The public index

What we found in Slovenian websites.

K.I.S.S. is our public cyber exposure index. We scan the publicly reachable websites of limited liability companies by postal area and publish the aggregate, so the scale of the problem is visible without naming anyone.

2026 across industries, in numbers.

5,565
websites scanned across 21 postal areas
2.9–4.35
vulnerabilities found per site, on average
66–78
index score per area, out of 100

The same three things, nearly every time.

Across every area we scanned, the pattern barely changed. These are not exotic weaknesses. They are the ones that go unnoticed because nobody looked.

Outdated or misconfigured encryption20% – 57%
The most common finding by a distance, and it rose with the size of the sample.
Remote access reachable from the internet10% – 47%
Administrative doors left open to anyone who knocks. In the largest samples, almost half.
Outdated software still running1% – 5%
The rarest of the three and the most dangerous: usually the easiest way in.

What is HF K.I.S.S.?

K.I.S.S. — Kibernetski Indeks Spletnih Strani (Cyber Index of Web Pages), is an index measuring the cyber exposure level of a website or set of publicly accessible websites of business entities, classified by industry or registration location.

How is the K.I.S.S. score produced?

Each site is analysed individually using our own tool. The analysis is non-invasive and does not interfere with running systems. A K.I.S.S. score is calculated per site and aggregated into the overall index. AI adds its own risk opinion alongside our score.

Why K.I.S.S.?

K.I.S.S. is part of our mission to raise cybersecurity awareness. We want to encourage everyone, not just website owners, to invest energy into analysing and detecting vulnerabilities. We believe that transparency helps the entire digital ecosystem become safer.