← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Nearly half of small business websites lack basic security headers

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Study analyzed 4,688 unique small business websites.
  • 49.7% of sites met none of seven security header criteria.
  • The study focused on directory-listed U.S. local businesses.
  • Data was collected via HTTPS request-chain scans in 2026.

Study Overview

RACKCRUNCH conducted a study in 2026 examining the security header configurations of 7,040 directory-listed U.S. local business websites. The research aimed to understand the adoption of security headers among businesses that may not have dedicated web-security staff, such as plumbers, law offices, and local shops. The sample was drawn from the public Curlie web directory's U.S. local "Business and Economy" categories.

Methodology

The study involved running two HTTPS request-chain scans on each sampled URL, following up to three redirects. Response headers were read, but page content was not. The final analysis focused on 4,688 unique domains that provided a usable HTTP-200 response. The study defined seven specific security header criteria to evaluate each site's configuration.

Key Findings on Security Header Adoption

The study revealed that 49.7% of the 4,688 small business websites analyzed did not meet any of the seven defined security header criteria. This indicates a significant gap in the implementation of basic web security measures. While the study anticipated low adoption, the extent of non-compliance was a notable finding.

Implications for Small Businesses

The lack of security headers can leave websites vulnerable to common attacks like cross-site scripting (XSS), clickjacking, and other content injection exploits. For small businesses, this can lead to data breaches, reputational damage, and loss of customer trust. The findings highlight a need for increased awareness and easier implementation of fundamental web security practices in this sector.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 13 stories · Sep 25

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A 2026 study of 4,688 U.S. local business websites found that 49.7% did not meet any of seven defined security header criteria. This indicates a widespread lack of fundamental web security configurations among small and local businesses, potentially exposing them and their users to common web vulnerabilities.