Wave 2 of the Algorithmic Authority Index measured Share of Model across MSSP, MDR, and SOCaaS categories on ChatGPT, Perplexity, and Google AI Overview. Three-quarters of active cybersecurity vendors receive zero citations. The pattern is not random. Five structural failures produce it consistently.
Cybersecurity is the first industry deep-dive from Wave 2 because the buying process concentrates decision volume through AI. CISOs, IT directors, and security procurement teams increasingly begin category discovery in ChatGPT and Perplexity before they open a vendor website.
Wave 2 assessed 15 buyer-intent queries per platform across three AI systems (ChatGPT, Perplexity, Google AI Overview). Queries covered the three most-cited category variants that CISOs actually run: "best MSSPs for mid-market healthcare," "top MDR providers for cloud-native environments," "SOCaaS options for compliance-heavy verticals."
Each response was structured for named-vendor extraction. Citations were cross-referenced with the ~3,000 active vendors in the Momentum Cyber category map. The result is the Share of Model measurement for every named vendor in the category.
The pattern is severe. Five findings surface at four layers of the Algorithmic Authority Stack.
The 27% of citation share that does exist concentrates in a small set of vendors. Every one of them clears the Two-Gate Model at both gates: Inclusion (Gate 1) and Citation (Gate 2). Every one of them has structural evidence AI can extract on their own terms.
The remaining 2,992 active cybersecurity vendors appear inconsistently, sporadically, or not at all. Fifteen to twenty regional and vertical-specific vendors appear in one or two queries. The rest receive zero citations across the full query set.
Traditional inbound gave the mid-market a fighting chance on page one. AI hands buyers a shortlist of eight. You are named, or you are absent.
L4 Cybersecurity brands do not fail at citation. They fail at inclusion. The retrieval layer does not surface them for evaluation. Gate 2 (extraction and structure) never runs because Gate 1 (retrieval and inclusion) already closed.
The Two-Gate Model separates AI visibility failures into two structural moments. Gate 1 Inclusion determines whether an AI system retrieves a brand at all when a category query runs. Gate 2 Citation determines whether the retrieved brand gets extracted into a response.
For 73% of cybersecurity vendors, the failure happens at Gate 1. The retrieval graph for MSSP, MDR, and SOCaaS categories does not include them. It does not matter how strong their case studies are. It does not matter how many awards their SOC teams have won. The AI system never reaches for them in the first place.
This is Citation Invisibility at Layer 4 of the Algorithmic Authority Stack. Not a ranking problem. A retrieval problem. The category does not know they exist.
Cybersecurity brands ranking on page one of Google for their category can hold zero Share of Model on the same category query in ChatGPT.
L1 The four dominant cybersecurity service categories share overlapping definitions, overlapping vendor claims, and near-identical positioning language. To an AI classifier, they are one blurred category.
Category Confusion is the L1 Identity Fragmentation pattern applied at category scale rather than brand scale. Individual brands may have clean identity signals. The category itself does not.
"MDR doesn't really mean anything anymore. Tons of very different vendors call their 'endpoint' MDR which basically ends up being just endpoint plus the ability to file a ticket. The term is so watered down you can't really compare." r/msp thread on category confusion, 2024
The category collapse produces four consistent patterns across the ~3,000 vendor homepages Wave 2 sampled:
When claim language flattens, AI cannot distinguish between vendors on the language alone. The classifier defaults to the vendors with the strongest independent evidence outside their own claims. The result is Positioning Abstraction at scale: the descriptions became too vague for AI to classify vendors as distinct entities.
Category Confusion produces a compounding effect. Each new vendor entering the category with the same claim language deepens the collapse. 2,992 identical homepages train AI to see one entity, not three thousand.
L6 When brand-owned content fails extraction, AI does not return an empty response. It substitutes third-party sources it can extract from. Trust Seed substitution is the mechanism producing the observed citation pattern in cybersecurity.
Six third-party surfaces dominate the citation graph for cybersecurity vendor discovery. Brand-owned surfaces do not appear in the same graph at meaningful frequency.
Gartner Peer Insights and G2 dominate. PeerSpot enterprise reviews and Capterra category grids provide secondary corroboration.
Extraction pattern: verified customer reviews at scale, structured comparison data, vendor-neutral ratings.
Gartner Magic Quadrant for MSSP. Forrester Wave for MDR. IDC MarketScape for MSS. Omdia and GigaOm as secondary sources.
Extraction pattern: Wave and MQ inclusion functions as primary authority signal for enterprise-segment queries.
r/msp, r/cybersecurity, r/sysadmin. Peerlyst archives. TechCommunity forums.
Extraction pattern: Perplexity cites Reddit heavily. Unfiltered practitioner sentiment carries category authority.
Dark Reading, SC Media, CyberScoop, The Register security, SecurityWeek.
Extraction pattern: independent editorial corroboration by named security journalists carries citation weight.
Person-attributed threat intelligence. Named CVE disclosures. Black Hat, DEF CON, and RSA conference talks with LinkedIn ties to the brand entity.
Extraction pattern: content attributed to a verifiable Person entity resolves back to the Organization.
Verizon DBIR. Mandiant M-Trends. CrowdStrike Global Threat Report. Proprietary telemetry with cited methodology.
Extraction pattern: original research increases AI visibility 30 to 40% versus promotional content on the same domain.
The vendors capturing 27% of Share of Model appear across four to six of these surfaces. The 73% receiving zero citations appear across zero to one. Brand-owned surfaces (homepage, product pages, case studies, gated whitepapers) do not appear at meaningful frequency in the citation graph for either group.
Trust Seed substitution is a symptom, not a fix. AI substitutes third-party evidence because brand-owned content is not structurally extractable. The pattern reverses when the L4 structural signals return.
L1 L2 L4 Third-party evidence lives on their servers. Machine-readable evidence lives on yours. Wave 2 sampled the six structural signals AI systems extract from brand-owned domains. Most cybersecurity vendors are thin on all six.
Complete Organization schema. sameAs to LinkedIn, Crunchbase, Wikidata, Gartner Peer Insights profile. legalName and alternateName resolved.
Typical: Organization schema missing or partial. No sameAs chain. AI cannot resolve the entity across surfaces.
Threat research attributed to verifiable Person entities. Author markup linked to the Organization. LinkedIn ties confirmed.
Typical: "Threat Research Team" bylines. No named humans. Authority Collapse at L2.
One category term used identically on homepage, product pages, case studies. The L3 fix pattern.
Typical: four to five variants across the site. "MDR" here. "Managed detection" there. "SOC-as-a-service" elsewhere. Semantic Drift.
Category comparison questions ("MSSP versus MDR?") answered on-domain with extractable H2 and paragraph structure.
Typical: answers buried inside gated content or absent entirely. AI extracts them from Reddit instead.
Buyer FAQs marked as FAQPage. Question-answer pairs extractable as structured data.
Typical: FAQ pages as HTML prose without markup. AI processes them as decorative content.
Threat research, benchmarks, and detection data published as HTML pages on-domain.
Typical: best evidence locked behind PDF gates AI cannot cross. The proof exists but stays invisible.
The Two-Gate Model predicts that vendors thin on structural extraction signals fail at Gate 2 even when Gate 1 clears. The finding here is more severe: for 73% of cybersecurity vendors, the structural weakness compounds the retrieval weakness. Gate 1 does not clear because there is nothing structural for the retrieval layer to reach for.
Every structural signal above is under the brand's control. Most cybersecurity vendors publish none of them.
Peer-reviewed research on Generative Engine Optimisation (Aggarwal et al., KDD 2024, Princeton) quantifies which content types AI systems cite most consistently. The pattern is stable across ChatGPT, Perplexity, and Google AI Overview. Marketing content ranks bottom. Named research ranks top.
The cybersecurity content mix flips this hierarchy. Vendor blogs describe the vendor. Case studies quote the vendor. Whitepapers gate the vendor's own research. The content types that get cited are the ones cybersecurity brands publish least: named-researcher expert commentary, extractable original threat data, statistics with published methodology.
Vendor blog posts that describe the vendor rank last in AI citation frequency. Threat research that names the researcher ranks first.
AI systems learn cybersecurity categories through two loops. A fast retrieval loop that updates within weeks. A slow parametric loop that locks category associations into model memory for 18 to 24 months. Every quarter of continued absence hardens the wrong picture of the category.
Wave 1 measured Parametric Decay across multiple categories. Cybersecurity shows the fastest hardening curve of any category tested to date. The reason is category concentration: eight vendors already hold the full parametric picture of MSSP, MDR, and SOCaaS in the current model generation. The window for the 2,992 absent vendors to be included in the next parametric update is measured in quarters, not years.
The Two-Loop Problem is asymmetric. The retrieval loop rewards fast intervention. The parametric loop punishes delay. The brand that fixes the structural signals this quarter enters the next model generation. The one that fixes them in 2027 corrects a locked-in classification instead.
The Cybersecurity Industry Snapshot names the pattern at category scale. The Snapshot names the pattern for your specific brand. A structured audit of your Share of Model, the layer failures producing your Category Absence, and the structural gaps between your current state and the eight named winners.
Wave 2 uses the same measurement framework as Wave 1 of the Algorithmic Authority Index, adapted for category-level rather than brand-level analysis. Queries are buyer-intent phrasings drawn from CISO and IT procurement research patterns. Response citations are extracted, deduplicated, and cross-referenced with the active vendor set. Share of Model is calculated as the percentage of the total category response set that names a specific vendor across all platforms.
Category sources: Momentum Cyber Market Review 2025 (vendor count). Semrush AI Search Study 2025 (Category Absence Rate). Similarweb 2025 (Zero-Click Rate). Aggarwal et al., KDD 2024 GEO Study, Princeton University (content extraction lift measurements). r/msp threads on category confusion, 2024 (practitioner sentiment).