Technical report · 2026-S1
HNDL exposure by sector, 39,903 organizations.
Published under a CC-BY license, with mandatory attribution. Data aggregated under k-anonymity — no individual organization is named.
What this report measures
We consolidate the Quantum Exposure Index (IEQ) for 39,903 organizations, aggregated by sector under k-anonymity (K = 30 — no published group contains fewer than 30 organizations, enough that none can be singled out). No individual entity is named or ranked; results are published only in aggregate.
The dataset is a 2026-S1 snapshot, collected incrementally between March 30 and June 15, 2026, with average signal coverage of 68.6% — heterogeneity that is incorporated into the index's uncertainty.
The central finding
Observed cryptographic vulnerability is high and nearly uniform across sectors (68–71 out of 100): the same three signals dominate in nearly every sector — vulnerable internal systems, the cryptographic algorithm family in use, and vulnerable hardware security modules (HSMs) — each present in ~100% of organizations. Observed fragility is structural, not sector-specific.
What actually separates sectors is Timeline (H) — temporal urgency — which ranges from about 21 to 92. Since vulnerability barely varies, timeline is what mostly explains each sector's relative position in the ranking.
The sector ranking
76.4% of organizations fall in the Critical or High exposure bands. The distribution isn't a smooth gradient — it organizes into three blocks. Tier 1 — Critical, act now: Government/Unclassified (median 85.0), Hospitals & health services (84.8), Pharma & biotech (82.0), Private health insurance (81.3), Materials & chemicals (76.2), Agribusiness (75.9), Industrial manufacturing (75.0), Defense & aerospace (72.8).
Tier 2 — Moderate, plan: Utilities/energy (58.2), Oil, gas & energy (56.8), Traditional finance (55.3), Payment processing (54.7). Tier 3 — Low/Minimal, maintain and monitor: Cloud (39.7), Telecom (38.4), SaaS (30.7), Retail & brands (18.4), E-commerce & marketplace (18.1).
The correct reading is by block, not by exact position: 9 pairs of neighboring sectors have overlapping 90% confidence intervals (CI90), so exact ordering within each block shouldn't be read as resolved.
Ten exposure archetypes
Beyond the per-sector ranking, we applied unsupervised clustering (k-means, k = 10) over the 13 observed technical signals, identifying ten recurring exposure profiles (archetypes A through J) that cut across sector boundaries — no sector maps onto a single archetype as a block. The signals that most differentiate the archetypes are mostly everyday web-security hygiene controls (enforcing secure connections, basic domain protections), not cryptographic fragility itself — reinforcing the central finding: cryptographic fragility is uniformly high; what varies is everyday operational hygiene.
Blast radius: risk from third parties
A sector's own score isn't the whole picture: many organizations depend on a small number of shared providers — cloud platforms, telecom carriers, content-delivery networks (CDNs). A sector can show a low IEQ on the strength of its own observable signals and still be exposed if it leans heavily on a provider, or class of providers, with a weaker cryptographic posture.
Stated limitations
Where public data is sparse, the model assumes the worst case — so scores for little-documented organizations should be read as a plausible ceiling, not a definitive measurement. The dataset is a point-in-time snapshot, not continuous monitoring. No exploit attempts were performed; collection is limited to public-facing signals.