Summary
LeakTrace assessed the public surface of 1,460 Canadian owner-run firms in Q3 2026: email authentication, TLS configuration, exposed administrative interfaces, subdomain sprawl, lookalike domains and keys left in website code. The average external Rating across those 1,460 firms was 93.0 of 100, and 98.4% of them were rated Critical or High.
Separately, the owner or principal email address of 163 of those firms was checked against monitored breach databases; 25.2% of the 163 appeared in at least one breach record.
This report gives the sector and regional breakdowns, the method, and the mitigation steps that apply across sectors. Every firm in the population was assessed from outside, before any engagement, using public data only.
Findings at a glance
External exposure
How the 1,460 firms assessed fall across the four severity bands, from outside checks of email authentication, TLS configuration, exposed administrative interfaces, subdomain sprawl and software versions.
| Severity band | Share of 1,460 | |
|---|---|---|
| Critical | 84.9% | |
| High | 13.5% | |
| Moderate | 1.1% | |
| Low | 0.4% |
Credential exposure
Bands for the 163 firms whose owner address was checked against monitored breach databases. Passwords and financial data weigh more than personal identifiers, which weigh more than usernames alone.
| Band | Share of 163 | |
|---|---|---|
| Severe | 11.7% (19) | |
| Moderate | 13.5% (22) | |
| Minor | 0% (0) | |
| None identified | 74.8% (122) |
How firms were exposed
Share of the 1,460 firms assessed where each condition was found, most common first.
| Condition | Share of 1,460 |
|---|---|
| Infrastructure misconfigurationsDNS, TLS/SSL, DMARC, SPF, or DKIM configurations flagged as high-risk during external scanning. | 98.8% |
| Registered typosquat domainsLook-alike domain variants already registered by third parties, brand impersonation and BEC infrastructure. | 65.8% |
| JavaScript secret exposureAPI keys, tokens, or credentials embedded in front-end JavaScript bundles reachable from the homepage. | 63.3% |
| Vulnerable JavaScript librariesFront-end libraries with known CVEs loaded on production pages, direct client-side outside exposure. | 25.9% |
| WordPress user enumerationWordPress installations leaking usernames through unauthenticated REST endpoints, enables targeted credential-stuffing. | 23.6% |
| Exposed configuration endpointsPublicly-accessible admin panels, config files, or unprotected API endpoints identified via non-invasive probing. | 11.1% |
| Sensitive open portsInternet-facing ports exposing services with known CVEs or authentication concerns, per public internet indexes. | 5.8% |
| Cloud storage exposurePublicly-listable S3/GCS/Azure buckets associated with the domain, data exfiltration risk. | 5.5% |
By sector
“Firms” is the number assessed in each sector as stored; the Rating runs from 0 to 100, and a lower rating is better. Owner-credential rates are not broken out by sector because the counts are too small to publish.
| Sector | Firms | Rating | Critical or High |
|---|---|---|---|
| Financial Services | 574 | 96.9 | 100.0% |
| Legal | 554 | 100.0 | 100.0% |
| Dental | 176 | 93.2 | 98.3% |
| Construction | 62 | 91.7 | 100.0% |
| Manufacturing | 33 | 95.5 | 100.0% |
| Other | 23 | 93.1 | 100.0% |
| Healthcare | 19 | 98.6 | 100.0% |
| Accounting | 19 | 93.2 | 100.0% |
By province
“Firms” is the number assessed there. Differences reflect the mix of firms as much as their upkeep.
| Province | Firms | Rating | Critical or High |
|---|---|---|---|
| Ontario | 1033 | 92.8 | 98.4% |
| Manitoba | 312 | 91.2 | 94.3% |
| British Columbia | 94 | 94.1 | 100.0% |
| Alberta | 80 | 93.3 | 98.7% |
| Quebec | 48 | 95.0 | 100.0% |
| Nova Scotia | 20 | 92.8 | 100.0% |
| Saskatchewan | 7 | 100.0 | 100.0% |
Recommended mitigations
For Canadian owner-run firms in this monitoring population:
- ImmediateOutside exposure remediation
With an average external threat surface risk score of 93.0/100 and 98.4% of businesses classified as Critical or High risk, outside exposure reduction is the highest-leverage single investment. Priorities: enable DMARC enforcement, remediate SSL/TLS misconfigurations, retire exposed administrative interfaces, and review subdomain sprawl.
- ImmediateForce password rotation for owner/executive accounts
With 14.1% of businesses in our monitoring showing password-class breach exposure, credential stuffing attacks are a realistic near-term threat. Rotating passwords + enabling MFA closes this vector immediately.
- Near-term (30 days)Deploy business email compromise (BEC) monitoring
Owner email addresses in breach databases enable BEC / whaling attacks where attackers pose as the executive. Monitoring for spoofed sender activity + implementing DMARC enforcement mitigates this.
- Near-term (30 days)Employee awareness training
With 3.1% of businesses showing financial-data exposure and the elevated infrastructure risk profile, staff awareness training is the highest-leverage human-factor investment. Focus on recognizing phishing, verifying wire requests, and reporting suspicious contact.
- QuarterlyRepeat the exposure check
Breach databases update daily and infrastructure changes affect risk scores. Quarterly re-checking is standard threat intelligence hygiene.
- StrategicCyber insurance review
With the combined infrastructure + credential exposure profile observed across the Canadian owner-run firm landscape, cyber insurance policies should be reviewed for adequate coverage. Current premiums assume active mitigation programs; documented mitigation reduces premiums.
Visibility
LeakTrace maintains an ongoing threat intelligence pipeline monitoring Canadian owner-run firms across sectors including healthcare, legal, financial services, dental, and professional services. Our monitoring combines public data sources with proprietary discovery workflows and covers firms assessed before any engagement.
Coverage dimensions
- Infrastructure, outside exposure checks covering DNS security posture, TLS/SSL configuration, exposed administrative interfaces, subdomain sprawl, and vulnerable framework detection.
- Credential exposure, matching owner and executive email addresses against monitored breach databases and data-class exposure classification.
- Public web exposure, open-source intelligence aggregation covering code repository leaks, paste site mentions, and publicly-indexed disclosure activity.
Sources
- Monitored breach databases
- Supplementary monitored breach databases
- Open-source intelligence aggregation of publicly-indexed web content
- Publicly-available corporate registry data and business directories
- outside exposure checks across DNS, TLS, subdomain, and framework layers
Methodology
For each business in our monitoring pipeline, we run parallel exposure checks across the coverage dimensions above. Infrastructure risk scores are computed on a 0-100 scale where higher indicates greater exposure surface. Credential exposure scores are classified by data class weight (passwords + financial > PII > usernames only). Severity bands are harmonized across dimensions.
Limitations
- Public data only, no dark web or non-licensed sources
- Credential coverage limited to owners/executives whose emails are publicly discoverable
- Infrastructure reading is non-invasive, passive external observation only
- Severity indicates exposure surface, not active threat targeting
No firm is named. Every firm was assessed from outside, before any engagement, from public data only.
The outside watch for your firm: see what is open before anyone else does, with the proof for the lead finding. Check my firm →