Research · September 2026
UK SME External Exposure Snapshot: September 2026
By Nathan Hill-Haimes · Published 23 September 2026 · Data collected 15–23 September 2026
What was scanned?
The cohort is a September 2026 bulk assessment of 1,083 internet-facing assets belonging to UK small and medium-sized enterprises: 778 apex domains and 305 associated IP addresses. The sample is a broad cross-section of UK SMEs rather than a stratified statistical sample -- treat the percentages as a strong signal about the segment, not a census. Scanning was external-only -- the same view an attacker has -- across SurfaceLoop's seven risk categories. No credentials, agents or internal access were involved. Findings below are open findings: externally observable at the time of scanning and not resolved during the collection window.
This report publishes aggregates only. No scanned organisation is named or identifiable; counts below three are suppressed. The full aggregation method is on the methodology page.
How exposed were the domains, by category?
3,760 open findings across the cohort. Percentages are the share of assets with at least one open finding in that category.
| Category | Open findings | % of domains affected | % of IPs affected |
|---|---|---|---|
| DNS/email spoofing risk (missing or weak SPF, DMARC, DKIM) | 855 | 73.9% | n/a |
| Missing HTTP security headers | 1,835 | 85.6% | 41% |
| Exposed web admin panels and CVE-flagged software | 531 | 37.8% | 0% |
| Anomalous TCP symptoms (unexpected services) | 242 | 18.6% | 18.4% |
| Certificate issues (expired, mismatched, self-signed) | 186 | 8.6% | 33.8% |
| Exposed remote admin ports (SSH) | 111 | 11.8% | 6.2% |
Severity mix across all open findings: 111 critical, 717 high, 843 medium, 2,089 low. TLS protocol/cipher checks recorded no findings in this cohort and are excluded from the table -- see the methodology note.
Which security headers were missing most often?
85.6% of domains were missing at least one recommended header. Counts are per affected web endpoint.
| Header | Missing (count) |
|---|---|
| Permissions-Policy | 1,777 |
| Content-Security-Policy | 1,563 |
| Referrer-Policy | 1,486 |
| X-Content-Type-Options | 1,250 |
| X-Frame-Options | 1,231 |
| Strict-Transport-Security | 632 |
Which CVEs appeared most often?
Three of the five most common CVEs are email-related -- the same pattern as the SPF/DKIM/DMARC results. Identifiers link to the National Vulnerability Database.
| CVE | What it is | Severity | Occurrences |
|---|---|---|---|
| CVE-2020-12272 | OpenDMARC authentication-result forgery — lets a sender inject false SPF/DKIM results | Medium | 534 |
| CVE-2016-9963 | Exim DKIM private-key disclosure via bounce messages | Medium | 254 |
| CVE-2020-28037 | WordPress installation-check bypass leading to remote code execution | Critical (9.8) | 174 |
| CVE-2023-48795 | Terrapin — SSH prefix-truncation attack on affected configurations | Medium | 111 |
| CVE-2024-7209 | Email spoofing via shared SPF records at multi-tenant hosts | Medium | 67 |
Download the data
The full aggregate dataset is available under CC BY 4.0 -- cite it as SurfaceLoop UK SME External Exposure Snapshot, September 2026.
uk-sme-exposure-snapshot-2026-09.json uk-sme-exposure-snapshot-2026-09.csv
Frequently asked questions
- What data does this snapshot contain? +
- Aggregate statistics only: counts, percentages and medians from an external scan of 1,083 internet-facing assets of UK small and medium-sized enterprises in September 2026. It contains no hostnames, no IP addresses, and nothing that identifies a scanned organisation. Categorical values with fewer than three occurrences are suppressed.
- How were the findings produced? +
- By SurfaceLoop's standard scanning pipeline: external-only probes across seven risk categories -- open ports, web panels, TLS, certificates, security headers, known CVEs, and DNS/email configuration. The methodology page describes the scanners, deduplication and false-positive handling.
- Why do so many UK SME domains fail on email security? +
- SPF, DKIM and DMARC have to be configured deliberately, and misconfigurations are invisible in day-to-day use -- email still flows. 73.9% of scanned domains carried at least one spoofing-relevant gap, which is consistent with the pattern that three of the five most common CVEs in the dataset are also email-related.
- Does a finding mean an organisation was breached? +
- No. A finding is an externally visible weakness -- something an attacker could see and potentially use, like a missing DMARC record or an exposed admin port. The point of external attack surface management is fixing these before they become incidents.
- Can I reproduce or cite these numbers? +
- Yes. The aggregates are downloadable as JSON and CSV under CC BY 4.0 -- cite 'SurfaceLoop UK SME External Exposure Snapshot, September 2026'. The aggregation method (including the small-cell suppression rule) is described on the methodology page.
Want to see what your own business exposes? SurfaceLoop runs the same seven-category external scan continuously, with plain-English findings and a flat price.