ThreatMate Research · 2026

    The State of the SMB Attack Surface

    What does security actually look like across a real MSP-managed SMB base?

    ThreatMate analyzed a research sample of 1,692 professionally managed SMB environments across vulnerabilities, identity, email and domain security, endpoint configuration, internet exposure and live testing.

    Measured security data · 1,692 sampled environments · Edition One

    Cover of The State of the SMB Attack Surface, ThreatMate Research, 2026 Edition One

    Three findings

    Familiar controls, applied unevenly.

    01

    91.5%

    of endpoint-covered environments had at least one vulnerability on CISA's Known Exploited Vulnerabilities catalogue.

    n = 1,090 endpoint-covered environments

    02

    1.7x

    Users found in known breach data were 1.7x as likely to lack MFA as the broader monitored-user population.

    Median per-environment comparison across 1,094 environments

    03

    60.7%

    of environments with a monitored domain had at least one domain or email integrity issue.

    n = 1,412 environments

    The individual numbers are useful. The pattern across them is the bigger story.

    Get the full research

    What we measured

    One SMB. Multiple attack surfaces.

    The report looks across layers that are usually measured separately, then asks where the same patterns repeat.

    Environments
    1,692
    Devices
    245,042
    User accounts
    119,087

    Counts describe the research sample. Not every instrument covers every environment.

    One SMBenvironmentIdentity01Endpoints02Email + Domain03Network04Internet-facing systems05Live testing06

    Inside the report

    What you'll find inside

    Twenty-one pages across six chapters, a self-check benchmark table and a full methodology.

    1. 01

      Vulnerability exposure

      How common known-exploited vulnerabilities are, how prevalence changes by customer size, and what live reachability changes about urgency.

    2. 02

      Identity

      Where MFA coverage is strongest, where it breaks down, and how known breach history changes the picture.

    3. 03

      Email + domain security

      How often domain controls are clean, missing or only partially enforced.

    4. 04

      Endpoint hardening

      What millions of CIS Level 1 configuration checks say about security baselines across SMB environments.

    5. 05

      Lifecycle and remediation

      Where unsupported operating systems persist and why some classes of findings take much longer to close.

    6. 06

      Consistency

      What the combined data suggests about the operational challenge facing MSPs across an entire customer base.

    Methodology

    Measured in real managed environments.

    This is not survey data. The report is based on a research sample of 1,692 professionally managed SMB environments. Different measurements require different telemetry, so every finding carries its own denominator.

    01

    Measured, not self-reported

    Findings come from observed security data.

    02

    Every statistic carries its denominator

    Different surfaces have different measured populations.

    03

    Point-in-time benchmark

    Edition One establishes the baseline for future research.

    Download

    Read the full benchmark.

    MSPs already know what good looks like. The opportunity is applying it consistently across every customer. Edition One shows where that consistency is already holding and where the same gaps repeat.

    Cover of The State of the SMB Attack Surface, ThreatMate Research, 2026 Edition One
    • 21 pages, six chapters
    • 40+ denominated statistics
    • 01 self-check table to compare your book against the cohort
    • 06 priorities for the next quarter

    Get the full report

    Download Edition One of The State of the SMB Attack Surface.

    By submitting, you agree to ThreatMate's Privacy Policy. You can unsubscribe from marketing communications at any time.

    Ready to see ThreatMate in action?

    15 minutes. No pressure. Real MSP workflows.