How to stand out in agentic security when everyone is agentic

Phill Keaney-BollandPhill Keaney-Bolland· Co-founder and Designer, Yaya7 min read

Key takeaways

  • The agentic-security category is norming around identical messaging, and a CISO is pitched by somebody new in this space nearly every day.
  • No two agentic-security teams actually think about the problem the same way; the differentiation is real but sits one level below the headline.
  • Your competitor set includes the frontier AI labs, and vertical slivers of domain depth are the moat against them.
  • Refusing to ship a feature can differentiate harder than shipping one, as ThreatLocker's public refusal of an 85%-accurate AI feature shows.
  • When buyers cannot distinguish vendors, the memorable one wins the shortlist and the forgettable ones get compared on price.

There is a sentence being said in hundreds of pitch meetings this quarter: we use AI to secure AI. It appears as "AI for security, security for AI," as "securing the agentic enterprise," as "trust for autonomous systems." The wording shifts. The claim does not. Agentic security is the fastest-forming category in cybersecurity, and like every fast-forming category it is norming around identical messaging while the products underneath diverge wildly.

The buyer feels this before the founders do. A CISO responsible for AI risk is pitched by somebody new in this space nearly every day. Every deck opens with the same market context, the same adoption statistics, the same threat framing. By the fourth vendor in a fortnight, the words have stopped carrying information. The category has arrived at the point where saying what everyone says costs the same as saying nothing.

This is the specific problem of standing out in agentic security: the pressure to adopt is real, the budgets are forming, and the buyer cannot tell you apart.

The differentiation is real. The messaging hides it.#

Here is the strange part. In our work across agentic-security clients, we have never met two teams who think about the problem the same way. One team sees it as a threat-detection problem: agents as a new class of adversary and attack path. Another sees it as a misbehavior problem: the agent is not malicious, it is overeager, and the risk is what it does with legitimate access. Some build guardrails at the prompt and policy layer. Some anchor everything in identity, treating every agent as a workforce member with credentials and entitlements. Some sit at runtime, watching what agents actually do. Some sit at the endpoint, some at the gateway.

These are different theories of the problem, and they lead to different products, different buyers, and different futures. Yet almost none of that thinking survives the trip to the homepage. It gets sanded down into the category-default sentence, because the category-default sentence feels safe.

It is not safe. It is camouflage. Meanwhile, being findable when a buyer describes their use case to a search engine or an LLM is table stakes now, not a story. Discoverability gets you into the consideration set. It cannot make anyone remember which vendor you were.

Your theory of the problem is the differentiator. The headline claim stopped being one the moment everyone adopted it.

Differentiate against the labs, not just each other#

Most agentic-security founders benchmark themselves against peer startups. The more dangerous competitor is bigger and quieter. Justin Woody of Twine, speaking on our podcast, puts it in shipping terms. "You're avoiding these little boats. The ones that are close, you need to make these quick corrections, but you're always looking out for the big container ships because they move so fast, and if you aren't careful, that's going to run you over." The container ships are the frontier AI labs, whose models absorb capabilities that entire startups were founded on. "Keep an eye out for the big ships that are coming," he says, "because they're the ones that can wipe you out."

Woody's answer is vertical slivers. "There's no way these big companies like OpenAI and Anthropic have the discipline for the million different slivers that are out there," he told us. "They're going to build this broad platform, and what we're building is these deep vertical slivers to address people's needs. That's the moat." Depth in a specific domain, its workflows, its failure modes, its regulatory texture, is the moat a horizontal model provider has no incentive to cross. A lab will ship a general capability. It will not learn the operational reality of your niche, because your niche does not move their metrics.

For positioning, this cuts two ways. First, your story should make the sliver explicit: name the domain depth that makes you defensible, rather than gesturing at breadth that makes you look like a feature the labs will ship next quarter. Second, differentiate from the labs out loud. Most vendors only position against peer startups, which tells the buyer nothing about the question they are quietly asking: why won't the model providers just do this?

Philosophy as positioning: the power of refusal#

The sharpest differentiation move in an AI-saturated market may be a public refusal. Rob Allen of ThreatLocker told us on the podcast about testing AI for allow/deny categorization. "It got it right somewhere in the region about 85% of the time." They refused to ship it, because ThreatLocker's philosophy is deny-by-default, and any error rate applied to a deny decision is catastrophic. "Anything greater than 0% is going to be less good than default deny." Fifteen percent wrong is not a feature. It is an outage generator with a marketing budget.

See it in action.

Consider what that refusal communicates. In a market where every vendor is bolting AI onto everything, a company that says "we tested it, here is the number, and here is why we will not ship it" has told you more about their engineering seriousness than any capabilities page could. The refusal is the positioning. It draws a line the buyer can trust precisely because it cost something to draw.

Geordie's founders make a parallel move at the level of architecture. "We are specifically focused on AI agents. We're not building for every AI application in the business," as they put it on our podcast. Agents are a genuinely new kind of actor, so watching them demands thinking built for agents, not endpoint-era instincts retrofitted with a new data source. Agree or disagree, it is a position, and a position invites a reaction. Arjun Bisen of Overwatch adds the commercial version of the same instinct on his own episode. Everyone in security has been burnt by vendors over-promising, so saying "certain things we can't do yet, but we're willing to work with you to get there" earns disproportionate credit.

Every one of these is the same underlying move. A philosophy, stated plainly, with the costs shown.

The forgettable get compared on price#

Why does this matter commercially rather than aesthetically? Because of what happens after the meeting.

Our research keeps returning to the same behavioral fact: days later, at a peer dinner, buyers half-remember the vendors they saw. The pressure to adopt is real, so a shortlist will be formed. The vendor with a distinct theory of the problem, a name that telegraphs the domain, a refusal worth retelling, gets recalled and recommended. The vendors who all said the category sentence collapse into a single blur, and the blur gets evaluated the only way a blur can be: on price. Undifferentiated brands get commoditized, and commoditization in an unformed category is a brutal place to live, because you inherit price competition before you have inherited revenue.

The buyer is simultaneously pressured to adopt and unable to distinguish. That combination does not slow purchases. It routes them to whichever vendor is easiest to remember and safest to forward. Memorability is not a branding luxury in this market. It is the mechanism by which shortlists form.

In a category the buyer cannot parse, the memorable vendor wins the shortlist and the rest negotiate discounts.

Becoming a category of one in a category of hundreds#

The endgame is not to win the comparison. It is to make comparison beside the point. We call this becoming a category of one: a position built on your actual theory of the problem, expressed so distinctly that the buyer has nothing to line you up against. The full argument lives in our category-of-one piece, but the agentic-security application is specific enough to state here.

Start with the market truth every buyer already feels, the contradiction between mandated AI adoption and vanishing visibility, which we unpack in the enterprise contradiction. Then, where every competitor states the category, state your philosophy: the lane you claim, the sliver that defends you from the labs, the thing you refuse to build and why. Then make it concrete. A philosophy that never becomes a mechanism is poetry, and buyers cannot buy poetry; the test of whether yours survives is the five-second homepage.

None of this is hypothetical bravery. We helped both Twine and Geordie reach the RSA Innovation Sandbox final, with Geordie taking the win. Both compete in exactly this crowded space. Neither leads with the category sentence.

Everyone is agentic now. That is precisely why saying so has stopped working. The vendors who will own this category are the ones willing to say the second sentence, the one about what they actually believe, and to let it cost them something. Different by design, in the one corner of the market where sounding the same is the default setting.

Phill Keaney-Bolland

Phill Keaney-Bolland

Co-founder and Designer, Yaya

Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.