Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...

The Rankiteo MCP server is now available.

Discover MCP
!

Top 25 Worst Companies in United States

Identify the lowest-scoring most renowned companies in United States. Understand where critical cyber risk exposure exists in this country. 5121 companies scored.

10,000
Companies in United States
5121
Scored
750.2
Avg Score
1,610
Cyber Incidents
Bottom 25
Shown

United States Cybersecurity Risk Assessment - Lowest-Scoring Companies in 2026

Out of 10,000 companies in United States monitored by Rankiteo, this page highlights the Bottom 25 organizations with the weakest cybersecurity posture. These rankings are based on our proprietary Cyber Resilience Score, which integrates time-decayed incident exposure, sector-sensitive impact analysis, and market-cap-aware baseline and dampening to produce a single, interpretable score between 100 and 1,000.

Companies at the bottom of this ranking carry the heaviest accumulated cyber incident burden - including recent or severe ransomware attacks, data breaches with significant financial losses or records exposed, and repeated disclosure events. Understanding where these risk concentrations exist is essential for supply chain risk management, regulatory compliance, and competitive benchmarking within United States.

The current average score for the most notable companies in United States is 750.2 out of 1,000. Companies shown below score significantly lower than this average, falling far behind a country that generally maintains reasonable security standards.

Risk Highlights

345
Lowest Score
750.2
Country Average
5%
Scoring B or Below
1,610
Recorded Incidents

Score Distribution

Aaa
0 (0.0%)
Aa
3 (0.1%)
A
91 (1.8%)
Baa
4083 (79.7%)
Ba
673 (13.1%)
B
142 (2.8%)
Caa
48 (0.9%)
Ca
20 (0.4%)
C
61 (1.2%)
#CompanyLabelScoreBandIncidentsScore Bar
1
23andMe23andme.com
Others100C7
2
AT&Tatt.com
Telecommunications100C22
3
BleepingComputerbleepingcomputer.com
Others100C4
4
Chainalysischainalysis.com
Software Publishers100C2
5
Change Healthcarechangehealthcare.com
Computer Systems Design and Related Services100C18
6
Coinbasecoinbase.com
Finance and Insurance100C10
7
Conduentconduent.com
Management, Scientific, and Technical Consulting Services100C14
8
Coupangaboutcoupang.com
Software Publishers100C17
9
DaVita Kidney Caredavita.com
Health Care and Social Assistance100C8
10
Discorddiscord.com
Software Publishers100C12
11
Federal Bureau of Investigation (FBI)fbijobs.gov
Police Protection100C8
12
Ciscocisco.com
Software Publishers111C22
13
Colonial Pipeline Companycolpipe.com
Oil and Gas Extraction117C6
14
Carnival Corporationcarnivalcorp.com
Travel Arrangement and Reservation Services143C4
15
Comcastcomca.st
Telecommunications156C17
16
Citrixbit.ly
Software Publishers166C11
17
Ascensionascension.org
Health Care and Social Assistance180C7
18
Equifaxequifax.com
Finance and Insurance240C10
19
Checkmarxcheckmarx.com
Others259C3
20
ADTadt.com
Other Services (except Public Administration)260C1
21
Envoy Airenvoyair.com
Air Transportation267C5
22
City of Columbuscolumbus.gov
Public Administration294C2
23
Bettermentbetterment.com
Finance and Insurance305C3
24
City of Saint Paulstpaul.gov
Public Administration309C3
25
CareCloudcarecloud.com
Computer Systems Design and Related Services345C6

How Cyber Risk Scores Are Calculated

Rankiteo's Cyber Resilience Score produces a single value between 100 and 1,000 for each organization, where higher scores indicate lower estimated cyber risk. The framework integrates three principal components that together balance evidence, context, and comparability across industries and company sizes. Learn more in our AI Cyber Score methodology.

Understanding the Risk Bands

Each score maps to a letter-grade band. Companies appearing in this lowest-scoring ranking typically fall in the bottom bands:

  • Aaa (900-1,000): Exceptional cyber resilience - very few companies in a worst list reach this level.
  • Aa (800-899): Very strong security posture with minimal weaknesses.
  • A (700-799): Strong practices with some areas for improvement.
  • Baa (600-699): Adequate protection but notable security configuration gaps exist.
  • Ba (500-599): Below average - multiple risk areas require attention.
  • B (400-499): Weak security with significant exposure across categories.
  • Caa (300-399): Very weak with a high probability of exploitable vulnerabilities.
  • Ca (200-299): Critically poor with severe, widespread security gaps.
  • C (0-199): Extreme risk - immediate remediation is needed across all dimensions.

Why Monitoring Low-Scoring Companies in United States Matters

Cybersecurity risk doesn't exist in isolation. If your organization works with, purchases from, or shares data with companies in United States, their security weaknesses become your risk. Supply chain attacks - where adversaries compromise a less-secure vendor to reach a larger target - have become one of the most common and damaging attack vectors in recent years.

Rankiteo continuously monitors 10,000 companies in United States, keeping these rankings up to date so you always have an accurate, current picture of the country's risk landscape.