Cythentic's External Attack Surface Report · 2026 Q3
The external attack surface of 18,374 organizations, graded from the outside in, the way an adversary sees them.
Cythentic Research · Exposure Index 2026 Q3 · Edition 1
A census of the external attack surface of 18,374 organizations, graded across 21 risk areas from the outside in, the way an adversary sees them. What is exposed, what it correlates with, and what to fix first.
01 / Executive summary
18,374 organizations graded from the outside. Average score 7.13/10, a C.
What ships on by default is near universal. What needs a person to decide is not. That one split explains most of this report.
Issued and renewed automatically, or created by a mail provider's setup wizard.
Free, documented, and available in the same admin console as the controls above.
Only 32% enforce p=reject, the one policy that blocks spoofed mail.
94% have a valid certificate; 39% send no security headers at all.
Encryption ›92% of organizations are clean. The rest carry a median of 20 each.
Patching ›Each one is a reachable data store or admin console with no network control in front of it.
Exposed services ›78% run Microsoft 365, and the tenant signals say enforcement is partial or absent.
Identity ›85% of organizations have employee credentials in public corpora.
Threat intelligence ›3.8% of the full population. Victims sit almost entirely in the F grade, alongside CVEs and exposed services.
Threat intelligence ›78% have a typosquat carrying live web content or a mail server.
Threat intelligence ›The whole argument. The rest is evidence.
Population, sources, and what this report cannot see.
02 / Strategic analysis
Each claim below is argued in full in the section it points to. If you read only this page, you have the argument.
Every control this population is good at was switched on for them by a vendor. Every control they are bad at required a person to decide. Prefer platforms whose secure state is the default state, because the product is the policy.
92% have a clean edge and a policy problem that configuration fixes for free. The rest have an infrastructure problem: legacy servers that need retiring, not patching. One group needs an admin with a checklist, the other needs a migration budget.
This population buys protection for the mail it receives and neglects the free control that protects everyone who receives mail from them. Business email compromise flows straight through that asymmetry.
No leader in this population would say their organization has no MFA. The external signals say enforcement is partial, conditional or absent for most of them, and the gap between licensed and enforced is only visible from outside the tenant, which is where the adversary stands.
Leak-site listings sit almost entirely among F-graded organizations that also show known CVEs and exposed services. The 1,488 CVE-bearing organizations here are a forecast, not a finding. A partner or an insurer holding this list knows who is next.
The CDN itself blocks little. What matters is what choosing one implies: managed hosting, no on-premises web server, and none of the ports that came with it. Putting the site behind an edge proxy is a five-hour task that forces an origin clean-up years overdue.
03 / Strategic recommendations
Ranked by the share of this population each action moves out of a failing state. The first four cost nothing but attention. Together they take the median organization here from a C to a B in ninety days.
Two weeks at p=none with reporting to find your legitimate senders, then p=quarantine, then p=reject.
One redirect rule and one response header at the edge, plus the six remaining security headers from a published baseline.
A firewall rule and an allow-list. The 1,572 exposed services here are the shortest path from a leaked password to a ransom note.
The 1,488 affected organizations have a named list of software and versions. Anything on the CISA KEV catalog goes this week.
Included in Microsoft 365 Business Premium and E3. Require phishing-resistant methods for admins, block legacy authentication, allow-list external access.
Proxy the public site, then audit every service the origin still exposes now that it is no longer reachable by address.
CAA for the certificate authority you actually use, registrar transfer lock with 2FA, and a published security.txt so the next researcher who finds something has someone to tell.
Register the highest-risk permutations, file takedowns on typosquats carrying mail records, and alert on your domain in breach and stealer corpora.
security.txt, an external scan on a schedule, and someone whose job it is to read it.The five-control pass rate: DMARC enforced, HSTS set, HTTPS forced, no known CVEs, no exposed admin or database ports.
Currently 7.4% of this population passes all five. It is binary, measurable from outside, and cannot be gamed by a questionnaire.
For a managed-service partner this report is a service catalogue; for an underwriter it is a pricing model.
The 19% graded D or F are identifiable by name, their failing controls are enumerated, and most are one quarter of configuration away from a B.
04 / How to read this report
Every organization's primary domain was assessed from the public internet using passive open-source intelligence: DNS, certificate transparency, WHOIS/RDAP, HTTP headers, Shodan's InternetDB, NVD/CISA KEV/EPSS, breach corpora (HIBP, XposedOrNot, Breachsense counts), RansomwareLive leak-site data, and Microsoft/Google tenant metadata.
One outbound TLS handshake is made to read the certificate. No ports are probed, no exploits run, nothing is authenticated.
Each of 21 risk areas is scored 0–10 from a documented formula (starting score, tiered deductions, sources cited per step) and letter-graded.
The composite is a weighted blend: A ≥ 9.0, B 7.5–8.9, C 6.0–7.4, D 4.0–5.9, F ≤ 3.0. Areas that do not apply to a domain (no cookies set, no registration data) are graded N/A and excluded from that area's denominators.
This is a measurement of 18,374 organizations, not a questionnaire.
Unlike survey-based industry reports there is no self-report bias and no sampling error at the population level. 697 of 19,071 attempted scans (3.7%) returned no result within the window (unresolvable or timed out) and are excluded.
Anything behind authentication: internal networks, endpoint controls, backups, staff training.
MFA posture is inferred from tenant metadata, not verified. CVE counts are derived from software versions identified in public banners (CPE matching). They indicate exposure to known vulnerabilities, not confirmed exploitability. Treat every figure here as a floor on exposure, not a ceiling.
Deep-dive metrics in this chapter are computed on a uniformly random sample of 2,404 of the 18,374 scanned domains (margin of error at 95% confidence: ±2.0 points on a 50% proportion). Population-level grades, scores and flags use all 18,374.
05 / The big picture
36% of organizations land in the C band and 44% reach A or B. The distribution is not symmetric: a long left tail of 3,519 D and F organizations pulls the mean below the median, and 300 organizations sit at the floor score of 1.5.
Standard deviation 1.87. The 10th percentile organization scores 4.5; the 90th scores 9.1. The gap between them is the difference between a company that will and will not appear in next year's breach statistics.
27% of organizations carry at least one critical-severity finding; 1,915 carry two or more. The median organization has 16 findings of any severity; the mean is 29.5, again skewed by the tail.
8,125 critical and 473,335 warning-level findings across the population, an average of 26 per organization. The remediation backlog this represents is the real subject of this report.
| Critical finding | Organizations | Share |
|---|---|---|
| No DMARC record | 2,369 | 12.9% |
| Known CVEs on infrastructure | 1,266 | 6.9% |
| No SPF record | 881 | 4.8% |
| MySQL exposed | 739 | 4.0% |
| No TLS certificate | 577 | 3.1% |
| Domain hijacked/parked/misconfigured | 429 | 2.3% |
| Untrusted certificate | 408 | 2.2% |
| MSSQL exposed | 305 | 1.7% |
| RDP exposed | 298 | 1.6% |
| Possible DNS hijack / split-brain | 148 | 0.8% |
| SMB exposed | 105 | 0.6% |
| PostgreSQL exposed | 89 | 0.5% |
| Self-signed certificate | 42 | 0.2% |
| VNC exposed | 28 | 0.2% |
| Sensitive file public | 11 | 0.1% |
| Redis exposed | 4 | 0.0% |
| Telnet exposed | 2 | 0.0% |
| MongoDB exposed | 2 | 0.0% |
06 / The 21 risk areas
Each bar is the full population's grade distribution for one risk area.
The number at right is the share graded D or F. The pattern is unmistakable: areas governed by a default (certificates, DNS resolution, takeover hygiene) are overwhelmingly A; areas governed by a decision (collaboration federation, cookie flags, patch cadence, mail policy) are where the D and F grades live.
| Risk area | Graded | A | B | C | D | F | D+F | Mean |
|---|---|---|---|---|---|---|---|---|
| Collaboration Exposure | 2,404 | 1,530 | 0 | 0 | 874 | 0 | 36.4% | 7.86 |
| Cookie & Session Security | 1,177 | 734 | 127 | 76 | 240 | 0 | 20.4% | 8.31 |
| Software Patching | 2,404 | 2,190 | 8 | 19 | 17 | 170 | 7.8% | 9.26 |
| Web App Hardening | 2,404 | 1,581 | 435 | 213 | 101 | 74 | 7.3% | 8.75 |
| Email Security | 2,404 | 1,286 | 643 | 306 | 169 | 0 | 7.0% | 8.44 |
| Web Encryption | 2,404 | 1,867 | 157 | 214 | 17 | 149 | 6.9% | 9.01 |
| Network Filtering | 2,404 | 2,192 | 51 | 32 | 24 | 105 | 5.4% | 9.41 |
| Ransomware Exposure | 2,404 | 2,306 | 0 | 0 | 8 | 90 | 4.1% | 9.68 |
| Domain Registration Risk | 1,076 | 928 | 123 | 7 | 12 | 6 | 1.7% | 9.64 |
| Subdomain Takeover | 2,132 | 2,125 | 0 | 0 | 0 | 7 | 0.3% | 9.97 |
| DNS Security | 2,404 | 2,177 | 203 | 21 | 3 | 0 | 0.1% | 9.79 |
| Breach Events | 2,404 | 2,384 | 0 | 18 | 0 | 2 | 0.1% | 9.97 |
| Web Application Security | 2,404 | 401 | 2,003 | 0 | 0 | 0 | 0.0% | 8.7 |
| Identity & Access | 952 | 812 | 29 | 111 | 0 | 0 | 0.0% | 9.34 |
| Attack Surface | 2,404 | 2,376 | 28 | 0 | 0 | 0 | 0.0% | 9.76 |
| SaaS Sprawl | 2,404 | 1,370 | 1,034 | 0 | 0 | 0 | 0.0% | 9.19 |
| Domain Reputation | 2,404 | 2,354 | 0 | 50 | 0 | 0 | 0.0% | 9.92 |
| Resilience | 2,401 | 1,169 | 970 | 262 | 0 | 0 | 0.0% | 8.84 |
| Exposed Secrets & Repos | 2,404 | 2,401 | 0 | 3 | 0 | 0 | 0.0% | 10.0 |
Every control above 85% adoption in this report is one a vendor turned on for the customer: certificate issuance and renewal (94%), TLS 1.3 (85%), and SPF records created by a mail provider's onboarding wizard (96%).
Every control that required the customer to make a decision sits far lower: DMARC enforcement (60%), HSTS (12%), CAA (12%) and a published security.txt (5%). Awareness campaigns have had twenty years. Defaults work in one release cycle.
07 / Email authentication
Phishing is present in 16% of confirmed breaches and pretexting in a further 6% (DBIR 2026), and email is how nearly all business-email-compromise fraud is executed.
The controls are free and twenty years old. Adoption tells a story of good intentions: records get published, and then nobody flips the switch.
12.6% publish no DMARC record at all.
Of those that do, 27.8% of all organizations sit at p=none, monitoring mode that blocks nothing; 27.4% at quarantine and 32.1% at reject. A p=none record is a promise to the world that spoofing your domain will be tolerated.
Google Workspace 32%, Microsoft Exchange Online Protection 30%, Proofpoint 12%.
19% of organizations layer a dedicated secure-email gateway in front of their provider (Proofpoint, Mimecast, Barracuda). Layering does not substitute for DMARC: a gateway filters inbound mail; DMARC protects everyone else from mail forged in your name.
p=none and missing-record domain to quarantine would lift 40% of this population into an enforcing posture with zero capital cost. It is the highest-leverage single change available to this population, and the one most likely to be blocked by a fear of breaking marketing mail that a two-week monitoring period would resolve.This population spends on inbound filtering, with 19% layering a gateway in front of their mailbox provider, while leaving their own domain available to be forged against their customers, suppliers and banks.
The asymmetry is the finding: organizations buy protection for the mail they receive and neglect the free control that protects everyone who receives mail from them. Business-email-compromise losses flow directly through that gap, and the fix is a DNS record and two weeks of reporting.
08 / Web encryption & transport
This is the clearest natural experiment in the dataset.
Certificates are issued and renewed by machines; 61% of certificates now have a lifetime of 90 days or less, which is only possible with automation. Every control that lives one layer up, and needs a human to type a line of configuration, collapses.
| Issuer | Share |
|---|---|
| Let's Encrypt | 32.9% |
| Google Trust Services | 25.8% |
| DigiCert Inc | 10.7% |
| Amazon | 10.2% |
| Sectigo Limited | 5.2% |
| none | 3.3% |
4.6% of certificates expire within 30 days of the scan; 0.7% were already expired; 0.2% self-signed; 5.5% presented no usable certificate.
Without HSTS, a user's first connection, on hotel Wi-Fi or at a conference or on a compromised home router, is a plain-HTTP request that an attacker on the path can answer.
The 50% of sites that do not even redirect HTTP to HTTPS make this trivial. HSTS is one response header. It is the cheapest control in this report and one of the least adopted.
CAA adoption of 12% means that for almost every organization here, the right to issue certificates in their name rests entirely on their registrar and DNS host being uncompromised.
1.0% of domains already return different answers from different public resolvers, a possible hijack or split-brain signal.
5.3% of organizations publish a security.txt file, the standard (RFC 9116) way for a researcher to report a vulnerability. The other 95% have no published route for the outside world to tell them something is wrong.
09 / Software patching & vulnerabilities
Vulnerability exploitation is now the leading initial-access vector in confirmed breaches (31%, DBIR 2026), and Mandiant's M-Trends 2026 records exploits as the top entry point for the sixth consecutive year.
In this population the exposure is concentrated: most organizations show no known-vulnerable software on the public edge, and a minority show a great deal.
Long-unpatched web servers, control panels and mail stacks whose version strings map to dozens of published CVEs at once.
An organization at 87+ CVEs is not missing a patch; it is running software that stopped receiving patches. In the sample, 88 organizations carry at least one vulnerability on the CISA Known Exploited Vulnerabilities list, the ones adversaries are using right now.
The DBIR 2026 reports that only 26% of critical KEV vulnerabilities were fully remediated by organizations in 2025, down from 38%, with a median time to full resolution of 43 days.
Among SMB ransomware victims, 29% had unpatched vulnerabilities in edge devices. The 1,488 organizations in Figure 8 are the population's edge-device problem, made visible.
10 / Exposed services
3.9% of organizations expose a database engine directly to the internet and 6.4% expose a remote-administration protocol (RDP, VNC, SSH or Telnet).
Neither has a legitimate reason to be reachable from every address on Earth. Each is a critical finding because each is one credential, often one already in a stealer log, away from full compromise.
| Port | Service | Organizations | Share |
|---|---|---|---|
| 21 | FTP | 122 | 5.1% |
| 22 | SSH | 114 | 4.7% |
| 3306 | MySQL | 90 | 3.7% |
| 135 | MS-RPC | 41 | 1.7% |
| 389 | LDAP | 41 | 1.7% |
| 1433 | MSSQL | 40 | 1.7% |
| 9200 | Elasticsearch | 39 | 1.6% |
| 3389 | RDP | 39 | 1.6% |
| 1521 | Oracle DB | 39 | 1.6% |
| 5900 | VNC | 39 | 1.6% |
| 5901 | VNC | 39 | 1.6% |
| 445 | SMB | 14 | 0.6% |
| 5432 | PostgreSQL | 10 | 0.4% |
| 6379 | Redis | 1 | 0.0% |
51% of organizations expose nothing but ports 80 and 443, the correct end state for a public web presence.
The mean primary address answers on 19.6 ports, but for CDN-fronted sites those are the edge provider's standard listeners (Cloudflare's 2052–2096, 8080, 8443, 8880), not the organization's own. The gap that matters is the hosting-control-panel ports (cPanel, WHM, webmail) inherited from shared hosting, plus the databases and remote-access services above, all of which sit on the organization's own origin.
Exposed services co-occur with unpatched software (the same neglected server), with hybrid on-premises topologies, and with the absence of a CDN or WAF in front of the origin.
In the grade correlation table (Section 14), exposed databases are found almost exclusively in D and F organizations. It is less a finding than a diagnosis.
11 / Identity & collaboration
78% of organizations run Microsoft 365; 11% run Google Workspace.
Their identity provider is now the front door to email, files, chat and, through single sign-on, most of their SaaS estate. The scan cannot log in, but tenant metadata says a great deal about how that door is guarded.
Microsoft exposes a tenant's realm type, federation brand, device-registration and MDM endpoints publicly.
A tenant that is unfederated, shows no Conditional Access-linked device registration, is classified LIKELY_GAP; one with federation to a modern IdP or device-registration evidence is LIKELY_ENFORCED. This is a signal, not a verdict. Microsoft Security Defaults and per-user Conditional Access produce no external signal whatsoever, so a tenant that enforces MFA by either route is classified LIKELY_GAP here: the figure is the share that cannot be confirmed from outside, not the share that is exposed. It is, however, the same signal an attacker reads before choosing a password-spray target. Across all organizations: Likely Gap 39%, Likely Enforced 34%, Unknown 11%, Unverifiable Google 10%.
874 organizations (36%) are graded D or F on Collaboration Exposure: Microsoft Teams external federation left open to any tenant, or legacy Lync/Skype for Business discovery records still published.
Open federation is the delivery channel for the Teams-based phishing and malware campaigns that have replaced much of email as the initial lure: an attacker in any tenant can message any user. Restricting federation to an allow-list is an admin-center setting.
No leader in this population would describe their organization as having no MFA, and none would be lying.
The data says enforcement is partial, conditional or absent for a majority: 78% run identity on Microsoft 365, 50% of those show signals consistent with a gap, 36% leave collaboration federation open, and a median of 174 employee credentials are already circulating. The distance between licensed and enforced is where the breaches of 2027 will come from, and it is only visible from outside the tenant, which is exactly where the adversary is standing.
12 / Threat intelligence
Three external signals say whether an organization has already been touched: whether its people's credentials are circulating, whether it has appeared in a disclosed breach, and whether a ransomware crew has published its name. The first is nearly universal. The last is rare, and nearly always preceded by the findings in Sections 09 and 10.
Across the 98 organizations named on leak sites, 16,234,288 records tied to their domains are already circulating in public breach and infostealer corpora, 2,575,825 of them employee credentials. Their median employee-credential count is 1,762 against a population median of 174: ten times the exposure. Credential volume is not a consequence of being named; it is the condition that preceded it.
Background on each group. CISA #StopRansomware advisories carry the tactics and detection guidance; tracker pages carry the current victim list.
Credential exposure counts come from Breachsense's public index of breach dumps and infostealer logs.
They are counts, not passwords, but the count is what an attacker sees when deciding whether a password spray or a credential-stuffing run against an organization is worth the effort. With a median of 174 exposed employee credentials, the answer for most of this population is yes. This is why the MFA gap in Section 11 is not a hygiene issue but the difference between a leaked password and a breach.
98 organizations appear on active leak sites.
The DBIR 2026 puts ransomware in 48% of all breaches and 83% of SMB breaches, with roughly 96% of ransomware victims being SMBs, which is this population's exact profile. In the grade correlations (Section 14) leak-site victims appear almost exclusively among F-graded organizations, alongside exposed databases and triple-digit CVE counts. The order of events is not ambiguous.
Brand impersonation: 91% of organizations have registered look-alike domains they do not control (mean 13.6 per brand; 78% with at least one rated critical, meaning a live site or mail server). 1.5% of domains lack a registrar transfer lock; 5.0% expire within 90 days of the scan.
Leak-site listings are found almost entirely among F-graded organizations that also show known CVEs and exposed services.
Industry data agrees: the DBIR 2026 attributes 29% of SMB ransomware to unpatched edge devices and 38% to compromised credentials. The operational implication is that the 1,488 CVE-bearing organizations in this dataset are a forecast rather than a finding. A platform partner or an underwriter holding this list already knows who is next, which makes it an intervention opportunity and not merely a risk register.
13 / Infrastructure & hosting
The single strongest structural correlate of a good grade in this dataset is whether the organization's web origin is hidden behind a CDN or edge proxy.
It is not the CDN that makes the difference; it is what a CDN implies: managed hosting, no legacy server, no forgotten ports.
| Provider | Share |
|---|---|
| Cloudflare | 31.0% |
| Unknown | 24.0% |
| Amazon Web Services | 13.4% |
| WP Engine | 4.8% |
| Microsoft Azure | 3.8% |
| Google Cloud | 3.4% |
| Webflow | 3.4% |
| Vercel | 3.1% |
37% of organizations still run a hybrid estate with on-premises public IP space, the topology in which exposed databases, RDP and unpatched appliances are found.
38% expose a VPN endpoint. The 34% that are CDN-fronted have, in effect, outsourced their perimeter, and it shows in their grades.
Server software is disclosed by 80% of sites via the Server header; path probing finds a public API surface on 46% of sites and an AI or chat endpoint on 26%: an attack surface, covered by the OWASP API and LLM Top 10 lists, that did not exist in most of these organizations two years ago.
CDN-fronted organizations grade dramatically better, but the CDN itself blocks very little.
What matters is what choosing one usually implies: the organization has moved to managed hosting, retired the on-premises web server, and closed the ports that came with it. For an organization still running a hybrid estate, putting the site behind an edge proxy is a five-hour task that removes an entire class of exposure and forces the origin clean-up that should have happened years ago. Maturity, in this dataset, is purchasable.
14 / What separates A from F
Reading the columns left to right is reading the life cycle of a breach.
A-graded organizations are not perfect, and their MFA and DMARC gaps are real, but they have no exposed databases, no unpatched edge, and no leak-site listings. F-graded organizations have all three.
| Control or signal | A | B | C | D | F |
|---|---|---|---|---|---|
| Organizations | 360 | 738 | 870 | 286 | 150 |
| DMARC enforcing | 94% | 48% | 59% | 44% | 62% |
| HSTS present | 14% | 13% | 13% | 8% | 11% |
| Known CVEs on edge | 0% | 1% | 6% | 38% | 29% |
| Database exposed | 0% | 0% | 1% | 29% | 3% |
| CDN-fronted origin | 70% | 63% | 56% | 31% | 61% |
| Collaboration graded D/F | 0% | 6% | 74% | 37% | 53% |
| Likely MFA gap (M365 tenants) | 73% | 66% | 31% | 51% | 47% |
| Critical look-alike domain | 81% | 74% | 81% | 68% | 83% |
| Median exposed employee creds | 97 | 94 | 412 | 144.5 | 506 |
| Ransomware leak-site listing | 0% | 0% | 1% | 0% | 60% |
Share of organizations in each composite grade exhibiting the control or signal (n = 2,404 random sample of 18,374). Grade-A organizations are not free of identity and email gaps, which the composite weights less heavily than exposed infrastructure; this is a deliberate choice that the strategic analysis below revisits.
The population is bimodal and the two halves need different medicine.
92% have a clean edge, and their remaining problems are policy gaps in email, identity and headers: remediation is configuration, costs nothing, and fits in a quarter. The other 8.1%, plus the 3.9% with exposed databases and the 3.8% on leak sites, have an infrastructure problem, and legacy servers need retiring rather than patching. Treating both groups with one security-awareness programme serves neither. The first needs an admin with a checklist; the second needs a migration budget.
15 / Vertical: SoCal community banking
195 community banks and credit unions headquartered in Southern California, scanned with the same engine and graded on the same 21 areas.
The population average is 7.13. Examinations have not moved this number.
18% graded D or F against 19% in the population, but only 10% reach an A against 14%.
External Teams federation left open to any tenant. An attacker in any Microsoft tenant can message any employee.
Identity ›Against 78% of the general population, and 40% show no external MFA enforcement signal.
Both bars are the share of organizations. Ahead and behind are judged per metric, because lower is better for half of them.
Aggregate only. No institution is named in this report, and no institution's grade is disclosed to anyone but that institution. 196 domains attempted, 195 returned a complete scan. DNSSEC is reported for this sector because it was scanned after the probe fix described in the methodology; it is not comparable to the population figure.
16 / Quarterly trend & benchmarks
This report is published quarterly against the same population and the same definitions, so the numbers below are comparable across editions. Each is externally measurable, binary or a rate, and tied to a recommendation above.
| Metric | 2026 Q3 |
|---|---|
| Mean composite score | 7.13/10 |
| Graded D or F | 19.2% |
| Five-control pass rate | 7.4% |
| Carry a critical finding | 27.4% |
| DMARC enforced | 59.5% |
| HSTS set | 12.2% |
| HTTPS forced | 83.4% |
| Database exposed to internet | 3.9% |
| Remote-admin port exposed | 6.4% |
| Carrying known CVEs | 8.1% |
| Named on a ransomware leak site | 3.8% |
| Publish a security.txt | 5.3% |
Baseline quarter: 2026 Q3. There is no prior edition to compare against, so no change is shown. The next edition will render a change column against these figures. Definitions are frozen across editions; a metric whose definition changes is retired and replaced rather than silently redefined.
| Indicator | 2026 Q3 | External reference (2026) | Target |
|---|---|---|---|
| Mean composite score | 7.13 / 10 | n/a | ≥ 7.5 (B) |
| Share graded D or F | 19.2% | n/a | ≤ 10% |
| Five-control pass rate | 7.4% | n/a | ≥ 25% |
| Organizations with ≥1 critical finding | 27.4% | n/a | ≤ 15% |
| DMARC record published | 87.4% | 52.1% of top 1.8M domains (EasyDMARC) | ≥ 95% |
| DMARC enforcing (quarantine/reject) | 59.5% | Inc. 5000 at reject: 15.2%; Fortune 500: 62.7% (EasyDMARC) | ≥ 70% |
| HSTS present | 12.2% | n/a | ≥ 50% |
| HTTPS forced | 83.4% | n/a | ≥ 98% |
| Organizations with known CVEs on edge | 8.1% | KEV fully remediated: 26% (DBIR 2026) | ≤ 4% |
| Database engine exposed to internet | 3.9% | n/a | 0% |
| Remote-admin protocol exposed | 6.4% | n/a | ≤ 1% |
| M365 tenants with likely MFA gap | 49.8% | MFA exposures fully remediated: 23% (DBIR 2026) | ≤ 25% |
| Collaboration Exposure graded D/F | 36.4% | n/a | ≤ 15% |
| Ransomware leak-site listings | 703 (3.8%) | Ransomware in 48% of breaches; 83% of SMB breaches (DBIR 2026) | Fewer than 2026 |
| security.txt published | 5.3% | n/a | ≥ 20% |
IBM's 2025 Cost of a Data Breach study puts the global average breach at USD 4.44 million and the United States average at a record USD 10.22 million, with a mean of 241 days to identify and contain.
Against those figures, every recommendation in Section 03 is a rounding error, and the 3,519 D and F organizations in this population represent a concentrated, addressable pool of that expected loss.
Mandiant's M-Trends 2026 reports the median hand-off from initial-access broker to ransomware affiliate has fallen to 22 seconds; CrowdStrike's 2026 Global Threat Report puts average eCrime breakout time at 29 minutes.
There is no detection-and-response program in this population that operates at that speed. The only controls that do are the preventive ones measured here, which is why this report measures them.
17 / Methodology & data quality
19,071 organization domains supplied by a platform partner, deduplicated and normalized.
18,374 (96.3%) returned a complete scan between September 4–6, 2026; 697 did not resolve, timed out or returned no data and are excluded from every figure. The population is predominantly United States small and mid-market organizations across all sectors, with a tail of large enterprises, universities and consumer internet services; 15,543 are .com. It is not a random sample of the internet and should not be read as one. Where a metric is dominated by that tail (credential-exposure counts for consumer mail providers, for example) the report uses medians and percentiles rather than totals.
Each domain was scanned once by the Cythentic Exposure Scan Engine from a fixed set of egress addresses, at a pace of roughly ten domains per minute, with every third-party source queried through its public, documented interface and within its rate limits.
Results are stored immutably with a per-domain identifier; every figure in this report can be traced to the underlying scan records.
| Source | Coverage |
|---|---|
| crt.sh Certificate Transparency | 100.0% |
| RansomwareLive | 100.0% |
| Netlify Blobs (scan history + industry avg) | 100.0% |
| CISA KEV Catalog | 100.0% |
| FIRST.org EPSS | 100.0% |
| ARIN WHOIS | 99.9% |
| NVD (CPE-based discovery) | 98.1% |
| Shodan InternetDB | 96.4% |
| Microsoft OpenID + GetUserRealm | 78.5% |
Coverage is the share of scans in which the source returned a usable answer. Shodan InternetDB coverage below 100% reflects addresses (largely CDN edges) with no indexed record, which is itself a positive signal.
External references: Verizon 2026 Data Breach Investigations Report; EasyDMARC 2026 DMARC Adoption & Enforcement Report (1.8M domains, Fortune 500, Inc. 5000); IBM Cost of a Data Breach Report 2025; Mandiant M-Trends 2026; CrowdStrike 2026 Global Threat Report. Figures quoted from these reports are theirs; all other figures are Cythentic measurements.
18 / Appendix
| TLD | Organizations | Mean score | Share D/F |
|---|---|---|---|
| .com | 15,543 | 7.1 | 19.5% |
| .org | 771 | 7.2 | 15.4% |
| .edu | 452 | 6.38 | 22.8% |
| .net | 314 | 6.92 | 26.4% |
| .io | 310 | 7.99 | 11.6% |
| .ai | 219 | 8.07 | 5.9% |
| .co | 174 | 7.75 | 12.6% |
| .us | 86 | 7.16 | 20.9% |
| .ca | 78 | 6.95 | 23.1% |
| .me | 32 | 8.34 | 9.4% |
| .app | 22 | 8.44 | 4.5% |
| .tv | 21 | 7.37 | 19.0% |
Newer TLDs (.io, .ai, .co) score materially higher than .com and .net. That is a cohort effect: organizations founded on cloud-native stacks have no legacy edge to expose.
| Grade | Composite score | Reading |
|---|---|---|
| A | 9.0 – 10.0 | No critical findings; policy gaps at most. |
| B | 7.5 – 8.9 | Minor exposure; one or two unenforced policies. |
| C | 6.0 – 7.4 | Typical: valid TLS, working mail, several unenforced controls. |
| D | 4.0 – 5.9 | At least one class of exposed infrastructure or many policy failures. |
| F | 1.5 – 3.0 | Multiple critical findings: exposed services, unpatched software, or a leak-site listing. |
Software Patching · Web Encryption · Web Application Security · Network Filtering · DNS Security · Email Security · Identity & Access · Collaboration Exposure · Attack Surface · SaaS Sprawl · Breach Events · Ransomware Exposure · Brand Impersonation · Domain Reputation · Web App Hardening · Resilience · Cookie & Session Security · Certificate Hygiene · Domain Registration Risk · Subdomain Takeover · Exposed Secrets & Repositories.
| Term | Meaning |
|---|---|
| SPF / DKIM / DMARC | The three DNS-published standards that let a receiving mail server verify a message really came from the sending domain. DMARC's policy value (none / quarantine / reject) decides what happens when it did not. |
| HSTS | HTTP Strict Transport Security: a response header instructing browsers to use only HTTPS for a site, defeating first-connection downgrade attacks. |
| CAA | A DNS record restricting which certificate authorities may issue certificates for a domain. |
| CVE / KEV / EPSS | Publicly catalogued vulnerabilities; CISA's list of those known to be exploited in the wild; and FIRST's probability score that a given CVE will be exploited in the next 30 days. |
| Leak site | A ransomware group's public website where victims who did not pay are named and their stolen data published. |
| Look-alike domain | A registered domain that is a character-level permutation of a brand's name (omission, transposition, homoglyph), used for phishing and fraud. |
| Conditional Access | Microsoft Entra's policy engine for requiring MFA, compliant devices or trusted locations before granting access. |
Every organization in this population has an immutable scan record with its full 21-area breakdown. Any organization can run the same assessment at cythentic.com/scan in under three minutes.
Discuss the findings with Cythentic© 2026 Cythentic Inc. · Cythentic Research · Cite as: Cythentic, 2026 Domain Exposure Report, Edition 1. Figures may be reproduced with attribution and without modification.
Take it with you
Every section, every figure and the full methodology, formatted to print and share with a board or a client. Tell us where to send it.
Your turn
This report is the population. The same engine that produced it will grade your own domain across the same 21 risk areas, place your score against these 18,374 organizations, and tell you which findings to fix first. No agent, no access, nothing to install: it reads only what the internet already publishes about you.
Passive only. Nothing is installed, nothing is logged in to, and no port is probed. About two minutes.