CyberBadger Labs · Research

New York City Business Website Security

14,595 sites scanned · New York City · August 2026 · passive, public data only · 2 scans tracked

We ran a passive, read-only security scan of 14,595 New York City business websites, using only what any browser or mail server can already see. 1.2% run software with a known security vulnerability, and the typical independent business site scores a D. Here is what the outside of New York City's small-business web looks like, and how to close the most common gaps.

1.2%
of independent New York City businesses run software with a known security vulnerability.

How New York City grades out

Every site gets one A to F grade. The typical independent New York City business scores a D.

C
D+
D
A 5.8%B 4.1%C 14.2%D+ 28.1%D 42.1%D- 2.4%F 3.3%
Typical grade by category
Email
F
Headers
B
TLS
A+
DNS
A+
Cookies
A+
Software
A+

The overall grade is held down by its weakest category. The rest of the region’s web is often in far better shape.

What we found, and how to fix it

Share of independent businesses with each gap, next to New York City's 1,318 chains and franchises for comparison. Every one is fixable.

89.7%
Local
60.4%
Chains
Can be impersonated in email (no DMARC enforcement)
11,903 of 13,277 sites
How to fix this →
1.2%
Local
1.1%
Chains
Running software with a known CVE
165 of 13,277 sites
How to fix this →
76.5%
Local
66.7%
Chains
WordPress sites exposing their admin usernames
1,803 of 2,356 WordPress sites
How to fix this →
65.2%
Local
54.2%
Chains
No Content-Security-Policy header
8,652 of 13,277 sites
How to fix this →
48.2%
Local
41.9%
Chains
Missing core security headers
6,402 of 13,277 sites
How to fix this →
59.6%
Local
46.7%
Chains
No HSTS (browsers can be downgraded to HTTP)
7,918 of 13,277 sites
How to fix this →
40.8%
Local
26.7%
Chains
No SPF record
5,411 of 13,277 sites
How to fix this →
18.6%
Local
12.2%
Chains
Not enforcing HTTPS
2,468 of 13,277 sites
How to fix this →
4%
Local
2.8%
Chains
Expired or untrusted TLS certificate
532 of 13,277 sites
How to fix this →

Context: 17.7% of these sites run WordPress (2,356 of 13,277). Running WordPress is not a problem in itself; it just means the WordPress-specific gaps above apply.

What New York City gets right

Security basics a good share of these businesses already have in place.

76.7%enforce HTTPS
91.3%have a valid, trusted certificate
10.3%enforce DMARC (quarantine or reject)
30.7%send a strong HSTS header
18.6%have a strict SPF record (-all)

How New York City has changed

2 scans since July 2026. Lower is better on every line.

Spoofable email
89.7%▼ 0.3 pts
was 90%
No HTTPS
18.6%▼ 2 pts
was 20.6%
No HSTS
59.6%▼ 1.7 pts
was 61.3%
0%25%50%75%100%July 2026August 2026Spoofable emailNo HTTPSNo HSTS

Grade mix over time

D
C
July 2026
typ. D
D
C
August 2026
typ. D

Where does your site land?

Run the same free scan on your own website and get your grade, plus the exact fixes, in under a minute. No login.

Run a free security scan

Method & sources

  • Passive and read-only: public DNS records plus a single homepage request per site. No logins, no test emails, no active or intrusive testing.
  • Sites were drawn from OpenStreetMap within New York City's administrative boundary, deduplicated by domain. 14,595 of 15,602 sites had a reachable website and were scored; the rest had no reachable website.
  • Of those, the headline figures cover the 13,277 independent businesses; the 1,318 chains and franchises (a domain at many locations, or carrying a brand tag) were set aside so the numbers reflect locally-owned businesses.
  • Figures are aggregate and anonymized: no individual business is named.

Data sources: © OpenStreetMap contributors.

Cite this report

CyberBadger Labs, "New York City Business Website Security" (2026). n=14595 new york city business websites. Data: © OpenStreetMap contributors.