External Attack Surface Report · 2026 Q3
Your bank is not the main target.
Your business customers are.
195 banks and credit unions headquartered in Southern California, graded from the outside in. This is the baseline. Your customers sit below it, and they are the ones approving the wires.
The finding
Mean 7.23/10 across 195 institutions. The general population of 18,374 organizations scores 7.13.
Where does your institution sit in this? Run your domain and every one of the 21 areas is shown against this sector's average as well as the wider population. Two minutes, passive only, no email required.
01 / What is open
02 / Size
03 / Charter type
04 / What to do
Each step below shows the share of the sector that has not done it yet. To see which side of each number your own institution is on, run your domain: the scan grades all 21 areas and marks each one against this sector's average.
The single most-failed area in the sector. One setting in the Teams admin centre closes the direct-message path from any Microsoft tenant on earth to your staff.
Two weeks at p=none with reporting to find your legitimate senders, then enforce. It stops your own domain being used against your customers.
Included in the Microsoft 365 licence 91% of the sector already pays for. Require phishing-resistant methods for administrators and block legacy authentication.
One response header and one DNS record. 20% of the sector sets HSTS and 5% publishes CAA, which is below the general population on CAA.
05 / Method
Every bank and credit union headquartered in the ten Southern California counties, built from FDIC BankFind and the NCUA quarterly call report: banks under $10B in assets and all credit unions. 196 domains attempted, 195 returned a complete scan. Institutions with no website on record are excluded and are disproportionately the smallest: eight of the twelve hold under $3M in assets.
Each domain was scanned once by the Cythentic Exposure Scan Engine using passive OSINT only: certificate transparency, DNS, WHOIS, HTTP response headers, Shodan InternetDB, NVD and the CISA KEV catalogue, Have I Been Pwned, Breachsense, RansomwareLive, and Microsoft and Google tenant metadata. Nothing was authenticated, no ports were probed, and no institution was contacted before or during the scan.
This report publishes aggregate findings only. No institution is identified, and no institution's grade, findings or domain appear anywhere in it. Every institution in this population is entitled to its own results, and those go to that institution alone, on request, at no cost.
Take it with you
Formatted to print and share with a board, an examiner or an IT committee.
Where the losses actually start
This report graded the sector's own domains, and the sector grades reasonably well. That is not where the money goes. It goes when a business customer approves a wire that looks routine, on the Thursday before payroll, from an email thread that was already being read. FDIC insurance does not cover that loss, and the customer brings it to you anyway. Cythentic gives your business customers a free exposure scan and a personal security assessment for every employee, under your brand, at no cost to the institution.
Your institution is one of the 195 in this report. We have not told anyone your grade and we will not. If you want your own 21-area breakdown, run your domain free: two minutes, passive only, no email required.
The full cross-industry study this sector is compared against is the Cythentic Exposure Index, 2026 Q3.