We Scanned the S&P 500's External Attack Surface. Here's What We Found.

492 Fortune-500 corporate sites probed for 11 sensitive ports and 7 security headers. Zero live exposures — but WAFs lied about 4% of them, half the index ships without CSP, and Consumer Discretionary is dead last on hygiene.

VulnScanners team5 min read

We profiled the public attack surface of every S&P 500 company: 503 index constituents, 492 with a live web presence. Eleven sensitive TCP ports each (FTP, SSH, Telnet, RDP, four databases, Redis, Docker, Kubernetes API, Elasticsearch), full HTTP security-header analysis on every corporate site, and an ASN fingerprint of the edge stack each company runs behind. Unauthenticated, unprivileged, no exploitation — the same first-pass external assessment any pentest starts with.

Here's what the Fortune 500's front doors actually look like.

The one-line summary: the ports are locked, the headers aren't, and your scanner is probably lying to you about both.

Finding 1: Zero live sensitive services — and a warning about the tools that say otherwise

The raw scan said 20 companies were exposing between 7 and 11 sensitive ports each. Things like "Redis open on a payment company's edge" or "MySQL reachable at a Big-Three auto supplier."

Every single one was false.

The tell was that all 20 "open" hosts shared an identical port signature — 21, 2375, 3306, 3389, 6379, 6443, 9200 — like a rubber stamp. So we went one layer deeper: we connected to each "open" port and waited for the service to speak. A real Redis answers PING with +PONG. MySQL opens with a protocol greeting. SSH sends its banner. Elasticsearch answers HTTP.

None did. One edge answered our Redis probe with HTTP/1.1 400 Bad Request.

ASN lookup confirmed the pattern: 17 of the 20 were Imperva (Incapsula) edges, plus one Cloudflare, one Optimizely, one Squiz, and one corporate firewall — all answering SYN on any port with nothing behind it. It's anti-reconnaissance behavior: don't tell the attacker which ports are filtered.

The lesson cuts both ways. If your vulnerability report shows "exposed MongoDB" on a company whose traffic is visibly behind Imperva, your scanner is equating a TCP handshake with exposure — and selling you fear. Conversely, banks like KeyBank and PNC drop non-browser probes entirely, so naive scanners see nothing on exactly the companies with the strictest posture. Tooling that doesn't validate at the application layer over-reports and under-reports at the same time.

The validated result: 0 of 492 companies expose a live service on any of the 11 sensitive ports. Two decades of "close port 3306" have landed. Management planes are behind VPNs and bastions. That's the good news, and it's real.

Finding 2: Half the index fails the free stuff

Headers are the cheapest security control that exists — one config line per edge. Here's how the S&P 500 does on seven baseline headers:

Strict-Transport-Security73.8%
X-Content-Type-Options62.9%
X-Frame-Options62.2%
Content-Security-Policy50.1%
Referrer-Policy33.8%
Permissions-Policy17.6%
Cross-Origin-Opener-Policy6.6%

Adoption across the 455 corporate sites that returned parseable headers.

Scoring each site on all seven: only 15 of 455 (3.3%) deploy them all. 71 deploy none.

0 of 7
71
1 of 7
52
2 of 7
43
3 of 7
88
4 of 7
85
5 of 7
56
6 of 7
45
7 of 7
15

Companies by count of baseline headers deployed. Green = all seven, red = none.

And HSTS quality is softer than adoption suggests: of 336 sites sending it, just 108 include preload, and 64 use a max-age shorter than a year.

Finding 3: 81.8% of corporate sites announce their stack

Four out of five sites return a Server: header on the first request. The most common disclosures: Cloudflare (81), Akamai (49), Apache (35), F5 BIG-IP (34), nginx (32), AWS ELB (15), IIS (14), Vercel (12).

58 sites go further and leak X-Powered-By — including ASP.NET (18), Next.js (15), WP Engine (10), and PHP with exact version numbers. Seven still send X-ASPNET-Version, a header Microsoft itself deprecated.

None of this is a vulnerability. All of it is free reconnaissance. An attacker's very first request returns vendor, framework, and sometimes patch level — before a single scan packet is sent.

Finding 4: The sector league table nobody expects

Energy3.71
Materials3.56
Communication Services3.43
Financials3.40
Information Technology3.25
Consumer Staples3.19
Industrials3.01
Utilities2.93
Health Care2.84
Real Estate2.77
Consumer Discretionary2.05

Average count of seven baseline security headers deployed, by GICS sector. Green ≥ 3.4, cyan ≥ 2.9, amber ≥ 2.5, red below.

Three surprises:

Consumer Discretionary is dead last — the sector that handles the most payment-card data, behind PCI DSS's most prescriptive requirements, runs the weakest corporate-site hygiene in the index (2.05 of 7, CSP at 30.8%).

Health Care is 9th of 11. A sector under permanent HIPAA scrutiny, whose business associates are audited on technical safeguards, averages fewer headers than utilities.

Information Technology is mid-pack (3.25) — the companies selling the security infrastructure don't visibly outperform the index on their own front doors. Arista Networks, which sells network visibility for a living, deploys zero of the seven headers on its corporate site — alongside Analog Devices, Booking Holdings, Aflac, and Fifth Third Bancorp.

(Corporate domains, not storefronts; customer-facing properties may differ. Missing headers are a hygiene gap, not a vulnerability — no exploit is implied for any named company.)

What this means for your team

  1. Demand banner validation from your scanner. A TCP SYN-ACK is not an open service. Any report that doesn't confirm at the application layer is manufacturing criticals on WAF-protected targets — 4% of the Fortune 500, by our count.
  2. The header gap is the cheapest win in external security. CSP and Referrer-Policy have the worst adoption-to-effort ratio in the whole study. If your site is in the 48% without CSP, that's an afternoon of work.
  3. Strip the banners. One config line per edge removes free intel from every attacker's first request.
  4. Compliance ≠ posture. The most-regulated sectors sit at the bottom of the table. Audit checklists don't move your public attack surface; configuration does.

Methodology notes

Where the S&P 500's web traffic actually lives (ASN of resolved IPs, n = 446):

26.2%
17.9%
17.3%
15%
9%
Direct/otherAWSAkamaiCloudflareAzureImpervaFastlyGCP

Targets: 503 index constituents → official corporate domains via Wikidata (with manual correction of 46 stale, subdomain, or vandalized entries — Qualcomm's Wikidata site pointed at consumerrights.wiki) → 500 DNS-resolved → 492 with live HTTP(S). Port scan: nmap -sT --open -T4 with rate limiting and randomized order across 10 parallel shards, from a residential US connection. Headers: curl -sIL with browser UA, final-response grading. Validation: application-layer banner probes on every port hit; ASN enrichment (Team Cymru) on all 500 IPs. Every statistic states its denominator. 11 companies actively block non-browser probes and are excluded from header stats (documented, not silently dropped).

Full methodology, the sector tables, and the WAF-deception appendix are in the complete report. Raw data available on request for verification.


Scans limited to 11 TCP ports with rate limiting, September 15, 2026. No vulnerability testing or exploitation attempted. Nothing here constitutes a security claim about any named company.

This is the same class of external assessment — with TLS auditing, web DAST, and analyst-reviewed reports layered on — that VulnScanners runs as a self-serve product. Full Nmap + Nuclei + ZAP + testssl.sh on one target starts at $10, credits never expire.