Threat intelligence · Report LT-Q3-2026-US-001

State of American Owner-Run Firm Cybersecurity, Q3 2026

What 2,305 outside assessments of American owner-run firms found about email, domains, exposed services and staff credentials.

Report LT-Q3-2026-US-001Region United StatesPeriod April to July 2026Published 8 Jul 2026By LeakTrace Intelligence Desk
The period in figures

What the assessments found.

2,305
American owner-run firms assessed from outside, before any engagement
95.1
Average external Rating, of 100. A lower rating is better.
96.8%
Rated Critical or High

Source: LeakTrace assessments, of 2,305 firms assessed, April to July 2026.

Summary

LeakTrace assessed the public surface of 2,305 American owner-run firms from April to July 2026: email authentication, TLS configuration, exposed administrative interfaces, subdomain sprawl, lookalike domains and keys left in website code. The average external Rating across those 2,305 firms was 95.1 of 100, and 96.8% of them were rated Critical or High.

Owner-credential exposure was measured for 3 firms in this population, too few to publish a rate.

This report gives the sector and regional breakdowns, the method, and the mitigation steps that apply across sectors. Every firm in the population was assessed from outside, before any engagement, using public data only.

Findings at a glance

100.0%
Infrastructure misconfigurations
Source: LeakTrace assessments, of 2,305 firms assessed, April to July 2026
73.0%
JavaScript secret exposure
Source: LeakTrace assessments, of 2,305 firms assessed, April to July 2026
60.3%
Registered typosquat domains
Source: LeakTrace assessments, of 2,305 firms assessed, April to July 2026

Owner-credential exposure was measured for 3 firms in this population, too few to publish a rate.

External exposure

How the 2,305 firms assessed fall across the four severity bands, from outside checks of email authentication, TLS configuration, exposed administrative interfaces, subdomain sprawl and software versions.

Severity bandShare of 2,305
Critical
93.7%
High
3.2%
Moderate
3.2%
Low
0%

How firms were exposed

Share of the 2,305 firms assessed where each condition was found, most common first.

ConditionShare of 2,305
Infrastructure misconfigurationsDNS, TLS/SSL, DMARC, SPF, or DKIM configurations flagged as high-risk during external scanning.100.0%
JavaScript secret exposureAPI keys, tokens, or credentials embedded in front-end JavaScript bundles reachable from the homepage.73.0%
Registered typosquat domainsLook-alike domain variants already registered by third parties, brand impersonation and BEC infrastructure.60.3%
WordPress user enumerationWordPress installations leaking usernames through unauthenticated REST endpoints, enables targeted credential-stuffing.41.3%
Exposed configuration endpointsPublicly-accessible admin panels, config files, or unprotected API endpoints identified via non-invasive probing.25.4%
Sensitive open portsInternet-facing ports exposing services with known CVEs or authentication concerns, per public internet indexes.20.6%
Vulnerable JavaScript librariesFront-end libraries with known CVEs loaded on production pages, direct client-side outside exposure.15.9%
Cloud storage exposurePublicly-listable S3/GCS/Azure buckets associated with the domain, data exfiltration risk.15.9%

By sector

“Firms” is the number assessed in each sector as stored; the Rating runs from 0 to 100, and a lower rating is better. Owner-credential rates are not broken out by sector because the counts are too small to publish.

SectorFirmsRatingCritical or High
Healthcare195796.095.2%
Legal27994.3100.0%
Dental2996.2100.0%
Other2395.295.7%
Law1791.294.1%

By state

“Firms” is the number assessed there. Differences reflect the mix of firms as much as their upkeep.

StateFirmsRatingCritical or High
Texas141194.095.5%
Illinois57590.792.9%
Washington279100.0100.0%
New York2099.1100.0%
Pennsylvania898.1100.0%
California5100.0100.0%

Recommended mitigations

For American owner-run firms in this monitoring population:

  1. Immediate
    Outside exposure remediation

    With an average external threat surface risk score of 95.1/100 and 96.8% of businesses classified as Critical or High risk, outside exposure reduction is the highest-leverage single investment. Priorities: enable DMARC enforcement, remediate SSL/TLS misconfigurations, retire exposed administrative interfaces, and review subdomain sprawl.

  2. Immediate
    Force password rotation for owner/executive accounts

    Owner and executive credentials appearing in known breach databases enable credential stuffing attacks as a realistic near-term threat. Rotating passwords + enabling MFA closes this vector immediately.

  3. Near-term (30 days)
    Deploy business email compromise (BEC) monitoring

    Owner email addresses in breach databases enable BEC / whaling attacks where attackers pose as the executive. Monitoring for spoofed sender activity + implementing DMARC enforcement mitigates this.

  4. Near-term (30 days)
    Employee awareness training

    Given the elevated infrastructure risk profile observed across the American owner-run firm landscape, staff awareness training is the highest-leverage human-factor investment. Focus on recognizing phishing, verifying wire requests, and reporting suspicious contact.

  5. Quarterly
    Repeat the exposure check

    Breach databases update daily and infrastructure changes affect risk scores. Quarterly re-checking is standard threat intelligence hygiene.

  6. Strategic
    Cyber insurance review

    With the elevated infrastructure exposure profile observed across the American owner-run firm landscape, cyber insurance policies should be reviewed for adequate coverage. Current premiums assume active mitigation programs; documented mitigation reduces premiums.

Sources and method

Visibility

LeakTrace maintains an ongoing threat intelligence pipeline monitoring American owner-run firms across sectors including healthcare, legal, financial services, and professional services. Our monitoring combines public data sources with proprietary discovery workflows and covers firms assessed before any engagement.

Coverage dimensions

  • Infrastructure, outside exposure checks covering DNS security posture, TLS/SSL configuration, exposed administrative interfaces, subdomain sprawl, and vulnerable framework detection.
  • Credential exposure, matching owner and executive email addresses against monitored breach databases and data-class exposure classification.
  • Public web exposure, open-source intelligence aggregation covering code repository leaks, paste site mentions, and publicly-indexed disclosure activity.

Sources

  • Monitored breach databases
  • Supplementary monitored breach databases
  • Open-source intelligence aggregation of publicly-indexed web content
  • Publicly-available corporate registry data and business directories
  • outside exposure checks across DNS, TLS, subdomain, and framework layers

Methodology

For each business in our monitoring pipeline, we run parallel exposure checks across the coverage dimensions above. Infrastructure risk scores are computed on a 0-100 scale where higher indicates greater exposure surface. Severity bands are harmonized across dimensions.

Limitations

  • Public data only, no dark web or non-licensed sources
  • Infrastructure reading is non-invasive, passive external observation only
  • Severity indicates exposure surface, not active threat targeting

No firm is named. Every firm was assessed from outside, before any engagement, from public data only.

Share on LinkedIn

The outside watch for your firm: see what is open before anyone else does, with the proof for the lead finding. Check my firm →