Technical report · 2026-S1
HNDL exposure by sector, 39,903 organizations.
Published under a CC-BY license, with mandatory attribution. Data aggregated under k-anonymity: no individual organization is named.
What this report measures
We consolidate the Quantum Exposure Index (IEQ) for 39,903 organizations, aggregated by sector under k-anonymity (K = 30: no published group contains fewer than 30 organizations, enough that none can be singled out). No individual entity is named or ranked; results are published only in aggregate.
The dataset is a 2026-S1 snapshot, collected incrementally between March 30 and June 15, 2026, with average signal coverage of 68.6%. That heterogeneity is incorporated into the index's uncertainty.
The central finding
Observed cryptographic vulnerability is high and nearly uniform across sectors (68–71 out of 100): the same three signals dominate in nearly every sector: vulnerable internal systems, the cryptographic algorithm family in use, and vulnerable hardware security modules (HSMs), each present in ~100% of organizations. Observed fragility is structural, not sector-specific.
What actually separates sectors is Timeline (H), temporal urgency, which ranges from about 21 to 92. Since vulnerability barely varies, timeline is what mostly explains each sector's relative position in the ranking.
The sector ranking
76.4% of organizations fall in the Critical or High exposure bands. The distribution isn't a smooth gradient: it organizes into three blocks. Tier 1 (Critical), act now: Government/Unclassified (median 85.0), Hospitals & health services (84.8), Pharma & biotech (82.0), Private health insurance (81.3), Materials & chemicals (76.2), Agribusiness (75.9), Industrial manufacturing (75.0), Defense & aerospace (72.8).
Tier 2 (Moderate), plan: Utilities/energy (58.2), Oil, gas & energy (56.8), Traditional finance (55.3), Payment processing (54.7). Tier 3 (Low/Minimal), maintain and monitor: Cloud (39.7), Telecom (38.4), SaaS (30.7), Retail & brands (18.4), E-commerce & marketplace (18.1).
The correct reading is by block, not by exact position: 9 pairs of neighboring sectors have overlapping 90% confidence intervals (CI90), so exact ordering within each block shouldn't be read as resolved.
Ten exposure archetypes
Beyond the per-sector ranking, we applied unsupervised clustering (k-means, k = 10) over the 13 observed technical signals, identifying ten recurring exposure profiles (archetypes A through J) that cut across sector boundaries. No sector maps onto a single archetype as a block. The signals that most differentiate the archetypes are mostly everyday web-security hygiene controls (enforcing secure connections, basic domain protections), and not cryptographic fragility itself, which reinforces the central finding: cryptographic fragility is uniformly high; what varies is everyday operational hygiene.
Blast radius: risk from third parties
A sector's own score isn't the whole picture: many organizations depend on a small number of shared providers: cloud platforms, telecom carriers and content-delivery networks (CDNs). A sector can show a low IEQ on the strength of its own observable signals and still be exposed if it leans heavily on a provider, or class of providers, with a weaker cryptographic posture.
Stated limitations
Where public data is sparse, the model assumes the worst case. Scores for little-documented organizations should therefore be read as a plausible ceiling, and not as a definitive measurement. The dataset is a point-in-time snapshot, not continuous monitoring. No exploit attempts were performed; collection is limited to public-facing signals.