Seventeen of the twenty-six providers we were listing were not real companies. We found them by calling the phone numbers. Here is what that says about every other directory you are using to pick a security vendor.
Seventeen of the twenty-six cybersecurity providers on this site did not exist.
Not “had stale information.” Not “went out of business.” Did not exist. Every one of them carried a phone number in the 555 range — the block reserved for fiction, the one film studios use so nobody’s real line gets flooded. Nine of them pointed at domains that returned NXDOMAIN, which is the internet’s way of saying there is nothing here and there never was.
We found them in our own directory. We put them there.
How phantom businesses get into a directory
Nobody sat down and invented seventeen security firms. What happened is more ordinary and more instructive.
We asked an AI research agent to find cybersecurity companies in a metro area. It came back with a clean, formatted table: company names, phone numbers, websites, specializations, even a tidy summary noting which fields had been successfully collected. Some of those companies were real. Some were not. The output gave no indication which was which.
That is the part worth sitting with. The failure was not that a model hallucinated — models do that, it is a known cost. The failure was that the result arrived indistinguishable from research. Same table. Same confidence. Same green checkmarks. A person reviewing it would have to independently verify every row to find the fabrications, at which point the agent has saved nobody any time.
We caught ours by accident, chasing an unrelated bug. Then we ran the obvious test on a second batch from the same pipeline: eleven of twenty-four domains did not resolve. One entry appeared in two different cities under two different phone numbers — the same invented company, franchised by a language model.
Why this matters more in security than in pizza
A fake taqueria in a restaurant directory is a wasted evening.
A fake incident response firm is something else. The moment a business needs that listing is the worst hour of its year — ransomware on the file server, a wire fraud in progress, an auditor asking where the data physically lives. That is when someone dials the number. That is when they find out.
The people most likely to be hurt are the ones with the least slack: the twelve-person medical practice with a HIPAA obligation, the machine shop that just picked up a defense subcontract and discovered CMMC exists, the family business that has never bought security before and has no idea what to even ask for. They are the ones who trust a directory, because a directory is what you use when you do not yet know the landscape well enough to have opinions about it.
Those buyers cannot tell a real MSSP from a plausible-sounding one. That is the entire reason they are on a directory in the first place.
Verification is now the product
For twenty years, the hard part of running a directory was gathering listings. Coverage was the moat. Whoever had the most entries won.
Generative AI collapsed that overnight. Anyone can produce five hundred plausible business listings this afternoon, complete with addresses, specializations, and a confident paragraph about each company’s approach to zero trust. Coverage is worthless now, because coverage is free.
Which inverts the whole business. The scarce thing is no longer the list — it is the assurance that the list is true. Every entry that survives a check is worth more than a hundred that were never checked, and a directory that cannot say which is which is not a directory. It is a search result with better typography.
So we cut ours by two thirds and published the smaller number.
What we actually do now
Nothing sophisticated. That is rather the point — this is not hard, it is just work nobody was doing:
- Every domain must resolve and serve a page. NXDOMAIN is an automatic reject.
- Every phone number is checked against reserved ranges. No 555. No pattern numbers.
- Every listing must exist in our directory system, not only in a research file. If it never made it to a human-maintained record, it does not go live.
- AI research output is treated as a lead, never as a listing. It goes through the same gate as a cold submission.
Three mechanical checks. They would have caught all seventeen of ours and eleven of the next twenty-four, with no judgment required from anybody.
What you should do before you call anyone
If you are choosing a security partner off any list, ours included, take ninety seconds:
- Call the number before you need it. Not when you are breached. Today, on a Tuesday. Someone should answer.
- Look up the domain registration date. A firm claiming fifteen years of experience on a domain registered in March is telling you something.
- Ask for one named reference in your industry. Not a logo wall — a person who will take your call.
- Ask what they would decline to sell you. Anyone who says yes to everything has not understood your problem, and probably has not tried.
That last one matters most, and it is the one nobody asks. The right partner will tell you which of your problems is not theirs to solve.
There is a companion argument to this one worth reading alongside it: any good IT person can manage 150 end users, but that number has nothing to do with cybersecurity. That piece is about why the person you already trust may not be the right person for this. This one is about why the list you would use to replace them may not be real either.
We would rather have fourteen providers who answer the phone than forty who do not. If you are a real Orange County or Southwest security firm and you are not listed here, tell us — we will check you, and the check is the point.
