Detectify

H2 2026

A biannual read on external attack surface exposure across 1,293 organizations in the US, UK, and Nordics. The Index measures the condition of internet-facing exposure before an incident occurs. Five signals separate teams closing risk from teams letting it age.

Security teams are finding risk faster than ever, but unresolved backlogs and expanding attack surfaces are creating a widening exposure gap.

Key findings
01
Critical vulnerabilities

Old exposures dominate the backlog.

The clearest finding across all three markets: the overwhelming majority of open critical and high-severity vulnerabilities have been sitting exposed for more than 90 days. Because these specific assessments test real-world exploitability through 100% payload-based methodology, organizations know these backlog vulnerabilities are verified risks.

Even in the best-performing market, fewer than 1 in 7 open critical/high findings are inside a 90-day window. However, a delayed fix does not always signal inaction; a technically critical vulnerability on a low-sensitivity asset or behind compensating controls may reflect a calculated business decision to deprioritize risk based on internal context.

Open critical or high vulns exposed over 90 days
peak of the backlog
Nordics
0%
United Kingdom
0%
United States
0%
02
Attack surface monitoring

The gap between what's known and what's watched.

UK organizations actively monitor 72.4% of their verified internet-facing domains, more than double the rate in the Nordics (31.9%) and US (28.9%). This is where the three markets diverge most sharply.

The US combines the largest measured attack surface with the lowest monitoring coverage. Greater visibility, however, does not automatically translate into faster remediation, as Finding 04 shows.

Monitored share of verified external assets
Snapshot: September 2026
United Kingdom
0%
Nordics
0%
United States
0%
Verified surface Actively monitored
+0pp
Signal spread

UK vs US monitoring gap is the widest single signal in the Index

72.4% vs 28.9% is a 43.5-point spread, the largest gap between any two markets on any signal we measure. At this scale, monitoring isn't a nice-to-have; it's the difference between an assessable surface and an assumed one.

03
Sector rankings

Sector shapes outcomes more than geography.

Manufacturing is the only sector to perform relatively well in every market with sufficient data. CPG / Brands rank lowest overall, largely because of the scale of their vulnerability backlogs, not their response speed.

The same industry can face very different hygiene challenges across markets. Tech consistently struggles with asset completeness; public-sector organizations perform particularly poorly on resolution.

Cyber Hygiene score by sector · cross market
Nordics
UK
US
Average
Manufacturing
60.6
Insufficient data
62.7
61.7
Tech
59.2
59.1
58.2
58.8
Financial & Banking
57.6
61.2
57.3
58.7
Public Sector
56.9
58.7
58.2
57.9
CPG / Brands
54.2
59.3
55.2
56.2
04
Resolution rates

A different, complementary lens on vulnerabilities.

The 90-day backlog is a point-in-time view. Resolution rate is the cumulative measure of critical/high findings ever detected: what share has eventually been closed. The two metrics move independently.

Nordic organizations have both the stalest current backlog and the highest cumulative closure rate. UK organizations lead the Index on monitoring but close the fewest of what they find. Visibility and remediation are different capabilities.

Critical or high vulnerability resolution rate · by market
Cumulative: open + resolved, lifetime of the account
Nordics
0%
United States
0%
United Kingdom
0%

Sector data reveals the widest contrast in the Index. CPG / Brands faces the biggest overall hygiene challenge — at 56.2, the lowest sector average measured. Yet it resolves critical and high-severity vulnerabilities at 46.2%, the highest of any sector. Its weakness is the scale of the backlog, not the speed of response.

Public sector shows the opposite pattern. It closes just 8.3% of critical and high-severity findings, less than one-fifth of the CPG rate and well below every other sector measured. In the Nordics and US the picture is starker still: only 4.3% and 2.3% respectively are formally resolved.

Critical or high vulnerability resolution rate · by sector
CPG / Brands
0%
Tech
0%
Financial & Banking
0%
Manufacturing
0%
Public Sector
0%
Measured in a 90 day window from first detection
<0%
Early sign

AI exposure points to remediation bottlenecks.

Detectify is increasingly identifying publicly exposed instances of self-hosted AI platforms (Open WebUI, LibreChat, Lovable, Base44) across customer estates. Early signs: organizations with exposed AI tooling resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base. These platforms are typically stood up outside the security team's inventory and inherit no monitoring by default.

05
Exposure trends

The attack surface keeps growing faster than coverage.

Among organizations in the sample using Detectify for at least 12 months, verified internet-facing domains grew 20% in the US, 14% in the UK, and 3.4% in the Nordics.

Combined with the 28.9% US monitoring coverage from Finding 02: new exposure is being created faster than existing exposure is being closed.

Surface growth · Sep 2025 → Sep 2026
Net verified assets per market
United States
+0%
United Kingdom
+0%
Nordics
+0%

See where your sector sits on the Index

The full H2 2026 edition includes per signal breakdowns, the sector level appendix, and additional cross-market insights.