Cybersecurity in ChatGPT: When the Buyer Names the Vendors, Your Own Site Becomes the Whole Evidence Base
Cybersecurity vendors took 66.7% of ChatGPT's citations in this category, above the 65.9% corpus average and well ahead of other enterprise categories like ERP at 52.5% and healthcare EHR at 48.7%. The mechanism is visible in a single capture: asked to compare CrowdStrike and SentinelOne, ChatGPT read 43 results from just three domains and sent all eight of its citations to the two vendors' own product and pricing pages. When the buyer supplies the shortlist, ChatGPT stops shopping and starts fact-checking – which makes the vendor's own site the entire evidence base.
The category at a glance
| Measure | Cybersecurity | Corpus average |
|---|---|---|
| Mean results read per answer | 45.8 | 44.7 |
| Mean citations per answer | 6.0 | 6.1 |
| Distinct cited domains (6 prompts) | 10 | – |
| Distinct brands surfaced | 12 | – |
| Vendor-owned citation share | 66.7% | 65.9% |
| Citation concentration (HHI) | 1,358 | – |
| Most-named brand | CrowdStrike | – |
| Shortlist stability (Jaccard) | 0.430 | 0.338 |
| Distinct leaders across 6 prompts | 4 | 3.8 |
Cybersecurity is unusual among enterprise categories: gated pricing in much of the market, yet a higher-than-average vendor citation share and the second-most-stable shortlist in the study at 0.430, behind only CRM.
The head-to-head capture
Prompt (P27, head-to-head comparison): "Compare CrowdStrike vs SentinelOne for endpoint detection and response."
ChatGPT read 43 results but from just three domains. It rendered eight citations: four to crowdstrike.com and four to sentinelone.com. Two brands named. Answer latency: 8.6 seconds.
The answer positioned CrowdStrike on ecosystem strength, threat intelligence, threat hunting and mature SOC/XDR workflows, and SentinelOne on autonomous response, operational simplicity and rollback. Both were backed by sources – their own.
Forty-three results were read from three domains, and all eight citations went to the two competitors' own product and pricing pages. This is the cleanest illustration in the corpus of a general rule: when the buyer supplies the shortlist, retrieval is spent verifying feature and price claims rather than shopping.
Across the whole study, head-to-head prompts took 91.0% of their citations from vendor-owned domains – the second-highest of any archetype, behind only budget-constrained questions at 92.3%. They also named the fewest brands, at a mean of 2.1, and produced the longest answers at a mean of 1,034 words.
| Archetype | Brands named | Vendor citation share | Words |
|---|---|---|---|
| Head-to-head comparison | 2.1 | 91.0% | 1,034 |
| Budget / requirement constrained | 3.6 | 92.3% | 460 |
| Segment-constrained best-of | 5.1 | 68.3% | 827 |
| Unconstrained best-of | 6.3 | 47.8% | 404 |
| Alternatives-to | 7.8 | 47.8% | 741 |
| Category + vendor landscape | 10.9 | 41.7% | 929 |
The implication for a security vendor is direct. In every head-to-head your prospects run, the answer is built almost entirely from your website and your competitor's. There is no third party to blame and no analyst to hide behind.
Which security brands the model already believes in
| Brand | Answers naming it | Times ranked #1 | Mean rank | Total mentions |
|---|---|---|---|---|
| CrowdStrike | 6 | 3 | 1.83 | 51 |
| SentinelOne | 6 | 0 | 3.17 | 38 |
Both appeared in all six cybersecurity prompts. The gap is in conviction rather than presence: CrowdStrike led half of them with a mean rank of 1.83, SentinelOne led none with a mean rank of 3.17.
That is a substantial positional difference for two vendors who are near-peers in market perception. SentinelOne is always in the consideration set and rarely the recommendation.
At domain level, crowdstrike.com earned 9 citations across four answers and sentinelone.com 5 across two. The most interesting entry is huntress.com at 5 citations across a single answer – a smaller vendor concentrating five citations in one response, which is exactly the pattern a well-structured product and pricing page produces when it matches a constrained question.
Four distinct vendors took the top slot across six prompts, with CrowdStrike holding 50%.
What this means if you sell security software
Your competitive comparison pages are load-bearing. Head-to-head answers pull 91.0% of citations from the two named vendors' sites. If your "vs" page is stale, thin, or does not exist, the answer to that question is built from your competitor's page and whatever the model remembers. Publish one for every named competitor you regularly lose to, with a current date and a real table.
Publish the operational facts, not just the positioning. The claims that earned citations in this capture were concrete: detection coverage, response capability, rollback, workflow maturity. Supported OS and kernel versions, agent footprint, MITRE ATT&CK evaluation results, deployment models, SOC integration, log retention, response time SLAs – all checkable, all citable, and most of them currently live in a datasheet PDF behind a form.
Pricing still matters even here. Cybersecurity sits above the enterprise average on vendor citation share partly because parts of the market do publish. Where you cannot publish a per-endpoint price, publish the pricing model, endpoint minimums and what each tier includes.
Do not assume scale wins. huntress.com, a far smaller vendor than either of the two named above, concentrated five citations in a single answer. Structured, extractable product detail on a page that matches a constrained question beats brand size at the retrieval layer.
Watch the ranking gap, not just presence. SentinelOne's presence is identical to CrowdStrike's and its mean rank is 1.34 places worse. Presence-based AI visibility reporting would show those two brands as tied. Mean rank and times-ranked-first are the metrics that expose the actual gap.
FAQ
Does ChatGPT cite cybersecurity vendors' own websites?
Yes, more than average. Cybersecurity vendors took 66.7% of citations against a 65.9% corpus average, and well above other enterprise categories such as ERP at 52.5%. In head-to-head comparisons specifically, vendor citation share across the whole study was 91.0%.
What happens when you ask ChatGPT to compare two named security vendors?
It stops shopping and starts fact-checking. A CrowdStrike versus SentinelOne prompt read 43 results from just three domains and rendered eight citations, four to each vendor's own site. The question had already picked the shortlist, so retrieval was spent verifying feature and price claims.
Does ChatGPT prefer CrowdStrike or SentinelOne?
Both appeared in all six cybersecurity prompts tested, but CrowdStrike led three of them with a mean rank of 1.83 while SentinelOne led none with a mean rank of 3.17. Four distinct vendors took the top slot across the six prompts.
Do smaller security vendors get cited by ChatGPT?
They can. huntress.com earned five citations concentrated in a single answer in this corpus - as many citations in one response as sentinelone.com achieved across two. Structured, extractable product detail matching a constrained question outperforms brand size at the retrieval layer.
What content should security vendors publish for AI search?
Competitive comparison pages for every named rival, dated and tabular, plus concrete operational facts: supported OS and kernel versions, agent footprint, evaluation results, deployment models, SOC integration, retention and response SLAs. Most of these currently sit in gated datasheets where retrieval cannot reach them.
Related in this series
- How ChatGPT Shortlists Software Brands, the full report as a PDF
- Forty-Five Reads, Six Links: How ChatGPT Actually Cites Software Brands
- Same Buyer, Same Category, Different Shortlist: Prompt Shape Rewrites the Answer
- The Page Shapes AI Retrieval Actually Finds: 525 Versus Pages, 17 Reviews
- Publish Your Prices: Why Gated Pricing Costs You 30 Points of AI Citation Share
About the research. Nathan Mzumara is an organic growth and AI search practitioner. Category figures rest on six observations and should be read as directional. Method and limitations are stated in the pillar report.
Tags