Skip to content
AEO HQ

Industry guide · Industries

SEO, AEO, and GEO for cybersecurity and IT services

SEO, AEO, and GEO for cybersecurity vendors and MSPs: what buyers are told to check, which sources AI cites, the rules on security claims, and what to measure.

By , founder of AEO HQ

Published · Updated

SEO, answer engine optimization (AEO), and generative engine optimization (GEO) for cybersecurity and IT services are the work of making a security vendor's or IT service provider's facts easy for search engines and AI assistants to find, cite, and state correctly: what the product or service does, what it has been tested or audited against, how it handles vulnerabilities and incidents, and where it is offered. AEO and GEO rest on SEO, because assistants that search the web draw their sources from search indexes. For security companies, the research points to four additions: claims about performance, AI, and compliance that are worded exactly and backed by evidence, because regulators have acted on exactly these claims; public pages for the facts that government agencies tell buyers to check; accurate profiles on the review platforms, marketplaces, and communities that answers cite; and measurement per assistant and, for managed service providers, per city.

Many security vendors sell software, so most of SEO, AEO, and GEO for B2B SaaS companies applies to them, including its sections on pricing pages and comparison pages. This page covers what differs for security and IT services: the rules on security, AI, and compliance claims; the questions U.S. and allied cybersecurity agencies tell buyers to ask; and local search for managed service providers (MSPs).

This page is part of AEO HQ's guides by industry. It covers SEO, AEO, and GEO together, as one practice that AEO HQ calls SEO+. Google's guidance on outside services uses both names for the same work, referring to "AI experiences (sometimes called AEO for 'answer engine optimization' or GEO for 'generative engine optimization')" (opens in a new tab) (official documentation). AEO HQ's keyword data showed no AEO or GEO queries for cybersecurity, MSPs, or IT services, so this page is not built around a measured query. It is built from evidence on how technology buyers use AI, which sources AI answers cite, the guidance government agencies give to buyers, and the regulators' own documents. Facts link to their sources, evidence strength is labeled where it matters, and recommendations are marked as ours. Much of the evidence on AI citations comes from companies that sell marketing services or data, and the text says so each time. The summary of rules is not legal advice.

Scope and definitions

This page is for marketing, product marketing, and compliance staff at U.S. cybersecurity vendors, MSPs, managed security service providers (MSSPs), and IT services firms, and for the agencies that work for them. It covers unpaid visibility in search results and AI answers, and the pages, profiles, and reviews behind it. The rules and program terms covered are U.S. ones, as read on 27 September 2026: FTC law and policy on deceptive claims, substantiation, reviews, and endorsements; the FTC's guidance on HIPAA claims; the AICPA's terms for SOC logos; the Department of War's CMMC program; FedRAMP; CISA's Secure by Design pledge; and a False Claims Act settlement over cybersecurity representations. State laws and rules outside the United States are not covered.

How security and IT buyers use AI assistants

No survey found for this page is specific to cybersecurity buyers or to the businesses that hire MSPs. The closest evidence comes from surveys of technology and software buyers, most of them published by review platforms or marketing-software companies. The table gives each finding with its sample.

Security review is where deals slow down. Buyers who reach a shortlist through AI still have to clear their own security review, and the survey above names it as the biggest delay after selection. Our reading: public, specific security documentation answers the questions that a security review asks, and it is also what an assistant can retrieve and cite.

Limits. All of these figures are self-reported, and each publisher sells products or services to software vendors or marketers (our assessment). None of the surveys separates security products from other software, and no study found for this page describes how small and midsize businesses find or choose an MSP. The direction of the evidence is consistent (moderate); how well it transfers to security buying is unknown.

How assistants find and choose security vendors and IT providers

An assistant can answer from what its model learned in training, its parametric knowledge, or it can search the web and write from the pages it retrieves. Four findings describe security and IT questions:

Evidence on which sources AI answers cite for security and IT questions is thin, and all of it comes from companies with a commercial interest:

StudyWhat it foundMethod and strength
An AEO vendor's cybersecurity benchmark73% of cybersecurity vendors tested "received zero citations from ChatGPT when buyers asked for vendor recommendations in their category" (opens in a new tab)100 vendors, 250 prompts, six platforms, September 2025 to January 2026; the vendor calls its scores "directional benchmarks" (opens in a new tab), and its figure of 48% of ChatGPT citations from Wikipedia (opens in a new tab) matches another vendor's share of ChatGPT's top 10 cited sources (47.9%), not of all citations (7.8%) (see next row); weak
An AI-visibility vendor's citation countsGartner was among the 10 most-cited domains on Google AI Overviews (0.7% of citations) and Perplexity (1.0%); G2 on ChatGPT (1.1%) and Perplexity (0.6%); Reddit led Perplexity (6.6%); and Wikipedia made up 7.8% of ChatGPT's citations and 47.9% of the citations among its top 10 domains (opens in a new tab)680 million citations, August 2024 to June 2025; all topics; moderate for the ranking
An agency study of decision-stage promptsReddit appeared in about 62% of responses, YouTube in about 25%, and G2 in about 5% (opens in a new tab); comparison pages were the largest share of cited URL types, followed by "best tools" lists, while product pages and homepages appeared at single-digit rates (opens in a new tab)About 1,000 prompts across industries, January 29 to February 4, 2026; moderate
A services marketplace's ChatGPT appClutch launched an app inside ChatGPT that surfaces "verified profiles, review highlights, pricing signals, and real client feedback" for service providers (opens in a new tab)Product announcement, April 23, 2026; shows a route into ChatGPT, not how often it is used
An MSP marketing agency's observationDirectories such as Clutch, Cloudtango, Expertise, and UpCity appear in Google results for searches like "managed it services orlando" (opens in a new tab)Agency guide, updated January 2026; no counts; weak

Answers also change from one run to the next. When the same prompt was repeated, ChatGPT and Google's AI returned the same list of brands less than once in 100 runs, and Claude only slightly more often (opens in a new tab) (2,961 runs, November–December 2025; industry study; a co-investigator works for a tracking vendor). How ChatGPT, Gemini, Claude, Perplexity, and Copilot find and cite sources describes each assistant's index and crawlers.

The questions buyers ask, and what security marketers ask

Questions CISA tells software buyers to ask

CISA's Secure by Demand guide (August 2024) (opens in a new tab) gives organizations that buy software a list of questions for manufacturers and a list of artifacts to collect. It notes that buyers' due diligence often focuses "on the enterprise security measures of the manufacturers, such as by ensuring the manufacturers meet various compliance standards," and that "customers also need to focus on how a manufacturer approaches product security" (opens in a new tab). Each item below is a fact a vendor can publish and a buyer or an assistant can check. The right-hand column is our recommendation.

TopicWhat CISA tells buyers to ask or collectPublic page that answers it
Secure by Design pledge"Has the manufacturer taken CISA's Secure by Design Pledge? What progress reports has the manufacturer published in line with its commitments to the pledge?" (opens in a new tab)The date you signed and each progress report
Patching"How does the manufacturer make it simple for customers to install security patches?" (opens in a new tab)A security update policy
AuthenticationWhether standards-based single sign-on is supported "at no additional cost," whether multi-factor authentication is on "by default, and at no cost," and whether default passwords have been eliminated (opens in a new tab)A security features page, by plan
Classes of vulnerabilityWhich classes of vulnerability the manufacturer has systematically addressed, and whether it has a roadmap for the rest, such as a memory safe roadmap (opens in a new tab)A secure development page
Evidence of intrusionsSecurity logs in the baseline version of the product; for cloud and SaaS providers, logs retained "for at least six months at no additional charge" (opens in a new tab)Logging documentation, by plan
Software supply chainAn SBOM "in a standard, machine-readable format," and how open source components are vetted (opens in a new tab)An SBOM availability page
Vulnerability reportingAccurate CWE and CPE fields "in every CVE record," timely CVE records, and a published VDP "that authorizes testing by members of the public" (opens in a new tab)The VDP, security advisories, and a list of CVE records

Questions MSP customers are told to settle

A joint advisory from U.S., UK, Australian, Canadian, and New Zealand cybersecurity agencies tells MSP customers what their contracts should cover, and tells MSPs what to explain. The right-hand column is our recommendation.

TopicWhat the advisory saysPublic page that answers it
ScopeMSPs "should provide clear explanations of the services the customer is purchasing, services the customer is not purchasing, and all contingencies for incident response and recovery" (opens in a new tab)A service scope page that lists what is and is not included
ResponsibilitiesEach customer should ensure that its contract "specifies whether the MSP or the customer owns specific responsibilities, such as hardening, detection, and incident response" (opens in a new tab)A responsibilities table
Multi-factor authentication"Contracts should also require MFA to be enforced on all MSP accounts used to access customer environments" (opens in a new tab)A security practices page
LogsThe agencies recommend that all organizations "store their most important logs for at least six months" (opens in a new tab)Logging and monitoring terms
Backups and recoveryCustomers should ensure their contracts include backup services that meet their resilience and disaster recovery requirements (opens in a new tab)Backup and recovery terms
Incident notice"contracts should detail how and when MSPs notify the customer of an incident affecting the customer's environment" (opens in a new tab)An incident notification commitment
SubcontractorsCustomers should understand the supply chain risk of their MSP, "including risk associated with third-party vendors or subcontractors" (opens in a new tab)A list of subcontractors and core tools
Offboarding"disabling MSP accounts can be overlooked when a contract terminates" (opens in a new tab)An offboarding process

Questions buyers put to assistants

The example wording below is illustrative. The evidence column shows why each kind of question matters.

Question typeExample wording (illustrative)EvidencePage that should answer it
Shortlist"Best endpoint detection for a 300-person company"The benchmark above used prompts of this form: ["What are the best [category] tools for [use case]?"](https://gracker.ai/data-and-research-reports/state-of-ai-search-visibility-cybersecurity-2026)Category and use-case pages; review profiles
Head-to-head"[Vendor A] vs [Vendor B] for a Microsoft 365 environment"Comparing vendors' strengths and weaknesses is the most common use of AI chatbots in software research (41%) (opens in a new tab)Comparison pages; see the B2B SaaS guide
Compliance fit"Does [Vendor] have a SOC 2 report?" or "Is [Vendor] FedRAMP authorized?"IT security review is the biggest delay after a vendor is chosen (39%) (opens in a new tab)A trust center page with exact statuses and dates
Product security"Does [Product] support SSO on every plan?"CISA's questions aboveSecurity features and VDP pages
Local provider"Managed IT services near me""who are my local msps" appeared in search suggestions (AEO HQ's query research)Google Business Profile; a page for each area you actually serve
Scope and cost"What's included in managed cybersecurity services?"An MSP marketing agency gives "How much does managed IT support cost?" and "What's included in managed cybersecurity services?" (opens in a new tab) as typical questions (weak)A service scope and pricing page

What security and IT marketers ask about AEO

In AEO HQ's keyword data for the United States, pulled on 27 September 2026, no AEO or GEO query named cybersecurity, infosec, MSPs, managed service providers, or IT services. The pull was seeded with AEO and GEO terms, so demand worded differently may exist that it did not capture.

In AEO HQ's query research (Google and Bing suggestions, and forum thread titles, 27 September 2026), security and IT marketers' questions fell into the groups below. Four questions are FAQ headings on agency guides that appeared in the search results, one for cybersecurity companies (opens in a new tab) (December 2025) and one for MSPs (opens in a new tab) (January 2026), and are marked "FAQ heading." The seed "how to choose an msp" returned mostly unrelated Bing suggestions, a sign of little search demand for that wording.

What they want to knowWording seen in suggestions, headings, and thread titlesWhere this page answers it
Whom to hire"cybersecurity seo agency"; "b2b cybersecurity seo agency"; "msp seo agency"; "msp marketing companies"Frequently asked questions
How the two businesses differ"What Makes SEO in Cybersecurity Different From MSP SEO?" (FAQ heading)Frequently asked questions
Whether AI changes SEO"Is SEO Still Necessary in the Age of AI?" (FAQ heading); "Will AI Replace SEO?" (FAQ heading); "What is MSP AI Search?" (FAQ heading)Frequently asked questions
Whether SEO pays"SEO not worth it?"; "How often do you write SEO blogs? Does it work?"; "What's actually working in MSP marketing right now?"Frequently asked questions
Getting clients"how to get msp clients"; "how to find msp clients"Local search for MSPs; how to do it
Content in a technical field"Seo in cybersecurity industry - need tips"; "Cybersecurity content & marketing challenges"; "cybersecurity marketing strategy"Content that complies and still answers the question

Rules that limit security marketing claims

This section is not legal advice. It summarizes U.S. regulator documents and program terms read on 27 September 2026. Rules and program terms change, and CMMC and FedRAMP both changed in 2026. Before publishing, have counsel or compliance staff check every claim against the rules and contracts that apply to you.

Performance, AI, and privacy claims (FTC)

Rule or caseWhat it saysWhat it means for search and AI work
FTC substantiation policyAdvertisers must "have a reasonable basis for advertising claims before they are disseminated," and when an ad says "tests prove," "doctors recommend," or "studies show," the FTC expects at least the advertised level of substantiation (opens in a new tab)"Blocks 99.9% of attacks" or "independently tested" needs the test behind it, on file before the page goes live
Evolv Technologies (November 2024)The FTC alleged that a company whose AI-powered weapons scanners are used in schools, sports stadiums, and hospitals falsely claimed its scanners would detect all weapons and that its AI made screening more accurate, efficient, and cost-effective than metal detectors, and would cut labor costs by 70%; the proposed order bars misrepresentations about detection, accuracy and false alarm rates, "testing, or the results of any testing," and "any material aspect of its performance, including the use of algorithms, artificial intelligence, or other automated systems or tools" (opens in a new tab)The customers were organizations such as school systems, not individual consumers: the FTC acts on security and AI claims made to organizational buyers
Avast (February 2024)A security software maker agreed to pay $16.5 million after the FTC charged that it sold browsing data while promising its products would protect users from online tracking; the FTC's consumer protection director said Avast "promised users that its products would protect the privacy of their browsing data but delivered the opposite" (opens in a new tab)Privacy and protection promises must match what the product and the company actually do
AI claimsAnnouncing a 2024 enforcement sweep, the FTC's chair said its actions "make clear that there is no AI exemption from the laws on the books" (opens in a new tab), and one proposed order in that sweep would prohibit claims about a service's "ability to substitute for any professional service without evidence to back it up" (opens in a new tab)"Replaces your SOC analysts" and similar claims need evidence (our reading)
Commissioned tests and researchIn the FTC's Endorsement Guides, a company that paid for a test behind a "fastest" claim should disclose that relationship, and if the tester "is not a bona fide independent testing organization" or did not run valid tests, the claim is deceptive (opens in a new tab); the Guides also say a reasonable fee for a certification seal's evaluation is expected and need not be disclosed (opens in a new tab)Say who paid for any test or study you cite
Customer resultsAn ad in which a customer describes results on a key attribute will likely be read as showing what customers generally achieve; without support for that, the ad should disclose the generally expected performance, and a disclaimer such as "Results not typical" is not enough (opens in a new tab)Case studies with a single best result. The Guides speak of consumers; they do not say how this applies to business customers (our reading)
ComparisonsThe FTC's 1979 policy says comparative advertising, "when truthful and non-deceptive, is a source of important information to consumers," (opens in a new tab) and is evaluated like any other advertisingClaims about competitors' products need the same support as claims about your own

Compliance and certification claims

ClaimWhat the primary source saysWording to use instead (our recommendation)
"SOC 2 certified"The AICPA's SOC logos are designed to help service organizations communicate that they "have received a SOC report issued by a licensed, independent CPA" (opens in a new tab). The AICPA describes a report, not a certification (our reading)"We have received a SOC 2 report from [CPA firm] covering [period]." Name the report type and say how customers can request it
"HIPAA compliant," "HIPAA certified"The FTC tells companies: "don't make false or misleading claims that you are 'HIPAA Compliant,' 'HIPAA Secure,' 'HIPAA Certified' or the like" (opens in a new tab)Describe the specific safeguards and agreements you offer health care customers
"CMMC certified"On July 13, 2026, the Department of War suspended CMMC Phase II requirements; the program "is paused in Phase 1 and may only require self-assessments at two levels": Level 1 is an annual self-assessment against 15 requirements, and Level 2 a self-assessment every three years against the 110 requirements of NIST SP 800-171 Revision 2, with results entered in the Supplier Performance Risk System (SPRS) (opens in a new tab)State the level, whether it was a self-assessment or a third-party assessment, and the date
"We certify clients for CMMC"The Cyber AB says a Registered Practitioner Organization delivers a "non-certified advisory service," that such organizations are "consultative organizations or MSPs," and that they "do not conduct Certified CMMC Assessments" (opens in a new tab); assessments are conducted by CMMC Third-Party Assessment Organizations (C3PAOs) (opens in a new tab)"We help clients prepare for CMMC assessments"
"FedRAMP compliant," "FedRAMP equivalent"FedRAMP's Marketplace is "the authoritative place to confirm whether a cloud service offering has a FedRAMP designation" (opens in a new tab). FedRAMP's playbook says terms such as "FedRAMP Compliant" or "FedRAMP Equivalent" "are NOT certified by FedRAMP" (opens in a new tab) (legacy documentation, kept for reference during the move to FedRAMP's 2026 rules), and FedRAMP has released new certification designations (opens in a new tab)Use only the designation your Marketplace listing shows, in its exact words, with a link to the listing
"CISA-approved" or "CISA certified"CISA says the Secure by Design pledge "is voluntary and not legally binding" (opens in a new tab), that "CISA does not enforce nor verify adherence to the pledge," (opens in a new tab) and that a reference to a company on its pages "does not constitute or imply endorsement, recommendation, or favoring by CISA" (opens in a new tab)"We signed CISA's Secure by Design pledge on [date]. Our progress report: [link]"

Representations to government customers

In March 2025 a defense contractor agreed to pay $4.6 million to settle False Claims Act allegations over cybersecurity requirements in its Army and Air Force contracts; it admitted that it had reported a score of 104 for its implementation of NIST SP 800-171 controls when a consultant later put the score at −142, and that it had used an email host that did not meet security requirements equivalent to the FedRAMP Moderate baseline (opens in a new tab). The case concerned formal representations, not marketing. Our recommendation: keep public claims about your security posture consistent with what you report to government customers, so the two never contradict each other.

Reviews, endorsements, and community participation

RuleWhat it saysWhere it applies
FTC rule on consumer reviews and testimonials, in effect since October 21, 2024It prohibits fake reviews and testimonials, including AI-generated ones; incentives conditioned on a positive or negative review; undisclosed insider reviews; company-controlled "independent" review sites; and review suppression (opens in a new tab). FTC guidance says incentives are allowed when they do not require a particular sentiment, but failing to disclose them could violate the FTC Act, and asking only customers "whom we think are happy" "could violate the FTC Act" (opens in a new tab). In December 2025 the FTC warned 10 companies that violations can bring civil penalties of up to $53,088 per violation (opens in a new tab). The FTC's guidance does not say how the rule applies to reviews by business customers (our reading)Review campaigns on G2, Gartner Peer Insights, PeerSpot, Clutch, and Google
FTC Endorsement GuidesA connection between an endorser and a seller that might materially affect the weight or credibility of the endorsement, and that the audience would not expect, must be disclosed clearly and conspicuously; in the Guides' example, an employee who promotes the employer's product in an online community should disclose the relationship (opens in a new tab)Staff posting in r/cybersecurity, r/sysadmin, r/msp, and similar forums
Google Maps content policyMerchants may not offer "payment, discounts, free goods and/or services" for any review or selectively solicit positive reviews (opens in a new tab)Google reviews for MSPs and IT services firms

Chat assistants

If a chat assistant on your site serves people in the European Union, Article 50 of the EU AI Act applies from 2 August 2026, and AI systems that interact directly with people must be designed so that people are informed from the first interaction that they are dealing with an AI system, unless this is obvious (opens in a new tab). Our recommendation, wherever you sell: say that the assistant is AI, and answer questions about certifications, statuses, and incidents only from approved text.

Content that complies and still answers the question

Assistants favor specific, checkable facts. In lab trials, specifications, comparisons, evidence, confident wording, and consistent claims raised a source's odds of being cited first in at least four of six models, and a stated price and a recent date did so in all six (opens in a new tab) (peer-reviewed; laboratory setting; the authors work for a marketing software vendor). The FTC's substantiation policy asks for the same thing from a different direction: a claim needs evidence before it is published. Our observation: a claim with its test, date, and scope attached is both the compliant form and the checkable form.

ContentPublishAvoidRules
Detection and prevention resultsThe test, the tester, the date, the product version and configuration, the result, a link to the full results, and who paid for the test"Detects all threats," "blocks 100% of ransomware," undated or unsourced test claimsFTC substantiation policy; Evolv order; Endorsement Guides
AI featuresWhat the model does, the data it uses, measured error rates with the method, and what a person reviews"Autonomous SOC" or "replaces your analysts" without evidenceFTC AI enforcement; Evolv order
Privacy and protection promisesWhat data the product collects, keeps, shares, or sellsPromises that your data practices contradictAvast order
Compliance statusEach report, assessment, or designation in the source's own words, with the date, scope, and a link or request path"SOC 2 certified," "HIPAA compliant," "FedRAMP compliant," "CMMC certified" without the facts behind themAICPA; FTC; FedRAMP; Department of War; Cyber AB
Secure by Design pledgeThe date you signed and your progress reports"CISA-approved" or wording that implies CISA verified youCISA pledge page
Customer resultsThe customer's result with its context and, if it is not typical, what customers generally achieveA best case presented as typicalEndorsement Guides § 255.2
Analyst placements and awardsThe exact report name, year, and placement, following the rater's own terms for quoting it, and who paid for any commissioned studyImplying an analyst firm endorses youEndorsement Guides (commissioned research); rater terms (our recommendation)
ComparisonsSourced, dated facts about competitors' productsClaims about competitors you cannot supportFTC comparative advertising policy
MSP service scopeWhat is included and excluded, who is responsible for what, incident notification, and backup terms"Complete protection," "we handle everything"FTC substantiation policy; the joint MSP advisory (buyer guidance)
Vulnerability and incident informationThe VDP, security advisories, CVE records, and a history of incidents that affected customersA security page with no way to report a flawCISA's buyer guidance (not a rule)
Titles, meta descriptions, and markupThe same claims and qualifiers as the visible page"Best," "#1," "certified," or "guaranteed" in hidden fieldsOur recommendation; the rules above apply to the claim wherever it appears

Google's systems "give even more weight to content that aligns with strong E-E-A-T for topics that could significantly impact the health, financial stability, or safety of people" (opens in a new tab) (experience, expertise, authoritativeness, and trustworthiness). Much security advice fits that description (our reading). Our recommendation: publish security guidance under the name of a practitioner who does the work, show when it was written and reviewed, and add what your team has seen in real incidents rather than restating common knowledge.

Local search for MSPs and IT services firms

For an MSP that serves businesses in its own region, Google's local results and Business Profiles matter more than they do for a product vendor (our reading).

Location pages. An MSP marketing agency advises creating location pages to target each area an MSP covers, including cities where it has no office (opens in a new tab). Google's spam policies list "having multiple domain names or pages targeted at specific regions or cities that funnel users to one page" (opens in a new tab) as doorway abuse, and Google's guidance says that creating "separate content for every possible variation" (opens in a new tab) of how people search, primarily to manipulate rankings or AI responses, violates its scaled content abuse policy. Our recommendation: publish a page for an area only when you actually serve it, and fill it with facts specific to that area, such as the staff who cover it, on-site response times, and clients there who have agreed to be named.

AI answers for local IT support draw on different sources than Google. Given the 0.1% domain overlap for IT support (opens in a new tab) (above), an MSP cannot assume that its Google ranking carries into assistants' answers. Marketplace and directory profiles are one candidate route, since Clutch now runs an app inside ChatGPT (above); no study found for this page measures how often assistants cite MSP directories.

Profiles, entity facts, and crawling

An entity is a person or organization that search systems treat as one distinct thing. Our recommendation: keep your company name, product names, certifications and their dates, supported platforms, and service areas identical on your site, trust center, review profiles, marketplace listings, government listings such as the FedRAMP Marketplace, and partner directories. The reason is indirect: language models often merge information about different entities that share a name (opens in a new tab) (peer-reviewed), and in lab trials consistent rather than contradictory claims raised a source's odds of being cited first in at least four of six models (opens in a new tab) (peer-reviewed; laboratory setting). No study has tested this for security companies, so treat it as an inference. Organization structured data can help Google "disambiguate your organization in search results" (opens in a new tab), but it is not an AI citation lever: in a matched study of 1,885 pages that added structured data, AI Overview citations fell 4.6%, and changes for AI Mode (+2.4%) and ChatGPT (+2.2%) were statistically indistinguishable from zero (opens in a new tab) (vendor study).

Assistants can cite only pages their crawlers can reach. Sites that block OAI-SearchBot "will not be shown in ChatGPT search answers" (opens in a new tab); blocking Claude-SearchBot may reduce visibility in Claude's search results (opens in a new tab); PerplexityBot access is controlled by robots.txt (opens in a new tab); and Google's AI features can show only pages that are indexed and eligible to appear with a snippet (opens in a new tab) (all official documentation). In December 2024, none of the major AI crawlers rendered JavaScript (opens in a new tab) (network measurement), and Microsoft advises against hiding key answers in tabs or expandable menus, or leaving them only in PDFs or images (opens in a new tab). A trust center that loads by script, sits behind a login, or offers only a PDF shows assistants little or nothing (our reading). If your site sits behind bot protection or a web application firewall, check that its rules let the search crawlers through (our recommendation).

Which third-party sources carry weight

SourceExamplesEvidence that AI answers use itWhat to check first
Analyst firmsGartner, ForresterGartner was among the 10 most-cited domains on Google AI Overviews and Perplexity (above); 13% of technology buyers used analyst reports in their purchase decision, a 63% decrease since 2022 (opens in a new tab)Disclose who paid for any commissioned study you cite (FTC Endorsement Guides), and follow the firm's terms for quoting it (our recommendation)
Peer review platformsG2, Gartner Peer Insights, PeerSpot, TrustRadius45% of software buyers say review-site citations are the most confidence-inspiring signal in an AI answer (opens in a new tab); review sites (38%) overtook AI chatbots (37%) as the top influence on software shortlists (opens in a new tab); G2 in about 5% of decision-stage answers (above)Incentives disclosed and not tied to sentiment; every customer asked the same way (FTC rule and guidance)
Communitiesr/cybersecurity, r/sysadmin, r/mspReddit in about 62% of decision-stage answers across industries, and the most-cited domain on Perplexity (above)Staff disclose where they work (FTC Endorsement Guides)
Services marketplacesClutch, UpCity, CloudtangoClutch's app inside ChatGPT; one agency's observation that such directories rank in Google for local IT searches (both above; weak)Review requests within the FTC rule
Government program listingsFedRAMP Marketplace, the Cyber AB's marketplace, CISA's list of pledge signersNo citation study found; the FedRAMP Marketplace is the authoritative record of FedRAMP status (above)Claim only what the listing shows
Vulnerability recordsCVE records, security advisoriesNo citation study found; CISA tells buyers to check them (above)Accurate, timely records
Your own siteTrust center, documentation, VDP, service scope71% of U.S. B2B professionals who use AI visit a vendor's website after an AI names it (opens in a new tab), though product pages and homepages are rarely cited in decision-stage answers (above)FTC substantiation for every claim

What the evidence does not show. No study found for this page measures which sources assistants cite for cybersecurity questions with a published method, or whether profiles on review platforms cause recommendations rather than accompany them. Established vendors tend to have both (our reading).

Our recommendations:

  1. Complete the free profiles first: review platforms, marketplaces, and program listings, with the same facts as your site.
  2. Ask every customer for reviews the same way, disclose any incentive, and never tie an incentive to a positive review.
  3. Take part in communities under your own name and say where you work. Google says "seeking inauthentic 'mentions' across the web isn't as helpful as it might seem" (opens in a new tab). The evidence on brand mentions has its own guide.
  4. Publish evidence others can cite: advisories, test results with their methods, and research with its data.

How to measure SEO and AEO for a security or IT services company

Measure AI visibility as a rate across repeated runs, per assistant, per product category, and, for MSPs, per city, and connect it to pipeline by asking new customers how they found you. A single answer shows little, because answers change from run to run (see above).

What to measureHowLimits
Mention rate, citation rate, and share of voiceA fixed panel of buyer questions for each category, each run several times per assistant. 7 to 8 runs per prompt brought the standard error of a per-prompt detection rate below 0.10 (opens in a new tab) (preprint). Adding prompts buys more precision than adding runs (opens in a new tab). Report Wilson or Bayesian intervals, because normal-approximation intervals are too narrow below a few hundred data points (opens in a new tab). MSPs should run the panel from the city they serve or name the city in the promptResults differ by assistant, account, location, and day
Which sources answers citeRecord every cited URL and count review platforms, analyst sites, communities, marketplaces, and your own pagesShows which profiles to fix; does not prove cause
Accuracy of security factsAsk each assistant about your SOC report, FedRAMP designation, CMMC status, supported platforms, and service areas, and score the answers against your trust center (our method)No study has measured how accurately assistants state security vendors' compliance status
Citations in Microsoft Copilot and Bing's AI summariesBing Webmaster Tools' AI Performance report shows citations, cited pages, and the search phrases behind them, without click data (opens in a new tab)Microsoft surfaces only
Impressions in AI Overviews and AI ModeSearch Console's generative AI performance report shows impressions, not clicks (opens in a new tab)Google surfaces only
AI referral trafficGA4's AI Assistant channel counts visits "from sources like ChatGPT, Gemini, Deepseek, Copilot, or Grok" and counts AI Overviews and AI Mode as Organic Search (opens in a new tab); ChatGPT adds utm_source=chatgpt.com to referral links (opens in a new tab)Traffic from Claude's app carries no referrer (opens in a new tab), and volumes are small: 0.17% of visitors across 3,000 sites came from AI assistants (opens in a new tab) (early 2025)
Pipeline by sourceAsk "How did you hear about us?" on demo and contact forms, with each assistant as an option, and store the answer in the CRMIn one agency's records, first-touch attribution credited AI with only 28 of the 189 leads (15%) who named an AI tool (opens in a new tab) (single firm; weak)

Change one thing at a time, and keep a group of pages you did not change. In the only controlled field study found, ChatGPT referrals to pages that were not changed grew 3.5 times over the same period (opens in a new tab) (preprint; one site), so a before-and-after comparison without a control would have credited that growth to the changes.

How to do SEO and AEO for a cybersecurity or IT services company

These steps are recommendations. Each draws on the evidence above.

  1. Inventory every security, AI, and compliance claim on your site, profiles, listings, and sales material, and match each one to the evidence on file. Remove or reword any claim without evidence.
  2. List the questions buyers ask: CISA's questions for software vendors, the joint advisory's contract points for MSPs, and the questions in your sales calls and security questionnaires.
  3. Publish the facts buyers are told to check: the VDP, security advisories and CVE records, SBOM availability, security features and logging by plan, and the patch policy; for MSPs, the service scope, responsibilities, incident notification, and backup terms.
  4. Word every status exactly: the SOC report and its period, the CMMC level and assessment type, the FedRAMP designation as the Marketplace shows it, and the date you signed CISA's pledge.
  5. Make the pages crawlable and indexable: keep the trust center public and server-rendered, and check that your own bot protection lets the search crawlers through.
  6. Make profiles, listings, and your site state the same facts.
  7. For MSPs, follow Google's Business Profile rules and publish location pages only for areas you actually serve.
  8. Ask every customer for reviews the same way, and have staff disclose where they work when they post in communities.
  9. Measure with a fixed prompt panel and a form question, and change one thing at a time.

Checklist for cybersecurity and IT services

CheckHow to verifyPass whenSource
Every claim has evidenceList performance, AI, privacy, and compliance claims with their evidence filesNo claim lacks evidence that existed before it was publishedFTC substantiation policy (opens in a new tab)
No absolute detection claimsSearch for "all," "100%," "every," and "guarantee"None unless a documented test supports the exact claimFTC Evolv action (opens in a new tab)
Tests disclosedRead each test or study you citeTester, date, version, method, and who paid are statedFTC Endorsement Guides § 255.5 (opens in a new tab)
SOC wordingSearch for "SOC 2 certified"Replaced with the report, the CPA firm, and the periodAICPA SOC logo terms (opens in a new tab)
HIPAA wordingSearch for "HIPAA compliant," "HIPAA secure," and "HIPAA certified"None that is false or misleadingFTC health information guidance (opens in a new tab)
CMMC wordingRead every CMMC mentionLevel, assessment type, and date stated; an RPO says it advises and does not certifyDepartment of War (opens in a new tab); Cyber AB (opens in a new tab)
FedRAMP wordingCompare every FedRAMP mention with your Marketplace listingThe exact designation, linked to the listing; no "compliant" or "equivalent"FedRAMP Marketplace rules (opens in a new tab)
Pledge wordingRead every mention of CISASigning date and progress report; no implied endorsementCISA pledge page (opens in a new tab)
Buyer artifacts publicOpen the VDP, advisories, SBOM page, and security features page in a private windowEach is public and readable without a loginCISA Secure by Demand guide (opens in a new tab)
MSP scope publicRead the service pagesIncluded and excluded services, responsibilities, incident notification, and backups are statedJoint MSP advisory (opens in a new tab)
Business Profiles follow Google's rulesReview each profileStaffed offices only; address hidden for service-area businesses; realistic service areasGoogle Business Profile guidelines (opens in a new tab)
No doorway location pagesCompare location pages with areas actually servedEach page has facts specific to its areaGoogle spam policies (opens in a new tab)
Review requests follow the rulesRead the request templates and incentive termsSent to all customers; incentives disclosed and not tied to sentimentFTC rule guidance (opens in a new tab)
Crawlers allowedRead robots.txt, WAF, and bot-protection settings; check server logsSearch crawlers get 200 responses on public pagesOpenAI crawler documentation (opens in a new tab)
Facts in server-rendered HTMLView the trust center's source with JavaScript turned offStatuses and dates appear as textVercel (opens in a new tab)
Measurement in placePrompt log, analytics, form questionRepeated runs per assistant, with intervals; form question liveRuns per prompt (opens in a new tab)

What the evidence shows and does not show

Claim testedWhat the evidence showsStrength
Technology buyers use AI assistants in research63% used AI to research a software purchase (opens in a new tab); 82% sourced recommendations from a chatbot in two years (opens in a new tab)Moderate (review-platform surveys; not security-specific)
Most cybersecurity vendors are missing from ChatGPT's recommendationsOne vendor benchmark reports 73% with zero citations (opens in a new tab)Weak
AI Overview citations for B2B technology track organic rankings71.0% overlap (opens in a new tab)Moderate (one vendor)
AI answers for local IT support draw on different sources than Google0.1% domain overlap (opens in a new tab)Moderate (one preprint)
Review platforms and communities feed AI answersSeveral vendor and agency studies agree (above)Moderate for communities; weak for review platforms
Publishing CISA's buyer artifacts earns AI citationsNot studied; the case rests on buyer guidance and verificationNo evidence
Structured data earns AI citationsNo reliable lift in a matched study (opens in a new tab)Moderate evidence against
A security company can expect a known time to its first AI recommendationA review of 45 studies found no technique with a stable, longitudinal, cross-platform causal effect (opens in a new tab)No evidence

Antipatterns in security marketing

Each antipattern below is common in security and IT marketing and fails for a documented reason.

AntipatternWhy it failsHow to detect it
"Detects all threats" or "blocks 100% of ransomware"The FTC acted against a security screening company over alleged claims that its scanners would detect all weapons (opens in a new tab), and claims need a reasonable basis before they are made (opens in a new tab)Search the site and profiles for absolutes
"AI-powered" or "autonomous" with no evidence behind itThe FTC says there is "no AI exemption from the laws on the books" (opens in a new tab)Ask for the file that supports each AI claim
"SOC 2 certified" or "HIPAA compliant" as a badgeThe AICPA logo marks a report received from a CPA (opens in a new tab), and the FTC warns against false "HIPAA Compliant" claims (opens in a new tab)Search for "certified" and "compliant"
"FedRAMP compliant" or "FedRAMP equivalent"FedRAMP says such terms are not certified by FedRAMP (opens in a new tab)Compare with the Marketplace listing
An MSP that says it "certifies" clients for CMMCRegistered Practitioner Organizations "do not conduct Certified CMMC Assessments" (opens in a new tab)Read the CMMC service page
"CISA-approved" after signing the pledgeCISA does not enforce or verify the pledge, and does not endorse companies (opens in a new tab)Read every mention of CISA
Commissioned tests presented as independentThe Endorsement Guides call for disclosing a paid tester and treat invalid tests as deceptive (opens in a new tab)Check who paid for each cited test
A trust center behind a login, in a PDF, or loaded by scriptMajor AI crawlers did not render JavaScript (opens in a new tab), and Microsoft advises against leaving answers only in PDFs (opens in a new tab)Open it in a private window with JavaScript turned off
Your own bot protection blocking the search crawlersSites that block OAI-SearchBot are not shown in ChatGPT's search answers (opens in a new tab)Check firewall logs for crawler requests and their status codes
A location page for every city in the stateGoogle treats city pages that funnel users to one page as doorway abuse (opens in a new tab)Compare location pages with areas actually served
Staff praising the product in forums without saying where they workThe FTC's Endorsement Guides call for disclosure (opens in a new tab)Review staff activity policies and posts
Marketing claims that go beyond what you report to government customersA contractor agreed to pay $4.6 million to settle allegations over its cybersecurity representations (opens in a new tab)Compare public claims with formal representations

Frequently asked questions

What makes SEO for cybersecurity different from SEO for an MSP?

They differ mainly in who buys and where the search happens. A security product sold to organizations goes through the buyer's security review, which is the biggest delay after a vendor is chosen (opens in a new tab). An MSP that serves businesses in its own region competes in Google's local results, where Business Profile rules (opens in a new tab) apply, and AI answers for local IT support draw on different sources than Google's results (opens in a new tab). The rules on claims are the same for both.

Is SEO still necessary now that buyers use AI assistants?

Yes. Google says optimizing for its generative AI features "is optimizing for the search experience, and thus still SEO" (opens in a new tab), and Bing says its Copilot experiences rely on the same crawling, indexing, and ranking foundation as traditional search (opens in a new tab). Assistants that search can cite only what they can retrieve. AEO adds work on third-party sources, exact facts, and measurement; it does not replace SEO.

An MSP marketing agency defines it as making sure an MSP "appears in AI-powered search results and chatbot responses when potential customers ask questions about IT services" (opens in a new tab). It is the same practice as AEO, applied to IT service providers. The parts specific to MSPs are local: Business Profiles, service-area pages, marketplace profiles, and measurement by city.

Can we call ourselves "SOC 2 certified" or "HIPAA compliant"?

Check with counsel. The AICPA describes a SOC report "issued by a licensed, independent CPA" (opens in a new tab), not a certification, so the accurate statement names the report, the firm, and the period (our reading). The FTC tells companies not to make false or misleading claims that they are "HIPAA Compliant," "HIPAA Secure," or "HIPAA Certified" (opens in a new tab). Specific statements are also easier for buyers and assistants to check.

Do the FTC's rules apply when our customers are businesses?

The FTC's review rule and its guidance are written for consumer reviews and do not say how the rule applies to reviews by business customers (opens in a new tab) (our reading). The FTC's action against Evolv shows that it acts on security and AI claims made to organizations: Evolv's scanners are used in schools, sports stadiums, and hospitals, and its customers include school systems (opens in a new tab). Our recommendation: treat claims to business buyers as held to the same substantiation standard.

How much does SEO or AEO cost for a security company, and which agency should we hire?

We found no published survey of what security companies or MSPs pay for SEO or AEO. A software company that sells its own AEO product puts agency work at about $3,000 and up for a one-time audit or sprint, and about $9,000 to $15,000 or more a month for ongoing programs (opens in a new tab) (September 2026); the index of what AEO costs compares published prices. AEO HQ sells this work itself (see Answer engine optimization (AEO) services), so we have an interest, and we do not rank agencies. Google says third-party tools "can't guarantee performance," and lists AEO and GEO tools among the services to evaluate critically (opens in a new tab). How to choose an AEO or GEO agency lists the questions to ask; for a security company, add one: who checks every performance, AI, and compliance claim against the evidence before it is published?

How long does it take?

No study has measured it. A 2026 review of 45 studies found no technique with a stable, longitudinal, cross-platform causal effect on organic discoverability (opens in a new tab) (preprint), so there is no evidence base for a timeline. Google says crawling a URL "can take anywhere from a few days to a few weeks" (opens in a new tab). Treat a promised timeline as a sales claim.

Next steps

AEO HQ sells this work at fixed, published prices, from a $499 automated audit to $8,995 for an audit, a plan, and technical implementation that includes analytics setup. We do not give legal advice or compliance opinions: your counsel or compliance staff approve every claim before it is published. See the prices and what each package includes.

Change log

  • September 28, 2026: First published.

Sources

  1. Google. (2026, June 5). Google Search's guidance on using third-party SEO tools, services, and advice. Google Search Central. https://developers.google.com/search/docs/fundamentals/third-party-seo (opens in a new tab)
  2. AEO HQ. (2026). Keyword demand data from Ahrefs Keywords Explorer (API v3), United States [Unpublished data set; pulled September 27, 2026]. https://www.aeohq.ai/methodology (opens in a new tab)
  3. Cybersecurity and Infrastructure Security Agency, National Security Agency, Federal Bureau of Investigation, National Cyber Security Centre (UK), Australian Cyber Security Centre, Canadian Centre for Cyber Security, & National Cyber Security Centre (NZ). (2022, May 11). Protecting against cyber threats to managed service providers and their customers (Cybersecurity Advisory AA22-131A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a (opens in a new tab)
  4. AICPA & CIMA. (2026, April 22). SOC logos for service organizations – registration and guidelines. https://www.aicpa-cima.com/resources/download/soc-for-service-organizations-logo-guidelines-for-service-organization (opens in a new tab)
  5. U.S. Department of War, Chief Information Officer. (2026). About CMMC. Retrieved September 27, 2026, from https://dodcio.defense.gov/cmmc/About (opens in a new tab)
  6. FedRAMP. (2026). The FedRAMP Marketplace [FedRAMP Consolidated Rules for 2026]. U.S. General Services Administration. Retrieved September 27, 2026, from https://www.fedramp.gov/2026/marketplace/ (opens in a new tab)
  7. Cybersecurity and Infrastructure Security Agency. (2024, August). Secure by demand guide: How software customers can drive a secure technology ecosystem [Fact sheet]. https://www.cisa.gov/resources-tools/resources/secure-demand-guide (opens in a new tab)
  8. Google. (2025, September 11). Search quality evaluator general guidelines. https://static.googleusercontent.com/media/guidelines.raterhub.com/en//searchqualityevaluatorguidelines.pdf (opens in a new tab)
  9. TrustRadius. (2026, July 15). TrustRadius 2026 B2B Buying Disconnect report reveals AI has changed how buyers research, but not what they trust [Press release]. PR Newswire. https://www.prnewswire.com/news-releases/trustradius-2026-b2b-buying-disconnect-report-reveals-ai-has-changed-how-buyers-research-but-not-what-they-trust-302825792.html (opens in a new tab)
  10. G2. (2026, April 15). New G2 research: Half of B2B software buyers now start their research with AI chatbots [Press release]. PR Newswire. https://www.prnewswire.com/news-releases/new-g2-research-half-of-b2b-software-buyers-now-start-their-research-with-ai-chatbots-302742807.html (opens in a new tab)
  11. G2. (2026, July 22). AI is making software easier to find and harder to buy, according to new G2 research [Press release]. PR Newswire. https://www.prnewswire.com/news-releases/ai-is-making-software-easier-to-find-and-harder-to-buy-according-to-new-g2-research-302831346.html (opens in a new tab)
  12. Loktionova, M. (2026, July 8). How AI tools shape the B2B buying process: A survey of 600+ US business professionals. Semrush. https://www.semrush.com/blog/how-ai-shapes-b2b-buying/ (opens in a new tab)
  13. Google. (2026, July 10). Optimizing your website for generative AI features on Google Search. Google Search Central. https://developers.google.com/search/docs/fundamentals/ai-optimization-guide (opens in a new tab)
  14. Microsoft Bing. (n.d.). Bing Webmaster Guidelines. Retrieved September 27, 2026, from https://www.bing.com/webmasters/help/webmaster-guidelines-30fba23a (opens in a new tab)
  15. OpenAI. (n.d.). Searching the web with ChatGPT [Help Center article]. Retrieved September 27, 2026, from https://help.openai.com/en/articles/9237897-chatgpt-search (opens in a new tab)
  16. BrightEdge. (2025, September 18). AI Overview citations now 54% from organic rankings. https://www.brightedge.com/resources/weekly-ai-search-insights/rank-overlap-after-16-months-of-aio (opens in a new tab)
  17. Chen, M., Wang, X., Chen, K., & Koudas, N. (2025). Generative engine optimization: How to dominate AI search (arXiv:2509.08919) [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2509.08919 (opens in a new tab)
  18. GrackerAI. (2026, February). The state of AI search visibility in cybersecurity, 2026 benchmark report. https://gracker.ai/data-and-research-reports/state-of-ai-search-visibility-cybersecurity-2026 (opens in a new tab)
  19. Lafferty, N. (2025, June 5; updated August 2025). AI platform citation patterns: How ChatGPT, Google AI Overviews, and Perplexity source information. Profound. https://www.tryprofound.com/blog/ai-platform-citation-patterns (opens in a new tab)
  20. Flanigan, R. (n.d.). Where AI gets its buying advice [BOFU data study]. Siege Media. Retrieved September 27, 2026, from https://www.siegemedia.com/research/ai-buying-advice (opens in a new tab)
  21. Clutch. (2026, April 23). Clutch launches first B2B services marketplace app on ChatGPT, bringing verified provider data into AI conversations [Press release]. https://clutch.co/press-releases/b2b-custom-gpt-app (opens in a new tab)
  22. Porteous, A. (2026, January 7). MSP SEO & AI search guide: How to rank higher on Google and LLMs to get more leads. Pronto Marketing. https://www.prontomarketing.com/blog/msp-seo/ (opens in a new tab)
  23. Fishkin, R. (2026, January 28). NEW research: AIs are highly inconsistent when recommending brands or products; marketers should take care when tracking AI visibility. SparkToro. https://sparktoro.com/blog/new-research-ais-are-highly-inconsistent-when-recommending-brands-or-products-marketers-should-take-care-when-tracking-ai-visibility/ (opens in a new tab)
  24. AEO HQ. (2026). Industry evidence for the SEO+ industry pages [Unpublished research dossier, track 08; search suggestions and forum thread titles collected September 27, 2026]. https://www.aeohq.ai/methodology (opens in a new tab)
  25. Lindsay, J. (2025, December 10). Cybersecurity SEO: The ultimate guide for 2026. Opollo. https://opollo.com/blog/cybersecurity-seo-the-ultimate-guide-for-2026/ (opens in a new tab)
  26. Federal Trade Commission. (1984, November 23). FTC policy statement regarding advertising substantiation. https://www.ftc.gov/legal-library/browse/ftc-policy-statement-regarding-advertising-substantiation (opens in a new tab)
  27. Federal Trade Commission. (2024, November 26). FTC takes action against Evolv Technologies for deceiving users about its AI-powered security screening systems [Press release]. https://www.ftc.gov/news-events/news/press-releases/2024/11/ftc-takes-action-against-evolv-technologies-deceiving-users-about-its-ai-powered-security-screening (opens in a new tab)
  28. Federal Trade Commission. (2024, February 22). FTC order will ban Avast from selling browsing data for advertising purposes, require it to pay $16.5 million over charges the firm sold browsing data after claiming its products would block online tracking [Press release]. https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-order-will-ban-avast-selling-browsing-data-advertising-purposes-require-it-pay-165-million-over (opens in a new tab)
  29. Federal Trade Commission. (2024, September 25). FTC announces crackdown on deceptive AI claims and schemes [Press release]. https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes (opens in a new tab)
  30. Disclosure of material connections, 16 C.F.R. § 255.5 (Guides Concerning the Use of Endorsements and Testimonials in Advertising) (via Legal Information Institute). Retrieved September 27, 2026, from https://www.law.cornell.edu/cfr/text/16/255.5 (opens in a new tab)
  31. Consumer endorsements, 16 C.F.R. § 255.2 (Guides Concerning the Use of Endorsements and Testimonials in Advertising) (via Legal Information Institute). Retrieved September 27, 2026, from https://www.law.cornell.edu/cfr/text/16/255.2 (opens in a new tab)
  32. Federal Trade Commission. (1979, August 13). Statement of policy regarding comparative advertising. https://www.ftc.gov/legal-library/browse/statement-policy-regarding-comparative-advertising (opens in a new tab)
  33. Federal Trade Commission. (2024, August). Collecting, using, or sharing consumer health information? Look to HIPAA, the FTC Act, and the Health Breach Notification Rule. https://www.ftc.gov/business-guidance/resources/collecting-using-or-sharing-consumer-health-information-look-hipaa-ftc-act-health-breach (opens in a new tab)
  34. The Cyber AB. (n.d.). Navigating roles & professions of the ecosystem. Retrieved September 27, 2026, from https://cyberab.org/CMMC-Ecosystem/Ecosystem-roles (opens in a new tab)
  35. FedRAMP. (n.d.). The FedRAMP Marketplace [Legacy documentation, kept for reference during the transition to the Consolidated Rules for 2026]. U.S. General Services Administration. Retrieved September 27, 2026, from https://www.fedramp.gov/legacy/playbook/agency/authorization/marketplace/ (opens in a new tab)
  36. FedRAMP. (n.d.). FedRAMP Marketplace designations [Brand guidelines]. U.S. General Services Administration. Retrieved September 27, 2026, from https://www.fedramp.gov/brand/fedramp-marketplace/marketplace-designations/ (opens in a new tab)
  37. Cybersecurity and Infrastructure Security Agency. (n.d.). Secure by Design pledge. Retrieved September 27, 2026, from https://www.cisa.gov/securebydesign/pledge (opens in a new tab)
  38. U.S. Department of Justice. (2025, March 26). Defense contractor MORSECORP Inc. agrees to pay $4.6 million to settle cybersecurity fraud allegations [Press release]. https://www.justice.gov/opa/pr/defense-contractor-morsecorp-inc-agrees-pay-46-million-settle-cybersecurity-fraud (opens in a new tab)
  39. Federal Trade Commission. (2024, August 14). Federal Trade Commission announces final rule banning fake reviews and testimonials [Press release]. https://www.ftc.gov/news-events/news/press-releases/2024/08/federal-trade-commission-announces-final-rule-banning-fake-reviews-testimonials (opens in a new tab)
  40. Federal Trade Commission. (2024, November). The Consumer Reviews and Testimonials Rule: Questions and answers. https://www.ftc.gov/business-guidance/resources/consumer-reviews-testimonials-rule-questions-answers (opens in a new tab)
  41. Federal Trade Commission. (2025, December 22). FTC warns 10 companies about possible violations of the agency's new consumer review rule [Press release]. https://www.ftc.gov/news-events/news/press-releases/2025/12/ftc-warns-10-companies-about-possible-violations-agencys-new-consumer-review-rule (opens in a new tab)
  42. Google. (n.d.). Prohibited & restricted content. Maps User Generated Content Policy Help. Retrieved September 27, 2026, from https://support.google.com/contributionpolicy/answer/7400114 (opens in a new tab)
  43. European Commission. (2026, July 24). Transparency obligations under Article 50 of the AI Act [FAQ]. Shaping Europe's Digital Future. https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act (opens in a new tab)
  44. Vishwakarma, R., Kumar, S., & Jamidar, R. (2026). What gets cited: Competitive GEO in AI answer engines. In Proceedings of the 49th International ACM SIGIR Conference on Research and Development in Information Retrieval (pp. 4950–4954). ACM. https://doi.org/10.1145/3805712.3808445 (opens in a new tab)
  45. Google. (2025, December 10). Creating helpful, reliable, people-first content. Google Search Central. https://developers.google.com/search/docs/fundamentals/creating-helpful-content (opens in a new tab)
  46. Google. (n.d.). Guidelines for representing your business on Google. Google Business Profile Help. Retrieved September 27, 2026, from https://support.google.com/business/answer/3038177 (opens in a new tab)
  47. Google. (n.d.). Tips to improve your local ranking on Google. Google Business Profile Help. Retrieved September 27, 2026, from https://support.google.com/business/answer/7091 (opens in a new tab)
  48. Google. (2026, August 28). Spam policies for Google web search. Google Search Central. https://developers.google.com/search/docs/essentials/spam-policies (opens in a new tab)
  49. Lee, Y., Ye, X., & Choi, E. (2024). AmbigDocs: Reasoning across documents on different entities under the same name. In Proceedings of the First Conference on Language Modeling (COLM 2024). https://doi.org/10.48550/arXiv.2404.12447 (opens in a new tab)
  50. Google. (2026, September 8). Organization (Organization) structured data. Google Search Central. https://developers.google.com/search/docs/appearance/structured-data/organization (opens in a new tab)
  51. Linehan, L. (2026, May 11). We tracked 1,885 pages adding schema. AI citations barely moved. Ahrefs. https://ahrefs.com/blog/schema-ai-citations/ (opens in a new tab)
  52. OpenAI. (n.d.). Overview of OpenAI crawlers. OpenAI Developers. Retrieved September 27, 2026, from https://developers.openai.com/api/docs/bots (opens in a new tab)
  53. Anthropic. (2026, April 7). Does Anthropic crawl data from the web, and how can site owners block the crawler? Claude Help Center. https://support.claude.com/en/articles/8896518-does-anthropic-crawl-data-from-the-web-and-how-can-site-owners-block-the-crawler (opens in a new tab)
  54. Perplexity. (n.d.). Perplexity crawlers. Perplexity Docs. Retrieved September 27, 2026, from https://docs.perplexity.ai/guides/bots (opens in a new tab)
  55. Google. (2025, December 10). AI features and your website. Google Search Central. https://developers.google.com/search/docs/appearance/ai-features (opens in a new tab)
  56. Zecchini, G., Moore, A. A., Ubl, M., & Siddle, R. (2024, December 17). The rise of the AI crawler. Vercel. https://vercel.com/blog/the-rise-of-the-ai-crawler (opens in a new tab)
  57. Madhavan, K. (2025, October 8). Optimizing your content for inclusion in AI search answers. Microsoft Advertising Blog. https://about.ads.microsoft.com/en/blog/post/october-2025/optimizing-your-content-for-inclusion-in-ai-search-answers (opens in a new tab)
  58. Schulte, J., Bleeker, M., & Kaufmann, P. (2026). Don't measure once: Measuring visibility in AI search (GEO) (arXiv:2604.07585) [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2604.07585 (opens in a new tab)
  59. Miller, E. (2024). Adding error bars to evals: A statistical approach to language model evaluations (arXiv:2411.00640) [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2411.00640 (opens in a new tab)
  60. Bowyer, S., Aitchison, L., & Ivanova, D. R. (2025). Position: Don't use the CLT in LLM evals with fewer than a few hundred datapoints. In Proceedings of the 42nd International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol. 267). https://proceedings.mlr.press/v267/bowyer25a.html (opens in a new tab)
  61. Madhavan, K., Merchant, M., Canel, F., & Nigam, S. (2026, February 10). Introducing AI Performance in Bing Webmaster Tools public preview. Bing Webmaster Blog. https://blogs.bing.com/webmaster/February-2026/Introducing-AI-Performance-in-Bing-Webmaster-Tools-Public-Preview (opens in a new tab)
  62. Google. (2026). Generative AI performance report [Search Console Help]. Retrieved September 27, 2026, from https://support.google.com/webmasters/answer/16984139 (opens in a new tab)
  63. Google. (2026). Default channel group [Analytics Help]. Retrieved September 27, 2026, from https://support.google.com/analytics/answer/9756891 (opens in a new tab)
  64. OpenAI. (2026). Publishers and developers – FAQ [Help Center article]. Retrieved September 27, 2026, from https://help.openai.com/en/articles/12627856-publishers-and-developers-faq (opens in a new tab)
  65. Belson, D., & Rhea, S. (2025, July 1). The crawl before the fall... of referrals: Understanding AI's impact on content providers. Cloudflare Blog. https://blog.cloudflare.com/ai-search-crawl-refer-ratio-on-radar/ (opens in a new tab)
  66. Linehan, L. (2025, February 6). 63% of websites receive AI traffic (new study of 3,000 sites). Ahrefs. https://ahrefs.com/blog/ai-traffic-study/ (opens in a new tab)
  67. Birkett, A. (2026, August 28). First-touch attribution captures 15% of our AI-sourced leads [Research]. Omniscient Digital. https://beomniscient.com/blog/first-touch-vs-self-reported-attribution-aeo/ (opens in a new tab)
  68. Watanabe, K., & Nakayashiki, K. (2026). Disentangling answer engine optimization from platform growth: A log-based natural experiment on ChatGPT referral traffic (arXiv:2606.04362) [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2606.04362 (opens in a new tab)
  69. Martinez, O. (2026). Optimizing visibility in generative engines: A critical survey of generative engine optimization (2023–2026) (arXiv:2607.14035) [Preprint]. arXiv. https://doi.org/10.48550/arXiv.2607.14035 (opens in a new tab)
  70. HubSpot. (2026, September 8). How much does AEO cost? A breakdown by approach. HubSpot Blog. https://blog.hubspot.com/marketing/how-much-does-aeo-cost (opens in a new tab)
  71. Google. (2025, December 10). Ask Google to recrawl your URLs. Google Search Central. https://developers.google.com/search/docs/crawling-indexing/ask-google-to-recrawl (opens in a new tab)

How to cite this page

Maxwell, P. (2026). SEO, AEO, and GEO for cybersecurity and IT services. AEO HQ. Last updated September 28, 2026. https://www.aeohq.ai/industries/cybersecurity

Example engagement

Case study

AEO audit for a managed security services provider

A hypothetical managed security services provider, used to show how AEO HQ's audit would run in cybersecurity: buyer prompts, crawler and firewall checks, security and compliance claims, and the report. No results.

More in Industries

Next step

Find out who AI recommends.

Book the audit to see where you rank, where AI cites you, and where competitors win. The full audit price credits toward the Blueprint within 30 days.