
Shadow IT Security and why visibility beats another approval process
A staging site is meant to last a week, but six months later, it still resolves on a company subdomain, runs an old framework, and …
Detectify

The Detectify Cyber Hygiene Index Report H2 2026 measures something most reports ignore: not what happened after an attack, but what’s exposed right now, before one occurs. We analyzed anonymized data from a sample of +1290 organizations across the US, UK, and Nordics to understand how effectively they’re finding, monitoring, and closing vulnerabilities across their external attack surfaces.
The findings reveal a pattern: 97% of open critical and high-severity vulnerabilities in the Nordics have remained exposed for over 90 days. In the UK, that’s 92%. Even in the best-performing market, the US, it’s 86%. Our findings point towards stalling remediation rather than failing detection.
The UK monitors 72% of its verified attack surface (more than double the rate in the US and Nordics). That’s strong visibility. Yet the UK has the lowest vulnerability resolution rate of the three markets. The contrast is revealing: organizations can be excellent at finding exposure and terrible at closing it. These are separate skills, and most teams are unbalanced.
The US has the opposite problem. We measured the largest attack surface in the Index, yet only 29% of it is actively monitored. Worse, that attack surface grew 20% in a single year. Organizations are spinning up infrastructure faster than they can see it, let alone secure it.
Consumer brands carry the heaviest vulnerability backlogs of any sector, yet they resolve critical and high-severity findings at 46.2%, the fastest rate in the Index. Public-sector organizations resolve just 8.3%. The lesson: the size of your backlog tells you nothing about how fast you’ll fix your worst problems. One sector is drowning but moving. The other isn’t.
Manufacturing is the only sector to perform well across every market with sufficient data. Tech companies struggle with asset completeness. Financial institutions vary sharply by geography. The index shows that cyber hygiene isn’t a single problem to solve, it’s the ability to connect visibility, prioritization, and remediation across an attack surface that won’t stop changing.
We’re seeing an emerging threat: publicly exposed self-hosted AI platforms and AI-built applications scattered across production networks. Early signs point that organizations with exposed AI tooling resolve critical and high-severity vulnerabilities at less than half the rate of the broader customer base. It’s not clear whether this is a staffing problem, a prioritization problem, or AI projects just landing in security-blind spots. Either way, it’s a compounding risk as AI adoption accelerates.
Nine in ten critical and high-severity vulnerabilities currently exposed have been sitting there for more than 90 days, which points to an execution problem, it being ownership, remediation resourcing, or risk tolerance that drifts until unaddressed vulnerabilities become accepted defaults.
Because these specific assessments test real-world exploitability through 100% payload-based methodology, organizations know these backlog vulnerabilities are verified risks. However, a delayed fix does not always signal inaction; a technically critical vulnerability on a low-sensitivity asset or behind compensating controls may reflect a calculated business decision to deprioritize risk based on internal context.
The data suggests that the harder test of cyber hygiene increasingly comes after discovery. Finding exposure is necessary, but closing it is harder.
Read and download the report here to discover sector breakdowns, cross-market findings, and many other insights.

A staging site is meant to last a week, but six months later, it still resolves on a company subdomain, runs an old framework, and …

In the world of application security, vulnerabilities are always a moving target. As modern applications keep becoming increasingly API-driven, cloud-native, and dependent on third-party services, …