Field diagnoses of small public companies, from the outside
Intrusion Inc. built a threat-intelligence database it says no competitor will be able to provide, then spent five years selling it into a category that tells a different story. Commercial sales fell by more than half in the latest disclosed year while government concentration reached 94.6%. Whether the aim or something else explains it is the question this issue takes outside-in.
What this is: a marketing and positioning diagnosis of a public company, built entirely from the outside: their SEC filings and open demand signals. What this is not: investment research. We say nothing here about the stock, and you should draw no conclusion about it from anything below.
Intrusion Inc. is a Plano, Texas company that spent many years supplying threat intelligence to the United States government, and in 2021 it changed course: "After many years of gathering intelligence and providing our INTRUSION TraceCop and Savant solutions exclusively to government entities, we released our first commercial product in 2021, the INTRUSION Shield".
Five years in, the pivot's latest numbers read like this. Sales to commercial customers fell to $0.4 million, down from $0.9 million the year before. Government customers rose to 94.6% of revenue, up from 83.8%. Shield's share of revenue barely moved, 25% against 26% the year before.
The company's description of the asset underneath the bet is the most absolute sentence in the fiscal 2025 Form 10-K, filed March 25, 2026: "We have been continuously collecting the TraceCop data for more than 20 years, and we believe that none of our current or future competitors will have the ability to provide and reference this historical data." Twenty years of data, as the filing describes it, five years of selling it commercially, and almost none of the revenue turned out to be commercial. One candidate explanation is the aim: where the message points, and who it points at. How much of the gap the aim explains is a hypothesis, and this issue tests it from the outside.
The revenue chart is a round trip. Revenue peaked at $13.6 million in fiscal 2019 and fell 51% to $6.6 million in 2020. It has sat in a band between $5.6 million and $7.5 million ever since; fiscal 2025 came in at $7.1 million, below the $7.7 million the company reported for fiscal 2013 in an earlier annual filing.
The mix underneath is the sharper picture.
| FY2024 | FY2025 | |
|---|---|---|
| Revenue, $M | 5.8 | 7.1 |
| Shield share of revenue | 26% | 25% |
| U.S. government share of revenue | 83.8% | 94.6% |
| Commercial revenue, $M | 0.9 | 0.4 |
The company's own risk factors tie the customer-base problem to revenue, in the filing's words: "the loss of these customers or our failure to widen the scope of our customer base to include general commercial enterprises could negatively affect our revenues".
We have been continuously collecting the TraceCop data for more than 20 years, and we believe that none of our current or future competitors will have the ability to provide and reference this historical data. Intrusion Inc., Form 10-K for fiscal 2025, Item 1. Filed March 25, 2026.
Public demand signals, captured August 5, 2026. Google Trends measures relative search interest, a proxy for attention only; every series below is read that way, and none of it measures category revenue.
Search interest in the job Shield was built for roughly doubled; Shield's share of revenue did not move. Interest in "zero trust", the frame the filing itself uses for Shield, roughly doubled between 2022 and 2025 on calendar-year weekly means, and interest in "threat detection" rose from a weekly mean near 1.5 to near 7 over the same years, a move from a base low enough that we read it as direction only. Shield's revenue share sat at 26% and then 25% across the two disclosed years.
Search interest attaches to the named competitors, where it can be measured. The 10-K names Darktrace, Trellix, and Recorded Future as principal competitors. Two of the three are measurable; Trellix is excluded because the brand was created in a 2022 merger, so its series would measure how fast the new name spread. On the shared index, where 100 is Recorded Future's busiest week, Darktrace's full-year averages sit in the twenties. Individual weeks often reach the thirties and forties, two weeks in 2024 reached the sixties, and the partial 2026 window averages in the low thirties. Recorded Future's series rises roughly seventy percent between 2022 and 2025 on calendar-year weekly means; the captured pages record that the company was acquired by Mastercard, and news events contaminate brand-search series, so we read it for direction only. Both series fall back toward their 2021 levels in the final captured weeks; the last captured week is partial at the August 5 capture, and we note the remaining capture-edge decline without an explanation.
| series (weekly mean) | 2021 | 2022 | 2023 | 2024 | 2025 | 2026 |
|---|---|---|---|---|---|---|
| Darktrace | 19.7p | 22.9 | 23.9 | 27.6 | 26.1 | 33.4p |
| intrusion detection system | 26.8p | 27.7 | 28.8 | 29.9 | 36.4 | 55.4p |
| Intrusion Shield | 0p | 0 | 0 | 0 | 0 | 5.8p |
| Recorded Future | 17.2p | 23 | 26.7 | 32.6 | 39.3 | 53.5p |
| threat detection | 1.6p | 1.5 | 1.6 | 2.1 | 6.9 | 12.9p |
| zero trust | 6.9p | 9.6 | 10.1 | 10.6 | 19.8 | 47.8p |
The subject cannot be plotted on that chart, and the category conversation happens without them. The word "intrusion" is generic English, and the product brand sits below the measurement floor: across five years of weekly data, the series for "Intrusion Shield" is zero in 260 of 262 weeks, and the two nonzero weeks are an index artifact of near-zero volume. The buyer-facing page for the category query is owned by review platforms, listicles, and rivals' advertising; the captured snippet of the highest-ranked listicle names seven of its fifteen vendors, and the subject is not among them.
The company's surfaces speak in two registers, both in its own words. The filing sells the data moat. The website sells prevention: the homepage snippet calls Intrusion "a prevention-first cybersecurity company", and the product result on the review query opens "Detection tells you something bad already happened". The prevention register in particular is one no profiled vendor leads with on its own captured page.
The against-thesis signals are real, and there are three. First, demand for the words the company owns grew. The category term intrusion detection system, measurable in all 262 captured weeks, rose from a calendar-year weekly mean of 27.7 in 2022 to 36.4 in 2025, about a third; the partial 2026 window averaged 55.4, twice the 2022 mean. That partial window carries the same capture-edge falloff noted on the rival series; the depressed final weeks are inside the 55.4 average, which if anything understates the window. The category vocabulary the company is literally named after gained demand between 2022 and 2025 while the product brand sat below the measurement floor in all five captured years. Second, evaluative intent exists at the margin. The top autocomplete for the product name is "intrusion shield review", and the one hands-on review captured on that query, published in 2021, reads positive: "It was simple to install". We weigh that signal lightly and say why: the review dates from the launch year, the same brand string sits below the volume floor, and three of the five captured suggestions are about other things entirely. Third, the business grew last year. Revenue rose 22.9% in fiscal 2025, against fiscal 2024, the filing's own figure computed on unrounded amounts, on Department of Defense work for Shield OT Defender in the Asia-Pacific region. Most of the increase arrived as consulting revenue, $1.1 million of the $1.3 million. The Shield product line itself rose from $1.6 million to $1.8 million, as the MD&A reports the amounts; the filing's rounded dollars and its disclosed FY2024 share do not reconcile: $1.6 million on $5.8 million is 27.6%, against the 26% disclosed.
One hypothesis the data leans against: that the product simply does not work, and the silence is the buyers' verdict on the thing itself. What evidence there is runs the other way: the positive launch-year review above, and a government customer that kept buying more work around the product in fiscal 2025. The data does not establish that the product fails on contact, and government services growing while the product's share of revenue stays flat is itself the pivot-stall picture. What survives is narrower. The government customer keeps expanding the relationship, while the product brand generates too little commercial search volume to measure. And that silence sits inside a capture in which demand for the job roughly doubled between 2022 and 2025, and demand for the category vocabulary grew.
From the outside, this reads as a mimetic problem, in Rene Girard's sense of the word: buyers mostly want what a model they trust already wants.
Mechanism one is about who owns the angle. As captured on August 5, 2026, we profiled five vendors: the three the 10-K names, plus Vectra and ExtraHop, which recur on the captured page of alternatives. The five split across at least three distinct stories: Darktrace leads with "The Essential AI Cybersecurity Platform", Vectra with "AI-Native Security & Observability Platform", ExtraHop with "Modern NDR for the Modern Enterprise". Only two of the five lead with the intelligence-asset angle Intrusion claims: Trellix, with "Intelligence-led Cyber Resilience", and Recorded Future, with "Advanced Cyber Threat Intelligence". Counted from the captured pages, that puts Intrusion's angle at 40% overlap: differentiated, on paper. But the shared angle is not empty ground, and of its two occupants, Recorded Future is the one whose curve we can measure, and it rises across the window, capture-edge falloff aside, with the Mastercard acquisition on the captured record. Differentiation is strength only when the room desires what you alone have. Here the angle is claimed, and the measurable brand-search momentum among its occupants belongs to someone else.
Mechanism two is the one we hypothesize matters more: the model changed. Our hypothesis has two halves. The first half: in the many years when Intrusion sold exclusively to government entities, a buyer choosing a threat-data specialist could reasonably take the depth of the data as the thing to evaluate. The second half: today's commercial buying committee imitates a different model, the platform its peers already standardized on. The simulated committee reported below behaved exactly that way: the simulated message built on the data moat scored well behind a simulated message that feeds the platforms the room already trusts. A data moat persuades when the room's model points at it; from the outside, we see no commercial model pointing at this one.
A rival explanation, stated plainly because we cannot rule it out from outside: vendor viability. The liquidity discussion in the fiscal 2025 Form 10-K, filed March 25, 2026, recorded that the auditor's report includes an explanatory paragraph, and stated that "our historically recurring losses from operations, negative cash flows from operations, and dependence on equity and debt financings raise substantial doubt about our ability to continue as a going concern". A security buyer's risk officer can decline a vendor on that paragraph alone, whatever the message says. From outside we cannot separate how much of the commercial stall is the aim and how much is the balance sheet; that separation is inside-data work, and it is the first thing we would test.
The BEAR grid places a subject by two measures: how far its results run behind the demand curve it sits under, and how much of the profiled competitive set shares its angle.
| window | revenue | demand mean | revenue Δ | demand Δ | gap |
|---|---|---|---|---|---|
| FY2022 → FY2025 | $7.5M → $7.1M | 9.6 → 19.8 | -5.3% | +106.3% | -111.6 |
| FY2023 → FY2025 | $5.6M → $7.1M | 10.1 → 19.8 | +26.8% | +96% | -69.2 |
| FY2024 → FY2025 | $5.8M → $7.1M | 10.6 → 19.8 | +22.4% | +86.8% | -64.4 |
Differentiated message, running far behind the demand curve it sits under. Revenue fell 5.3% from fiscal 2022 to fiscal 2025 while demand-side interest in the job roughly doubled over the same window. The demand gap is negative from every base year we computed, fiscal 2022, 2023, and 2024, including the two from which revenue itself rose. One recorded caveat travels with the number: part of the 2025 and 2026 rise in "zero trust" interest rides the broader AI-security wave, so the gap's magnitude is proxy-dependent even though its direction is not. Hibernating is the repoint quadrant: nothing in this diagnosis questions the database the company claims, and the angle is scarce in the profiled set; what the hypotheses below move is the aim.
What we cannot see from outside, and say so plainly: Shield's commercial pipeline, customer counts and churn, per-channel sales economics, and the actual terms of the government work. One more limit belongs on this list: the committee behind mechanism two is a simulated panel, a constructed stand-in for the buying room, and a stand-in can be wrong about the room. The one number that would move this diagnosis fastest is Shield's commercial win rate: a healthy funnel would shift the story from aim to execution, and a thin one would confirm it. That is what inside data is for.
These are hypotheses, not recommendations. Each comes with the test that would confirm or kill it.
If the room's desire points at platforms, supply the platforms: deliver the twenty-year IP-reputation database as a feed into the SIEM, firewall, and XDR the buyer already runs. In the simulated panel reported below, this frame scored highest of the three tested, and it was the only simulated message that turned the committee's skeptics, including the platform-incumbent skeptic and the SOC lead.
The company is named after a category term whose demand grew: interest in the phrase intrusion detection system rose from a weekly mean of 27.7 in 2022 to 36.4 in 2025, the same figures cited above, while the product brand sat below the floor. The authority to claim it is on the shelf: the company's own profile carrying "Trusted by the U.S. Department of Defense" already ranks on the product's review query.
The one growth engine in the filings is government OT work: fiscal 2025 revenue rose 22.9%, per the filing, on Department of Defense work for Shield OT Defender. Our read, and it is only a read: critical-infrastructure operators take their security cues from government choices more than the rest of the commercial buying room does, so the reference that means little in the commercial room could be the model that moves the OT one.
Before publishing, we ran the positioning question past a simulated buying committee: twelve constructed personas of the mid-market security-buying room the 2021 pivot aims at, ten scored buyers and two deliberate out-of-market controls held out of every average. We use the simulated panel the way an architect uses a wind model: cheap directional pressure-testing before anyone builds anything. This is simulated data. It is not customer research, and no Intrusion customer data exists in it.
On the simulated panel's buyer-only weighted averages, the intelligence-feed frame led at 63.8%, the data-moat frame from the 10-K scored 51.8%, and the prevention-first frame the company's own website currently runs came last at 44.3%. The simulated split matters more than the simulated averages: the feed frame was the only one that turned the committee's simulated skeptics, moving the SOC lead from 38% under the data-moat frame to 72% under the feed frame, and the platform-incumbent skeptic from 44% to 71% on the same comparison, and the only one under which both out-of-market controls ruled themselves out, which is what a well-aimed message should do to buyers it is not for. The one simulated buyer left under 50% is the methodical IT-director persona, who wants a detection engine and hears a data product.
Shield's commercial funnel first: pipeline, win rates, and churn by segment, none of which the filings disclose. That funnel is also where the rival explanation lives: it is the data that separates a message problem from a balance-sheet problem. Then the OT economics behind the 22.9% growth year, to test whether H3 is a business or a contract. Then a live A/B of the feed message against the current site, which tests in a real market the direction the simulated 63.8% indicates, or kills it.
That is what a two-week BEAR Sprint is for.