Example engagement · Cybersecurity: managed security services provider (MSSP)
AEO audit for a managed security services provider
A hypothetical managed security services provider, used to show how AEO HQ's audit would run in cybersecurity: buyer prompts, crawler and firewall checks, security and compliance claims, and the report. No results.
An example engagement for a hypothetical company, showing how the audit runs and what it delivers. It is not a client result.
Industry guide: SEO, AEO, and GEO for cybersecurity and IT services
The company
| Item | Profile (hypothetical) |
|---|---|
| Services | 24/7 managed detection and response (MDR) on clients' endpoint tools, SIEM (security information and event management) operations, vulnerability management, incident response retainers, virtual CISO, and compliance readiness |
| Size | About 140 employees; a primary and a backup security operations center (SOC) in two U.S. cities |
| Clients | About 300 companies with 200 to 2,500 employees, in manufacturing, healthcare, financial services, and the defense supply chain |
| Buyers | IT directors, CIOs, and CFOs, often prompted by a cyber insurance renewal, an incident, or a customer's security questionnaire |
| Credentials | A SOC 2 Type II report; an ISO/IEC 27001 certificate from an accredited certification body; Registered Practitioner Organization (RPO) status with the Cyber AB; business associate agreements for healthcare clients |
| How buyers find it | Referrals from IT managed service providers, insurance brokers, and endpoint vendors' partner directories; peer groups; Gartner Peer Insights, G2, and Clutch; Reddit threads; search |
| Current marketing | Service pages; 14 near-identical "managed SOC in [city]" pages for cities without an office; case studies with client logos; a gated library of incident-response guides; claims such as "stops 100% of ransomware," "15-minute response," "CMMC certified," and "HIPAA-compliant MDR" |
Technology buyers use assistants but check them. In a TrustRadius survey of 1,862 technology buyers, 63% used AI during their purchase, and 94% of those fact-check its answers at least some of the time (July 2026; the publisher runs a review platform). No primary survey was found on how mid-market companies choose an MSSP.
The questions buyers ask assistants
The panel follows AEO HQ's measurement design: 40 buyer intents, each written three ways (120 unbranded prompts), plus 20 branded prompts. Prompts that ask for a provider name the region the company serves. Each prompt runs three times a week on each of the four assistants the audit measures (ChatGPT, Perplexity, Gemini, and Google AI Overviews), in a new chat with a clean session; the ten most important prompts run eight times a week. Results are reported as rates with error ranges, because ChatGPT and Google's AI returned the same list of brands less than once in 100 repeated runs (vendor study; 2,961 runs). The table shows 13 of the 140 prompts.
| Intent | Example prompt (illustrative) | What a correct answer needs from the company |
|---|---|---|
| Discovery | "Best managed security service provider for a 500-person manufacturer in [region]" | A page on whom the company serves, with checkable facts |
| Discovery | "MSSP vs MDR vs SOC as a service: what's the difference?" | A plain explainer that defines each term |
| Discovery | "Managed SOC providers that support Microsoft Sentinel and Defender for Endpoint" | Supported tools, and what "supported" means |
| Compliance | "Who can help us prepare for CMMC Level 2?" | An accurate statement of the company's CMMC role |
| Compliance | "Do we need SOC 2 or ISO 27001 to sell to enterprise customers?" | An explainer that separates reports from certificates |
| Compliance | "HIPAA security risk analysis provider for a clinic group" | A service page with scope and deliverables |
| Cost | "How much does managed detection and response cost per endpoint?" | A published pricing model |
| Evaluation | "Questions to ask an MSSP before signing a contract" | Published service-level definitions |
| Evaluation | "What response time should a managed SOC commit to?" | Response times that match the contract |
| Incident | "What should we do in the first hour of a ransomware attack?" | A dated guide by a named, credentialed author, in HTML |
| Branded | "Is [brand]'s SOC staffed in-house around the clock?" | Staffing facts for the SOC |
| Branded | "Is [brand] a CMMC C3PAO?" | The correct answer: an RPO, not an assessor |
| Branded | "[Brand] reviews" | Review profiles on Gartner Peer Insights, G2, and Clutch |
How the assistants reach the company
An assistant can cite a page through search only after its search system has crawled and indexed it. The diagrams show the documented routes; how AI assistants find and cite sources has the details. For a security company, the firewall matters as much as robots.txt:
- Google lists making sure crawling is allowed "in robots.txt, and by any CDN or hosting infrastructure" among the SEO fundamentals that still matter for its AI features, and Microsoft says Bing and Copilot "rely on the same core crawling, indexing, and ranking foundation as traditional search".
- OpenAI says that, to be eligible, a site's host or CDN must allow traffic from its published searchbot IP addresses. Perplexity recommends allowing PerplexityBot in robots.txt "and permitting requests from our published IP ranges," and gives firewall rules that match both user agent and IP. Anthropic publishes a list of the IP addresses its crawlers use.
Search-engine routes to the company
Google Search
- 01GooglebotMust pass robots.txt and CDN rules
- Service pages
- Trust page
- Guides
- SLA terms
- 02Google indexIndexed pages eligible for a snippet
- 03AI Overviews, AI ModeLink to indexed, snippet-eligible pages
Microsoft
- 01BingbotFinds pages through sitemaps and IndexNow
- 02Bing indexShared by Bing search and Copilot
- 03Microsoft CopilotBuilt on Bing's crawling and index
Assistant crawlers and indexes
OpenAI
- 01OAI-SearchBotAllow in robots.txt and at the CDN
- 02OpenAI index + partnersSearch partners include Microsoft
- 03ChatGPT searchRewrites queries; placement is not guaranteed
Anthropic
- 01Claude-SearchBotIPs listed at claude.com/crawling/bots.json
- 02Brave Search + own indexBrave's crawler follows Googlebot's rules
- 03Claude web searchSearches when facts are current or specific
Perplexity
- 01PerplexityBotMatch user agent and published IP ranges
- 02Perplexity indexNo third-party index documented
- 03Perplexity answersSurface and link the pages used
Third-party sources carry weight. In 680 million citations studied by a visibility-tracking vendor, Gartner was among the ten most-cited domains on Google AI Overviews and Perplexity, and G2 on ChatGPT and Perplexity. In an SEO agency's study of about 1,000 decision-stage prompts, Reddit appeared in about 62% of responses. Clutch launched an app inside ChatGPT in April 2026. Google's results are a weak guide to AI answers for local services: for IT support, the domains cited by Google and by a web-enabled AI engine overlapped by 0.1% (preprint). The first two studies come from companies that sell related services.
What the audit checks
Access, pages, and trust signals
- Crawler rules. robots.txt is read per crawler, since a crawler follows the group that names it and uses the
*group only when none does. Search crawlers are checked apart from training crawlers, and Anthropic tells site owners to repeat opt-out rules "for every subdomain". - Firewall and CDN. Bot-management rules are exported and tested against each crawler's user agent and published IP list.
- Facts in HTML. In Vercel's December 2024 data, none of the major AI crawlers rendered JavaScript, and Microsoft advises against relying on PDFs for core information. SOC staffing, supported tools, and service levels belong in page text, not in gated guides.
- City pages. Google's spam policies name pages "targeted at specific regions or cities that funnel users to one page" as doorway abuse. For its Business Profile, a service-area business should hide its address if it does not serve customers there, with a service area generally no more than about two hours' drive.
- Trust signals. Google's rater guidelines include "safety online" within "YMYL Health or Safety", so threat advisories and guides should carry a named, credentialed author and a date.
- Profiles. Gartner Peer Insights, G2, Clutch, and endpoint vendors' partner directories are compared with one fact sheet.
Security and compliance claims
Measurement setup
GA4 has a default AI Assistant channel, but links from Claude's app carry no referrer. The audit checks that the contact form asks "How did you hear about us?" with AI assistants as options and stores the answer in the CRM, and that the web logs the company already collects can be filtered by crawler user agent.
Sample findings
These are sample findings for the hypothetical company, showing the form a finding takes. They describe no real company, and nothing in them was measured.
| # | Finding (sample) | Evidence to collect | Impact | Effort | Owner |
|---|---|---|---|---|---|
| 1 | The CDN's bot rule challenges all unverified bots, including OAI-SearchBot, Claude-SearchBot, and PerplexityBot | Rule export; firewall logs; published IP lists | High: crawlers cannot fetch pages | Low | Security engineering, web team |
| 2 | robots.txt blocks ClaudeBot and Claude-SearchBot in one "AI" group, though the aim was to opt out of training | robots.txt; leadership's decision | High for Claude | Low | Web team; leadership decides |
| 3 | "Stops 100% of ransomware" appears on the home page with no test data | Test reports; incident records | High: an absolute performance claim | Low to rewrite | Marketing, SOC director, counsel |
| 4 | The defense page says "CMMC certified" and "we certify you for CMMC" | Cyber AB Marketplace listing | High: misstates the company's role | Low | Compliance lead, marketing |
| 5 | "ISO 27001 certified by ISO" appears with the ISO logo, and the certification body is not named | Certificate and scope statement | Medium | Low | Compliance lead |
| 6 | A "HIPAA-compliant MDR" badge sits on the healthcare page | Business associate agreement template | Medium | Low | Marketing, counsel |
| 7 | The site says "15-minute response," but the contract sets 15 minutes only for critical alerts | Service-level schedule; SOC metrics | Medium | Low | SOC director, marketing |
| 8 | 14 "managed SOC in [city]" pages differ only by city name | Page list; text comparison | Medium: doorway risk | Medium | Marketing, web team |
| 9 | SOC staffing, supported tools, and incident-response guidance exist only in gated PDFs | Page and form audit | Medium | Medium | Marketing |
| 10 | Case studies show client logos without recorded permission, and one quotes a client that received a service credit | Permission and credit records | Medium: undisclosed material connection | Low | Customer success, marketing |
| 11 | Gartner Peer Insights and G2 list an old service name and address; the Clutch profile is unclaimed | Profile exports | Medium | Low | Marketing |
The deliverable
The report has nine parts, followed by a readout call.
- Summary. Scope, dates, assistants tested, and the ten fixes to make first.
- Method. The full panel, session controls, run counts, matching rules, and statistics.
- Baseline measurement. For each assistant: mention rate, citation rate, share of voice against named competitors, and accuracy on branded prompts, each with a 95% interval, plus the cited domains sorted into the company's pages, review sites, forums, and publishers. No pooled score and no rank.
- Access report. A table by crawler of robots.txt status, firewall and CDN outcome, and index coverage, with the rule changes to make through the company's own change control.
- Claims register. Each claim, where it appears, the rule, the evidence on file, and suggested wording for counsel's review. AEO HQ flags; it gives no legal or compliance advice.
- Third-party profiles. Fact mismatches across Gartner Peer Insights, G2, Clutch, and partner directories.
- Content gaps. Each intent mapped to a page or marked as a gap.
- Priority fix list and measurement plan. Every finding with impact, effort, owner, and evidence, and the plan below.
- Run log. Every answer and citation from the baseline, as a spreadsheet.
Measurement plan
The plan follows how to measure AI visibility: rates use Wilson intervals, which suit small samples, and a change counts only when the interval for the difference excludes zero.
| Metric | Method | Frequency | Tool |
|---|---|---|---|
| Mention rate on unbranded prompts, per assistant | Share of runs naming the company; Wilson interval; cluster bootstrap by intent | Weekly runs; 4-week windows | Tracking tool or spreadsheet run log |
| Citation rate and cited domains | Share of runs citing a company page; domains sorted by type | Same | Same |
| Share of voice | Company mentions divided by mentions of 5 to 10 named MSSPs | Same | Same |
| Accuracy | 20 branded prompts graded against the fact sheet: SOC staffing, CMMC role, reports, service levels | Every 4 weeks | Run log and fact sheet |
| Crawler access | Requests and blocks by user agent and IP list | Weekly | CDN and firewall logs |
| AI Overviews and AI Mode impressions | Generative AI performance report, which counts impressions, not clicks (opens in a new tab) | Monthly | Search Console |
| Copilot citations | AI Performance report (opens in a new tab) | Monthly | Bing Webmaster Tools |
| AI referral visits and contact requests | AI Assistant channel plus a custom channel, with contact requests as key events | Monthly | GA4 |
| Pipeline by self-reported source | Form answer stored on the contact and the deal | Monthly | CRM |
Engagement timeline
The pricing page gives the audit's current delivery time; this example assumes about two weeks from completed intake.
| Week | Activities |
|---|---|
| Intake | Read-only access to Search Console, Bing Webmaster Tools, GA4, the site, exports of CDN and firewall bot rules, and a CRM report; the fact sheet; 5 to 10 competitors; a named compliance lead |
| Week 1 | Crawl and access tests, including the firewall; claims register built from the site, case studies, and profiles; panel drafted, reviewed, and frozen; baseline runs start |
| Week 2 | Runs finish; coding and grading; findings ranked; claims register sent to counsel; report and readout call |
| After delivery | Rule changes go through the company's change control; the company runs the measurement plan |
Fix and measure loop
Fix
- 01Claims hygieneCounsel approves new wording
- SOC 2 report
- ISO certificate
- CMMC role
- Service levels
- 02Access fixesrobots.txt, firewall, and CDN bot rules
- 03Page fixesFacts in HTML; city pages consolidated
- 04Profile fixesGartner Peer Insights, G2, and Clutch
Measure
- 01Same panelFrozen prompts on the same four assistants
- 024-week windowRates per assistant with 95% intervals
- 03Compare windowsReport a change only if the interval excludes 0
- Prompts
- 140
- Assistants run
- 4
- Baseline window
- 2 weeks
- Re-measure window
- 4 weeks
What this example does not show
- Results. No rates, citations, traffic, or pipeline figures, because the company does not exist. No study has measured how long changes like these take to show up in AI answers.
- Real prompts. A real panel comes from sales calls, security questionnaires, and Search Console queries.
- Legal conclusions. The claims table summarizes rules and cases; counsel decides. The CMMC program was under review on 27 September 2026 and may change.
- Evidence specific to MSSPs. The buyer survey covers technology purchases in general, and the citation studies come from companies that sell related services.
- Every assistant. Runs cover four assistants. Copilot and Google AI Mode appear only through Microsoft's and Google's reports, and Claude only through logs and referrals.
Next step
The audit's current scope, price, and delivery time are on the pricing page. The cybersecurity industry page covers AEO for security companies more broadly, and the methodology page gives the full measurement design.