Research · September 2026

UK SME External Exposure Snapshot: September 2026

By Nathan Hill-Haimes · Published 23 September 2026 · Data collected 15–23 September 2026

What was scanned?

The cohort is a September 2026 bulk assessment of 1,083 internet-facing assets belonging to UK small and medium-sized enterprises: 778 apex domains and 305 associated IP addresses. The sample is a broad cross-section of UK SMEs rather than a stratified statistical sample -- treat the percentages as a strong signal about the segment, not a census. Scanning was external-only -- the same view an attacker has -- across SurfaceLoop's seven risk categories. No credentials, agents or internal access were involved. Findings below are open findings: externally observable at the time of scanning and not resolved during the collection window.

This report publishes aggregates only. No scanned organisation is named or identifiable; counts below three are suppressed. The full aggregation method is on the methodology page.

How exposed were the domains, by category?

3,760 open findings across the cohort. Percentages are the share of assets with at least one open finding in that category.

Category Open findings % of domains affected % of IPs affected
DNS/email spoofing risk (missing or weak SPF, DMARC, DKIM) 855 73.9% n/a
Missing HTTP security headers 1,835 85.6% 41%
Exposed web admin panels and CVE-flagged software 531 37.8% 0%
Anomalous TCP symptoms (unexpected services) 242 18.6% 18.4%
Certificate issues (expired, mismatched, self-signed) 186 8.6% 33.8%
Exposed remote admin ports (SSH) 111 11.8% 6.2%

Severity mix across all open findings: 111 critical, 717 high, 843 medium, 2,089 low. TLS protocol/cipher checks recorded no findings in this cohort and are excluded from the table -- see the methodology note.

Which security headers were missing most often?

85.6% of domains were missing at least one recommended header. Counts are per affected web endpoint.

Header Missing (count)
Permissions-Policy 1,777
Content-Security-Policy 1,563
Referrer-Policy 1,486
X-Content-Type-Options 1,250
X-Frame-Options 1,231
Strict-Transport-Security 632

Which CVEs appeared most often?

Three of the five most common CVEs are email-related -- the same pattern as the SPF/DKIM/DMARC results. Identifiers link to the National Vulnerability Database.

CVE What it is Severity Occurrences
CVE-2020-12272 OpenDMARC authentication-result forgery — lets a sender inject false SPF/DKIM results Medium 534
CVE-2016-9963 Exim DKIM private-key disclosure via bounce messages Medium 254
CVE-2020-28037 WordPress installation-check bypass leading to remote code execution Critical (9.8) 174
CVE-2023-48795 Terrapin — SSH prefix-truncation attack on affected configurations Medium 111
CVE-2024-7209 Email spoofing via shared SPF records at multi-tenant hosts Medium 67

Download the data

The full aggregate dataset is available under CC BY 4.0 -- cite it as SurfaceLoop UK SME External Exposure Snapshot, September 2026.

uk-sme-exposure-snapshot-2026-09.json uk-sme-exposure-snapshot-2026-09.csv

Frequently asked questions

What data does this snapshot contain?
+
Aggregate statistics only: counts, percentages and medians from an external scan of 1,083 internet-facing assets of UK small and medium-sized enterprises in September 2026. It contains no hostnames, no IP addresses, and nothing that identifies a scanned organisation. Categorical values with fewer than three occurrences are suppressed.
How were the findings produced?
+
By SurfaceLoop's standard scanning pipeline: external-only probes across seven risk categories -- open ports, web panels, TLS, certificates, security headers, known CVEs, and DNS/email configuration. The methodology page describes the scanners, deduplication and false-positive handling.
Why do so many UK SME domains fail on email security?
+
SPF, DKIM and DMARC have to be configured deliberately, and misconfigurations are invisible in day-to-day use -- email still flows. 73.9% of scanned domains carried at least one spoofing-relevant gap, which is consistent with the pattern that three of the five most common CVEs in the dataset are also email-related.
Does a finding mean an organisation was breached?
+
No. A finding is an externally visible weakness -- something an attacker could see and potentially use, like a missing DMARC record or an exposed admin port. The point of external attack surface management is fixing these before they become incidents.
Can I reproduce or cite these numbers?
+
Yes. The aggregates are downloadable as JSON and CSV under CC BY 4.0 -- cite 'SurfaceLoop UK SME External Exposure Snapshot, September 2026'. The aggregation method (including the small-cell suppression rule) is described on the methodology page.

Want to see what your own business exposes? SurfaceLoop runs the same seven-category external scan continuously, with plain-English findings and a flat price.

Start a free 14-day trial Book a demo