We built the Positioning Gallery to answer a simple question: how do cybersecurity companies actually position themselves? Not what they think they're saying, but what their homepage, messaging, and competitive framing actually communicate to buyers. After scoring 300+ companies across 7 dimensions, most are invisible.

The average composite score across our dataset is 51.9 out of 100. Only three companies out of 300+ broke 75. The vast majority cluster in a functional but undifferentiated middle, saying the same things in the same way, indistinguishable from their competitors.


The distribution

When you score 300+ cybersecurity homepages on a 0-100 scale, here’s what you get:

Score Range Companies % of Gallery What It Means
75+ 3 1.0% Exceptional — clear category, sharp differentiation, real evidence
50–75 168 58% Functional — competent positioning that rarely stands out
25–50 113 39% Commoditized — sounds like everyone else in the category
Below 25 5 1.7% Broken — buyer can't tell what you do or why you're different

Put the two middle bands together and 97% of the market sits between 25 and 75. These companies have a homepage, a product description, maybe some logos and a demo CTA. Even the 58% in the functional tier rarely give a buyer a concrete reason to choose them over a competitor.

research.innitlabs.io/gallery
Three company cards from the Innit Labs Positioning Gallery showing AI-SOC vendors with their screenshots, taglines, evidence tiers, and funding details
Company cards from our Positioning Gallery — each scored across 7 dimensions.

What the top performers do differently

The three companies that scored above 75 don’t share a category or a target buyer. Dropzone AI (78.5) and ContraForce (76.0) automate the SOC. Pentera (76.0) validates security controls. What they share is a positioning pattern.

They name the problem before the product. ContraForce’s homepage opens with “More tenants. More alerts. Same team.” — the exact bind every Microsoft-native security team lives in. Dropzone leads with the analyst’s job, “Hunt, investigate, and respond at machine scale,” not a feature tour. The buyer sees their own world before they see a product.

They prove it, or pay for not proving it. Pentera quantifies the outcomes its buyers actually track: 80% lower cyber risk, 90% faster mean time to remediate. That kind of specificity is rare. Evidence is consistently one of the weakest dimensions in the whole gallery, and even Dropzone and ContraForce lean on unsourced numbers, which is the main thing still capping their scores. A claim with a number behind it reads as evidence. A claim without one reads as marketing.

They pick an audience. ContraForce speaks only to Microsoft-native security teams. Dropzone speaks to SOC teams drowning in alerts. Neither tries to serve the whole market, and that restraint is what makes the message land. Specificity creates relevance, and relevance is what gets you on the shortlist.

Below the top three, a cluster of companies in the 70–75 range follow the same patterns: Anvilogic (74.5, AI-SOC), Seraphic Security (73.5, Browser Security), Cyberhaven (73.0, DLP), Exaforce (72.5, AI-SOC), and XM Cyber (72.0, Exposure Management). Each one leads with the buyer’s world, not the vendor’s product.

research.innitlabs.io/gallery
Detailed positioning analysis popup from the Innit Labs Positioning Gallery showing score gauge, homepage screenshot, summary, messaging metrics, evidence strip, and headline history
Each company gets a full positioning breakdown — score, messaging analysis, evidence quality, and headline history.
Explore the gallery.

The category gap

Not all sub-verticals position equally. Some categories have mature analyst coverage, clear buyer expectations, and vendors who’ve learned to differentiate. Others are still figuring out the basics.

Category Avg Score Companies Positioning Maturity
AI-SOC 57.6 33 Strong — analyst consensus (Gartner Hype Cycle, SACR report) created shared language
Exposure Management 55.0 52 Mature — well-defined use cases, clear buyer expectations
Data Security 51.0 26 Fragmented — Gartner identifies 5 DSPM subcategories that "bear only a slight resemblance"
Identity Security 50.6 39 Established — vendors know their differentiation vectors
AI Governance 45.8 12 Young — explosive growth, category still forming
Threat Intelligence 45.4 26 Crowded — many vendors, thin differentiation

The spread between the best-positioned category (AI-SOC at 57.6) and the weakest (Threat Intelligence at 45.4) is 12.2 points, nearly a full tier of positioning maturity. Categories with strong analyst consensus and clear buyer definitions produce better-positioned vendors. Categories without them produce noise.


The pattern that predicts everything

After scoring 300+ companies, one pattern emerges above all others: the companies that score highest talk about the buyer’s world first and the product second. The companies that score lowest do the opposite.

This is structural, not stylistic. Our scoring model evaluates seven dimensions, from category clarity to competitive framing to evidence quality, and the companies that lead with the buyer’s problem outperform on nearly every one. Not because we weight buyer-focus the highest (Value Differentiation carries the most weight at 25%), but because buyer-first positioning forces clarity on every other dimension. When you start with the buyer’s pain, you’re compelled to be specific about your category, precise about your differentiation, and concrete about your evidence.

When you start with your product, none of that is required. You can be vague about the category (“security platform”), generic about differentiation (“AI-powered”), and abstract about evidence (“trusted by leading enterprises”). Feature-first positioning lets you skip the hard work, and the scores reflect it.


What this means for you

If you’re a cybersecurity startup, the odds are against you. A 51.9 average means most of your competitors, and likely you, are stuck in the functional-but-forgettable middle. But that’s also the opportunity. When 97% of the market scores between 25 and 75, standing out doesn’t require being louder. It requires being clearer.

The companies in our Positioning Gallery that score in the top quartile share three traits: they name a specific problem, they prove their claim with named evidence, and they pick an audience instead of trying to serve everyone. That’s a positioning decision, not a marketing budget problem.

At a 51.9 average, your positioning almost certainly has gaps. The real question is whether you know where they are and which one to fix first.