H2 2026
A biannual read on external attack surface exposure across 1,293 organizations in the US, UK, and Nordics. The Index measures the condition of internet-facing exposure before an incident occurs. Five signals separate teams closing risk from teams letting it age.
Security teams are finding risk faster than ever, but unresolved backlogs and expanding attack surfaces are creating a widening exposure gap.
The clearest finding across all three markets: the overwhelming majority of open critical and high-severity vulnerabilities have been sitting exposed for more than 90 days. Because these specific assessments test real-world exploitability through 100% payload-based methodology, organizations know these backlog vulnerabilities are verified risks.
Even in the best-performing market, fewer than 1 in 7 open critical/high findings are inside a 90-day window. However, a delayed fix does not always signal inaction; a technically critical vulnerability on a low-sensitivity asset or behind compensating controls may reflect a calculated business decision to deprioritize risk based on internal context.
UK organizations actively monitor 72.4% of their verified internet-facing domains, more than double the rate in the Nordics (31.9%) and US (28.9%). This is where the three markets diverge most sharply.
The US combines the largest measured attack surface with the lowest monitoring coverage. Greater visibility, however, does not automatically translate into faster remediation, as Finding 04 shows.
72.4% vs 28.9% is a 43.5-point spread, the largest gap between any two markets on any signal we measure. At this scale, monitoring isn't a nice-to-have; it's the difference between an assessable surface and an assumed one.
Manufacturing is the only sector to perform relatively well in every market with sufficient data. CPG / Brands rank lowest overall, largely because of the scale of their vulnerability backlogs, not their response speed.
The same industry can face very different hygiene challenges across markets. Tech consistently struggles with asset completeness; public-sector organizations perform particularly poorly on resolution.
The 90-day backlog is a point-in-time view. Resolution rate is the cumulative measure of critical/high findings ever detected: what share has eventually been closed. The two metrics move independently.
Nordic organizations have both the stalest current backlog and the highest cumulative closure rate. UK organizations lead the Index on monitoring but close the fewest of what they find. Visibility and remediation are different capabilities.
Sector data reveals the widest contrast in the Index. CPG / Brands faces the biggest overall hygiene challenge — at 56.2, the lowest sector average measured. Yet it resolves critical and high-severity vulnerabilities at 46.2%, the highest of any sector. Its weakness is the scale of the backlog, not the speed of response.
Public sector shows the opposite pattern. It closes just 8.3% of critical and high-severity findings, less than one-fifth of the CPG rate and well below every other sector measured. In the Nordics and US the picture is starker still: only 4.3% and 2.3% respectively are formally resolved.
Detectify is increasingly identifying publicly exposed instances of self-hosted AI platforms (Open WebUI, LibreChat, Lovable, Base44) across customer estates. Early signs: organizations with exposed AI tooling resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base. These platforms are typically stood up outside the security team's inventory and inherit no monitoring by default.
Among organizations in the sample using Detectify for at least 12 months, verified internet-facing domains grew 20% in the US, 14% in the UK, and 3.4% in the Nordics.
Combined with the 28.9% US monitoring coverage from Finding 02: new exposure is being created faster than existing exposure is being closed.
The full H2 2026 edition includes per signal breakdowns, the sector level appendix, and additional cross-market insights.