{
    "regional_msp_audit_2026": {
        "context": "An independent baseline analysis of 26 Managed IT Service Providers operating in the Northern Virginia corridor (Stafford, Fredericksburg, Dale City, Triangle) to evaluate the security posture of the regional digital supply chain.",
        "methodology": "Data extracted exclusively from publicly available DNS records.",
        "data": {
            "totalCompanies": 26,
            "freeMailCount": 0,
            "freeMailPercent": 0,
            "missingControls": {
                "spf": {
                    "count": 1,
                    "percent": 3.85
                },
                "dkim": {
                    "count": 7,
                    "percent": 26.92
                },
                "dmarc": {
                    "count": 7,
                    "percent": 26.92
                },
                "rdns": {
                    "count": 0,
                    "percent": 0
                }
            },
            "scoreDistribution": {
                "good": {
                    "count": 19,
                    "percent": 73.08
                },
                "ok": {
                    "count": 7,
                    "percent": 26.92
                },
                "bad": {
                    "count": 0,
                    "percent": 0
                }
            },
            "meanScore": 81.04,
            "medianScore": 76
        },
        "enuclea_analysis": "While the MSP segment scores higher (81.04 mean) than the general business population, over 26% of local IT providers completely lack DMARC and DKIM enforcement. This exposes a systemic industry blindspot where foundational identity controls are inconsistently applied by the providers responsible for regional security."
    }
}