| Rank | Brand | Top of Mind | Top of Model | Composite Score |
|---|---|---|---|---|
| 1 | CrowdStrike | 92.3 | 68.3 | 80.3 |
| 2 | SentinelOne | 66.4 | 70.0 | 68.2 |
| 3 | Palo Alto | 67.7 | 63.3 | 65.5 |
| 4 | Microsoft | 70.3 | 60.0 | 65.2 |
| 5 | 38.3 | 86.7 | 62.5 | |
| 6 | Red Canary | 28.7 | 80.0 | 54.4 |
| 7 | Sophos | 46.9 | 60.0 | 53.5 |
| 8 | Arctic Wolf | 44.4 | 61.7 | 53.0 |
| 9 | Expel | 27.3 | 75.0 | 51.1 |
| 10 | Unit 42 | 24.5 | 75.0 | 49.7 |
| 11 | Huntress | 23.0 | 75.0 | 49.0 |
| 12 | NIST | 0.3 | 95.0 | 47.7 |
| 13 | Splunk | 27.0 | 66.7 | 46.8 |
| 14 | SANS | 3.2 | 88.3 | 45.8 |
| 15 | Have I Been Pwned? | 5.0 | 85.0 | 45.0 |
| 16 | Corelight | 7.3 | 81.7 | 44.5 |
| 17 | MITRE | 0.6 | 88.3 | 44.5 |
| 18 | Rapid7 | 29.7 | 58.3 | 44.0 |
| 19 | eSentire | 27.9 | 60.0 | 43.9 |
| 20 | CISA | 4.5 | 83.3 | 43.9 |
| 21 | Black Hills Information Security | 1.1 | 86.7 | 43.9 |
| 22 | The DFIR Report | 0.4 | 86.7 | 43.5 |
| 23 | Dragos | 2.9 | 83.3 | 43.1 |
| 24 | Recorded Future | 12.8 | 73.3 | 43.1 |
| 25 | NCSC | 0.4 | 85.0 | 42.7 |
| 26 | Tines | 1.4 | 83.3 | 42.4 |
| 27 | Trend Micro | 30.3 | 53.3 | 41.8 |
| 28 | Cisco | 1.1 | 81.7 | 41.4 |
| 29 | Coveware | 0.4 | 81.7 | 41.0 |
| 30 | Wiz | 5.1 | 76.7 | 40.9 |
| 31 | Zscaler | 11.8 | 70.0 | 40.9 |
| 32 | Velociraptor | 0.8 | 80.0 | 40.4 |
| 33 | SpecterOps | 0.5 | 80.0 | 40.3 |
| 34 | Elastic | 15.4 | 65.0 | 40.2 |
| 35 | Security Onion | 0.3 | 80.0 | 40.2 |
| 36 | Sygnia | 1.1 | 78.3 | 39.7 |
| 37 | Secureworks | 22.0 | 56.7 | 39.3 |
| 38 | Cyber Security Agency of Singapore | 0.3 | 78.3 | 39.3 |
| 39 | Active Countermeasures | 1.1 | 76.7 | 38.9 |
| 40 | U.S. Government Accountability Office | 0.5 | 76.7 | 38.6 |
| 41 | ZDI | 0.4 | 76.7 | 38.6 |
| 42 | ThreatLocker | 3.4 | 73.3 | 38.3 |
| 43 | Material Security | 1.1 | 75.0 | 38.0 |
| 44 | Kroll | 2.6 | 73.3 | 38.0 |
| 45 | Cloudflare | 0.8 | 75.0 | 37.9 |
| 46 | Silverfort | 0.4 | 75.0 | 37.7 |
| 47 | Vectra AI | 5.4 | 70.0 | 37.7 |
| 48 | Axonius | 0.3 | 75.0 | 37.7 |
| 49 | Claroty | 0.3 | 75.0 | 37.7 |
| 50 | ExtraHop | 0.3 | 75.0 | 37.7 |
| 51 | osquery | 0.3 | 75.0 | 37.7 |
| 52 | Krebs Stamos Group | 1.4 | 73.3 | 37.4 |
| 53 | Stamus Networks | 0.5 | 73.3 | 36.9 |
| 54 | Schneier Security | 0.3 | 73.3 | 36.8 |
| 55 | CyberArk | 1.7 | 71.7 | 36.7 |
| 56 | Tenable | 1.1 | 71.7 | 36.4 |
| 57 | Orca | 1.1 | 71.7 | 36.4 |
| 58 | Rubrik | 0.9 | 71.7 | 36.3 |
| 59 | Sublime Security | 0.8 | 71.7 | 36.2 |
| 60 | Tanium | 0.8 | 71.7 | 36.2 |
| 61 | Varonis | 0.6 | 71.7 | 36.1 |
| 62 | Bitdefender | 15.5 | 56.7 | 36.1 |
| 63 | Visa | 0.4 | 71.7 | 36.1 |
| 64 | IBM | 1.8 | 70.0 | 35.9 |
| 65 | Taosecurity | 1.3 | 70.0 | 35.7 |
| 66 | Proofpoint | 1.2 | 70.0 | 35.6 |
| 67 | XM Cyber | 1.2 | 70.0 | 35.6 |
| 68 | Alston & Bird | 1.0 | 70.0 | 35.5 |
| 69 | Forrester | 1.0 | 70.0 | 35.5 |
| 70 | Fortinet | 9.1 | 61.7 | 35.4 |
| 71 | Wazuh | 0.6 | 70.0 | 35.3 |
| 72 | Check Point | 0.4 | 70.0 | 35.2 |
| 73 | Cyber Threat Alliance | 0.4 | 70.0 | 35.2 |
| 74 | Team T5 | 0.4 | 70.0 | 35.2 |
| 75 | FireEye | 18.2 | 51.7 | 34.9 |
| 76 | Sysdig | 1.0 | 68.3 | 34.7 |
| 77 | The Crypsis Group | 0.9 | 68.3 | 34.6 |
| 78 | WithSecure | 5.9 | 63.3 | 34.6 |
| 79 | Pentera | 0.6 | 68.3 | 34.5 |
| 80 | Silent Push | 0.6 | 68.3 | 34.5 |
| 81 | TheHive | 0.6 | 68.3 | 34.5 |
| 82 | Attivo Networks | 0.4 | 68.3 | 34.4 |
| 83 | Flare | 0.3 | 68.3 | 34.3 |
| 84 | Flashpoint | 0.3 | 68.3 | 34.3 |
| 85 | AttackIQ | 1.4 | 66.7 | 34.0 |
| 86 | GuidePoint Security | 1.4 | 66.7 | 34.0 |
| 87 | Morphisec | 1.1 | 66.7 | 33.9 |
| 88 | Bugcrowd | 1.0 | 66.7 | 33.8 |
| 89 | Index Engines | 1.0 | 66.7 | 33.8 |
| 90 | Critical Start | 2.4 | 65.0 | 33.7 |
| 91 | ReliaQuest | 8.9 | 58.3 | 33.6 |
| 92 | Azeria Labs | 0.4 | 66.7 | 33.6 |
| 93 | Zerto | 0.4 | 66.7 | 33.6 |
| 94 | ANY.RUN | 0.3 | 66.7 | 33.5 |
| 95 | NCC Group | 0.3 | 66.7 | 33.5 |
| 96 | Netskope | 0.3 | 66.7 | 33.5 |
| 97 | ThreatConnect | 3.4 | 63.3 | 33.4 |
| 98 | Swimlane | 3.4 | 63.3 | 33.3 |
| 99 | JupiterOne | 1.1 | 65.0 | 33.0 |
| 100 | SentinelLabs | 0.9 | 65.0 | 32.9 |
Cybersecurity category definition
The TOM Index defines Cybersecurity as brands whose core offering is protecting organizations from threats: threat detection and response, security operations, identity, and the platforms that defend data, networks, and endpoints.
We score brands here on how clearly buyers and AI systems recognize them as a security authority specifically, which is why a brand can score very differently in Cybersecurity than in a category like Infrastructure or Networking. A brand with a credible security portfolio can appear in both, scored independently on each.
Category reality
In Cybersecurity, visibility is shaped by trust signals, subcategory precision, and defensible proof. Buyers are filtering noise at speed, and the margin for error is low.
The category never stops moving. New entrants arrive constantly. Incumbents reposition. Everyone claims AI, platform, and prevention. Buying committees, including CISOs, SecOps leads, IT, risk, and procurement, have developed fast, skeptical heuristics for sorting signal from noise.
They increasingly use AI-mediated research to shortlist faster. If you are not clearly placed and easy to defend internally, you are filtered out before sales knows the deal existed.
In this category, being broadly credible is not enough. You have to be specifically trustworthy.
How your brand gets evaluated
Buying committees and AI systems judge your brand's credibility, category fit, and proof quality fast. Often before your sales team is aware the evaluation has started. Here's what's shaping those impressions:
Subcategory Placement: Can AI place you accurately in the right buying bucket? XDR/MDR, SIEM, IAM/PAM, endpoint, network security? Imprecise placement means you get compared to the wrong competitors, or not compared at all.
Persona Recognition: Does your message reach CISO, SecOps, IT, risk, compliance, and procurement, each with different concerns, or does it only land with one of them?
Shortlist Surfacing: When a security team searches for top cybersecurity vendors, are you named distinctly, or buried behind louder, less precise competitors?
Side-by-Side Evaluation: When the committee compares you against category leaders or emerging challengers, do your differentiators survive the summary?
Leadership Visibility: Are your executives and practitioners visible as credible operators with relevant perspective, not just as brand spokespeople?
Narrative Consistency: Can your brand evolve product and positioning without confusing the market every quarter?
Trustworthiness Under Scrutiny: When a risk-averse procurement team digs, does your story hold, or does it raise more questions than it answers?

