Skip to content

The TOM 100: Cybersecurity

The 100 Cybersecurity brands buyers and AI notice first. Index data updated July 2026.

Rank Brand Top of Mind Top of Model Composite Score
1 CrowdStrike 88.3 66.7 77.5
2 SentinelOne 71.9 68.3 70.1
3 Microsoft 67.5 63.3 65.4
4 Palo Alto 64.5 58.3 61.4
5 Google 42.9 78.3 60.6
6 Red Canary 35.3 75.0 55.1
7 Expel 29.5 76.7 53.1
8 Arctic Wolf 45.4 53.3 49.4
9 Huntress 33.2 63.3 48.2
10 Sophos 50.4 45.0 47.7
11 Splunk 25.4 70.0 47.7
12 Wireshark 0.7 90.0 45.4
13 SANS 0.8 88.3 44.5
14 MITRE 1.9 86.7 44.3
15 VirusTotal 4.6 83.3 44.0
16 Black Hills Information Security 1.2 86.7 43.9
17 National Cyber Security Centre 0.3 86.7 43.5
18 TrustedSec 3.4 81.7 42.6
19 Unit 42 23.4 61.7 42.5
20 SpecterOps 2.6 81.7 42.1
21 IANS Research 0.8 81.7 41.3
22 Have I Been Pwned 0.3 81.7 41.0
23 Rapid7 26.1 55.0 40.6
24 Mandiant Consulting 0.9 80.0 40.4
25 Dragos 10.5 70.0 40.2
26 eSentire 27.1 53.3 40.2
27 Velociraptor 2.8 76.7 39.7
28 Arkime 0.6 78.3 39.5
29 Zeek 0.6 78.3 39.5
30 Cribl 0.3 78.3 39.3
30 Semperis 0.3 78.3 39.3
32 Wiz 6.8 71.7 39.3
33 CISA 1.2 76.7 39.0
34 Volatility 1.1 76.7 38.9
35 Tines 2.6 75.0 38.8
36 MS-ISAC 0.6 76.7 38.6
37 Elastic 17.1 60.0 38.5
38 Recorded Future 10.3 66.7 38.5
39 Nextron Systems 2.6 73.3 38.0
40 Coveware 2.4 73.3 37.9
41 Cybersecurity and Infrastructure Security Agency 0.8 75.0 37.9
42 Fortinet 18.4 56.7 37.5
43 Zscaler 8.2 66.7 37.4
44 Corelight 4.8 70.0 37.4
45 MISP 1.4 73.3 37.3
46 Trend Micro 26.0 48.3 37.1
47 Suricata 0.8 73.3 37.0
48 Shodan 0.6 73.3 37.0
49 Kroll 10.6 63.3 37.0
50 Nextron 0.4 73.3 36.9
51 TheHive 1.2 71.7 36.5
52 Picus Security 1.2 71.7 36.4
53 Exabeam 15.5 56.7 36.1
54 Axonius 0.3 71.7 36.0
54 Illumio 0.3 71.7 36.0
56 Abnormal Security 1.2 70.0 35.6
57 Silverfort 0.8 70.0 35.4
58 John Reed Stark Consulting LLC 0.4 70.0 35.2
59 Nozomi Networks 0.4 70.0 35.2
60 XM Cyber 0.3 70.0 35.2
61 Tanium 1.4 68.3 34.9
62 Sygnia 1.3 68.3 34.8
63 LMG Security 1.3 68.3 34.8
64 Autopsy 1.0 68.3 34.7
65 Bitdefender 19.2 50.0 34.6
66 Applied Network Defense 0.7 68.3 34.5
67 Timesketch 0.6 68.3 34.5
68 ReliaQuest 8.9 60.0 34.5
69 ThreatLocker 1.4 66.7 34.0
70 Cisco 21.4 46.7 34.0
71 ExtraHop 4.3 63.3 33.8
72 Stroz Friedberg 0.9 66.7 33.8
73 Vectra AI 9.2 58.3 33.8
74 Cloudflare 2.2 65.0 33.6
75 Rubrik 3.8 63.3 33.6
76 Joe Sandbox 0.4 66.7 33.5
77 Panther Labs 2.0 65.0 33.5
78 watchTowr 1.3 65.0 33.2
79 Varonis 1.0 65.0 33.0
80 Morphisec 2.6 63.3 33.0
81 Claroty 0.9 65.0 32.9
81 GuidePoint Security 0.9 65.0 32.9
83 The Sleuth Kit 0.9 65.0 32.9
84 OpenCTI 0.8 65.0 32.9
85 Stellar Cyber 17.5 48.3 32.9
86 Krebs Stamos Group 2.1 63.3 32.7
87 Flashpoint 0.4 65.0 32.7
87 Signal Sciences 0.4 65.0 32.7
87 Veeam 0.4 65.0 32.7
90 Armis 0.3 65.0 32.7
91 Aqua 1.9 63.3 32.6
92 LimaCharlie 1.7 63.3 32.5
93 Torq 4.8 60.0 32.4
94 FTI Consulting 1.4 63.3 32.4
95 Praetorian 1.2 63.3 32.3
96 Darktrace 10.9 53.3 32.1
97 Cado Security 0.9 63.3 32.1
97 Hunters.ai 0.9 63.3 32.1
97 Kroll Cyber and Data Resilience 0.9 63.3 32.1
100 IBM 4.1 60.0 32.1

The TOM 100 shows the rankings.

Your free Snapshot shows the why.

Get your brand's full 8-signal breakdown behind both scores and the same breakdown for your category's top 3, so you can see exactly where the leaders are winning. Free, even if you're not in the TOM 100.

TOM_Index_

Cybersecurity category definition

The TOM Index defines Cybersecurity as brands whose core offering is protecting organizations from threats: threat detection and response, security operations, identity, and the platforms that defend data, networks, and endpoints.

We score brands here on how clearly buyers and AI systems recognize them as a security authority specifically, which is why a brand can score very differently in Cybersecurity than in a category like Infrastructure or Networking. A brand with a credible security portfolio can appear in both, scored independently on each.

Category reality

In Cybersecurity, visibility is shaped by trust signals, subcategory precision, and defensible proof. Buyers are filtering noise at speed, and the margin for error is low.

The category never stops moving. New entrants arrive constantly. Incumbents reposition. Everyone claims AI, platform, and prevention. Buying committees, including CISOs, SecOps leads, IT, risk, and procurement, have developed fast, skeptical heuristics for sorting signal from noise.

They increasingly use AI-mediated research to shortlist faster. If you are not clearly placed and easy to defend internally, you are filtered out before sales knows the deal existed.

In this category, being broadly credible is not enough. You have to be specifically trustworthy.

How your brand gets evaluated

Buying committees and AI systems judge your brand's credibility, category fit, and proof quality fast. Often before your sales team is aware the evaluation has started. Here's what's shaping those impressions:

icon-check-circle-black-1

Subcategory Placement: Can AI place you accurately in the right buying bucket? XDR/MDR, SIEM, IAM/PAM, endpoint, network security? Imprecise placement means you get compared to the wrong competitors, or not compared at all.

icon-check-circle-black-1

Persona Recognition: Does your message reach CISO, SecOps, IT, risk, compliance, and procurement, each with different concerns, or does it only land with one of them?

icon-check-circle-black-1

Shortlist Surfacing: When a security team searches for top cybersecurity vendors, are you named distinctly, or buried behind louder, less precise competitors?

icon-check-circle-black-1

Side-by-Side Evaluation: When the committee compares you against category leaders or emerging challengers, do your differentiators survive the summary?

icon-check-circle-black-1

Leadership Visibility: Are your executives and practitioners visible as credible operators with relevant perspective, not just as brand spokespeople?

icon-check-circle-black-1

Narrative Consistency: Can your brand evolve product and positioning without confusing the market every quarter?

icon-check-circle-black-1

Trustworthiness Under Scrutiny: When a risk-averse procurement team digs, does your story hold, or does it raise more questions than it answers?

Perspectives shaping what's next