Skip to main content
Updated 16 August 2026

The UK SMB Security Benchmark

Aggregated insights from 613 anonymous Mode 1 scans across 16 UK sectors. All figures are cohort-derived; no individual sites are identified.

Headline findings

Sector cohorts

Median score, cohort size, and top three issues per UK sector. Click a sector to deep-dive.

General / uncategorised
n=160
61/100
median score
p25 57 · p75 67
  • criticalHomepage unreachable48%
  • criticalNo TLS certificate21%
  • criticalNo modern TLS protocol supported21%
E-commerce
n=91
72/100
median score
p25 65 · p75 77
  • criticalHomepage unreachable4%
  • criticalNo TLS certificate2%
  • criticalnext@unknown — CVE-2025-29927 (CVSS 9.1)2%
Financial services
n=68
75/100
median score
p25 71 · p75 79
  • criticalnext@unknown — CVE-2025-29927 (CVSS 9.1)1%
  • criticalNo modern TLS protocol supported1%
  • criticalCVE-2024-45440: 87.5% exploitation probability1%
Healthcare
n=60
74/100
median score
p25 70 · p75 78
  • criticallodash@unknown — CVE-2019-10744 (CVSS 9.1)8%
  • criticalHomepage unreachable5%
  • criticalCVE-2024-45440: 87.5% exploitation probability3%
Media & Publishing
n=54
73/100
median score
p25 68 · p75 75
  • criticalPossible Generic API Key in rendered page19%
  • criticalHomepage unreachable4%
  • criticalnext@unknown — CVE-2025-29927 (CVSS 9.1)4%
Legal
n=51
73/100
median score
p25 68 · p75 77
  • criticalhandlebars@4.0.11 — CVE-2021-23369 (CVSS 9.8)8%
  • criticalPublic bucket listing: azure-blob — feaasstatic/packages6%
  • criticalNo modern TLS protocol supported4%
SaaS / Technology
n=42
77/100
median score
p25 71 · p75 78
  • criticalnext@unknown — CVE-2025-29927 (CVSS 9.1)10%
  • criticalPossible Generic API Key in rendered page2%
  • criticalCVE-2024-45440: 87.5% exploitation probability2%
Manufacturing
n=30
71/100
median score
p25 66 · p75 77
  • criticalNo modern TLS protocol supported7%
  • criticalHomepage unreachable3%
  • criticalNo TLS certificate3%
charity-non-profit
n=16
74/100
median score
p25 68 · p75 76
  • criticalHomepage unreachable6%
  • criticalCVE-2024-45440: 87.5% exploitation probability6%
  • criticalNo modern TLS protocol supported6%
public-sector
n=15
69/100
median score
p25 66 · p75 70
  • criticalOpenAI API key exposed in page source20%
  • highDoes not meet bulk-sender email requirements100%
  • highMissing HSTS header67%
education
n=10
71/100
median score
p25 68 · p75 75
  • criticalPossible Generic API Key in rendered page20%
  • criticallodash@unknown — CVE-2019-10744 (CVSS 9.1)10%
  • criticalHomepage unreachable10%
retail
n=7
59/100
median score
p25 59 · p75 63
  • criticalHomepage unreachable57%
  • highContent Security Policy missing100%
  • highMissing HSTS header100%
hospitality
n=3
68/100
median score
p25 67 · p75 68
  • highMissing HSTS header100%
  • highDoes not meet bulk-sender email requirements100%
  • highContent Security Policy missing67%
technology
n=3
64/100
median score
p25 54 · p75 64
  • criticalNo modern TLS protocol supported67%
  • criticalHomepage unreachable33%
  • highDoes not meet bulk-sender email requirements100%
media
n=2
59/100
median score
p25 59 · p75 59
  • criticalHomepage unreachable100%
  • highMissing HSTS header100%
  • highContent Security Policy missing100%
real-estate
n=1
75/100
median score
p25 75 · p75 75
  • highUK GDPR: 4 UK GDPR gaps detected — Article 32 requires "appropriate technical measures"100%
  • highContent Security Policy missing100%
  • highDoes not meet bulk-sender email requirements100%

Deep-dive: technology

Top 10 most-prevalent issues in this cohort. Bars show the percentage of cohort sites affected.

← Clear filter
Score distribution
  • 0-39 (poor)0 · 0%
  • 40-59 (weak)1 · 33%
  • 60-79 (fair)2 · 67%
  • 80-100 (strong)0 · 0%
Top issues — 10 of cohort n=3
  • critical
    No modern TLS protocol supported
    67%(2/3)
    tls-protocol-no-modern
  • critical
    Homepage unreachable
    33%(1/3)
    homepage-unreachable
  • high
    Does not meet bulk-sender email requirements
    100%(3/3)
    email-auth-bulk-sender-noncompliant
  • high
    Missing HSTS header
    67%(2/3)
    http-missing-hsts
  • high
    UK GDPR: 4 UK GDPR gaps detected — Article 32 requires "appropriate technical measures"
    67%(2/3)
    regime-uk-gdpr-gap
  • high
    Content Security Policy missing
    67%(2/3)
    csp-missing
  • high
    CSP allows 'unsafe-inline' in script-src
    33%(1/3)
    csp-unsafe-inline-script
  • high
    Check Point Gaia firewall admin exposed on public internet
    33%(1/3)
    enterprise-edge-device-exposed
  • high
    Homepage returned HTTP 429
    33%(1/3)
    homepage-error-status
  • medium
    No HTTP/2 or HTTP/3 advertised — likely HTTP/1.1 only
    100%(3/3)
    transport-h1-only-no-altsvc

Methodology

  • Scope: SiteIntel Mode 1 (Public Passive) — 46 checks across DNS, TLS, headers, supply-chain, breach exposure, threat intel.
  • Corpus: Public UK sites from FCA register, IMRG Top 500, ABPI member list, The Lawyer 200, Make UK members, Press Gazette top 50. Anonymised at ingest (domain hashed, no identifying metadata persisted).
  • Score: Composite 0-100; weighted across security, performance, SEO, accessibility, tech-debt.
  • Composite signals: Pairs of finding codes with ≥5% co-occurrence and ≥1.5× score-drop lift versus sector baseline.
  • Cohort floor: Sectors with <5 scans are excluded from percentile reporting (too thin to be stable).
  • Refresh: Cached 1 hour. PDF report regenerated on demand.