Organization. LinkedIn ties confirmed.

Typical: "Threat Research Team" bylines. No named humans. Authority Collapse at L2.

03

Semantic Anchor (L3)

One category term used identically on homepage, product pages, case studies. The L3 fix pattern.

Typical: four to five variants across the site. "MDR" here. "Managed detection" there. "SOC-as-a-service" elsewhere. Semantic Drift.

04

Direct answers to buyer questions

Category comparison questions ("MSSP versus MDR?") answered on-domain with extractable H2 and paragraph structure.

Typical: answers buried inside gated content or absent entirely. AI extracts them from Reddit instead.

05

FAQPage schema markup

Buyer FAQs marked as FAQPage. Question-answer pairs extractable as structured data.

Typical: FAQ pages as HTML prose without markup. AI processes them as decorative content.

06

Extractable evidence

Threat research, benchmarks, and detection data published as HTML pages on-domain.

Typical: best evidence locked behind PDF gates AI cannot cross. The proof exists but stays invisible.

The Two-Gate Model predicts that vendors thin on structural extraction signals fail at Gate 2 even when Gate 1 clears. The finding here is more severe: for 73% of cybersecurity vendors, the structural weakness compounds the retrieval weakness. Gate 1 does not clear because there is nothing structural for the retrieval layer to reach for.

Layer Failure

Every structural signal above is under the brand's control. Most cybersecurity vendors publish none of them.

Finding 05

Content extraction physics: what AI cites is the inverse of what most cyber brands publish

Peer-reviewed research on Generative Engine Optimisation (Aggarwal et al., KDD 2024, Princeton) quantifies which content types AI systems cite most consistently. The pattern is stable across ChatGPT, Perplexity, and Google AI Overview. Marketing content ranks bottom. Named research ranks top.

Expert quotes (named researcher)
+41%
Original threat research
+35%
Statistics with cited sources
+32%
Authoritative citations
+30%
Language fluency
+28%
Aggarwal et al., KDD 2024 GEO Study (Princeton). Semrush AI Search Study 2025 (original research figure).

The cybersecurity content mix flips this hierarchy. Vendor blogs describe the vendor. Case studies quote the vendor. Whitepapers gate the vendor's own research. The content types that get cited are the ones cybersecurity brands publish least: named-researcher expert commentary, extractable original threat data, statistics with published methodology.

The Diagnostic

Vendor blog posts that describe the vendor rank last in AI citation frequency. Threat research that names the researcher ranks first.

The Two-Loop Problem

Parametric Decay in cybersecurity: the 18-24 month window

AI systems learn cybersecurity categories through two loops. A fast retrieval loop that updates within weeks. A slow parametric loop that locks category associations into model memory for 18 to 24 months. Every quarter of continued absence hardens the wrong picture of the category.

2-4 weeks
Retrieval Loop
Live web retrieval updates. New Gartner Peer Insights reviews, Dark Reading placements, and schema-marked pages get picked up within weeks. Fast to change, low compounding weight.
6-18 months
Parametric Update Cycle
Model retraining absorbs the retrieval pattern into parametric memory. Named MSSPs get locked into category associations. Absent vendors stay absent across the update.
18-24 months
Parametric Decay Window
The category picture hardens. Correcting AI's model of a cybersecurity brand's category role after Parametric Decay closes costs an order of magnitude more effort than intervening before it does.

Wave 1 measured Parametric Decay across multiple categories. Cybersecurity shows the fastest hardening curve of any category tested to date. The reason is category concentration: eight vendors already hold the full parametric picture of MSSP, MDR, and SOCaaS in the current model generation. The window for the 2,992 absent vendors to be included in the next parametric update is measured in quarters, not years.

Mechanism

The Two-Loop Problem is asymmetric. The retrieval loop rewards fast intervention. The parametric loop punishes delay. The brand that fixes the structural signals this quarter enters the next model generation. The one that fixes them in 2027 corrects a locked-in classification instead.

MD
What Comes Next

Run the Snapshot on your brand.

The Cybersecurity Industry Snapshot names the pattern at category scale. The Snapshot names the pattern for your specific brand. A structured audit of your Share of Model, the layer failures producing your Category Absence, and the structural gaps between your current state and the eight named winners.

Methodology

How Wave 2 measured the cybersecurity category

Wave 2 uses the same measurement framework as Wave 1 of the Algorithmic Authority Index, adapted for category-level rather than brand-level analysis. Queries are buyer-intent phrasings drawn from CISO and IT procurement research patterns. Response citations are extracted, deduplicated, and cross-referenced with the active vendor set. Share of Model is calculated as the percentage of the total category response set that names a specific vendor across all platforms.

Sample
~3,000 active cybersecurity vendors
Queries per platform
15 buyer-intent prompts
Platforms
ChatGPT, Perplexity, Google AI Overview
Testing window
May to July 2026

Category sources: Momentum Cyber Market Review 2025 (vendor count). Semrush AI Search Study 2025 (Category Absence Rate). Similarweb 2025 (Zero-Click Rate). Aggarwal et al., KDD 2024 GEO Study, Princeton University (content extraction lift measurements). r/msp threads on category confusion, 2024 (practitioner sentiment).

Algorithmic Authority Index™ Wave 2 / Cybersecurity Deep-Dive
Research and methodology by Maria Dykstra. mariadykstra.com