---
title: "How network security vendors win buyers who ask AI"
description: "By being named, in NIST and CISA terms, in AI answers about firewall refreshes, SASE and zero trust access, with a public security record buyers can check."
canonical: "https://underneath.agency/resources/network-security-zero-trust-customers-ai-search"
published: 2026-10-07
updated: 2026-10-08
publisher: "Underneath (https://underneath.agency/agent)"
entity: "https://underneath.agency/.well-known/entity.json"
---
Guide · AI search

# How do network security vendors win buyers who ask AI about zero trust?

By being named in the AI answers that turn “we need zero trust” into a shortlist, in the framework language buyers already use, and by keeping a public security record that survives checking. Network security is in the middle of a large replacement cycle: firewalls are being refreshed, and remote access is moving to zero trust. The questions buyers ask during that move are architectural, and the answers decide who gets the evaluation.

## The short version

1. The core market is still growing: [Gartner forecasts](https://softwarestrategiesblog.com/2026/04/01/top-10-fastest-growing-security-categories-gartner-2026-forecast/), as summarized by Louis Columbus, put firewall equipment at $16.8 billion of spending in 2025, growing 15.9% in 2026.
2. Zero trust access is replacing older tools: the same forecast has zero trust network access (ZTNA) growing 23.0% in 2026, while intrusion prevention falls 6.3% and network access control 7.7%.
3. [Dell’Oro Group](https://www.delloro.com/news/sase-revenue-grows-above-20-percent-as-sd-wan-reaccelerates-in-2q-2026/) counted $3.5 billion of secure access service edge (SASE) revenue in the second quarter of 2026, its fifth straight quarter of growth above 20%, and calls the single-vendor versus multi-vendor question “contested.”
4. Buyers have a public playbook: [NIST’s 2025 guidance](https://www.nist.gov/news-events/news/2025/06/nist-offers-19-ways-build-zero-trust-architectures) offers 19 example zero trust architectures built with commercial products from 24 industry collaborators, and [CISA’s maturity model](https://www.cisa.gov/zero-trust-maturity-model) sets out five pillars.
5. The perimeter itself is under attack: [Verizon’s 2025 breach report](https://verizon.com/about/news/2025-data-breach-investigations-report) found exploitation of vulnerabilities rose 34% as an initial attack vector, with a focus on perimeter devices and VPNs.

## Who signs off on a network security platform, and how big is the deal?

A network and security team buys it together, for the whole organization, usually as a multi-year platform decision.

Network security covers the controls between users, devices, applications and data: firewalls, secure web gateways, ZTNA, SD-WAN, and the cloud-delivered bundles sold as SASE or security service edge (SSE). Unlike many security tools, it sits in the path of every connection, so a bad choice breaks the business, not only a dashboard. That makes buyers careful and decisions slow.

The buying group is two teams with different priorities. Networking cares about performance, branch connectivity and operations. Security cares about policy, inspection and risk. Dell’Oro notes that SASE growth now comes from both: branch network refreshes and security services expanding into data protection and AI governance. A vendor has to win both teams.

Customers are large. Netskope said at its 2025 [initial public offering](https://www.netskope.com/press-releases/netskope-announces-pricing-of-initial-public-offering) that its customers include more than 30% of the Fortune 100. Platform deals bundle firewall, access and inspection, so one decision can cover every office and remote worker for years.

Budgets are being reshuffled rather than simply increased. In the Gartner forecast summarized by Columbus, overall security spending growth for 2026 is 12.2%, and the firewall equipment line alone is projected to reach $26.7 billion by 2030. ZTNA is forecast to grow from a $2.4 billion base to $6.4 billion by 2030, while older categories shrink. The money follows the move to zero trust.

## At what point do network security buyers turn to AI?

At the research stage, alongside sales calls, peers and frameworks; no public study isolates network security buyers.

The closest evidence covers business buyers generally. In a [Gartner survey](https://www.gartner.com/en/newsroom/press-releases/2026-05-20-gartner-survey-finds-sixty-nine-percent-of-b-two-b-buyers-turn-to-sales-reps-to-validate-ai-generated-insights) of 645 B2B buyers in 2025, 45% had used generative AI in a recent purchase, mainly to gather information on vendors and products. Gartner’s headline finding was that 69% turned to sales reps to validate AI-generated insights, and a slight majority said they were more likely to meet misleading information from generative AI than from a rep.

That pattern fits network security closely, we infer. A buyer can ask an assistant to explain SASE or compare ZTNA approaches in minutes, but no one replaces the firewalls at 400 branches on an AI answer alone. The answer shapes which vendors get the call; the proof of concept decides who wins.

Google’s AI features are also in the path, and Google says AI Overviews and AI Mode [may use a “query fan-out” technique](https://developers.google.com/search/docs/appearance/ai-features), turning one zero trust question into several related searches across subtopics. A question about zero trust for a hospital network, we infer, fans out into framework, vendor, compliance and review searches at once.

## What do firewall and SASE buyers type into AI assistants?

Architecture, framework, migration, comparison and vendor-risk questions. Each prompt below is our own illustration of how a CISO or network architect might phrase the question; none were collected from real buyers.

| Stage | Illustrative prompt |
|---|---|
| Strategy | “How do we move from VPN to zero trust access for 8,000 employees without breaking legacy apps?” |
| Framework | “Which vendors map to the CISA Zero Trust Maturity Model network pillar at the advanced level?” |
| Architecture | “Single-vendor SASE or best-of-breed SD-WAN plus SSE for a manufacturer with 120 sites?” |
| Refresh | “Our firewalls reach end of support next year: should we replace them or move to firewall as a service?” |
| Comparison | “Zscaler vs Netskope vs Palo Alto Prisma Access for a company on Microsoft 365” |
| Vendor risk | “Which firewall vendors have had actively exploited vulnerabilities in the last two years?” |
| Compliance | “Which ZTNA products are FedRAMP authorized for a federal contractor?” |

The framework questions matter because buyers borrow the government’s vocabulary. NIST’s Zero Trust Architecture (SP 800-207) describes the concept, and its 2025 implementation guide (SP 1800-35) shows 19 worked examples. CISA’s model gives five pillars, three cross-cutting capabilities and four maturity stages from traditional to optimal. A vendor whose public material maps its products to those terms gives an assistant an easy way to connect it to the question, we infer.

The vendor-risk questions are real, too. In September 2025 CISA issued [Emergency Directive 25-03](https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices) ordering federal agencies to identify and mitigate potential compromise of certain Cisco firewall products, and updated it in April 2026. Every network security vendor faces questions about its own record, and buyers increasingly ask them of AI.

## How does a firewall or SASE vendor get from an AI mention to a signed platform deal?

Through the architecture decision: an AI answer frames the approach and names vendors, then a pilot decides.

1. A CISO, network architect or IT director asks how to replace VPNs, refresh firewalls or meet a zero trust goal.
2. The answer describes an approach (single-vendor SASE, SSE plus existing SD-WAN, firewall as a service) and names vendors that fit it.
3. The team checks those vendors against frameworks, analyst views, peers and vulnerability history.
4. Two or three vendors run a pilot on real users and sites, often through a reseller or managed service provider.
5. The winner signs a multi-year platform agreement that expands as sites and users move over.

Step 2 is where AI answers matter most, because the approach chosen narrows the vendor field before any vendor is called. Consolidation makes the stakes higher. In a [2022 Gartner survey](https://www.gartner.com/en/newsroom/press-releases/2022-09-12-gartner-survey-shows-seventy-five-percent-of-organizations-are-pursuing-security-vendor-consolidation-in-2022), 75% of organizations were pursuing security vendor consolidation, up from 29% in 2020, and SASE was named as a main area for it. When buyers consolidate, the vendor framed as the platform wins several product lines at once.

Tracing a SASE or firewall deal back to an AI answer is hard. The answer is rarely a click; it is a name on a whiteboard months before a reseller files the deal. How that hidden influence shows up later is the subject of [what lost clicks mean for pipeline](https://underneath.agency/resources/ai-answers-pipeline-revenue).

## Why does an assistant name one SASE or firewall vendor over another?

No platform explains its vendor choices; studies point to named sources and fresh pages, and security buyers check everything.

**Documented by the platforms.** When a buyer asks about ZTNA or a firewall refresh, Google’s and OpenAI’s AI answers run their own web searches and link the pages they used, as both companies document. Neither company says how a firewall or SASE vendor ends up in the answer.

**Observed in studies.** In [our hidden-searches study](https://underneath.agency/research/ai-hidden-searches-study), when an assistant’s search named a specific source, the answer cited that source 44.0% of the time, against 8.1% when it did not. In security, named sources would include analyst reports, independent test labs and government guidance, we infer. When [our freshness study](https://underneath.agency/research/ai-source-freshness-study) dated the pages each assistant cited, those under 90 days old were 17.4% to 22.6% of the total, against 6.9% of Google’s top 10. In a field where vulnerabilities and products change monthly, stale pages are a real weakness. Practitioner communities matter as well: [our Reddit study](https://underneath.agency/research/ai-reddit-citations-study) found r/cybersecurity among the communities Google’s AI cited most.

**What network security buyers check.** Framework alignment, independent test results, certifications such as FedRAMP, vulnerability and patch history, and references from similar organizations. Verizon’s finding that attackers increasingly exploit perimeter devices and VPNs means a vendor’s own security record is part of the evaluation.

**Our inference.** The evidence that convinces a network architect is mostly public: NIST and CISA mappings, test reports, advisories, certifications and peer reviews. Those are the same pages an assistant can find. A reasonable expectation is that vendors whose proof is public, current and framed in the buyer’s framework language are named more often for the right questions. Nobody has yet tested that idea on firewall, ZTNA or SASE vendors.

## What happens to a firewall or SASE vendor that AI answers leave out?

Missed platform decisions that last years, though no study has measured the loss directly.

- **Refresh cycles are long.** A vendor left off the shortlist at a firewall refresh may wait for the next refresh, years later, we infer.
- **Consolidation multiplies the miss.** If the winning platform covers firewall, ZTNA and web gateway, missing the first decision means missing several product lines.
- **Old categories are shrinking.** With intrusion prevention and network access control forecast to decline, vendors framed only in those terms risk being described as legacy.
- **Inaccurate answers carry risk.** An AI answer that mixes up your products, or repeats an old vulnerability without the fix, can remove you from a list. If an assistant gets your products or patch history wrong, start with [how to fix wrong brand information in AI answers](https://underneath.agency/resources/fix-wrong-brand-information-in-ai-answers).

## What does GEO involve for a zero trust or SASE vendor?

It links your firewall, ZTNA and SASE products to the frameworks buyers already cite, in sources assistants trust. Being named is never guaranteed.

1. **Framework-mapped documentation.** Publish plain pages that map each product to NIST SP 800-207 components and CISA’s pillars and maturity stages, with honest limits.
2. **A public security record.** Keep advisories, patch timelines and certifications on readable pages. Transparent handling of your own vulnerabilities is evidence; hidden handling invites worse answers.
3. **Independent proof.** Independent test results, analyst coverage, participation in public projects such as NIST’s, and customer stories with named organizations give assistants sources other than you. For network security vendors, that outside proof is what [how brands build authority for AI search](https://underneath.agency/resources/how-brands-build-authority-for-ai-search) is about.
4. **Architecture guides.** Write honest guides to the real decisions: single-vendor or multi-vendor SASE, VPN replacement, firewall refresh. Third-party rankings of SASE and firewall vendors still carry weight, as our piece on [best-of lists](https://underneath.agency/resources/best-of-lists-ai-recommendations) shows.
5. **Fresh, consistent facts.** Keep product names, bundles and certifications current everywhere, including partner and reseller pages, since renamed products confuse buyers and assistants alike.
6. **Repeated checks on the zero trust questions.** Run the CISA-pillar, VPN-migration and vendor-risk questions your buyers ask through ChatGPT, Gemini, Perplexity, Claude, Copilot and Google’s AI features, more than once each. Our note on [how many prompts to track](https://underneath.agency/resources/how-many-prompts-to-track-ai-visibility) helps size that list.

For the wider picture of how security buyers use AI and what they trust, see our guide for [cybersecurity software companies](https://underneath.agency/resources/cybersecurity-software-revenue-from-ai-search). For the identity side of zero trust, see [how identity platforms get named by AI](https://underneath.agency/resources/iam-enterprise-demand-ai-search).

## What don’t we know yet about AI answers in zero trust buying?

Nobody has measured whether being named by AI changes who wins a firewall or SASE pilot.

- **No survey of network security buyers’ AI use.** Gartner’s figures cover B2B buyers in general.
- **Market figures are summarized forecasts.** The Gartner numbers here come from an analyst’s public summary of a paid forecast and will be revised.
- **The consolidation survey is dated.** Gartner’s vendor consolidation figures are from 2022.
- **The link to signed platform deals is the weakest part.** For what is known across categories, see [does AI visibility drive business results](https://underneath.agency/resources/does-ai-visibility-drive-business-results).

## Which questions should a firewall or SASE vendor test before the next refresh cycle?

The VPN replacement, SASE and firewall refresh questions that precede your pilots, plus how AI answers describe you.

List the decisions that lead to your pilots: VPN replacement, firewall refresh, SASE architecture, compliance needs. Put each one to the main assistants, and repeat it, so a single odd answer does not mislead you. Record whether you are named, how your products are framed against NIST and CISA terms, which sources are cited, and what is said about your security record. The gaps usually point to missing framework mappings, stale pages or thin independent proof.

To run that test with us, [ask us for a zero trust visibility review](https://underneath.agency/contact). We will look at where assistants place you in VPN replacement, SASE and firewall refresh answers, the decisions that feed pilots and multi-year platform agreements, and point out the gaps most likely to cost you those deals. The follow-up is described on our [generative engine optimization service](https://underneath.agency/services/generative-engine-optimization) page: framework mappings, a readable security record and repeated checks on the questions network and security teams ask.

## Frequently asked questions

### Do buyers really ask AI about zero trust vendors?

Many B2B buyers use AI in research: 45% in Gartner’s 2025 survey. No public study isolates network security buyers.

### Should we map our products to the CISA Zero Trust Maturity Model?

Yes, honestly. Buyers use its five pillars and maturity stages, and a clear mapping is easy for both people and assistants to repeat.

### Does a past vulnerability hurt AI visibility?

It can shape answers. Publish advisories, fixes and timelines plainly so assistants find the full story, not only the headline.

### Is single-vendor SASE always the winning position?

No. Dell’Oro calls the architecture contested; multi-vendor designs remain viable in complex enterprises, so describe where you fit.

### How fast do AI answers pick up new pages?

Often quickly. Pages under 90 days old were 17.4% to 22.6% of each assistant’s dated citations in our freshness study, so current advisories and architecture pages are worth the upkeep.

## Sources

- Louis Columbus, Software Strategies Blog (2026-04-01), [Gartner’s $246.2B Security Forecast shows 10 categories growing 2x to 3x the market](https://softwarestrategiesblog.com/2026/04/01/top-10-fastest-growing-security-categories-gartner-2026-forecast/)
- Dell’Oro Group (2026-09-15), [SASE Revenue Grows Above 20 Percent as SD-WAN Reaccelerates in 2Q 2026](https://www.delloro.com/news/sase-revenue-grows-above-20-percent-as-sd-wan-reaccelerates-in-2q-2026/)
- NIST (2025-06-11), [NIST Offers 19 Ways to Build Zero Trust Architectures](https://www.nist.gov/news-events/news/2025/06/nist-offers-19-ways-build-zero-trust-architectures)
- CISA (2023), [Zero Trust Maturity Model](https://www.cisa.gov/zero-trust-maturity-model)
- CISA (2025-09-25, updated 2026-04-23), [ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices](https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices)
- Verizon (2025), [2025 Data Breach Investigations Report](https://verizon.com/about/news/2025-data-breach-investigations-report)
- Netskope (2025-09-17), [Netskope Announces Pricing of Initial Public Offering](https://www.netskope.com/press-releases/netskope-announces-pricing-of-initial-public-offering)
- Gartner (2026-05-20), [Gartner Survey Finds 69% of B2B Buyers Turn to Sales Reps to Validate AI-Generated Insights](https://www.gartner.com/en/newsroom/press-releases/2026-05-20-gartner-survey-finds-sixty-nine-percent-of-b-two-b-buyers-turn-to-sales-reps-to-validate-ai-generated-insights)
- Gartner (2022-09-12), [Gartner Survey Shows 75% of Organizations Are Pursuing Security Vendor Consolidation in 2022](https://www.gartner.com/en/newsroom/press-releases/2022-09-12-gartner-survey-shows-seventy-five-percent-of-organizations-are-pursuing-security-vendor-consolidation-in-2022)
- Google Search Central (2025), [AI features and your website](https://developers.google.com/search/docs/appearance/ai-features)
- Underneath (2026), [The hidden searches AI assistants run before they answer](https://underneath.agency/research/ai-hidden-searches-study)
- Underneath (2026), [How fresh are the pages AI engines cite?](https://underneath.agency/research/ai-source-freshness-study)
- Underneath (2026), [When does a Reddit thread become evidence in Google’s AI?](https://underneath.agency/research/ai-reddit-citations-study)

---

This is the Markdown twin of https://underneath.agency/resources/network-security-zero-trust-customers-ai-search. The HTML page is canonical. Publisher: Underneath, https://underneath.agency/agent. Site index: https://underneath.agency/llms.txt.
