Which Attack Surface Management Platforms AI Engines Recommend: A 240,000-Response Study
TL;DR
- We analyzed 240,000 AI engine responses to 10,000 enterprise buyer-intent queries about attack surface management, across six engines and four markets. CyCognito led with 160,000 mentions, ahead of Palo Alto Networks at 115,000. The six engines converged on the same shortlist but shared almost no evidence: the highest cited-source overlap between any two engines was 0.37, and 196,100 of the 1,254,000 URLs they cited no longer resolve. If you are tracking AI visibility on a single engine, you are seeing a source population largely unrelated to the others.
TL;DR: We analyzed 240,000 AI engine responses to 10,000 enterprise buyer-intent queries about attack surface management, across six engines and four markets. CyCognito led with 160,000 mentions, ahead of Palo Alto Networks at 115,000. The six engines converged on the same shortlist but shared almost no evidence: the highest cited-source overlap between any two engines was 0.37, and 196,100 of the 1,254,000 URLs they cited no longer resolve. If you are tracking AI visibility on a single engine, you are seeing a source population largely unrelated to the others.
Enterprise security buyers increasingly open an AI engine before they open a vendor site, which means the shortlist an engine returns now shapes the consideration set before anyone fills in a contact form. We wanted to know what those engines actually say in one category, measured at scale rather than inferred from a handful of prompts.
Key Takeaways
- CyCognito recorded 160,000 mentions and Palo Alto Networks 115,000, the two highest in the category. Six vendors were named by all six engines tested.
- Mention volume and ordinal position move independently. Palo Alto Networks opened Microsoft Copilot's answers on 13,000 mentions in that engine, while CyCognito held 32,000 there without taking the opening slot.
- Cross-engine source overlap was 0.04 to 0.19 across vendor families, and 0.37 at its highest, between two Google surfaces.
- 15.6% of all cited URLs were unreachable, rising to 27.6% for Microsoft Copilot.
- The same vendors led in all four markets tested, though the ordering within that group shifted by country.
What We Analyzed and How
We issued 10,000 enterprise buyer-intent queries about attack surface management platforms to six AI engines: ChatGPT, Perplexity, Gemini, Microsoft Copilot, Google AI Overview, and Google AI Mode. Every query ran in four markets (United States, Canada, India, Germany), producing 40,000 responses per engine and 240,000 in total during August 2026.
For every response we recorded length, cited sources, whether each cited URL still resolved, each vendor named, and the ordinal position of that vendor's first appearance. The corpus contained 1,254,000 cited sources and 185 distinct product entries.
Two limits are worth stating up front. The engines are commercial services without pinned model versions, so a repeat run would not reproduce identical responses. And the query set is purposive rather than randomly sampled, so we report descriptive statistics only and make no claims of statistical significance. Full methodology and validity limits are in the complete benchmark report.
Which Vendors Do AI Engines Name Most in Attack Surface Management?
CyCognito led the category with 160,000 mentions, followed by Palo Alto Networks at 115,000 and Censys at 101,000. The ten most-mentioned vendors accounted for 805,000 mentions between them. Six vendors were named by all six engines: CyCognito, Palo Alto Networks, Microsoft, Tenable, CrowdStrike and IONIX.
Coverage was uneven inside that leading group in ways a single number hides. Bitsight recorded 18,000 mentions in Gemini and 1,000 in Google AI Overview, an eighteenfold difference across two engines for the same vendor. Bitsight did not appear in Microsoft Copilot at all, and Censys, Rapid7 and Qualys were each recorded in five engines rather than six.
At the product level, Cortex Xpanse recorded 149,000 mentions at a mean position of 1.8, the earliest of the ten most-mentioned products, while CyCognito's own product entry recorded 132,000 at a mean position of 2.7. Being named more often and being named earlier are not the same achievement.
Our finding: across 240,000 analyzed responses, three engines opened with CyCognito, two opened with Palo Alto Networks, and one opened with Microsoft. The split did not follow total mention volume in any engine.
Which Sources Do AI Engines Cite for ASM Recommendations?
ChatGPT supplied 360,000 citations and Google AI Overview 350,000, together 56.6% of the recorded evidence base. Microsoft Copilot supplied 156,000 from a comparable number of responses.
The sources differed sharply by engine. ChatGPT's top three were Palo Alto Networks' own documentation (59,000 citations), a major analyst firm (42,000), and Tenable's documentation (30,000). Google AI Overview's were CyCognito's documentation (53,000), IONIX's (30,000), and Palo Alto Networks' (27,000). Microsoft Copilot's top three were all small third-party security sites, at 24,000, 17,000, and 13,000 citations, two of which appeared in no other engine's top three.
Cross-engine overlap was low. Using Jaccard similarity, where 1.00 means identical domain sets and 0.00 means none shared, the highest value between two different engines was 0.37, between Google AI Mode and Google AI Overview. Across vendor families it fell to between 0.04 and 0.19.
This is the strongest argument in the dataset against single-engine measurement. An AI visibility programme instrumented on one engine observes a source population largely unrelated to the one another engine reads, and its conclusions will not transfer.
How Reliable Are the Sources AI Engines Cite?
Of the 1,254,000 cited URLs we tested, 196,100 did not resolve, an aggregate dead-link rate of 15.6%. The variation between engines was nearly threefold.
Microsoft Copilot cited unreachable URLs at 27.6%, more than a quarter of its evidence in this category, while Google AI Overview and Gemini stayed below 10%. Median cited-source age was recorded as zero days for every engine, a uniform value consistent with either same-day material or an undated default in extraction. The available metadata does not separate the two, so reachability rather than freshness is the finding to act on here.
For a vendor, the practical consequence is direct: the citation graph carrying your visibility decays continuously, and a dead source cannot carry a recommendation. Link integrity belongs on the visibility roadmap, not the maintenance backlog.
Do AI Recommendations Change by Country?
Not structurally. The same vendors led in all four markets, and no engine referenced country-specific regulatory or data-residency requirements when recommending a platform.
| Market | First | Second | Third |
|---|---|---|---|
| United States | Cortex Xpanse | CyCognito Platform | Tenable One |
| Canada | Cortex Xpanse | CyCognito | Microsoft Defender EASM |
| India | Tenable One | Cortex Xpanse | IONIX EASM |
| Germany | CyCognito | Cortex Xpanse | Bitsight EASM |
Source: GrackerAI AI Search Visibility Benchmark Series, August 2026.
Cortex Xpanse appeared in the leading three in all four markets and CyCognito in three of four. Only the ordering moved. The finding has a budget implication: vendors who maintain market-specific landing pages on the assumption that AI engines localise recommendations are, in this category, funding a difference the engines did not make.
Engine choice mattered far more than geography. Google AI Overview averaged 232.3 words per response with 6.5 citations per 100 words. ChatGPT averaged 647.4 words with 1.6. Two buyers asking the same question of different engines receive answers built to different shapes from different evidence.
Where Did the Engines Disagree?
The clearest disagreement was over merger and acquisition asset discovery. ChatGPT and Microsoft Copilot recommended Palo Alto Networks Cortex Xpanse, citing its global IPv4 scanning scale. Gemini and Google AI Mode recommended CyCognito, citing its seedless graph attribution. Same question, different platform, depending only on which engine the buyer opened.
Two claims appeared in a single engine and nowhere else. Microsoft Copilot alone described Vulcan Cyber exposure orchestration as a native integration milestone within Tenable One. ChatGPT alone identified runZero as the primary agentless internal CAASM complement to EASM. We record both as observed without assessing their accuracy.
Product naming was its own source of lost visibility. The corpus held 185 distinct product entries for a much smaller number of real products: Tenable appeared as 15 separate entries, Qualys as 11, Bitsight and Rapid7 as 10 each, Palo Alto Networks as 9, Censys as 7, and CyCognito as 6. Of the 185 entries, 104 registered 1,000 mentions or fewer. Inconsistent naming across a vendor's own published material splits that vendor's recorded visibility across several entries instead of consolidating it into one.
What Should Vendors and Buyers Do With This?
Buyers should treat the AI shortlist as one input. It is narrower than an analyst report, ordered differently by engine, and the vendor named first is the one with the strongest documentation footprint in that engine's evidence base, which is not the same as the best fit for your environment. Where the engines actively disagree, as they do on M&A asset discovery, evaluate both named platforms.
Vendors should instrument at least three engines drawn from different families, track mention volume and ordinal position as separate objectives, consolidate product naming, and audit link integrity on a schedule. One thing to stop doing: treating sentiment as a headline metric. All twelve vendors in our share-of-voice table fell between 0.70 and 0.84 on a scale from negative one to positive one, a spread of 0.14. There is almost no signal in it.
Frequently Asked Questions
How many AI responses did this attack surface management study analyze?
240,000 responses, generated from 10,000 enterprise buyer-intent queries issued to six AI engines across four markets in August 2026. The responses contained 1,254,000 cited sources and named 185 distinct product entries.
Which ASM vendor has the highest AI search visibility?
CyCognito, with 160,000 mentions. Palo Alto Networks followed at 115,000. Six vendors were named by all six engines tested: those two plus Microsoft, Tenable, CrowdStrike and IONIX.
Do all AI engines cite the same sources for security vendor recommendations?
No. The highest cited-source overlap between any two different engines was 0.37, and that pair was Google AI Mode and Google AI Overview, two surfaces from the same vendor. Across vendor families, overlap fell to between 0.04 and 0.19.
What percentage of AI-cited sources are dead links?
15.6% across the full corpus of 1,254,000 cited URLs. The rate ranged from 9.4% for Google AI Overview to 27.6% for Microsoft Copilot.
Should AI visibility be measured on more than one engine?
Yes. Because cross-family source overlap runs from 0.00 to 0.19, a programme measuring one engine observes a source population largely unrelated to the others, and its findings do not generalise to them.
Final Thoughts
Six AI engines answering the same attack surface management questions converged on a narrow vendor shortlist, disagreed on which vendor to name first, and drew that agreement from evidence bases that barely intersect. For vendors, the actionable gap is not brand perception but something measurable: the distance between market position and AI share of voice, and the 15.6% of supporting sources that have already stopped resolving.
Full per-engine tables, the source overlap matrix, and the study's validity limits are available in the complete benchmark report.
Disclosure: GrackerAI publishes this research and sells AI search visibility measurement for the category it covers. The study measured how AI engines describe vendors. It did not test, evaluate, or rank any vendor's product, and no vendor paid for or requested placement.