Cythentic RESEARCH

SoCal
Community
Banking

External Attack Surface Report · 2026 Q3

Your bank is not the main target.
Your business customers are.

195 banks and credit unions headquartered in Southern California, graded from the outside in. This is the baseline. Your customers sit below it, and they are the ones approving the wires.

195institutions scanned
61community banks
134credit unions
21risk areas
Cythentic Research · Aggregate findings onlyScroll

The finding

Examination has not moved the score

Mean 7.23/10 across 195 institutions. The general population of 18,374 organizations scores 7.13.

18%
Graded D or F
(35 institutions)
14%
Reach an A
(population: 14%)
91%
Run Microsoft 365
40% show no MFA signal externally
In one line: a supervised sector with mandatory IT examinations grades the same as a random sample of the internet, and produces fewer A grades than it.
Now ask the harder question. This is what banks look like from the outside: institutions with examiners, security budgets and a compliance function. Your business customers have none of that, and they are running the same Microsoft 365, with the same gaps, without anyone checking. They are also the ones approving the wires. When that goes wrong the money leaves their account, FDIC insurance does not cover it, and they bring the loss to you.

That is the part we fix. Cythentic gives your business customers a free exposure scan and a personal security assessment for every employee, under your brand, at no cost to the institution. See how it works →

Where does your institution sit in this? Run your domain and every one of the 21 areas is shown against this sector's average as well as the wider population. Two minutes, passive only, no email required.

01 / What is open

The five weakest areas in the sector

Share of institutions graded D or F, by risk area

scale 0 – 100% of institutions
Collabshare graded D or F
40%195 graded
Webappshare graded D or F
11%195 graded
Networkshare graded D or F
11%195 graded
Patchingshare graded D or F
7%195 graded
Cookiesshare graded D or F
7%121 graded
Collaboration exposure is the sector's open door. 40% fail it. External Microsoft Teams federation is left open to any tenant, so an attacker in any Microsoft tenant can message any employee directly. For an institution whose largest fraud exposure is business email compromise, that is the delivery channel, and restricting it is an admin-console setting.

02 / Size

Size predicts posture, but not in a straight line

7.28
$5B and above12 institutions · 25.0% D or F
7.69
$1B to $5B51 institutions · 9.8% D or F
7.42
$250M to $1B53 institutions · 15.1% D or F
6.8
Under $250M79 institutions · 24.1% D or F
The shape is the finding. The 51 institutions between $1B and $5B are the strongest at 7.69. Below $250M the mean falls to 6.8 with 24% graded D or F. Above $5B it worsens again: more estate, more legacy, more surface to hold.

03 / Charter type

Banks configure better and still fail more often

Community banks · 61 institutions

  • 70% enforce DMARC, against 58% of credit unions
  • 31% set HSTS, against 14%
  • 30% sign their DNS, against 11%
  • And yet 20% grade D or F, against 17%

Credit unions · 134 institutions

  • 13% carry known CVEs, nearly twice the 7% of banks
  • 14% reach an A, against 13%
  • 75% have employee credentials circulating, against 66%
  • Weaker on every control a person has to switch on
Two different problems. Configuration and exposure are not the same thing. Banks have the policies and the legacy estate; credit unions have neither. One "banking security" programme addresses neither well.

04 / What to do

Four things, none of which need budget

Each step below shows the share of the sector that has not done it yet. To see which side of each number your own institution is on, run your domain: the scan grades all 21 areas and marks each one against this sector's average.

This weekno budget

Restrict external Teams federation to an allow-list

The single most-failed area in the sector. One setting in the Teams admin centre closes the direct-message path from any Microsoft tenant on earth to your staff.

40%
of the sector fails this today
30 daysno budget

Move DMARC to quarantine, then reject

Two weeks at p=none with reporting to find your legitimate senders, then enforce. It stops your own domain being used against your customers.

38%
do not yet enforce a policy
30 dayslicensed already

Enforce MFA with Conditional Access for every user

Included in the Microsoft 365 licence 91% of the sector already pays for. Require phishing-resistant methods for administrators and block legacy authentication.

40%
show a gap from outside the tenant
60 daysno budget

Set HSTS and publish CAA

One response header and one DNS record. 20% of the sector sets HSTS and 5% publishes CAA, which is below the general population on CAA.

80%
have no HSTS today

05 / Method

How this was measured, and what is deliberately not here

Population

Every bank and credit union headquartered in the ten Southern California counties, built from FDIC BankFind and the NCUA quarterly call report: banks under $10B in assets and all credit unions. 196 domains attempted, 195 returned a complete scan. Institutions with no website on record are excluded and are disproportionately the smallest: eight of the twelve hold under $3M in assets.

Collection

Each domain was scanned once by the Cythentic Exposure Scan Engine using passive OSINT only: certificate transparency, DNS, WHOIS, HTTP response headers, Shodan InternetDB, NVD and the CISA KEV catalogue, Have I Been Pwned, Breachsense, RansomwareLive, and Microsoft and Google tenant metadata. Nothing was authenticated, no ports were probed, and no institution was contacted before or during the scan.

No institution is named

This report publishes aggregate findings only. No institution is identified, and no institution's grade, findings or domain appear anywhere in it. Every institution in this population is entitled to its own results, and those go to that institution alone, on request, at no cost.

Limitations

  • Passive only. This measures exposure, not compromise.
  • Inference. MFA posture is read from public tenant metadata and is a signal, not a verdict. Microsoft Security Defaults and per-user Conditional Access are invisible from outside a tenant, so an institution that enforces MFA by either route appears here as no signal. Read this figure as the share we could not confirm, not the share that is exposed.
  • Point in time. One scan per institution.
  • Small segments. The $5B-and-above band holds 12 institutions; read it as a direction, not a rate.

Take it with you

Download this report as a PDF

Formatted to print and share with a board, an examiner or an IT committee.

  • All 195 institutions in aggregate, by charter type and asset band
  • The five weakest of the 21 risk areas
  • The four no-budget actions, in order

Where the losses actually start

Your bank is not the main target.
Your business customers are.

This report graded the sector's own domains, and the sector grades reasonably well. That is not where the money goes. It goes when a business customer approves a wire that looks routine, on the Thursday before payroll, from an email thread that was already being read. FDIC insurance does not cover that loss, and the customer brings it to you anyway. Cythentic gives your business customers a free exposure scan and a personal security assessment for every employee, under your brand, at no cost to the institution.

Protect your business customers → Free for your customers · no cost to the institution · nothing to install

Your institution is one of the 195 in this report. We have not told anyone your grade and we will not. If you want your own 21-area breakdown, run your domain free: two minutes, passive only, no email required.

195institutions in this sector benchmark
18,374organizations in the wider benchmark
21risk areas graded

The full cross-industry study this sector is compared against is the Cythentic Exposure Index, 2026 Q3.