Study 3 · AI Visibility Gap
Fewer than one in four AI citations for UK cyber compliance queries go to a firm small enough to hire directly.
We audited how ChatGPT, Perplexity, Google AI Overviews, and Google Search recommend UK cyber security compliance consultants, tracking which firms get named, which sources get the link, and why a small number of firms dominate the answer.
The headline finding
Across every citation we recorded for these queries, fewer than one in four (21.6%) go to a firm small enough to be eligible for this study's boutique consultancy population. Another 24.4% go to firms this study excluded outright, on size, private equity ownership, or non-UK jurisdiction grounds. The remaining 54.0%, the largest single share, goes to entities that were never even candidates: enterprise players like Evalian, Bridewell, and NCC Group, plus government bodies, review platforms, and directory sites.
In other words: a buyer asking an AI assistant who to hire for NIS2 or Cyber Essentials compliance work is, more often than not, being shown a name that was never in the running to be a boutique consultancy in the first place.
Why do large firms dominate?
Key finding
Large firms' dominance is not only a function of size. Years of accumulated search authority play a real part, and that is not something a newer or smaller firm can shortcut. But that is not the whole story. Comparing citation patterns across firms of different sizes, we found consistent differences in how content is structured and organised on the pages that do get cited, differences that have nothing to do with company size, headcount, or budget. Smaller firms with the right approach to content structure were able to compete for AI citations against firms many times their size. The gap here is fixable. It just needs to be identified and addressed deliberately.
Evalian, the most-cited firm in this study, appears in six of the study's seven queries, with distinct, precisely-targeted content for nearly every query variant. Bridewell and URM Consulting show a similar pattern. This breadth compounds: covering more of the topic cluster means more chances to be the answer, in more contexts.
Third-party sites, not just size
Third-party sites make up a large share of how the biggest firms win citations. Evalian's citations trace to Trustpilot as well as its own site. Bridewell's citations trace to a compliance directory and a competitor's own roundup article, not just bridewell.com. This is not incidental: third-party validation and third-party listings are doing real, measurable work.
Most of these sites are not closed to smaller firms. Award programmes such as the Cyber Security Awards and SME News' IT Awards judge on submitted evidence, not company size, and several are free to enter. Trustpilot, LinkedIn, and Crunchbase are open to any business, at no cost. The UK Government's own procurement platform, the Digital Marketplace, is open to any firm that applies through the framework, and in this study, a single small firm's listing there was cited across three separate AI systems using an identical URL, something none of the large firms in the study matched.
A few categories are genuinely harder to reach. Trade show exhibitor directories require paying for a stand, often running into thousands of pounds. Full CREST accreditation and the NCSC's assured consultancy scheme both require real, assessed technical capability, not just an application. These are worth working toward, but they are not something a firm adds to its profile this month.
Small firms do break through
22.1% of the study's boutique and independent prospect pool secured at least one AI citation across the seven queries and four platforms. Not universal, but far from rare, roughly one in five small firms cracked the citation layer at all.
More significantly, six of those firms achieved citations across two or more platforms rather than a single one-off mention, showing the win is repeatable, not a fluke.
| Firm | Citations | Platforms | Mechanism |
|---|---|---|---|
| Mondas Consulting | 4 | ChatGPT, Perplexity, Google AIO | Single G-Cloud government procurement listing, identical URL every time |
| Webristle | 2 | ChatGPT, Perplexity | Dedicated own-site page written for the exact query topic |
| UK Cyber Security Group | 2 | Google AIO, Perplexity | Own blog post answering the literal query as asked |
| NetMonkeys | 2 | Google AIO, Google SERP | Dedicated own-site Cyber Essentials service page |
| Connection Technologies | 2 | Google AIO, Google SERP | Own blog listicle, cited as a source for other firms too |
| Intelance | 2 | ChatGPT, Google SERP | Small, focused firm, repeat organic and generative pickup |
Two playbooks emerge
Playbook 1 — content built for the exact question
- A dedicated page, not a general services page
- Structured around the query's actual phrasing
- An FAQ block answering distinct sub-questions
- No dependency on domain size or age
Playbook 2 — structural third-party placement
- A listing on a platform that structurally fits the query
- Government procurement directories, accreditation schemes
- No content marketing or domain authority required
- Open to firms of any size or age
Case studies
The SEO story vs. the platform-independent story
Paul Reynolds Cyber Security
Cited across Google AI Overview and Google's organic results, but has never once been cited by ChatGPT or Perplexity. A pattern consistent with strong SEO translating into Google's AI layer, without independent traction in conversational AI platforms.
Mondas Consulting
Cited identically across ChatGPT, Perplexity, and Google AI Overview, every time through the same single UK Government procurement listing. No content marketing, no domain authority. Just being present on a platform that structurally matches the query.
Credentialed, but invisible to AI
C3IA Solutions
One of the best-evidenced firms in the study population, with national press coverage and a government pilot programme to its name. Zero recorded AI citations across every platform and query tested.
Bondgate IT
Comparable credentials, comparable result. Genuine third-party validation did not, on its own, translate into a single AI citation in this study.
These two firms are the clearest illustration of the AI Visibility Gap inside this study's own data: real-world credibility that never reaches the AI layer.
Methodology
Each of seven buyer queries was tested across four platforms in clean sessions: ChatGPT, Perplexity, Google AI Overviews, and Google Search organic results. Every named entity in every response was logged, not only the firms already known to the study, so that citation patterns could be measured comprehensively rather than against a pre-selected shortlist.
Firms were excluded from the boutique study population on three grounds: more than approximately 50 direct employees, private equity or venture capital ownership regardless of headcount, or non-UK jurisdiction. Because large enterprise players were excluded from the prospect population by design, their own AI citation dominance, while visible in the raw data, was never systematically measured in the way this study measured the boutique population.
Need to know whether AI platforms recommend your firm?
We produce category-level and company-level AI visibility reports showing where your brand appears, where competitors appear, and which third-party sources influence AI recommendations in your category.
Summary
The mechanics behind large-firm dominance are not a mystery, and they are not exclusively theirs. Awards, reviews, and government directories are largely open to firms of any size. A handful of routes are gated by cost or genuine professional accreditation. Knowing which is which determines where a smaller firm should spend its time first.
Independent researcher measuring how AI systems perceive and recommend companies across B2B categories. Full methodology, credentials, and prior work on the About this research page. Service enquiries: CryptoContent.dev