Operating picture · measured 2026-09-09

16,794 US providers name cybersecurity. Every specific security service is named by under 3.1% of the market.

Cybersecurity is the most-claimed service in US IT. Ask what it contains and the answer collapses: penetration testing 3.0%, incident response 2.7%, awareness training 1.7%, zero trust 0.4%.

42.8%

of 39,235 US providers name cybersecurity; the widest named specific service reaches 3.0%

n = 39,235 published US providers. Each share is the count of firms naming that service anywhere in their published service list, over the whole 39,235. Services are on file for 35,344 of the 39,235, so every share here is a floor and an unknown counts against it. Categories overlap — a firm naming both compliance and penetration testing appears in both — so the shares do not sum to 100%. Measured 2026-09-09 in one repeatable-read snapshot.

Named security services, share of the whole directory%
Cybersecurity (generic)42.8
Backup / DR30.5
Compliance29.2
Penetration testing3
Network security / firewall3
Detection (SOC/SIEM/MDR/EDR)2.7
Vulnerability management2.7
Incident response2.7
Security awareness training1.7
Zero trust0.4
Providers naming cybersecurity as a servicebase 39,235
43% Name cybersecurity (16,794)Do not name cybersecurity (22,441)
The generic claim against the specific ones
The three broad claims
Named by 29% to 43% of the directory each
Cybersecurity (generic)
16,794
Backup / DR
11,960
Compliance
11,445
Combined breadth
42.8% at the top
The seven specific ones
Named by 0.4% to 3.0% of the directory each
Penetration testing
1,192
Detection stack
1,071
Incident response
1,041
Zero trust
168

The most-claimed service in the market is the least specific one

16,794 of 39,235 published US providers name cybersecurity, in one general form or another, among their services — 42.8%, the single most-claimed service line in this directory.

The two other broad claims are close behind: backup and disaster recovery at 11,960 firms, or 30.5%, and compliance at 11,445, or 29.2%. Those three are the shape of the market's security offer as it is advertised.

Every specific security service falls off a cliff. Penetration testing is named by 1,192 firms, 3.0%. Network security or firewall work by 1,163, also 3.0%. A detection capability by 1,071, 2.7%. Vulnerability management 1,078, incident response 1,041 — both 2.7%. Security awareness training 678, or 1.7%. Zero trust 168, or 0.4%.

What that means for a buyer comparing two proposals

A phrase claimed by 42.8% of a market carries no information. If two providers both name cybersecurity, nothing has been distinguished, and the directory cannot distinguish them either — which is why this card lists the sub-services rather than the headline.

The specific claims are where comparison becomes possible. Between them they describe a real range of practice: testing your defenses, watching for intrusion, managing known weaknesses, responding when something happens, and training the people who click.

Awareness training at 1.7% is the one worth pausing on, because phishing is how most incidents begin and training is the cheapest control on this list to deliver. 678 firms name it.

A note on how these were counted

Service names in this directory are short machine tags rather than sentences — security_awareness_training, penetration_testing, managed_detection_response — and that changes how they must be matched.

Matching on prose fails in both directions. Searching for "awareness training" with a space returned zero firms while security_awareness_training was on file for 321, and matching "edr" as a substring pulled in fedramp_compliance, because "f-EDR-amp" contains the letters. Every figure on this card is matched on token boundaries for short acronyms and on whole words for the rest.

That is not a footnote about method for its own sake. It is the difference between reporting that no provider in America trains its clients' staff and reporting that 678 do.

What this number can't tell you

  • ·Every share is a floor. Services are on file for 35,344 of the 39,235 published firms, and an unknown counts against the share.
  • ·This measures published service names, not delivered capability or quality. Naming penetration testing is not evidence of doing it competently, or at all.
  • ·The categories overlap and do not sum to 100%. A provider naming compliance, penetration testing and detection is counted in all three.
  • ·The generic cybersecurity count pools every general form of the claim, including cybersecurity, cyber security, managed cybersecurity, infosec and their consulting and assessment variants. It is deliberately broad, because the point of the card is that the broad claim is uninformative.
  • ·FedRAMP and cyberspace tags are excluded from the security counts: FedRAMP is a compliance authorization and it also false-matched the EDR pattern by accident of spelling.
  • ·The detection figure here is the same 1,071 as the managed security service provider card and is measured in the same snapshot; SOC 1 and SOC 2 audit references are excluded from it.
  • ·Absent from this list is anything about the tools behind the claims. We hold no measurement of which security products a provider actually operates.
  • ·This card does not restate the security-washing card, which measures certification among security sellers, or the MSSP definition card, which measures the service mix within the 1,897 classified MSSPs. Neither is rebased here.

What to do about it

  • Buying: treat "cybersecurity services" on a proposal as a heading, not a service, and ask which of the seven specific lines it contains. Two proposals that both say cybersecurity can differ by everything on this chart.
  • Selling: the generic claim is shared with 16,793 other firms. Naming two or three specific services puts a provider in a group of roughly a thousand instead, and awareness training at 1.7% is the cheapest of them to actually deliver.

Where does your firm sit on this?

Claim your MSP with a magic link from your company email to see your own certifications, reviews, web footprint and local rank measured against every provider we track.

Claim your MSP ▸

More findings

◂ All 39 findings