Bear Method

Field diagnoses of small public companies, from the outside


Specimen No. 004Intrusion Inc.August 2026bearmethod.ai

Twenty Years of Data, Five Years of Silence

Intrusion Inc. built a threat-intelligence database it says no competitor will be able to provide, then spent five years selling it into a category that tells a different story. Commercial sales fell by more than half in the latest disclosed year while government concentration reached 94.6%. Whether the aim or something else explains it is the question this issue takes outside-in.

What this is: a marketing and positioning diagnosis of a public company, built entirely from the outside: their SEC filings and open demand signals. What this is not: investment research. We say nothing here about the stock, and you should draw no conclusion about it from anything below.

The One Thing

Intrusion Inc. is a Plano, Texas company that spent many years supplying threat intelligence to the United States government, and in 2021 it changed course: "After many years of gathering intelligence and providing our INTRUSION TraceCop and Savant solutions exclusively to government entities, we released our first commercial product in 2021, the INTRUSION Shield".

Five years in, the pivot's latest numbers read like this. Sales to commercial customers fell to $0.4 million, down from $0.9 million the year before. Government customers rose to 94.6% of revenue, up from 83.8%. Shield's share of revenue barely moved, 25% against 26% the year before.

The company's description of the asset underneath the bet is the most absolute sentence in the fiscal 2025 Form 10-K, filed March 25, 2026: "We have been continuously collecting the TraceCop data for more than 20 years, and we believe that none of our current or future competitors will have the ability to provide and reference this historical data." Twenty years of data, as the filing describes it, five years of selling it commercially, and almost none of the revenue turned out to be commercial. One candidate explanation is the aim: where the message points, and who it points at. How much of the gap the aim explains is a hypothesis, and this issue tests it from the outside.

The Symptom

The revenue chart is a round trip. Revenue peaked at $13.6 million in fiscal 2019 and fell 51% to $6.6 million in 2020. It has sat in a band between $5.6 million and $7.5 million ever since; fiscal 2025 came in at $7.1 million, below the $7.7 million the company reported for fiscal 2013 in an earlier annual filing.

The mix underneath is the sharper picture.

Table 1.The pivot's fifth year, in the company's own mix
FY2024FY2025
Revenue, $M 5.87.1
Shield share of revenue 26%25%
U.S. government share of revenue 83.8%94.6%
Commercial revenue, $M 0.90.4
Source: Intrusion Inc. Form 10-K for fiscal 2025, SEC EDGAR. Shield share of revenue as disclosed in the MD&A gross-profit discussion; government and commercial shares from the concentration-of-revenues disclosure. The filing's rounded dollars do not recompute exactly against its disclosed shares in every row; the sharpest case, Shield FY2024, is shown in the third against-thesis finding in The Outside View.

The company's own risk factors tie the customer-base problem to revenue, in the filing's words: "the loss of these customers or our failure to widen the scope of our customer base to include general commercial enterprises could negatively affect our revenues".

We have been continuously collecting the TraceCop data for more than 20 years, and we believe that none of our current or future competitors will have the ability to provide and reference this historical data. Intrusion Inc., Form 10-K for fiscal 2025, Item 1. Filed March 25, 2026.
Fig. 1.Revenue by fiscal year: the round trip Intrusion Inc., total revenue by fiscal year ended December 31, $ millions.
Source: Intrusion Inc. Form 10-K XBRL company facts (RevenueFromContractWithCustomerIncludingAssessedTax), SEC EDGAR, CIK 0000736012. The chart begins at fiscal 2017; the fiscal 2013 figure cited in the text is from an earlier annual filing.
The Outside View

Public demand signals, captured August 5, 2026. Google Trends measures relative search interest, a proxy for attention only; every series below is read that way, and none of it measures category revenue.

Search interest in the job Shield was built for roughly doubled; Shield's share of revenue did not move. Interest in "zero trust", the frame the filing itself uses for Shield, roughly doubled between 2022 and 2025 on calendar-year weekly means, and interest in "threat detection" rose from a weekly mean near 1.5 to near 7 over the same years, a move from a base low enough that we read it as direction only. Shield's revenue share sat at 26% and then 25% across the two disclosed years.

Search interest attaches to the named competitors, where it can be measured. The 10-K names Darktrace, Trellix, and Recorded Future as principal competitors. Two of the three are measurable; Trellix is excluded because the brand was created in a 2022 merger, so its series would measure how fast the new name spread. On the shared index, where 100 is Recorded Future's busiest week, Darktrace's full-year averages sit in the twenties. Individual weeks often reach the thirties and forties, two weeks in 2024 reached the sixties, and the partial 2026 window averages in the low thirties. Recorded Future's series rises roughly seventy percent between 2022 and 2025 on calendar-year weekly means; the captured pages record that the company was acquired by Mastercard, and news events contaminate brand-search series, so we read it for direction only. Both series fall back toward their 2021 levels in the final captured weeks; the last captured week is partial at the August 5 capture, and we note the remaining capture-edge decline without an explanation.

Fig. 2.The competitors the filing names, measured against each other Google Trends weekly index, United States, August 2021 - August 2026, shared scale. 100 = Recorded Future's busiest week. The subject cannot be plotted: 'intrusion' is a generic word, and 'Intrusion Shield' sits below the measurement floor.
DarktraceRecorded Future
View data table
Source: Google Trends multi-keyword comparison, captured 2026-08-05. Relative indices rather than absolute volumes.
Show the computed means
series (weekly mean)202120222023202420252026
Darktrace19.7p22.923.927.626.133.4p
intrusion detection system26.8p27.728.829.936.455.4p
Intrusion Shield0p00005.8p
Recorded Future17.2p2326.732.639.353.5p
threat detection1.6p1.51.62.16.912.9p
zero trust6.9p9.610.110.619.847.8p
p partial year. Calendar-year means of the weekly Google Trends index, computed at build from the captured series; the index is relative and carries no absolute volumes. Partial years marked.

The subject cannot be plotted on that chart, and the category conversation happens without them. The word "intrusion" is generic English, and the product brand sits below the measurement floor: across five years of weekly data, the series for "Intrusion Shield" is zero in 260 of 262 weeks, and the two nonzero weeks are an index artifact of near-zero volume. The buyer-facing page for the category query is owned by review platforms, listicles, and rivals' advertising; the captured snippet of the highest-ranked listicle names seven of its fifteen vendors, and the subject is not among them.

The company's surfaces speak in two registers, both in its own words. The filing sells the data moat. The website sells prevention: the homepage snippet calls Intrusion "a prevention-first cybersecurity company", and the product result on the review query opens "Detection tells you something bad already happened". The prevention register in particular is one no profiled vendor leads with on its own captured page.

The against-thesis signals are real, and there are three. First, demand for the words the company owns grew. The category term intrusion detection system, measurable in all 262 captured weeks, rose from a calendar-year weekly mean of 27.7 in 2022 to 36.4 in 2025, about a third; the partial 2026 window averaged 55.4, twice the 2022 mean. That partial window carries the same capture-edge falloff noted on the rival series; the depressed final weeks are inside the 55.4 average, which if anything understates the window. The category vocabulary the company is literally named after gained demand between 2022 and 2025 while the product brand sat below the measurement floor in all five captured years. Second, evaluative intent exists at the margin. The top autocomplete for the product name is "intrusion shield review", and the one hands-on review captured on that query, published in 2021, reads positive: "It was simple to install". We weigh that signal lightly and say why: the review dates from the launch year, the same brand string sits below the volume floor, and three of the five captured suggestions are about other things entirely. Third, the business grew last year. Revenue rose 22.9% in fiscal 2025, against fiscal 2024, the filing's own figure computed on unrounded amounts, on Department of Defense work for Shield OT Defender in the Asia-Pacific region. Most of the increase arrived as consulting revenue, $1.1 million of the $1.3 million. The Shield product line itself rose from $1.6 million to $1.8 million, as the MD&A reports the amounts; the filing's rounded dollars and its disclosed FY2024 share do not reconcile: $1.6 million on $5.8 million is 27.6%, against the 26% disclosed.

One hypothesis the data leans against: that the product simply does not work, and the silence is the buyers' verdict on the thing itself. What evidence there is runs the other way: the positive launch-year review above, and a government customer that kept buying more work around the product in fiscal 2025. The data does not establish that the product fails on contact, and government services growing while the product's share of revenue stays flat is itself the pivot-stall picture. What survives is narrower. The government customer keeps expanding the relationship, while the product brand generates too little commercial search volume to measure. And that silence sits inside a capture in which demand for the job roughly doubled between 2022 and 2025, and demand for the category vocabulary grew.

The Diagnosis, Hypothesized

From the outside, this reads as a mimetic problem, in Rene Girard's sense of the word: buyers mostly want what a model they trust already wants.

Mechanism one is about who owns the angle. As captured on August 5, 2026, we profiled five vendors: the three the 10-K names, plus Vectra and ExtraHop, which recur on the captured page of alternatives. The five split across at least three distinct stories: Darktrace leads with "The Essential AI Cybersecurity Platform", Vectra with "AI-Native Security & Observability Platform", ExtraHop with "Modern NDR for the Modern Enterprise". Only two of the five lead with the intelligence-asset angle Intrusion claims: Trellix, with "Intelligence-led Cyber Resilience", and Recorded Future, with "Advanced Cyber Threat Intelligence". Counted from the captured pages, that puts Intrusion's angle at 40% overlap: differentiated, on paper. But the shared angle is not empty ground, and of its two occupants, Recorded Future is the one whose curve we can measure, and it rises across the window, capture-edge falloff aside, with the Mastercard acquisition on the captured record. Differentiation is strength only when the room desires what you alone have. Here the angle is claimed, and the measurable brand-search momentum among its occupants belongs to someone else.

Mechanism two is the one we hypothesize matters more: the model changed. Our hypothesis has two halves. The first half: in the many years when Intrusion sold exclusively to government entities, a buyer choosing a threat-data specialist could reasonably take the depth of the data as the thing to evaluate. The second half: today's commercial buying committee imitates a different model, the platform its peers already standardized on. The simulated committee reported below behaved exactly that way: the simulated message built on the data moat scored well behind a simulated message that feeds the platforms the room already trusts. A data moat persuades when the room's model points at it; from the outside, we see no commercial model pointing at this one.

A rival explanation, stated plainly because we cannot rule it out from outside: vendor viability. The liquidity discussion in the fiscal 2025 Form 10-K, filed March 25, 2026, recorded that the auditor's report includes an explanatory paragraph, and stated that "our historically recurring losses from operations, negative cash flows from operations, and dependence on equity and debt financings raise substantial doubt about our ability to continue as a going concern". A security buyer's risk officer can decline a vendor on that paragraph alone, whatever the message says. From outside we cannot separate how much of the commercial stall is the aim and how much is the balance sheet; that separation is inside-data work, and it is the first thing we would test.

The BEAR grid places a subject by two measures: how far its results run behind the demand curve it sits under, and how much of the profiled competitive set shares its angle.

Fig. 3.BEAR position Intrusion, editorial placement. Horizontal: revenue change against demand-side momentum in the job the product is hired for. Vertical: how much of the profiled competitive set leads with the same threat-intelligence data-asset angle.
HIBERNATINGGRIZZLYBEAR TRAPROAMING INTZ · Hibernating (placement shows the quadrant only) INTZ PERFORMANCE GAP ← underperforming the market beating the market → POSITIONING OVERLAP differentiated ← → converged
Source: Forms 10-K (revenue); Google Trends (demand-side interest); the profiled competitors' own homepage titles and snippets as surfaced by Google, captured 2026-08-05.
Show the gap arithmetic
Performance Gap = revenue change % minus job-demand search-interest change % ('zero trust' calendar-year weekly means), over the same window
windowrevenuedemand meanrevenue Δdemand Δgap
FY2022 → FY2025 $7.5M → $7.1M 9.6 → 19.8 -5.3% +106.3% -111.6
FY2023 → FY2025 $5.6M → $7.1M 10.1 → 19.8 +26.8% +96% -69.2
FY2024 → FY2025 $5.8M → $7.1M 10.6 → 19.8 +22.4% +86.8% -64.4
Positioning Overlap = 2 of 5 profiled vendors lead with the subject's angle (Trellix, Recorded Future) = 40.0%.
One recorded caveat travels with every row: part of the 2025 and 2026 rise in 'zero trust' interest rides the broader AI-security wave, so the gap's magnitude is proxy-dependent even though its direction is not. Grid placement stays editorial; this block shows the documented inputs, it does not plot them.
HibernatingINTZ · FY2025 · bearmethod.ai

Differentiated message, running far behind the demand curve it sits under. Revenue fell 5.3% from fiscal 2022 to fiscal 2025 while demand-side interest in the job roughly doubled over the same window. The demand gap is negative from every base year we computed, fiscal 2022, 2023, and 2024, including the two from which revenue itself rose. One recorded caveat travels with the number: part of the 2025 and 2026 rise in "zero trust" interest rides the broader AI-security wave, so the gap's magnitude is proxy-dependent even though its direction is not. Hibernating is the repoint quadrant: nothing in this diagnosis questions the database the company claims, and the angle is scarce in the profiled set; what the hypotheses below move is the aim.

What we cannot see from outside, and say so plainly: Shield's commercial pipeline, customer counts and churn, per-channel sales economics, and the actual terms of the government work. One more limit belongs on this list: the committee behind mechanism two is a simulated panel, a constructed stand-in for the buying room, and a stand-in can be wrong about the room. The one number that would move this diagnosis fastest is Shield's commercial win rate: a healthy funnel would shift the story from aim to execution, and a thin one would confirm it. That is what inside data is for.

Three Repositioning Hypotheses

These are hypotheses, not recommendations. Each comes with the test that would confirm or kill it.

H1Stop selling a fourth console. Sell the intelligence into the consoles they already have.

If the room's desire points at platforms, supply the platforms: deliver the twenty-year IP-reputation database as a feed into the SIEM, firewall, and XDR the buyer already runs. In the simulated panel reported below, this frame scored highest of the three tested, and it was the only simulated message that turned the committee's skeptics, including the platform-incumbent skeptic and the SOC lead.

Test: run the feed message against the current site message for eight weeks, judged on demo bookings from commercial visitors. Kill: the feed message fails to beat the current one.

H2Aim the words at the demand that already exists.

The company is named after a category term whose demand grew: interest in the phrase intrusion detection system rose from a weekly mean of 27.7 in 2022 to 36.4 in 2025, the same figures cited above, while the product brand sat below the floor. The authority to claim it is on the shelf: the company's own profile carrying "Trusted by the U.S. Department of Defense" already ranks on the product's review query.

Test: a content and comparison program aimed at the category vocabulary the company owns by name, measured on category-term impressions and review-platform visibility inside a quarter. Kill: no visibility movement in ninety days.

H3Let the government buyer be the model, on purpose.

The one growth engine in the filings is government OT work: fiscal 2025 revenue rose 22.9%, per the filing, on Department of Defense work for Shield OT Defender. Our read, and it is only a read: critical-infrastructure operators take their security cues from government choices more than the rest of the commercial buying room does, so the reference that means little in the commercial room could be the model that moves the OT one.

Test: an inside-data read of the OT engine, pipeline, deal margins, and clearance requirements, which only the company holds; this one cannot be run from outside. Kill: inside per-deal data showing OT work prices like consulting, without software economics.
Simulated · Synthetic Panel
What a Simulated Buyer Panel Said

Before publishing, we ran the positioning question past a simulated buying committee: twelve constructed personas of the mid-market security-buying room the 2021 pivot aims at, ten scored buyers and two deliberate out-of-market controls held out of every average. We use the simulated panel the way an architect uses a wind model: cheap directional pressure-testing before anyone builds anything. This is simulated data. It is not customer research, and no Intrusion customer data exists in it.

Fig. 4.Simulated conversion by positioning message, weighted
Data moatthe 10-K frame
51.8%
Prevention-firstthe website frame
44.3%
Intelligence feedthe repositioning frame
63.8%
Simulated synthetic panel, 10 scored mid-market buying-committee members, weighted; two out-of-market controls held out of scoring. Conversion event is booking a vendor consultation.
Fig. 4a.Simulated panel dimension scores: where the lead is widest, and where it narrows
Data moat Prevention-first Intelligence feed Direct Intent Simulated · Data moat · Direct Intent · 48.9% Simulated · Prevention-first · Direct Intent · 41.7% Simulated · Intelligence feed · Direct Intent · 64.1% Emotional Resonance Simulated · Data moat · Emotional Resonance · 55.9% Simulated · Prevention-first · Emotional Resonance · 47.8% Simulated · Intelligence feed · Emotional Resonance · 70.4% Behavioral Signals Simulated · Data moat · Behavioral Signals · 51.6% Simulated · Prevention-first · Behavioral Signals · 44.0% Simulated · Intelligence feed · Behavioral Signals · 65.9% Value Perception Simulated · Data moat · Value Perception · 51.9% Simulated · Prevention-first · Value Perception · 48.0% Simulated · Intelligence feed · Value Perception · 62.7% Urgency & Motivation Simulated · Data moat · Urgency & Motivation · 46.1% Simulated · Prevention-first · Urgency & Motivation · 38.0% Simulated · Intelligence feed · Urgency & Motivation · 56.6% Trust & Credibility Simulated · Data moat · Trust & Credibility · 54.7% Simulated · Prevention-first · Trust & Credibility · 44.8% Simulated · Intelligence feed · Trust & Credibility · 63.3% 35%55%75%
Simulated synthetic panel, weighted dimension scores per message across the scored buyers; rows ordered by the leading message's advantage over the data-moat message.

On the simulated panel's buyer-only weighted averages, the intelligence-feed frame led at 63.8%, the data-moat frame from the 10-K scored 51.8%, and the prevention-first frame the company's own website currently runs came last at 44.3%. The simulated split matters more than the simulated averages: the feed frame was the only one that turned the committee's simulated skeptics, moving the SOC lead from 38% under the data-moat frame to 72% under the feed frame, and the platform-incumbent skeptic from 44% to 71% on the same comparison, and the only one under which both out-of-market controls ruled themselves out, which is what a well-aimed message should do to buyers it is not for. The one simulated buyer left under 50% is the methodical IT-director persona, who wants a detection engine and hears a data product.

The Panel.The buying committee we simulated so Intrusion would not have to guess
Marcus: Healthcare CISO, Economic Buyer
Health-system CISO running a board-mandated stack review; the economic buyer who books the meeting
Skepticism mediumweight 15%
simulated conversion
53
56
57
Priya: Manufacturing IT/Network Ops Director, Deployment Owner
IT-ops director who owns sensor deployment across four plants and was burned by the last network tool
Skepticism highweight 13%
simulated conversion
59
29
66
Deshawn: Financial Services SOC Analyst Lead, Daily User
SOC lead benchmarking alternatives before a Vectra renewal; lives in the console and hates noise
Skepticism highweight 12%
simulated conversion
38
35
72
Sandra: Critical-Infrastructure CFO, Budget Approver
Utility CFO who approves the spend and wants a shorter vendor list
Skepticism very highweight 11%
simulated conversion
41
46
64
Robert: Finance Compliance & Risk Officer, Vendor-Viability Checker
Bank risk officer who pulls the vendor's 10-K before shortlisting and flinches at going-concern language
Skepticism very highweight 9%
simulated conversion
62
45
62
Angela: Healthcare IT Security Manager, Platform-Incumbent Skeptic
Security manager defending the platform bet she championed; arrives at the demo arms-crossed
Skepticism very highweight 8%
simulated conversion
44
43
71
James: Manufacturing CISO, Fence-Sitter Leaning Positive
Manufacturer CISO pushed by a cyber-insurance questionnaire toward network-layer detection
Skepticism mediumweight 10%
simulated conversion
61
55
73
Mei: Critical-Infrastructure SOC Analyst, Junior Daily-User Perspective
Tier 2 analyst drowning in incumbent-tool alerts; will validate or destroy any better-UX claim
Skepticism mediumweight 7%
simulated conversion
53
58
71
Victor: Finance IT Director, Cautious Evaluator
IT director forced to migrate off an end-of-life network tool; methodical, insists on a bake-off
Skepticism mediumweight 9%
simulated conversion
52
33
46
Karen: Healthcare Compliance Director, Audit-Focused
Compliance director who evaluates vendors on auditability and financial stability before features
Skepticism mediumweight 6%
simulated conversion
59
47
56
MISMATCH: Derek, 12-Person Accounting Firm Owner
Small-firm owner with no security staff; the deliberate mismatch, held out of scoring
Skepticism lowcontrol · held out
simulated conversion
65
61
37
MISMATCH: Tanya, E-Commerce Marketing Manager
Marketing manager researching blog content; the second deliberate mismatch, held out of scoring
Skepticism lowcontrol · held out
simulated conversion
43
37
43
Simulated panels like this one are how we pressure-test a message before a dollar of media spends. They are built in SimPanel, our synthetic buyer panel tool: describe your customer, get a weighted panel, run your copy against it. See how a panel is built →
What We Would Verify With Inside Data

Shield's commercial funnel first: pipeline, win rates, and churn by segment, none of which the filings disclose. That funnel is also where the rival explanation lives: it is the data that separates a message problem from a balance-sheet problem. Then the OT economics behind the 22.9% growth year, to test whether H3 is a business or a contract. Then a live A/B of the feed message against the current site, which tests in a real market the direction the simulated 63.8% indicates, or kills it.

That is what a two-week BEAR Sprint is for.

If you run a company and want this same read on your business, with your real data instead of the outside view, book a BEAR Sprint. If you just want the next diagnosis when it publishes, subscribe.
Published by Click Makers, LLC. This is marketing and positioning analysis for educational purposes. It is not investment research, not investment advice, and not a recommendation regarding any security. We hold no position in INTZ, have no relationship with the company, and received no compensation related to this report. All figures come from the cited public sources as of the capture dates stated above; Google Trends values are relative indices, not absolute volumes. The synthetic panel results are simulated and are labeled as such wherever they appear. INTRUSION, INTRUSION Shield, and TraceCop are trademarks of Intrusion Inc. If you are the company and believe any fact here is wrong, write to corrections@bearmethod.ai and we will review and correct promptly.
Bear Method · Specimen 004 · Set in the field-journal style · MMXXVI