Cythentic RESEARCH

The
Exposure
Index

Cythentic's External Attack Surface Report · 2026 Q3

The external attack surface of 18,374 organizations, graded from the outside in, the way an adversary sees them.

2026 Q3Edition 1
18,374organizations scanned
21risk areas
Cythentic Research · Published quarterlyScroll

Cythentic Research · Exposure Index 2026 Q3 · Edition 1

External
Exposure Report

A census of the external attack surface of 18,374 organizations, graded across 21 risk areas from the outside in, the way an adversary sees them. What is exposed, what it correlates with, and what to fix first.

1 in 5organizations is graded D or F. That is 3,519 of 18,374, each carrying at least one exposure an attacker can act on from the open internet.
A14%
B30%
C36%
D12%
F7%
Every organization scanned, by gradeMean 7.13 / 10 · grade C
Where do you stand? Compare yourself to 18,000+ companiesRun your free scan →
18,374 domains scanned21 risk areas · 481,460 findingsData collected September 4–6, 2026Passive OSINT · no intrusive testingPublished quarterly

01 / Executive summary

The perimeter has moved. Most organizations have not.

18,374 organizations graded from the outside. Average score 7.13/10, a C.

A14%
B30%
C36%
D12%
F7%
A · 2,626B · 5,544C · 6,685D · 2,302F · 1,217
19.2%
Graded D or F
(3,519 organizations)
27.4%
Carry at least one critical finding
(8,125 criticals in total)
7.4%
Pass all five foundational controls
(DMARC enforced, HSTS, HTTPS forced, no CVEs, no exposed admin/DB ports)

The whole report in one comparison

What ships on by default is near universal. What needs a person to decide is not. That one split explains most of this report.

Someone else turned it on
vendor default
94%
Valid, trusted certificate
85%
TLS 1.3 negotiated
96%
SPF record present
87%
DMARC record of some kind

Issued and renewed automatically, or created by a mail provider's setup wizard.

Someone had to decide
human configuration
60%
DMARC actually enforced
12%
HSTS set
12%
CAA published
5%
security.txt published

Free, documented, and available in the same admin console as the controls above.

Eight findings that matter

90%of organizations
Email authentication is the widest open door

Only 32% enforce p=reject, the one policy that blocks spoofed mail.

Email authentication ›
12%set HSTS
Certificates are solved. Configuration is not

94% have a valid certificate; 39% send no security headers at all.

Encryption ›
52,691known CVEs
Patching risk is a fat tail, not a curve

92% of organizations are clean. The rest carry a median of 20 each.

Patching ›
1,572exposed services
Databases and remote desktops still face the internet

Each one is a reachable data store or admin console with no network control in front of it.

Exposed services ›
50%of M365 tenants
Identity is the unmeasured exposure

78% run Microsoft 365, and the tenant signals say enforcement is partial or absent.

Identity ›
174median creds
The credentials are already out

85% of organizations have employee credentials in public corpora.

Threat intelligence ›
703of 18,374 on a leak site
Ransomware is the lagging indicator

3.8% of the full population. Victims sit almost entirely in the F grade, alongside CVEs and exposed services.

Threat intelligence ›
91%have a look-alike
Brand impersonation is universal

78% have a typosquat carrying live web content or a mail server.

Threat intelligence ›
In one line: default-on controls are above 90%; decision-required controls sit at 12% to 60%. Buy defaults, not policies.

Where the rest of the report goes

02 / Strategic analysis

Six things the data says

Each claim below is argued in full in the section it points to. If you read only this page, you have the argument.

Default-on beats best-practice, every time

Every control this population is good at was switched on for them by a vendor. Every control they are bad at required a person to decide. Prefer platforms whose secure state is the default state, because the product is the policy.

94%
Certificate issued and renewed for them
60%
DMARC enforced, which someone must choose
5%
security.txt published, one static file
Read the evidence: The 21 risk areas ›

The population is bimodal, and the halves need different medicine

92% have a clean edge and a policy problem that configuration fixes for free. The rest have an infrastructure problem: legacy servers that need retiring, not patching. One group needs an admin with a checklist, the other needs a migration budget.

92%
Clean edge, no known-vulnerable software
8%
Carrying known CVEs on public infrastructure
4%
Exposing a database to the internet
Read the evidence: What separates A from F ›

Email is the perimeter, and it is unguarded outward

This population buys protection for the mail it receives and neglects the free control that protects everyone who receives mail from them. Business email compromise flows straight through that asymmetry.

19%
Pay for an inbound mail gateway
90%
Have an SPF, DKIM or DMARC gap
40%
Publish no enforcing DMARC policy
Read the evidence: Email authentication ›

Identity risk is invisible to the people who own it

No leader in this population would say their organization has no MFA. The external signals say enforcement is partial, conditional or absent for most of them, and the gap between licensed and enforced is only visible from outside the tenant, which is where the adversary stands.

78%
Run identity on Microsoft 365
50%
Of those, signals consistent with an MFA gap
36%
Open collaboration federation (graded D or F)
Read the evidence: Identity & collaboration ›

Ransomware is a lagging indicator, so it can be led

Leak-site listings sit almost entirely among F-graded organizations that also show known CVEs and exposed services. The 1,488 CVE-bearing organizations here are a forecast, not a finding. A partner or an insurer holding this list knows who is next.

4%
Named on an active leak site
8%
Failing on software patching
10%
Exposing a database or remote-admin port
Read the evidence: Threat intelligence ›

The CDN is a proxy for maturity, and maturity is purchasable

The CDN itself blocks little. What matters is what choosing one implies: managed hosting, no on-premises web server, and none of the ports that came with it. Putting the site behind an edge proxy is a five-hour task that forces an origin clean-up years overdue.

70%
A-graded organizations behind a CDN
61%
F-graded organizations behind a CDN
42%
Serving their origin directly to the internet
Read the evidence: Infrastructure & hosting ›

03 / Strategic recommendations

What to fix first, and how much it moves

Ranked by the share of this population each action moves out of a failing state. The first four cost nothing but attention. Together they take the median organization here from a C to a B in ninety days.

30 daysno budget

Enforce DMARC on every domain you own

Two weeks at p=none with reporting to find your legitimate senders, then p=quarantine, then p=reject.

40%
of organizations move to an enforcing policy
30 daysno budget

Force HTTPS and send HSTS

One redirect rule and one response header at the edge, plus the six remaining security headers from a published baseline.

88%
of organizations gain HSTS
30 daysno budget

Close every internet-facing database and remote-admin port

A firewall rule and an allow-list. The 1,572 exposed services here are the shortest path from a leaked password to a ransom note.

10%
of organizations remove a critical finding
30 daysno budget

Patch or retire the vulnerable edge, KEV first

The 1,488 affected organizations have a named list of software and versions. Anything on the CISA KEV catalog goes this week.

8%
of organizations hold 100% of the CVEs
90 daysno budget

Harden the naming layer

CAA for the certificate authority you actually use, registrar transfer lock with 2FA, and a published security.txt so the next researcher who finds something has someone to tell.

95%
of organizations publish no security.txt

Five questions for a board

  1. What is our composite grade, and what is it against our peers? If nobody can answer in one number, exposure is not being managed.
  2. Is DMARC at reject on every domain we own? Not "do we have DMARC". The policy value is the whole question.
  3. Is MFA enforced for every user, including the ones who complained? Ask for the Conditional Access policy, not the licence count.
  4. What is on the public internet that should not be? Ask for the list of databases, remote desktops and end-of-life software, and the retirement date for each.
  5. How would we find out? A published security.txt, an external scan on a schedule, and someone whose job it is to read it.

The one metric to track

The five-control pass rate: DMARC enforced, HSTS set, HTTPS forced, no known CVEs, no exposed admin or database ports.

The full analysis

Currently 7.4% of this population passes all five. It is binary, measurable from outside, and cannot be gamed by a questionnaire.

For a managed-service partner this report is a service catalogue; for an underwriter it is a pricing model.

The full analysis

The 19% graded D or F are identifiable by name, their failing controls are enumerated, and most are one quarter of configuration away from a B.

04 / How to read this report

Scope, grading, and confidence

What was measured

Every organization's primary domain was assessed from the public internet using passive open-source intelligence: DNS, certificate transparency, WHOIS/RDAP, HTTP headers, Shodan's InternetDB, NVD/CISA KEV/EPSS, breach corpora (HIBP, XposedOrNot, Breachsense counts), RansomwareLive leak-site data, and Microsoft/Google tenant metadata.

The full analysis

One outbound TLS handshake is made to read the certificate. No ports are probed, no exploits run, nothing is authenticated.

How grades work

Each of 21 risk areas is scored 0–10 from a documented formula (starting score, tiered deductions, sources cited per step) and letter-graded.

The full analysis

The composite is a weighted blend: A ≥ 9.0, B 7.5–8.9, C 6.0–7.4, D 4.0–5.9, F ≤ 3.0. Areas that do not apply to a domain (no cookies set, no registration data) are graded N/A and excluded from that area's denominators.

Census, not survey

This is a measurement of 18,374 organizations, not a questionnaire.

The full analysis

Unlike survey-based industry reports there is no self-report bias and no sampling error at the population level. 697 of 19,071 attempted scans (3.7%) returned no result within the window (unresolvable or timed out) and are excluded.

What it cannot see

Anything behind authentication: internal networks, endpoint controls, backups, staff training.

The full analysis

MFA posture is inferred from tenant metadata, not verified. CVE counts are derived from software versions identified in public banners (CPE matching). They indicate exposure to known vulnerabilities, not confirmed exploitability. Treat every figure here as a floor on exposure, not a ceiling.

Deep-dive metrics in this chapter are computed on a uniformly random sample of 2,404 of the 18,374 scanned domains (margin of error at 95% confidence: ±2.0 points on a 50% proportion). Population-level grades, scores and flags use all 18,374.

05 / The big picture

A population that clusters at "C"

36% of organizations land in the C band and 44% reach A or B. The distribution is not symmetric: a long left tail of 3,519 D and F organizations pulls the mean below the median, and 300 organizations sit at the floor score of 1.5.

A (9.0–10.0)14.3%B (7.5–8.9)30.2%C (6.0–7.4)36.4%D (4.0–5.9)12.5%F (1.5–3.0)6.6%
Figure 1. Composite grade distribution (n = 18,374). Bands show the score range for each grade.
FDCBA1,0002,0003,0004,0005,00012345678910Composite risk score (0–10, higher is better)
Figure 2. Distribution of composite scores in half-point bins, with grade bands shaded (n = 18,374). The spike at 7.0 is the modal organization: valid TLS, working mail, one or two unenforced policies.

Mean 7.13 · Median 7.2

Standard deviation 1.87. The 10th percentile organization scores 4.5; the 90th scores 9.1. The gap between them is the difference between a company that will and will not appear in next year's breach statistics.

5,039 with a critical

27% of organizations carry at least one critical-severity finding; 1,915 carry two or more. The median organization has 16 findings of any severity; the mean is 29.5, again skewed by the tail.

481,460 findings

8,125 critical and 473,335 warning-level findings across the population, an average of 26 per organization. The remediation backlog this represents is the real subject of this report.

Where the criticals come from

No DMARC record2,369Known CVEs on infrastructure1,266No SPF record881MySQL exposed739No TLS certificate577Domain hijacked/parked/misconfigured429Untrusted certificate408MSSQL exposed305RDP exposed298Possible DNS hijack / split-brain148SMB exposed105PostgreSQL exposed89
Figure 3. The twelve most common critical-severity findings, by number of organizations affected (n = 18,374). Two of the top three are email authentication; five of the top twelve are databases or remote-access services exposed directly to the internet.
Table view
Critical findingOrganizationsShare
No DMARC record2,36912.9%
Known CVEs on infrastructure1,2666.9%
No SPF record8814.8%
MySQL exposed7394.0%
No TLS certificate5773.1%
Domain hijacked/parked/misconfigured4292.3%
Untrusted certificate4082.2%
MSSQL exposed3051.7%
RDP exposed2981.6%
Possible DNS hijack / split-brain1480.8%
SMB exposed1050.6%
PostgreSQL exposed890.5%
Self-signed certificate420.2%
VNC exposed280.2%
Sensitive file public110.1%
Redis exposed40.0%
Telnet exposed20.0%
MongoDB exposed20.0%

06 / The 21 risk areas

Where the population fails, area by area

Each bar is the full population's grade distribution for one risk area.

The full analysis

The number at right is the share graded D or F. The pattern is unmistakable: areas governed by a default (certificates, DNS resolution, takeover hygiene) are overwhelmingly A; areas governed by a decision (collaboration federation, cookie flags, patch cadence, mail policy) are where the D and F grades live.

ABCDFhover a grade to isolate itD+FCollaboration Exposure36.4%Cookie & Session Security20.4%Software Patching7.8%Web App Hardening7.3%Email Security7.0%Web Encryption6.9%Network Filtering5.4%Ransomware Exposure4.1%Domain Registration Risk1.7%Subdomain Takeover0.3%DNS Security0.1%Breach Events0.1%Web Application Security0.0%Identity & Access0.0%Attack Surface0.0%SaaS Sprawl0.0%Domain Reputation0.0%Resilience0.0%Exposed Secrets & Repos0.0%
Figure 4. Grade distribution for each risk area, sorted by share graded D or F (n = 2,404 random sample of 18,374). Areas graded N/A or informational for an organization are excluded from that area's denominator.
Table view
Risk areaGradedABCDFD+FMean
Collaboration Exposure2,4041,53000874036.4%7.86
Cookie & Session Security1,17773412776240020.4%8.31
Software Patching2,4042,190819171707.8%9.26
Web App Hardening2,4041,581435213101747.3%8.75
Email Security2,4041,28664330616907.0%8.44
Web Encryption2,4041,867157214171496.9%9.01
Network Filtering2,4042,1925132241055.4%9.41
Ransomware Exposure2,4042,306008904.1%9.68
Domain Registration Risk1,07692812371261.7%9.64
Subdomain Takeover2,1322,12500070.3%9.97
DNS Security2,4042,17720321300.1%9.79
Breach Events2,4042,384018020.1%9.97
Web Application Security2,4044012,0030000.0%8.7
Identity & Access95281229111000.0%9.34
Attack Surface2,4042,376280000.0%9.76
SaaS Sprawl2,4041,3701,0340000.0%9.19
Domain Reputation2,4042,354050000.0%9.92
Resilience2,4011,169970262000.0%8.84
Exposed Secrets & Repos2,4042,40103000.0%10.0

Worst three areas

  • Collaboration Exposure: 36.4% graded D/F
  • Cookie & Session Security: 20.4% graded D/F
  • Software Patching: 7.8% graded D/F

Best three areas

  • Domain Reputation: 0.0% graded D/F
  • Resilience: 0.0% graded D/F
  • Exposed Secrets & Repos: 0.0% graded D/F

Why the good scores are all in one column

Every control above 85% adoption in this report is one a vendor turned on for the customer: certificate issuance and renewal (94%), TLS 1.3 (85%), and SPF records created by a mail provider's onboarding wizard (96%).

The full analysis

Every control that required the customer to make a decision sits far lower: DMARC enforcement (60%), HSTS (12%), CAA (12%) and a published security.txt (5%). Awareness campaigns have had twenty years. Defaults work in one release cycle.

07 / Email authentication

Published, but not enforced

Phishing is present in 16% of confirmed breaches and pretexting in a further 6% (DBIR 2026), and email is how nearly all business-email-compromise fraud is executed.

The full analysis

The controls are free and twenty years old. Adoption tells a story of good intentions: records get published, and then nobody flips the switch.

SPF record published95.9%SPF record valid82.9%DKIM signing detected78.3%DMARC record published87.4%DMARC enforcing (quarantine/reject)59.5%DMARC at p=reject32.1%Full stack, all three enforced52.6%
Figure 5. The email-authentication funnel: share of organizations at each stage (n = 2,404 random sample of 18,374). Every step down is a policy decision that was never made.

DMARC policy mix

12.6% publish no DMARC record at all.

The full analysis

Of those that do, 27.8% of all organizations sit at p=none, monitoring mode that blocks nothing; 27.4% at quarantine and 32.1% at reject. A p=none record is a promise to the world that spoofing your domain will be tolerated.

Mail security stack

Google Workspace 32%, Microsoft Exchange Online Protection 30%, Proofpoint 12%.

The full analysis

19% of organizations layer a dedicated secure-email gateway in front of their provider (Proofpoint, Mimecast, Barracuda). Layering does not substitute for DMARC: a gateway filters inbound mail; DMARC protects everyone else from mail forged in your name.

This reportBenchmarkAny DMARC record87.4%52.1% EasyDMARC 2026, top 1.8M domainsDMARC at p=reject32.1%15.2% EasyDMARC 2026, Inc. 5000DMARC at p=reject32.1%62.7% EasyDMARC 2026, Fortune 500
Figure 6. This population against published 2026 DMARC benchmarks. The population is ahead of the general internet on publishing records and roughly level with the Inc. 5000 on enforcement, and far behind the Fortune 500.
Implication. Moving every p=none and missing-record domain to quarantine would lift 40% of this population into an enforcing posture with zero capital cost. It is the highest-leverage single change available to this population, and the one most likely to be blocked by a fear of breaking marketing mail that a two-week monitoring period would resolve.

The strategic read

This population spends on inbound filtering, with 19% layering a gateway in front of their mailbox provider, while leaving their own domain available to be forged against their customers, suppliers and banks.

The full analysis

The asymmetry is the finding: organizations buy protection for the mail they receive and neglect the free control that protects everyone who receives mail from them. Business-email-compromise losses flow directly through that gap, and the fix is a DNS record and two weeks of reporting.

08 / Web encryption & transport

Solved at the certificate. Abandoned at the header.

This is the clearest natural experiment in the dataset.

The full analysis

Certificates are issued and renewed by machines; 61% of certificates now have a lifetime of 90 days or less, which is only possible with automation. Every control that lives one layer up, and needs a human to type a line of configuration, collapses.

94%
Valid, trusted certificate
85%
Negotiate TLS 1.3
83%
Redirect HTTP → HTTPS
12%
Send HSTS
12%
Publish CAA records
5%
Publish a security.txt
X-Content-Type-Options46.3%X-Frame-Options44.0%Content-Security-Policy35.9%Referrer-Policy29.0%Permissions-Policy16.1%Strict-Transport-Security12.2%Cross-Origin-Opener-Policy7.4%Cross-Origin-Resource-Policy6.6%
Figure 7. Adoption of the eight standard HTTP security headers (n = 2,404 random sample of 18,374). 39% of sites send none of them; the mean site sends 1.98 of eight.

Who issues the certificates

IssuerShare
Let's Encrypt32.9%
Google Trust Services25.8%
DigiCert Inc10.7%
Amazon10.2%
Sectigo Limited5.2%
none3.3%

4.6% of certificates expire within 30 days of the scan; 0.7% were already expired; 0.2% self-signed; 5.5% presented no usable certificate.

Why HSTS at 12% matters

Without HSTS, a user's first connection, on hotel Wi-Fi or at a conference or on a compromised home router, is a plain-HTTP request that an attacker on the path can answer.

The full analysis

The 50% of sites that do not even redirect HTTP to HTTPS make this trivial. HSTS is one response header. It is the cheapest control in this report and one of the least adopted.

CAA adoption of 12% means that for almost every organization here, the right to issue certificates in their name rests entirely on their registrar and DNS host being uncompromised.

The full analysis

1.0% of domains already return different answers from different public resolvers, a possible hijack or split-brain signal.

5.3% of organizations publish a security.txt file, the standard (RFC 9116) way for a researcher to report a vulnerability. The other 95% have no published route for the outside world to tell them something is wrong.

09 / Software patching & vulnerabilities

92% clean. 8.1% carrying 52,691 CVEs.

Vulnerability exploitation is now the leading initial-access vector in confirmed breaches (31%, DBIR 2026), and Mandiant's M-Trends 2026 records exploits as the top entry point for the sixth consecutive year.

The full analysis

In this population the exposure is concentrated: most organizations show no known-vulnerable software on the public edge, and a minority show a great deal.

1-9 CVEs44510-49 CVEs74350-99 CVEs182100+ CVEs118
Figure 8. Organizations with known CVEs on public-facing infrastructure, by count (n = 1,488 of 18,374). Median 20 CVEs per affected organization; 90th percentile 87; maximum 530.

What drives the counts

Long-unpatched web servers, control panels and mail stacks whose version strings map to dozens of published CVEs at once.

The full analysis

An organization at 87+ CVEs is not missing a patch; it is running software that stopped receiving patches. In the sample, 88 organizations carry at least one vulnerability on the CISA Known Exploited Vulnerabilities list, the ones adversaries are using right now.

The industry context

The DBIR 2026 reports that only 26% of critical KEV vulnerabilities were fully remediated by organizations in 2025, down from 38%, with a median time to full resolution of 43 days.

The full analysis

Among SMB ransomware victims, 29% had unpatched vulnerabilities in edge devices. The 1,488 organizations in Figure 8 are the population's edge-device problem, made visible.

Implication. This is the one area where a small, identifiable list of 1,488 organizations, KEV-affected first, accounts for the entire population's exposure. It is also the area with the most direct line to ransomware: see Section 12.

10 / Exposed services

The internet-facing database

3.9% of organizations expose a database engine directly to the internet and 6.4% expose a remote-administration protocol (RDP, VNC, SSH or Telnet).

The full analysis

Neither has a legitimate reason to be reachable from every address on Earth. Each is a critical finding because each is one credential, often one already in a stealer log, away from full compromise.

FTP (21)5.1%SSH (22)4.7%MySQL (3306)3.7%MS-RPC (135)1.7%LDAP (389)1.7%MSSQL (1433)1.7%Elasticsearch (9200)1.6%RDP (3389)1.6%Oracle DB (1521)1.6%VNC (5900)1.6%VNC (5901)1.6%SMB (445)0.6%
Figure 9. Share of organizations with high-risk services reachable from the internet (n = 2,404 random sample of 18,374). Databases, Windows file sharing, LDAP and remote desktop should never be internet-facing; SSH and FTP should be restricted to known addresses.
Table view
PortServiceOrganizationsShare
21FTP1225.1%
22SSH1144.7%
3306MySQL903.7%
135MS-RPC411.7%
389LDAP411.7%
1433MSSQL401.7%
9200Elasticsearch391.6%
3389RDP391.6%
1521Oracle DB391.6%
5900VNC391.6%
5901VNC391.6%
445SMB140.6%
5432PostgreSQL100.4%
6379Redis10.0%

Only-web is the goal

51% of organizations expose nothing but ports 80 and 443, the correct end state for a public web presence.

The full analysis

The mean primary address answers on 19.6 ports, but for CDN-fronted sites those are the edge provider's standard listeners (Cloudflare's 2052–2096, 8080, 8443, 8880), not the organization's own. The gap that matters is the hosting-control-panel ports (cPanel, WHM, webmail) inherited from shared hosting, plus the databases and remote-access services above, all of which sit on the organization's own origin.

Why this correlates with everything

Exposed services co-occur with unpatched software (the same neglected server), with hybrid on-premises topologies, and with the absence of a CDN or WAF in front of the origin.

The full analysis

In the grade correlation table (Section 14), exposed databases are found almost exclusively in D and F organizations. It is less a finding than a diagnosis.

11 / Identity & collaboration

The tenant is the new perimeter

78% of organizations run Microsoft 365; 11% run Google Workspace.

The full analysis

Their identity provider is now the front door to email, files, chat and, through single sign-on, most of their SaaS estate. The scan cannot log in, but tenant metadata says a great deal about how that door is guarded.

78%
Microsoft 365 tenants
50%
of M365 tenants: likely MFA gap
16%
Federated to an external IdP
27%
Intune device management detected
36%
Collaboration Exposure graded D/F
4.9
Mean SaaS services detectable per org

How MFA posture is inferred

Microsoft exposes a tenant's realm type, federation brand, device-registration and MDM endpoints publicly.

The full analysis

A tenant that is unfederated, shows no Conditional Access-linked device registration, is classified LIKELY_GAP; one with federation to a modern IdP or device-registration evidence is LIKELY_ENFORCED. This is a signal, not a verdict. Microsoft Security Defaults and per-user Conditional Access produce no external signal whatsoever, so a tenant that enforces MFA by either route is classified LIKELY_GAP here: the figure is the share that cannot be confirmed from outside, not the share that is exposed. It is, however, the same signal an attacker reads before choosing a password-spray target. Across all organizations: Likely Gap 39%, Likely Enforced 34%, Unknown 11%, Unverifiable Google 10%.

Collaboration exposure

874 organizations (36%) are graded D or F on Collaboration Exposure: Microsoft Teams external federation left open to any tenant, or legacy Lync/Skype for Business discovery records still published.

The full analysis

Open federation is the delivery channel for the Teams-based phishing and malware campaigns that have replaced much of email as the initial lure: an attacker in any tenant can message any user. Restricting federation to an allow-list is an admin-center setting.

Industry context. The DBIR 2026 tracked third-party cloud MFA exposures over time and found only 23% of organizations fully remediated them; half of all findings were still open after a month. The population here is consistent with that: identity controls are widely available, widely licensed and inconsistently switched on.

The strategic read

No leader in this population would describe their organization as having no MFA, and none would be lying.

The full analysis

The data says enforcement is partial, conditional or absent for a majority: 78% run identity on Microsoft 365, 50% of those show signals consistent with a gap, 36% leave collaboration federation open, and a median of 174 employee credentials are already circulating. The distance between licensed and enforced is where the breaches of 2027 will come from, and it is only visible from outside the tenant, which is exactly where the adversary is standing.

12 / Threat intelligence

What the adversary already has

Three external signals say whether an organization has already been touched: whether its people's credentials are circulating, whether it has appeared in a disclosed breach, and whether a ransomware crew has published its name. The first is nearly universal. The last is rare, and nearly always preceded by the findings in Sections 09 and 10.

Share of the population each signal touches

scale 0 – 100% of organizations
Employee credentials circulatingin public breach and infostealer corpora
85%2,046 orgs
Listed on a ransomware leak sitenamed by an active extortion crew
4.1%98 orgs
Named in a disclosed breachHIBP / XposedOrNot
0.8%20 orgs
174
Median exposed employee credentials, counting only the organizations that have any
554
Organizations with 1,000 or more exposed employee credentials
7
Dangling subdomains open to takeover
16,234,288records exposed

Across the 98 organizations named on leak sites, 16,234,288 records tied to their domains are already circulating in public breach and infostealer corpora, 2,575,825 of them employee credentials. Their median employee-credential count is 1,762 against a population median of 174: ten times the exposure. Credential volume is not a consequence of being named; it is the condition that preceded it.

Clop28Shinyhunters13Dispossessor10Lockbit37Everest6Incransom5Lockbit23Ransomhub3Qilin3Medusa2
Figure 10. Ransomware groups with leak-site listings naming organizations in this sample (RansomwareLive, n = 2,404 random sample of 18,374). Listings are matched on domain and on company name, so a victim posted under a sibling domain is still counted.

Background on each group. CISA #StopRansomware advisories carry the tactics and detection guidance; tracker pages carry the current victim list.

Credentials: the quiet universal

Credential exposure counts come from Breachsense's public index of breach dumps and infostealer logs.

The full analysis

They are counts, not passwords, but the count is what an attacker sees when deciding whether a password spray or a credential-stuffing run against an organization is worth the effort. With a median of 174 exposed employee credentials, the answer for most of this population is yes. This is why the MFA gap in Section 11 is not a hygiene issue but the difference between a leaked password and a breach.

Ransomware: rare, and predictable

98 organizations appear on active leak sites.

The full analysis

The DBIR 2026 puts ransomware in 48% of all breaches and 83% of SMB breaches, with roughly 96% of ransomware victims being SMBs, which is this population's exact profile. In the grade correlations (Section 14) leak-site victims appear almost exclusively among F-graded organizations, alongside exposed databases and triple-digit CVE counts. The order of events is not ambiguous.

Brand impersonation: 91% of organizations have registered look-alike domains they do not control (mean 13.6 per brand; 78% with at least one rated critical, meaning a live site or mail server). 1.5% of domains lack a registrar transfer lock; 5.0% expire within 90 days of the scan.

The strategic read

Leak-site listings are found almost entirely among F-graded organizations that also show known CVEs and exposed services.

The full analysis

Industry data agrees: the DBIR 2026 attributes 29% of SMB ransomware to unpatched edge devices and 38% to compromised credentials. The operational implication is that the 1,488 CVE-bearing organizations in this dataset are a forecast rather than a finding. A platform partner or an underwriter holding this list already knows who is next, which makes it an intervention opportunity and not merely a risk register.

13 / Infrastructure & hosting

Where the origin lives

The single strongest structural correlate of a good grade in this dataset is whether the organization's web origin is hidden behind a CDN or edge proxy.

The full analysis

It is not the CDN that makes the difference; it is what a CDN implies: managed hosting, no legacy server, no forgotten ports.

Hybrid on-premises + cloud37.3%CDN-fronted (origin hidden)33.6%Cloud-only25.2%Distributed enterprise3.9%
Figure 11. Externally inferred network topology (n = 2,404 random sample of 18,374).
None42.1%Cloudflare22.8%AWS CloudFront20.5%Akamai5.0%Google Cloud CDN4.2%Fastly2.9%Vercel CDN2.6%
Figure 12. CDN / edge provider in front of the primary origin (n = 2,404 random sample of 18,374). 42% of organizations serve their origin directly.

Hosting providers

ProviderShare
Cloudflare31.0%
Unknown24.0%
Amazon Web Services13.4%
WP Engine4.8%
Microsoft Azure3.8%
Google Cloud3.4%
Webflow3.4%
Vercel3.1%

What the mix means

37% of organizations still run a hybrid estate with on-premises public IP space, the topology in which exposed databases, RDP and unpatched appliances are found.

The full analysis

38% expose a VPN endpoint. The 34% that are CDN-fronted have, in effect, outsourced their perimeter, and it shows in their grades.

Server software is disclosed by 80% of sites via the Server header; path probing finds a public API surface on 46% of sites and an AI or chat endpoint on 26%: an attack surface, covered by the OWASP API and LLM Top 10 lists, that did not exist in most of these organizations two years ago.

The strategic read

CDN-fronted organizations grade dramatically better, but the CDN itself blocks very little.

The full analysis

What matters is what choosing one usually implies: the organization has moved to managed hosting, retired the on-premises web server, and closed the ports that came with it. For an organization still running a hybrid estate, putting the site behind an edge proxy is a five-hour task that removes an entire class of exposure and forces the origin clean-up that should have happened years ago. Maturity, in this dataset, is purchasable.

14 / What separates A from F

The anatomy of a grade

Reading the columns left to right is reading the life cycle of a breach.

The full analysis

A-graded organizations are not perfect, and their MFA and DMARC gaps are real, but they have no exposed databases, no unpatched edge, and no leak-site listings. F-graded organizations have all three.

Control or signalABCDF
Organizations360738870286150
DMARC enforcing94%48%59%44%62%
HSTS present14%13%13%8%11%
Known CVEs on edge0%1%6%38%29%
Database exposed0%0%1%29%3%
CDN-fronted origin70%63%56%31%61%
Collaboration graded D/F0%6%74%37%53%
Likely MFA gap (M365 tenants)73%66%31%51%47%
Critical look-alike domain81%74%81%68%83%
Median exposed employee creds9794412144.5506
Ransomware leak-site listing0%0%1%0%60%

Share of organizations in each composite grade exhibiting the control or signal (n = 2,404 random sample of 18,374). Grade-A organizations are not free of identity and email gaps, which the composite weights less heavily than exposed infrastructure; this is a deliberate choice that the strategic analysis below revisits.

The pattern. CVE presence rises from 0% of A-graded organizations to 38% of D; exposed databases from 0% to 29%; median exposed employee credentials from 97 to 506; and ransomware listings appear only in the F column (60%). Identity and email do not follow the gradient: DMARC enforcement is 94% among A-graded organizations and 62% among F, and the likely-MFA-gap rate is 73% among A-graded Microsoft 365 tenants against 47% among F. The population's best-graded organizations are no better at identity and email policy than its worst. That is the single most important strategic finding in this report, and it is why the recommendations lead with those two controls.

The strategic read

The population is bimodal and the two halves need different medicine.

The full analysis

92% have a clean edge, and their remaining problems are policy gaps in email, identity and headers: remediation is configuration, costs nothing, and fits in a quarter. The other 8.1%, plus the 3.9% with exposed databases and the 3.8% on leak sites, have an infrastructure problem, and legacy servers need retiring rather than patching. Treating both groups with one security-awareness programme serves neither. The first needs an admin with a checklist; the second needs a migration budget.

15 / Vertical: SoCal community banking

A regulated sector, graded the same as everyone else

195 community banks and credit unions headquartered in Southern California, scanned with the same engine and graded on the same 21 areas.

7.05mean score / 10
Regulation is not showing up in the score

The population average is 7.13. Examinations have not moved this number.

10%graded A
Fewer disasters, fewer exemplars

18% graded D or F against 19% in the population, but only 10% reach an A against 14%.

40%fail collaboration
The open door is Microsoft Teams

External Teams federation left open to any tenant. An attacker in any Microsoft tenant can message any employee.

Identity ›
92%run Microsoft 365
One vendor holds the sector's identity

Against 78% of the general population, and 40% show no external MFA enforcement signal.

Against the wider population

This sectorAll 18,374
DMARC enforced
62%
60%
ahead
HSTS set
20%
12%
ahead
CAA published
5%
12%
behind
Credentials already circulating
72%
85%
ahead
Named on a ransomware leak site
1%
4%
ahead
Graded D or F
18%
19%
even

Both bars are the share of organizations. Ahead and behind are judged per metric, because lower is better for half of them.

Size predicts posture, but not in a straight line

7.41
$5B and above12 institutions · 25.0% D or F
7.65
$1B to $5B51 institutions · 9.8% D or F
7.12
$250M to $1B53 institutions · 15.1% D or F
6.57
Under $250M79 institutions · 25.3% D or F
The shape is the finding. The 51 institutions between $1B and $5B are the strongest in the sector at 7.65. Below $250M the mean falls to 6.57 with 25% graded D or F. Above $5B it gets worse again: more estate, more legacy, more surface.

Banks and credit unions are not the same population

Community banks · 61 institutions

  • 70% enforce DMARC, against 58% of credit unions
  • 31% set HSTS, against 14%
  • 30% have DNSSEC, against 11%
  • But 20% graded D or F, against 18%

Credit unions · 134 institutions

  • 13% carry known CVEs, nearly twice the 7% of banks
  • 11% reach an A, against 8%
  • 74% have employee credentials circulating, against 69%
  • Weaker on every control a person has to switch on
Read it this way. Banks configure better and still fail more often. Credit unions configure worse and fail less. Configuration and exposure are different problems, and a single "bank security" programme addresses neither well.

Aggregate only. No institution is named in this report, and no institution's grade is disclosed to anyone but that institution. 196 domains attempted, 195 returned a complete scan. DNSSEC is reported for this sector because it was scanned after the probe fix described in the methodology; it is not comparable to the population figure.

16 / Quarterly trend & benchmarks

This quarter set the baseline. Next quarter measures the movement.

This report is published quarterly against the same population and the same definitions, so the numbers below are comparable across editions. Each is externally measurable, binary or a rate, and tied to a recommendation above.

Quarter over quarter

Metric2026 Q3
Mean composite score7.13/10
Graded D or F19.2%
Five-control pass rate7.4%
Carry a critical finding27.4%
DMARC enforced59.5%
HSTS set12.2%
HTTPS forced83.4%
Database exposed to internet3.9%
Remote-admin port exposed6.4%
Carrying known CVEs8.1%
Named on a ransomware leak site3.8%
Publish a security.txt5.3%

Baseline quarter: 2026 Q3. There is no prior edition to compare against, so no change is shown. The next edition will render a change column against these figures. Definitions are frozen across editions; a metric whose definition changes is retired and replaced rather than silently redefined.

Against the outside world

Indicator2026 Q3External reference (2026)Target
Mean composite score7.13 / 10n/a≥ 7.5 (B)
Share graded D or F19.2%n/a≤ 10%
Five-control pass rate7.4%n/a≥ 25%
Organizations with ≥1 critical finding27.4%n/a≤ 15%
DMARC record published87.4%52.1% of top 1.8M domains (EasyDMARC)≥ 95%
DMARC enforcing (quarantine/reject)59.5%Inc. 5000 at reject: 15.2%; Fortune 500: 62.7% (EasyDMARC)≥ 70%
HSTS present12.2%n/a≥ 50%
HTTPS forced83.4%n/a≥ 98%
Organizations with known CVEs on edge8.1%KEV fully remediated: 26% (DBIR 2026)≤ 4%
Database engine exposed to internet3.9%n/a0%
Remote-admin protocol exposed6.4%n/a≤ 1%
M365 tenants with likely MFA gap49.8%MFA exposures fully remediated: 23% (DBIR 2026)≤ 25%
Collaboration Exposure graded D/F36.4%n/a≤ 15%
Ransomware leak-site listings703 (3.8%)Ransomware in 48% of breaches; 83% of SMB breaches (DBIR 2026)Fewer than 2026
security.txt published5.3%n/a≥ 20%

Cost context

IBM's 2025 Cost of a Data Breach study puts the global average breach at USD 4.44 million and the United States average at a record USD 10.22 million, with a mean of 241 days to identify and contain.

The full analysis

Against those figures, every recommendation in Section 03 is a rounding error, and the 3,519 D and F organizations in this population represent a concentrated, addressable pool of that expected loss.

Speed context

Mandiant's M-Trends 2026 reports the median hand-off from initial-access broker to ransomware affiliate has fallen to 22 seconds; CrowdStrike's 2026 Global Threat Report puts average eCrime breakout time at 29 minutes.

The full analysis

There is no detection-and-response program in this population that operates at that speed. The only controls that do are the preventive ones measured here, which is why this report measures them.

17 / Methodology & data quality

How the numbers were made

Population

19,071 organization domains supplied by a platform partner, deduplicated and normalized.

The full analysis

18,374 (96.3%) returned a complete scan between September 4–6, 2026; 697 did not resolve, timed out or returned no data and are excluded from every figure. The population is predominantly United States small and mid-market organizations across all sectors, with a tail of large enterprises, universities and consumer internet services; 15,543 are .com. It is not a random sample of the internet and should not be read as one. Where a metric is dominated by that tail (credential-exposure counts for consumer mail providers, for example) the report uses medians and percentiles rather than totals.

Collection

Each domain was scanned once by the Cythentic Exposure Scan Engine from a fixed set of egress addresses, at a pace of roughly ten domains per minute, with every third-party source queried through its public, documented interface and within its rate limits.

The full analysis

Results are stored immutably with a per-domain identifier; every figure in this report can be traced to the underlying scan records.

Sources and coverage

SourceCoverage
crt.sh Certificate Transparency100.0%
RansomwareLive100.0%
Netlify Blobs (scan history + industry avg)100.0%
CISA KEV Catalog100.0%
FIRST.org EPSS100.0%
ARIN WHOIS99.9%
NVD (CPE-based discovery)98.1%
Shodan InternetDB96.4%
Microsoft OpenID + GetUserRealm78.5%

Coverage is the share of scans in which the source returned a usable answer. Shodan InternetDB coverage below 100% reflects addresses (largely CDN edges) with no indexed record, which is itself a positive signal.

Limitations

  • Passive only. Nothing behind authentication is observed; the report measures exposure, not compromise.
  • Inference. MFA posture, topology and hosting are inferred from public metadata and labelled as such throughout.
  • CVE attribution is by software version (CPE) match and indicates known vulnerabilities in identified software, not confirmed exploitability.
  • Credential counts are provider-reported index counts, not verified live credentials.
  • DNSSEC is not graded. Support is uneven across the platforms this population actually uses, so an organization can be well run and unable to enable it. Marking its absence as a deficiency would penalise the host's choice rather than the organization's, and it is excluded from every figure in this report for that reason.
  • Point in time. A single scan per domain in a three-day window; transient failures are counted as findings only where the scanner could confirm the condition.
  • Composite weighting deliberately emphasizes exposed infrastructure over policy gaps; Section 14 shows the consequence and Section 02 argues for revisiting it.

External references: Verizon 2026 Data Breach Investigations Report; EasyDMARC 2026 DMARC Adoption & Enforcement Report (1.8M domains, Fortune 500, Inc. 5000); IBM Cost of a Data Breach Report 2025; Mandiant M-Trends 2026; CrowdStrike 2026 Global Threat Report. Figures quoted from these reports are theirs; all other figures are Cythentic measurements.

18 / Appendix

Reference tables

A. Composite grade by top-level domain

TLDOrganizationsMean scoreShare D/F
.com15,5437.119.5%
.org7717.215.4%
.edu4526.3822.8%
.net3146.9226.4%
.io3107.9911.6%
.ai2198.075.9%
.co1747.7512.6%
.us867.1620.9%
.ca786.9523.1%
.me328.349.4%
.app228.444.5%
.tv217.3719.0%

Newer TLDs (.io, .ai, .co) score materially higher than .com and .net. That is a cohort effect: organizations founded on cloud-native stacks have no legacy edge to expose.

B. Grade definitions

GradeComposite scoreReading
A9.0 – 10.0No critical findings; policy gaps at most.
B7.5 – 8.9Minor exposure; one or two unenforced policies.
C6.0 – 7.4Typical: valid TLS, working mail, several unenforced controls.
D4.0 – 5.9At least one class of exposed infrastructure or many policy failures.
F1.5 – 3.0Multiple critical findings: exposed services, unpatched software, or a leak-site listing.

C. The 21 risk areas

Software Patching · Web Encryption · Web Application Security · Network Filtering · DNS Security · Email Security · Identity & Access · Collaboration Exposure · Attack Surface · SaaS Sprawl · Breach Events · Ransomware Exposure · Brand Impersonation · Domain Reputation · Web App Hardening · Resilience · Cookie & Session Security · Certificate Hygiene · Domain Registration Risk · Subdomain Takeover · Exposed Secrets & Repositories.

D. Glossary

TermMeaning
SPF / DKIM / DMARCThe three DNS-published standards that let a receiving mail server verify a message really came from the sending domain. DMARC's policy value (none / quarantine / reject) decides what happens when it did not.
HSTSHTTP Strict Transport Security: a response header instructing browsers to use only HTTPS for a site, defeating first-connection downgrade attacks.
CAAA DNS record restricting which certificate authorities may issue certificates for a domain.
CVE / KEV / EPSSPublicly catalogued vulnerabilities; CISA's list of those known to be exploited in the wild; and FIRST's probability score that a given CVE will be exploited in the next 30 days.
Leak siteA ransomware group's public website where victims who did not pay are named and their stolen data published.
Look-alike domainA registered domain that is a character-level permutation of a brand's name (omission, transposition, homoglyph), used for phishing and fraud.
Conditional AccessMicrosoft Entra's policy engine for requiring MFA, compliant devices or trusted locations before granting access.

Benchmark your organization against this report

Every organization in this population has an immutable scan record with its full 21-area breakdown. Any organization can run the same assessment at cythentic.com/scan in under three minutes.

Discuss the findings with Cythentic

© 2026 Cythentic Inc. · Cythentic Research · Cite as: Cythentic, 2026 Domain Exposure Report, Edition 1. Figures may be reproduced with attribution and without modification.

Take it with you

Download the Exposure Index as a PDF

Every section, every figure and the full methodology, formatted to print and share with a board or a client. Tell us where to send it.

  • The complete 18,374-organization census
  • All 21 risk areas with grade distributions
  • The prioritized remediation roadmap

Your turn

Compare yourself to 18,000+ companies.
Where do you stand externally?

This report is the population. The same engine that produced it will grade your own domain across the same 21 risk areas, place your score against these 18,374 organizations, and tell you which findings to fix first. No agent, no access, nothing to install: it reads only what the internet already publishes about you.

Passive only. Nothing is installed, nothing is logged in to, and no port is probed. About two minutes.

18,374organizations in the benchmark
21risk areas graded
19%of them graded D or F