RACKCRUNCH conducted a study in 2026 examining the security header configurations of 7,040 directory-listed U.S. local business websites. The research aimed to understand the adoption of security headers among businesses that may not have dedicated web-security staff, such as plumbers, law offices, and local shops. The sample was drawn from the public Curlie web directory's U.S. local "Business and Economy" categories.
The study involved running two HTTPS request-chain scans on each sampled URL, following up to three redirects. Response headers were read, but page content was not. The final analysis focused on 4,688 unique domains that provided a usable HTTP-200 response. The study defined seven specific security header criteria to evaluate each site's configuration.
The study revealed that 49.7% of the 4,688 small business websites analyzed did not meet any of the seven defined security header criteria. This indicates a significant gap in the implementation of basic web security measures. While the study anticipated low adoption, the extent of non-compliance was a notable finding.
The lack of security headers can leave websites vulnerable to common attacks like cross-site scripting (XSS), clickjacking, and other content injection exploits. For small businesses, this can lead to data breaches, reputational damage, and loss of customer trust. The findings highlight a need for increased awareness and easier implementation of fundamental web security practices in this sector.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A 2026 study of 4,688 U.S. local business websites found that 49.7% did not meet any of seven defined security header criteria. This indicates a widespread lack of fundamental web security configurations among small and local businesses, potentially exposing them and their users to common web vulnerabilities.