Study 4: UK Cybersecurity Recruitment

We asked AI platforms which UK cybersecurity recruiter to use. On a third of the questions, they couldn't agree on a single name.

By David Wood, independent AI visibility researcher · Published 15 September 2026

We ran 16 buyer-journey queries across Google AI Overview, ChatGPT and Perplexity, covering broad "who's best" questions, five technical specialisms, contract vs permanent hiring, three UK cities, and two queries re-run with the exact same underlying need but different wording.

The point wasn't to crown a winner. It was to see how consistent AI recommendations actually are when the stakes go up, and what happens to that consistency when a real recruiter's own site content has a gap in it.

16 queries 3 platforms ~80 named agencies, consultancies and individuals Sept 2026 United Kingdom

AI Visibility Gap: the difference between how visible a brand is in traditional search and how often it is recommended by AI assistants. A large positive gap means Google knows you exist. AI buyers do not.

What we found

Five findings stood out enough to build the rest of this study around. None of them are about which recruiter is "best." They're about how AI platforms actually behave when a real buyer asks a real question.

Self-contradiction
Same need,
opposite advice
Asked one way, ChatGPT named the big global executive-search houses and then said not to use them: "I wouldn't start by emailing a dozen generic executive-search firms." Asked a different way, for the exact same hiring need, it put those same firms at the top of its list. Nothing about the underlying question had changed.
Zero agreement
5 of 16 queries, no overlap
On five separate queries, including "who's the top cybersecurity recruiter in London," Google AI Overview, ChatGPT and Perplexity named completely different firms, with not one name appearing in all three answers. It happened most often on senior or specialist hires, where the decision arguably matters most.
Data quality
A vendor,
called an agency
A third-party "Top 25" listicle that Google surfaced prominently named Mimecast, an email security product company and not a recruiter, as the UK's #1 cybersecurity "talent agency." Nothing in the answer flagged the mismatch.
Content gap
Strong everywhere,
missing the word
One of the study's most consistently visible recruiters had its own page flagged "Missing: contract" on the contract-hire query, then "Missing: permanent" on the permanent-hire query. Same company, two separate literal keyword gaps, on the two queries that mattered most for that decision.
Paid search
1 query in 16
showed any ads
Every query about hiring cybersecurity staff, permanent, contract, any specialism, any city, showed zero sponsored results. The one exception was fractional/outsourced CISO hiring, and we confirmed it with four follow-up queries: two synonyms of the same service (both showed the same two advertisers), and two unrelated cybersecurity services (neither showed any ads at all).
Business models
6 distinct
ways to sell this
Recruiter, consultancy, managed service provider, freelance marketplace, a practitioner that also runs its own SOC and recruits from it, and an IR35 umbrella-payroll provider. All six showed up answering variations of "who should I hire," often on the same query.

Where the three platforms actually agreed

For each query we checked whether any single firm appeared in all three platforms' answers. This is the cleanest, fully-verified number in the whole study: no estimation, just a straight count.

Q#QueryFirm(s) all three platforms agreed on
1Best cybersecurity recruitment agency in the UKInfoSec People, Robert Walters
2Strongest reputationNo overlap
3CISO executive searchIntaso, Barclay Simpson
4GRC specialistBarclay Simpson
5SOC analystsNo overlap (Barclay Simpson, dominant everywhere else, absent from all three)
6Penetration testerBarclay Simpson
7Security architect (re-run with "UK" added)La Fosse, Deerfoot, Barclay Simpson
8Contract staffBarclay Simpson
9Permanent hireInfoSec People, Barclay Simpson
10ManchesterAdria Solutions, Robert Walters
11BristolXist4, Adria Solutions
12LondonNo overlap
13"Which agency should I use to hire a CISO" (re-run of Q3)No overlap
14"Which recruiter would you recommend for a SOC hire" (re-run of Q5)No overlap
15IR35 for contractorsHamilton Barnes
16Fractional CISONo overlap (partial pairs only)

Full agreement on 10 of 16 queries; zero agreement on 6. The zero-agreement queries cluster at the senior/executive end (CISO, London, both re-run "validation" queries) and on the one query where a normally-dominant firm had a specific blind spot (SOC).

Same need, different wording, different answer

Three times in this study we asked about the identical underlying hiring need, worded two different ways, and got materially different results. This isn't a one-off quirk. It happened every time we tested for it.

Missing one word changes the country
Query without "UK"

Perplexity's answer was 5 of 6 explicitly US-based firms, including one it separately labelled "US-focused" in its own text.

Same query, "UK" added

Zero US companies. A completely different, fully UK-relevant shortlist, same platform, same specialism.

One word decided which country's recruiters got recommended.
"Specialise in" vs "which agency should I use" (CISO hiring)
"Which agencies specialise in CISO executive search"

ChatGPT named the global retained-search houses, then explicitly advised against them: "I wouldn't start by emailing a dozen generic executive-search firms."

"Which agency should I use to hire a CISO"

ChatGPT led with exactly those same global houses, calling one of them "Best for a genuinely C-suite search."

Same platform, same day, opposite recommendation, and a reversal of its own explicit prior advice.
"Best for finding" vs "would you actually recommend" (SOC hiring)
"Which UK recruiters are best for finding SOC analysts"

Google gave a two-tier "Elite Boutiques vs Large Scale" comparison, led by InfoSec People, LT Harper and Intaso.

"Which recruiter would you actually recommend"

All three of those names disappeared. Google's answer shrank to a flat three-name list, with a completely new firm (KORE1) appearing instead.

A more direct, "actually recommend" phrasing didn't just reorder the list. It replaced most of it.

Six ways to compete for the same buyer

Ask an AI platform who to hire, and it doesn't just answer with recruiters. Every one of these business models showed up answering some version of "who should I use."

Recruiter
The obvious answer: a staffing agency placing candidates, permanent or contract.
Consultancy
Sells a service (a penetration test, a GRC review), not a person. Kept surfacing on recruiter queries anyway.
Managed service provider
Runs an outsourced SOC as a service, rather than placing SOC staff into your team.
Freelance marketplace
Lists named individual contractors directly, rather than an agency's own consultants.
Practitioner-recruiter hybrid
Runs its own cybersecurity/SOC operation and recruits out of that same practitioner base.
Umbrella / payroll provider
Doesn't recruit at all. Handles the IR35-compliant payroll side of a contract placement.

Methodology

16 queries were run across Google AI Overview, ChatGPT and Perplexity: two broad "who's best" questions, five technical specialisms (CISO, GRC, SOC, penetration testing, security architecture), contract vs permanent hiring, three UK cities (Manchester, Bristol, London), two of the specialism queries re-run with validation-stage wording to isolate the effect of phrasing, and two further queries built from modifier lists the platforms themselves surfaced mid-study (IR35 compliance, fractional CISO). Four additional control queries confirmed the paid-search finding.

Every answer was recorded in full, including which firms appeared on which platform, any "Missing: [term]" annotations Google showed against a firm's own page, People Also Ask questions, related searches, and any clarifying question a platform asked before narrowing its answer. All 16 queries have since been re-checked directly against the original screenshots, not just the working notes taken at the time.

Every one of the roughly 120 named agencies, consultancies and individuals across the 15 recruiter-focused queries was tallied by platform. "Google" counts appearing in either the AI Overview text or the page-1 organic listing. The table below shows the top of that ranking; the full list, down to firms that appeared on a single query, is in the downloadable data.

AgencyGoogleChatGPTPerplexityTotal mentionsQueries appeared on
Barclay Simpson86102411 of 15
Robert Walters13822314 of 15
InfoSec People766199 of 15
La Fosse11351913 of 15
LT Harper713119 of 15
Trident Search281118 of 15
Intaso334105 of 15
Lorien802108 of 15
Deerfoot505107 of 15
Harvey Nash53198 of 15

Robert Walters appeared on 14 of the 15 queries, more than any other firm, but two-thirds of its mentions are on Google; Perplexity named it only twice. La Fosse shows the same shape against ChatGPT. LT Harper and Lorien both show a genuine zero or near-zero on one platform (ChatGPT) while performing solidly on Google. Barclay Simpson has the most even spread across all three, and the highest total, but still drops out entirely on the SOC-analyst query. Full rankings for all ~120 entities, including the long tail of single-query appearances, are in the downloadable dataset.

The "missing word" pattern

Google flags when a result's own page doesn't contain a word from the query, showing a "Missing: [word]" note next to the listing. Across the study this happened often enough, on genuinely relevant words, to be a real and checkable pattern rather than noise.

FirmMissing wordQuery
LT Harper"contract"Contract hire
LT Harper"permanent"Permanent hire
ARM Recruitment"permanent"Permanent hire
ARM Recruitment"Manchester"Manchester
ARM Recruitment"reputation"Strongest reputation
Lorien"agency" / "Manchester"Permanent hire / Manchester
Robert Walters"GRC"GRC specialist
Bridewell"recruit" / "hiring"Penetration tester / Security architect
Agency Central"CISO"CISO executive search
Consultancy.uk"recruiters"Strongest reputation

ARM Recruitment and LT Harper each carry the gap on more than one word, across more than one query. Robert Walters' is the sharpest single example: its own GRC recruitment page doesn't contain the word "GRC."

Frequently asked questions

Which UK cybersecurity recruiter does AI recommend most?

No single one, consistently. Robert Walters appeared on more queries than any other firm (14 of 15), and Barclay Simpson had the highest total mention count across all three platforms, but neither one was named on every query, and Barclay Simpson dropped out completely on the SOC-analyst question specifically.

Do Google, ChatGPT and Perplexity ever disagree on the best recruiter?

Yes, on 6 of the 16 queries in this study, all three platforms named completely different firms, with zero overlap between any of them. This happened most often on senior or highly specific hiring questions, including one where ChatGPT reversed its own earlier advice when the same question was worded differently.

Why would a well-known recruiter be missing from an AI Overview's answer?

Often a specific, checkable content gap. In this study, Google itself flagged ten instances where a firm's own page didn't contain a literal word from the search, "contract," "GRC," "Manchester," and in 9 of 10 directly comparable cases, that same firm was also left out of the AI-generated answer, even though its page still ranked in ordinary search.

How can a cybersecurity recruitment agency improve its AI visibility?

Start with specificity, not volume: make sure your own pages state the exact service, hire type, clearance level and location a buyer would search for, in plain language, since AI Overview answers seem to need literal grounding for a specific claim about your firm. Third-party consistency matters too, several of the strongest performers in this study were named the same way across multiple independent sources, not just their own site.

Why we didn't just automate this

A growing number of GEO/AEO tracking platforms offer exactly this kind of study as a one-click, API-driven product: run a few hundred or a few thousand prompts automatically, tally mention rates, publish a report. One competing UK recruitment AI-visibility study we came across claims 1,200 prompts across 12 sectors and 8 cities, run three times each for statistical reliability, a genuinely large dataset.

What that kind of study can't easily show, because no one is reading the individual answers, is why a firm was included or excluded, or what happens when the same question is asked a different way. Nothing in an automated mention-rate table would have caught ChatGPT reversing its own advice between two phrasings of the same hiring question, or a search result stating a company's own page as "Missing" the exact word a buyer searched for, or Google's AI Overview naming a completely different firm depending on which of three cities you asked about. Those are the findings that actually explain the mechanism, not just measure its size, and they only surface when a person reads what the AI actually said and checks it against what's really on the page.

It's also worth asking what a mention-rate number is actually measuring. A flat "appeared in 23% of prompts" figure doesn't say whether that 23% came from broad awareness-stage searches, specific comparison-stage searches, or the moment right before someone actually picks up the phone, and those are very different commercial outcomes for a real business. This study was built around that buyer journey deliberately: broad questions, five technical specialisms, contract versus permanent hiring, three cities, and two pairs of queries re-run with different wording specifically to test whether phrasing alone changes the answer. A single-click prompt-and-tally approach, however large the number of prompts, doesn't naturally produce that structure, because it's built to be run the same generic way for every industry.

None of this means larger, automated studies aren't useful, a bigger sample size genuinely tells you something a 16-query study can't. But scale and rigour answer different questions. We optimised for rigour: every finding on this page traces back to an actual screenshot, including the ones that complicate our own conclusions.

About this research

DW
David Wood
Independent researcher measuring how AI systems perceive and recommend companies. This study is part of an ongoing series tracking the AI Visibility Gap across B2B categories. Prior work includes the 2026 AI Citation Visibility Study for Crypto Protocols (50 protocols, 1,016 citation records, DOI: 10.5281/zenodo.20146677). Service enquiries: CryptoContent.dev

Cite this study: Wood, D. (2026). AI Visibility Gap: UK Cybersecurity Recruitment. aivisibilitygap.com/uk-cybersecurity-recruitment.html