HNDL exposure by sector, 39,903 organizations.

Published under a CC-BY license, with mandatory attribution. Data aggregated under k-anonymity — no individual organization is named.

What this report measures

We consolidate the Quantum Exposure Index (IEQ) for 39,903 organizations, aggregated by sector under k-anonymity (K = 30 — no published group contains fewer than 30 organizations, enough that none can be singled out). No individual entity is named or ranked; results are published only in aggregate.

The dataset is a 2026-S1 snapshot, collected incrementally between March 30 and June 15, 2026, with average signal coverage of 68.6% — heterogeneity that is incorporated into the index's uncertainty.

The central finding

Observed cryptographic vulnerability is high and nearly uniform across sectors (68–71 out of 100): the same three signals dominate in nearly every sector — vulnerable internal systems, the cryptographic algorithm family in use, and vulnerable hardware security modules (HSMs) — each present in ~100% of organizations. Observed fragility is structural, not sector-specific.

What actually separates sectors is Timeline (H) — temporal urgency — which ranges from about 21 to 92. Since vulnerability barely varies, timeline is what mostly explains each sector's relative position in the ranking.

The sector ranking

76.4% of organizations fall in the Critical or High exposure bands. The distribution isn't a smooth gradient — it organizes into three blocks. Tier 1 — Critical, act now: Government/Unclassified (median 85.0), Hospitals & health services (84.8), Pharma & biotech (82.0), Private health insurance (81.3), Materials & chemicals (76.2), Agribusiness (75.9), Industrial manufacturing (75.0), Defense & aerospace (72.8).

Tier 2 — Moderate, plan: Utilities/energy (58.2), Oil, gas & energy (56.8), Traditional finance (55.3), Payment processing (54.7). Tier 3 — Low/Minimal, maintain and monitor: Cloud (39.7), Telecom (38.4), SaaS (30.7), Retail & brands (18.4), E-commerce & marketplace (18.1).

The correct reading is by block, not by exact position: 9 pairs of neighboring sectors have overlapping 90% confidence intervals (CI90), so exact ordering within each block shouldn't be read as resolved.

Ten exposure archetypes

Beyond the per-sector ranking, we applied unsupervised clustering (k-means, k = 10) over the 13 observed technical signals, identifying ten recurring exposure profiles (archetypes A through J) that cut across sector boundaries — no sector maps onto a single archetype as a block. The signals that most differentiate the archetypes are mostly everyday web-security hygiene controls (enforcing secure connections, basic domain protections), not cryptographic fragility itself — reinforcing the central finding: cryptographic fragility is uniformly high; what varies is everyday operational hygiene.

Blast radius: risk from third parties

A sector's own score isn't the whole picture: many organizations depend on a small number of shared providers — cloud platforms, telecom carriers, content-delivery networks (CDNs). A sector can show a low IEQ on the strength of its own observable signals and still be exposed if it leans heavily on a provider, or class of providers, with a weaker cryptographic posture.

Stated limitations

Where public data is sparse, the model assumes the worst case — so scores for little-documented organizations should be read as a plausible ceiling, not a definitive measurement. The dataset is a point-in-time snapshot, not continuous monitoring. No exploit attempts were performed; collection is limited to public-facing signals.