01
91.5%
of endpoint-covered environments had at least one vulnerability on CISA's Known Exploited Vulnerabilities catalogue.
n = 1,090 endpoint-covered environments
ThreatMate Research · 2026
What does security actually look like across a real MSP-managed SMB base?
ThreatMate analyzed a research sample of 1,692 professionally managed SMB environments across vulnerabilities, identity, email and domain security, endpoint configuration, internet exposure and live testing.
Measured security data · 1,692 sampled environments · Edition One

Three findings
01
91.5%
of endpoint-covered environments had at least one vulnerability on CISA's Known Exploited Vulnerabilities catalogue.
n = 1,090 endpoint-covered environments
02
1.7x
Users found in known breach data were 1.7x as likely to lack MFA as the broader monitored-user population.
Median per-environment comparison across 1,094 environments
03
60.7%
of environments with a monitored domain had at least one domain or email integrity issue.
n = 1,412 environments
The individual numbers are useful. The pattern across them is the bigger story.
Get the full researchWhat we measured
The report looks across layers that are usually measured separately, then asks where the same patterns repeat.
Counts describe the research sample. Not every instrument covers every environment.
Inside the report
Twenty-one pages across six chapters, a self-check benchmark table and a full methodology.
How common known-exploited vulnerabilities are, how prevalence changes by customer size, and what live reachability changes about urgency.
Where MFA coverage is strongest, where it breaks down, and how known breach history changes the picture.
How often domain controls are clean, missing or only partially enforced.
What millions of CIS Level 1 configuration checks say about security baselines across SMB environments.
Where unsupported operating systems persist and why some classes of findings take much longer to close.
What the combined data suggests about the operational challenge facing MSPs across an entire customer base.
Methodology
This is not survey data. The report is based on a research sample of 1,692 professionally managed SMB environments. Different measurements require different telemetry, so every finding carries its own denominator.
01
Findings come from observed security data.
02
Different surfaces have different measured populations.
03
Edition One establishes the baseline for future research.
Download
MSPs already know what good looks like. The opportunity is applying it consistently across every customer. Edition One shows where that consistency is already holding and where the same gaps repeat.

Related
A practical approach to ranking what gets fixed first.
OpenWhy configuration is the next frontier for MSP security programs.
OpenWhat exposed credentials tell you about identity risk.
Open15 minutes. No pressure. Real MSP workflows.