The 90-Day AEO Plan for a Cybersecurity Vendor, Week by Week
Ninety days is enough to fix crawler access, baseline measurement, and restructure your ten highest-value pages. Week by week.

Ninety days is enough to fix crawler access, establish a measurement baseline, restructure your ten highest-value pages, and close the largest coverage gaps in your category. It is not enough to build entity authority or to move a training-data-driven answer. This is an AEO plan: answer engine optimization, the practice of getting a site cited directly inside AI-generated answers rather than only ranking in a results list. It sits under the broader umbrella of GEO, generative engine optimization; how the two terms relate is covered separately. This plan sequences the work so the things that produce observable change happen first, and the slow compounding work starts early enough to matter by quarter two.
TL;DR
- Weeks 1 to 4: access, baseline, entity foundation. Nothing downstream works until crawlers can reach you.
- Weeks 5 to 8: restructure existing pages, then fill sub-query gaps. Restructuring beats new content because the pages are already indexed.
- Weeks 9 to 12: measure against baseline, publish the pages nobody in security publishes, and hand the programme to a permanent owner.
- Assumes one part-time technical marketer, occasional engineering support, and a docs team that will accept pull requests. No new headcount.
- The single highest-yield week is week 1. A meaningful share of zero-visibility cases are a WAF (web application firewall) rule.
Assumptions
This plan assumes a B2B cybersecurity vendor with an existing marketing site, product documentation, and some organic search presence. It assumes nobody currently owns AI visibility, which is the normal starting condition. It assumes you can get an engineer for roughly four hours in week 1 and two hours in week 6.
If your site is not indexed in Google Search at all, stop and fix that first. Every AI surface in this plan is downstream of conventional indexing.
Phase overview
| Phase | Weeks | Goal | Observable by day 90? |
|---|---|---|---|
| Foundation | 1 to 4 | Reachable, measured, identifiable | Yes |
| Structure and coverage | 5 to 8 | Extractable pages, gaps closed | Yes, partially |
| Measurement and expansion | 9 to 12 | Trend established, owner assigned | Trend only |
| Entity authority | Ongoing from week 3 | Third-party mentions, consistent naming | No. Quarter two at earliest |
Weeks 1 to 4: foundation
| Week | Action | Owner | Success signal |
|---|---|---|---|
| 1 | Audit crawler access at the edge and at origin. Pull 30 days of logs, filter for retrieval and user-triggered bots, group by response code. | Engineering plus marketing | Non-zero 200s for OAI-SearchBot, Claude-SearchBot, PerplexityBot, Googlebot |
| 1 | Reconcile robots.txt against the WAF. Fetch robots.txt from outside your network. | Engineering | Edge policy and robots.txt agree |
| 2 | Write 50 buyer-realistic prompts from real sales calls, not keyword tools. Cover all buying stages. | Marketing plus sales | A prompt set a salesperson recognises |
| 2 | Run the full set manually across ChatGPT, Claude, Perplexity, and Google AI Mode. Save every answer verbatim. | Marketing | A baseline document, not a score |
| 3 | Audit Organization, Person, and Product schema. Add sameAs links to every profile you control. | Marketing plus engineering | Valid schema on homepage, product, and about pages |
| 3 | Standardise how the company, product, and category are named. One string each, everywhere. | Marketing | A written naming standard, applied to the top 20 pages |
| 4 | Map the fan-out for your three highest-value prompts. Grid the sub-queries against where you appear. | Marketing | A gap list of four to seven missing pages |
| 4 | Decide the training-crawler policy explicitly, with legal in the room. Document it. | Legal plus executive | A written decision, either way |
Week 1 is the highest-yield week in the plan. In security companies, bot policy is a security control owned by a team that has never been asked whether OAI-SearchBot should be allowed, and the default posture is deny. A rule written in 2022 to block unknown bots catches every crawler introduced since. Details and the exact user-agent tokens are in the crawler reference.
On week 2: save the raw answer text, not a score. The verbatim output is the asset. It tells you which competitors are named instead of you, which claims about your category are wrong, and which sub-questions the engine struggles to answer, and none of that survives compression into a number.
Weeks 5 to 8: structure and coverage
| Week | Action | Owner | Success signal |
|---|---|---|---|
| 5 | Restructure your five highest-traffic pages for extraction: direct answers per section, claim-shaped headings, explicit entity naming. | Marketing | Every section passes the orphan-paragraph test |
| 6 | Convert every prose comparison of three or more items into a real HTML table. Verify the design system emits real heading and table elements. | Marketing plus engineering | Real semantic markup in view-source |
| 6 | Add source and year to every statistic on those pages. Delete anything you cannot attribute. | Marketing | Zero unattributed numbers |
| 7 | Publish the pricing page. Real units, real numbers, what counts as billable. | Marketing plus product | A page that answers the pricing sub-query |
| 7 | Publish or ungate the deployment page: realistic time to value, prerequisites, known limits. | Product plus marketing | Operational specifics, not marketing copy |
| 8 | Publish an honest alternatives page covering your two main competitors, including where they win. | Marketing | A page a competitor would grudgingly call fair |
| 8 | Restructure the ten most-visited documentation pages the same way. | Docs plus marketing | Docs pages that survive extraction |
Restructuring first is deliberate. Existing pages already have crawl history, internal links, and whatever authority they accumulated. An hour spent making an indexed page extractable outperforms an hour spent on a new page that nothing links to. The mechanics are in the extraction patterns.
Weeks 7 and 8 are where this plan usually stalls. Pricing, deployment reality, and honest competitor comparisons are the three sub-queries almost no security vendor answers publicly, which is exactly why they are open. Every one of them is currently being answered about you by review sites and competitors working from secondhand information. The internal argument against publishing them is real and it is losing to the fact that the answer exists either way.
On documentation: docs consistently get retrieved for operational questions, and most security vendors treat them as engineering output rather than as the highest-intent content they own. See why documentation is the underrated GEO asset.
Weeks 9 to 12: measurement and handover
| Week | Action | Owner | Success signal |
|---|---|---|---|
| 9 | Re-run the week 2 prompt set across all four engines. Compare verbatim against baseline. | Marketing | Movement on restructured pages specifically |
| 9 | Re-check crawler logs. Confirm the new pages were fetched and returned 200. | Engineering | New URLs in retrieval-bot logs |
| 10 | Close the remaining fan-out gaps from week 4, in decision-stage order. | Marketing | Gap list cleared |
| 10 | Set the refresh cadence: quarterly review with a visible dateModified on the top 20 pages. | Marketing | A calendar entry with an owner |
| 11 | Decide whether to buy a monitoring tool, using the manual baseline as the requirement. | Marketing | A decision grounded in a known gap |
| 11 | Start the entity work: conference talks, podcast appearances, analyst briefings, consistent author bios. | Marketing plus executive | Two scheduled third-party appearances |
| 12 | Write the programme handover: prompt set, baseline, cadence, named owner. | Marketing | One person accountable for citation share |
| 12 | Report to leadership on citation share against baseline, not sessions. | Marketing | Leadership understands why sessions did not move |
Week 12 matters more than it looks. Programmes like this die when the person who ran the sprint moves on and no one owns the metric. Citation share belongs to nobody by default, which is the argument in the GEO org chart.
What to skip
- llms.txt. Ahrefs found 97% of these files receive zero requests. Ship one in quarter two if you want the option value, and do not spend a week of a 90-day plan on it. Reasoning in the llms.txt guide.
- Buying a monitoring tool in week 1. Manual baselining teaches you what your prompt set should contain. Buy in week 11 with requirements, using the tool comparison.
- Chasing every engine equally. Perplexity for fast feedback, Claude for B2B pipeline, Google for reach. The reasoning is in the engine mechanics reference.
- Rewriting everything. Ten pages restructured properly beats a hundred touched lightly.
What 90 days will not deliver
Entity authority compounds over quarters. If ChatGPT answers your category question from parametric knowledge rather than retrieval, structural changes to your site move nothing, and the fix is being written about across enough independent sources that the model's underlying knowledge names you. That work starts in week 11 and pays off much later.
Traffic will probably not move much either, and reporting this correctly is part of the job. Google's AI Mode shows a zero-click rate near 93%, so the majority of what you gain will not appear as sessions. Set that expectation with leadership in week 1, not in week 12 when the numbers are due.
Frequently Asked Questions
How long does AEO take to show results?
Restructured existing pages tend to show movement on a fixed prompt panel within four to eight weeks, because those pages are already indexed and the change affects how well they compete once retrieved. New pages take longer. Entity-level work, meaning third-party mentions and consistent naming across the web, generally does not show inside 90 days.
Who should own AEO in a cybersecurity company?
Someone with authority over page structure, schema, and the edge configuration, which usually means technical marketing or SEO rather than editorial. The part that fails without an explicit owner is measurement, since citation share does not belong to any existing role by default.
What is the first thing to do?
Check whether AI retrieval crawlers can reach your site. Pull 30 days of origin logs, filter for OAI-SearchBot, Claude-SearchBot, PerplexityBot, and Googlebot, and group by response code. In security companies especially, a WAF rule written years ago frequently blocks crawlers that did not exist when it was authored, and no amount of content work fixes that.
Do I need to publish pricing?
To win the pricing sub-query, yes. Buying prompts reliably decompose into a pricing retrieval, and if you do not answer it, review sites and competitors do, using estimates. Publishing a pricing model with real units is usually enough; a full price list is not required.
Should I buy an AI visibility tool at the start?
No. Baseline manually for the first two months. Running the prompts yourself teaches you what belongs in the set and shows you the verbatim answers, which is where the actionable information lives. Buy in month three with real requirements.
What if leadership expects traffic growth?
Reset that in week 1. AI Mode's zero-click rate runs near 93%, so most of the value is a citation with no session attached. Report citation share against a documented baseline, and pair it with direct-traffic and branded-search trends, which is where the uncredited demand surfaces.
Can a small team do this?
Yes. The plan assumes one part-time technical marketer, about six hours of engineering across the quarter, and a docs team that accepts pull requests. The constraint is not headcount, it is getting the pricing, deployment, and competitor pages approved for publication.
More from Deepak Gupta
Every page on guptadeepak.com is hand-curated by Deepak Gupta. Pick a thread:
- About Deepak Gupta
Founder, cybersecurity architect, and writer at guptadeepak.com.
- My journey
From LoginRadius (2013, 1B+ users) to GrackerAI, in milestones.
- Publications & patents
Books, free e-books, a journal special issue, and five granted patents.
- Research Hub
Curated research, buyer's guides, vendor comparisons, and technical deep-dives.
Get the newsletter
New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.