Cybersecurity companies, products & suppliers

Cybersecurity products protect systems, identities and data using conventional and increasingly ML-based controls. In this directory the category is general security tooling, not LLM-specific application security. Buyers comparing 'AI security' should use that category instead.

What is Cybersecurity?

Cybersecurity products protect systems, identities and data using conventional and increasingly ML-based controls. In this directory the category is general security tooling, not LLM-specific application security. Buyers comparing 'AI security' should use that category instead.

What problems does it solve?

Attack surface grows while security operations still triage noisy alerts.

Typical business use cases

  • Detection
  • Response
  • Identity
  • Cloud security

Important capabilities

  • Telemetry
  • Detection content
  • SOAR
  • Admin

What buyers should evaluate

  • Coverage
  • Data processing of telemetry
  • False positives
  • Integration

Risks and governance considerations

Telemetry sent to a vendor cloud without a data map.

Procurement checklist

  • Data map
  • Residency
  • Admin access
  • Detection content rights

Relevant AI Trustmark assurance

General cybersecurity certification is not an AI Trustmark, and vice versa.

Methodology · How verification works

Companies and providers

Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.

  • Abnormal Security develops AI-native email security for enterprise security teams. Its platform analyses communication behaviour to help identify business email compromise, phishin

  • Amazon Web Services is Amazon's cloud division selling compute, storage, Bedrock model hosting and related AI infrastructure. Public pages cover regional cloud services for builder

  • CrowdStrike is a global cybersecurity leader with an advanced cloud-native platform for protecting endpoints, cloud workloads, identities and data. CrowdStrike publishes Falcon Clo

  • CybSafe is a London cyber-security company selling behaviour-based security awareness software. Public marketing covers measuring and changing employee security behaviour rather th

  • Darktrace is a Cambridge-headquartered cyber-security company that sells AI-based threat detection and autonomous response products for enterprise networks, cloud and email. Darktr

  • Google is a US technology company that sells consumer and cloud AI products, including Gemini, Search, and related developer APIs on Google Cloud. Google publishes Imagen, Gemini f

  • Immersive Labs is a UK cyber-skills company selling hands-on technical training and crisis-exercise software. Public marketing covers measuring and developing security capability a

  • Material Security provides phishing protection, account-takeover prevention, and email DLP for Google Workspace and Microsoft 365. Material Security is used for Cybersecurity work.

  • Microsoft Corporation sells Windows, Azure, Microsoft 365 and Copilot AI products. Public pages cover cloud, productivity and developer APIs used by enterprises and consumers. Micr

  • Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’

  • Every AI-building team faces one question: can you trust what you're shipping? Snyk secures the code AI writes, the agents it runs, and the apps it builds. Get started for fre

  • Wiz connects code, cloud, and runtime into one agentic cybersecurity platform. Prevent risk, detect threats, and start secure – across every cloud and AI layer. Wiz, Inc. trades as

Products

Claimed products appear first. Ranking packs and payment do not change this list.

Related categories

Relevant procurement and assurance guides

Frequently asked questions

Is this the same as AI security?

No. AI security is controls for AI systems. Cybersecurity is broader enterprise security.

What is Cybersecurity?

Cybersecurity products protect systems, identities and data using conventional and increasingly ML-based controls. In this directory the category is general security tooling, not LLM-specific application security. Buyers comparing 'AI security' should use that category instead.

What security testing evidence should buyers request for an AI product?

Ask what was tested, against which version, whether prompt-injection, data-exfiltration and tenant isolation were in scope, and where failed prompts were stored. A generic ISO certificate or a vendor scanner screenshot is not by itself an AI TrustMark assessment.

How should prompt injection and tool-output attacks be controlled?

Agents that read untrusted content or tool output can be instructed to exfiltrate data or take writes. Buyers should ask what is treated as untrusted, whether tool output can change the plan, and what tests were run. Scanner marketing is not the same as independent testing.

What model or provider changes should a buyer insist on being told about?

Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.

How should buyers verify where AI customer data is processed?

Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.

Does a TrustMark on one product cover the rest of the company?

No. Independent assessment is scoped to the named organisation and, where relevant, the named product. Category pages list suppliers as a topic label. They do not imply that every listed company has been assessed.

What incident-handling evidence is useful for AI suppliers?

Buyers should see how AI-specific failures are detected, contained and notified — including unsafe outputs, data leakage and unauthorised agent actions. An incident policy that never mentions models, prompts or tools is incomplete for this class of product.