As of 13 August 2026, AI can only partly choose cybersecurity software for your business.
Most people should hand this to a purpose-built tool.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita colleague
What the alternative costsThe available product data gives no price for a human security consultant or managed security provider.
If this goes wrong: you buy software that leaves a real gap, fails to work with your systems or creates false confidence while an incident remains possible.
What to actually do
Use a tool built for this
The route this page recommends
Do it yourself
Second choiceA chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open a document and record your users, devices, operating systems, cloud services, sensitive data, remote-working arrangements, current security controls and main security concerns.
- Gather current vendor product pages, technical documentation, data-processing information, contract terms, quotes and any stated certifications, then paste the relevant text and links into the prompt.
- Add your business requirements, customer or insurance conditions, budget, deployment preferences and the technical skills available to maintain the software.
- Paste the complete prompt into a chatbot and ask it to produce the requirements summary, evidence-based comparison, shortlist, vendor questions and pilot plan.
- Open each cited vendor document and compare it with the drafted table, correcting any unsupported feature, compatibility, certification, data-handling or contract claim.
- Ask a technically capable colleague or cybersecurity professional to review the gaps and pilot the shortlisted product on non-critical systems before you approve a purchase.
Prompt
Act as a cautious cybersecurity procurement analyst for a UK business. Help me create a shortlist, not an automatic final decision. Business context: - Business type and size: [describe] - Number of users: [number] - Devices and operating systems: [describe] - Cloud services and important systems: [describe] - Remote working arrangements: [describe] - Sensitive or regulated data handled: [describe] - Current security controls and software: [describe] - Main concerns or recent incidents: [describe] - Required standards, customer requirements or insurance conditions: [describe] - Budget and contract preferences: [describe] - Technical skills available internally: [describe] Vendors or products to compare: [paste current product names, links, quotes and vendor documentation] Produce: 1. A concise statement of the security problem and requirements, separating facts I supplied from assumptions. 2. A comparison table covering protection offered, systems supported, deployment, administration, alerting, reporting, integrations, data handling, stated certifications, contract terms and important exclusions. 3. A shortlist of no more than three options, with evidence for each claim and a clear explanation of what each option does not cover. 4. Questions I must ask each vendor before buying. 5. A practical pilot plan using non-critical systems, including what to test and what would make us reject a product. 6. A decision record showing which requirements are essential, which are preferences and which remain unanswered. Use only current information in the material I provide. Do not invent prices, certifications, compliance, compatibility, detection rates or security guarantees. Mark missing or unverified information as unknown. Do not claim that any product makes the business secure or guarantees Cyber Essentials compliance. Tell me which conclusions require review by a qualified cybersecurity professional.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
Hand it to a person
The distant thirdA person who owns the outcome does this end to end, worth it when the failure is dear.
What it gets wrong
- AI cannot discover an undocumented weakness in your network, identity setup or business processes from a product comparison alone.
- AI cannot reliably confirm that a vendor's current feature, certification, data location or contract term still applies without checking the source directly.
- AI cannot judge how well the product will be configured, monitored and maintained by the people in your business.
- AI cannot carry the consequences of a purchase that leaves a security gap or disrupts your systems.
What caps this at PARTLY: judgement under ambiguity, real time truth and stakes of error.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 2 |
| Total | 7 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT choose the best cybersecurity software for my business?
- It can create a useful shortlist and compare products against requirements you provide. It cannot know your actual exposure or take responsibility for the final choice, so a colleague or cybersecurity professional should check the shortlist and pilot.
- Is it safe to use AI to choose antivirus software?
- It is reasonable to use AI for gathering requirements, comparing supplied documentation and writing vendor questions. Do not treat its recommendation as proof that the product covers your systems, and verify current features, exclusions and compatibility before buying.
- What information does AI need to recommend security software?
- Give it your users, devices, operating systems, cloud services, sensitive data, remote-working arrangements, current controls, technical capacity, budget and required standards. Include current vendor documentation and mark anything you do not know rather than letting the model fill the gap.
- Should a cybersecurity professional approve the software I buy?
- For a small, straightforward purchase, a technically capable colleague may be able to verify the comparison and run a limited pilot. Use a cybersecurity professional when the software affects important systems, sensitive data, compliance obligations or a significant security gap.
Nearby answers
- Can AI check whether my business passwords have been leaked?PARTLY
- Can AI check my business cybersecurity compliance with UK GDPR?NO
- Can AI check whether an email is a phishing attempt?PARTLY
- Can AI choose a password manager for my business?YES
- Can AI compare business antivirus software in the UK?PARTLY
- Can AI create a backup strategy for my small business?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.