{
  "$schema": "https://www.enuclea.com/schemas/digital-trust-audit-v1.json",
  "metadata": {
    "title": "Prince William Chamber of Commerce Digital Trust Audit (2026) — Sector Benchmarks",
    "slug": "prince-william-chamber-of-commerce",
    "cohort": "Prince William Chamber of Commerce directory list, local SMB universe",
    "published_by": "Enuclea LLC",
    "published_at": "2026-08-24T04:52:55.469264+00:00",
    "audit_year": 2026,
    "geography": "Prince William Chamber of Commerce, Virginia",
    "sample_size": 814,
    "chamber_identities": 1086,
    "scope": "Unique local small-to-midsize businesses. Fortune 500 chains, duplicate regional-bank branches, and government agencies separated. Providers scored on the same instruments and held out of the community mean.",
    "methodology": "Non-intrusive public DNS: SPF (RFC 7208), DKIM selector presence (RFC 6376), DMARC policy (RFC 7489), DNSBL/IP reputation where an outbound identity was visible. No mail sent. No mailbox accessed. Point-in-time snapshot.",
    "unit_of_analysis": "Primary published sending domain per unique local entity",
    "enforced_definition": "DMARC p=quarantine or p=reject. p=none is monitoring, not protection.",
    "community_kpis": {
      "mean_score": 66.2,
      "median_score": 65.0,
      "grade": "C+",
      "grade_label": "Basic authentication / monitoring",
      "good_band_floor": 80,
      "delta_vs_good_band": -13.8,
      "active_spoof_protection_pct": 23.3,
      "vulnerable_to_impersonation_pct": 76.7,
      "missing_dkim_pct": 52.6,
      "spf_published_pct": 79.2,
      "dnsbl_blacklisted_pct": 20.3
    },
    "free_mail": {
      "chamber_identities": 1086,
      "combined_free_mail_users": 144,
      "combined_free_mail_pct_of_chamber": 13.3,
      "pure_free_mail": 90,
      "pure_free_mail_pct_of_chamber": 8.3,
      "shadow_mail": 54,
      "shadow_mail_pct_of_chamber": 5.0,
      "shadow_mail_pct_of_community": 6.6,
      "note": "The 814 community scorecard is custom-domain SMBs (1086 chamber identities minus 90 pure free-mail minus excluded government/chains)."
    },
    "grade_distribution": {
      "A_plus": 75,
      "A": 15,
      "B": 178,
      "C": 298,
      "D": 152,
      "F": 96
    },
    "notes": [
      "Community mean 66.2 excludes the 5 IT/MSP providers so that cohort does not inflate the regional number.",
      "Named private firms are not in this public payload. Provider rows stay in the private run file."
    ]
  },
  "providers": {
    "held_out_from_community_mean": true,
    "it_msp_aggregate": {
      "sector_id": "it-providers-msps",
      "title": "Prince William Chamber of Commerce IT & Managed Service Providers",
      "cohort_description": "Commercial MSPs, IT consulting firms, and computer-service providers operating in the regional market. Same DNS instruments as the community scorecard. Held out of the community mean.",
      "total_providers_audited": 5,
      "scores": {
        "mean": 76.8,
        "median": 82.0,
        "min": 55,
        "max": 85,
        "benchmark_delta_vs_community": 10.6
      },
      "grade_distribution": {
        "A_plus": 0,
        "A": 0,
        "B": 4,
        "C": 0,
        "D": 1,
        "F": 0
      },
      "adoption_metrics": {
        "dmarc_enforced_n": 1,
        "dmarc_enforced_pct": 20.0,
        "dmarc_monitoring_n": 4,
        "dmarc_monitoring_pct": 80.0,
        "dmarc_missing_n": 0,
        "dmarc_missing_pct": 0.0,
        "open_to_spoof_n": 4,
        "open_to_spoof_pct": 80.0,
        "dkim_present_n": 5,
        "dkim_present_pct": 100.0,
        "missing_dkim_n": 0,
        "missing_dkim_pct": 0.0,
        "spf_published_n": 5,
        "spf_published_pct": 100.0,
        "spf_strict_hardfail_n": 0,
        "spf_strict_hardfail_pct": 0.0
      },
      "key_insights": [
        "Highest mean in the study (76.8), still 4 of 5 domains open to impersonation.",
        "1 of 5 enforce (p=quarantine or p=reject). 4 of 5 monitor at p=none. 0 of 5 publish no DMARC.",
        "0 of 5 have no DKIM public key. 0 of 5 publish no SPF.",
        "Gap is policy, not tooling. These firms already live on M365 or equivalent."
      ]
    }
  },
  "sectors": [
    {
      "sector_id": "general-commercial",
      "sector_name": "General Commercial",
      "total_businesses": 596,
      "pct_of_sample": 73.2,
      "scores": {
        "mean": 65.7,
        "median": 65.0,
        "benchmark_delta_vs_community": -0.5
      },
      "grade_distribution": {
        "A_plus": 53,
        "A": 11,
        "B": 123,
        "C": 224,
        "D": 115,
        "F": 70
      },
      "adoption_metrics": {
        "dmarc_enforced_n": 136,
        "dmarc_enforced_pct": 22.8,
        "dmarc_monitoring_n": 173,
        "dmarc_monitoring_pct": 29.0,
        "dmarc_missing_n": 287,
        "dmarc_missing_pct": 48.2,
        "open_to_spoof_n": 460,
        "open_to_spoof_pct": 77.2,
        "dkim_present_n": 273,
        "dkim_present_pct": 45.8,
        "missing_dkim_n": 323,
        "missing_dkim_pct": 54.2,
        "spf_published_n": 468,
        "spf_published_pct": 78.5,
        "spf_strict_hardfail_n": 0,
        "spf_strict_hardfail_pct": 0.0,
        "dnsbl_blacklisted_n": 117,
        "dnsbl_blacklisted_pct": 19.6
      },
      "why_it_matters": "As the largest sector cohort, General Commercial represents the core economic circulatory system of the county. Local B2B supply chains, regional wholesalers, equipment distributors, and commercial vendors transact via recurring email billing. Weak domain hygiene across this cohort enables widespread invoice interception and vendor impersonation fraud.",
      "sector_insights": "At 596 of 814 entities (73.2%), this single cohort anchors the county mean score (65.7 vs 66.2 regional mean). 287 of 596 domains (48.2%) publish no DMARC record, and 323 domains (54.2%) lack DKIM outbound signatures. 225 firms operate on Microsoft 365 and 157 on Google Workspace, but softfail (~all) configurations leave 77.2% open to lookalike forgery.",
      "remediation_playbook": [
        "Publish DMARC records to establish corporate identity governance.",
        "Configure DKIM cryptographic signatures in primary email hosting providers.",
        "Delist blacklisted sending IPs and migrate to dedicated cloud mail delivery."
      ]
    },
    {
      "sector_id": "construction-and-trades",
      "sector_name": "Construction & Trades",
      "total_businesses": 45,
      "pct_of_sample": 5.5,
      "scores": {
        "mean": 67.6,
        "median": 65.0,
        "benchmark_delta_vs_community": 1.4
      },
      "grade_distribution": {
        "A_plus": 3,
        "A": 1,
        "B": 11,
        "C": 19,
        "D": 7,
        "F": 4
      },
      "adoption_metrics": {
        "dmarc_enforced_n": 9,
        "dmarc_enforced_pct": 20.0,
        "dmarc_monitoring_n": 20,
        "dmarc_monitoring_pct": 44.4,
        "dmarc_missing_n": 16,
        "dmarc_missing_pct": 35.6,
        "open_to_spoof_n": 36,
        "open_to_spoof_pct": 80.0,
        "dkim_present_n": 24,
        "dkim_present_pct": 53.3,
        "missing_dkim_n": 21,
        "missing_dkim_pct": 46.7,
        "spf_published_n": 38,
        "spf_published_pct": 84.4,
        "spf_strict_hardfail_n": 0,
        "spf_strict_hardfail_pct": 0.0,
        "dnsbl_blacklisted_n": 11,
        "dnsbl_blacklisted_pct": 24.4
      },
      "why_it_matters": "In construction and contracting, financial transactions are high-value and episodic (draw requests, subcontractor disbursements, change orders). Threat actors monitor unauthenticated email threads to execute wire-redirection right before progress payments or closing. A single intercepted payment can paralyze active project job sites and result in mechanics' liens.",
      "sector_insights": "44.4% of the cohort (20 of 45 firms) is stalled in passive monitoring (p=none), leaving 80.0% open to lookalike forgery. Trade contractors rely heavily on standard cloud defaults (Microsoft 365: 19, Google Workspace: 13) without completing DKIM/DMARC alignment. 11 of 45 trade firms (24.4%) suffer from DNSBL blocklist hits caused by shared hosting and unauthenticated field dispatchers.",
      "remediation_playbook": [
        "Migrate primary customer inquiry routes from @gmail.com or ISP mail to authenticated corporate domains.",
        "Deploy DMARC at p=quarantine or p=reject to prevent unauthorized invoice generation on company letterhead.",
        "Configure SPF with strict -all to prevent rogue IP relays from claiming contractor authority."
      ]
    },
    {
      "sector_id": "healthcare-and-medical",
      "sector_name": "Healthcare & Medical",
      "total_businesses": 40,
      "pct_of_sample": 4.9,
      "scores": {
        "mean": 67.5,
        "median": 67.0,
        "benchmark_delta_vs_community": 1.3
      },
      "grade_distribution": {
        "A_plus": 4,
        "A": 0,
        "B": 13,
        "C": 8,
        "D": 13,
        "F": 2
      },
      "adoption_metrics": {
        "dmarc_enforced_n": 10,
        "dmarc_enforced_pct": 25.0,
        "dmarc_monitoring_n": 12,
        "dmarc_monitoring_pct": 30.0,
        "dmarc_missing_n": 18,
        "dmarc_missing_pct": 45.0,
        "open_to_spoof_n": 30,
        "open_to_spoof_pct": 75.0,
        "dkim_present_n": 25,
        "dkim_present_pct": 62.5,
        "missing_dkim_n": 15,
        "missing_dkim_pct": 37.5,
        "spf_published_n": 31,
        "spf_published_pct": 77.5,
        "spf_strict_hardfail_n": 0,
        "spf_strict_hardfail_pct": 0.0,
        "dnsbl_blacklisted_n": 10,
        "dnsbl_blacklisted_pct": 25.0
      },
      "why_it_matters": "Medical practices, dental clinics, specialty surgery centers, and therapy groups transmit HIPAA-regulated electronic Protected Health Information (ePHI). Spoofed clinical emails can facilitate fraudulent prescription routing, medical identity theft, and vendor payment diversion. OCR (HHS Office for Civil Rights) penalizes unauthenticated transmission of patient health identifiers.",
      "sector_insights": "Solid 67.5 mean score across 40 practices, with primary email on Google Workspace (15) and Microsoft 365 (13). 10 of 40 practices (25.0%) show DNSBL blocklist hits or SPF lookup penalties triggered by unaligned third-party EHR appointment reminders. 18 of 40 practices (45.0%) publish no DMARC record at all, leaving clinical communications vulnerable to impersonation.",
      "remediation_playbook": [
        "Audit all third-party clinical software (appointment reminders, billing platforms) and configure dedicated DKIM CNAMEs.",
        "Publish a DMARC policy with rua reporting to monitor who is sending on behalf of clinical domains.",
        "Ensure SPF records do not exceed the RFC 7208 10-lookup limit due to multiple vendor includes."
      ]
    },
    {
      "sector_id": "non-profit-and-community",
      "sector_name": "Non-Profit & Community",
      "total_businesses": 40,
      "pct_of_sample": 4.9,
      "scores": {
        "mean": 64.3,
        "median": 65.0,
        "benchmark_delta_vs_community": -1.9
      },
      "grade_distribution": {
        "A_plus": 3,
        "A": 2,
        "B": 8,
        "C": 11,
        "D": 8,
        "F": 8
      },
      "adoption_metrics": {
        "dmarc_enforced_n": 7,
        "dmarc_enforced_pct": 17.5,
        "dmarc_monitoring_n": 16,
        "dmarc_monitoring_pct": 40.0,
        "dmarc_missing_n": 17,
        "dmarc_missing_pct": 42.5,
        "open_to_spoof_n": 33,
        "open_to_spoof_pct": 82.5,
        "dkim_present_n": 17,
        "dkim_present_pct": 42.5,
        "missing_dkim_n": 23,
        "missing_dkim_pct": 57.5,
        "spf_published_n": 29,
        "spf_published_pct": 72.5,
        "spf_strict_hardfail_n": 0,
        "spf_strict_hardfail_pct": 0.0,
        "dnsbl_blacklisted_n": 7,
        "dnsbl_blacklisted_pct": 17.5
      },
      "why_it_matters": "Non-profits, charities, foundations, and community associations hold high public trust and process donor contributions and grant distributions. Attackers frequently spoof non-profit leadership during fundraising galas and capital campaigns to divert donor wire transfers. Compromised reputations directly impair grant eligibility, donor goodwill, and community board confidence.",
      "sector_insights": "0% reject enforcement across 40 community organizations (7 quarantine, 16 monitoring p=none, 17 no DMARC). 58% of non-profits (23 of 40) lack DKIM cryptographic signatures, sending unauthenticated donor solicitations. Heavy reliance on donated Microsoft 365 (18) and Google Workspace (4) grants without dedicated technical administration to activate DNS keys.",
      "remediation_playbook": [
        "Deploy DMARC enforcement to protect donors and board members from executive spoofing.",
        "Authenticate bulk donor outreach platforms (Mailchimp, Constant Contact) with custom DKIM and SPF includes.",
        "Enforce strict SPF hardfail to prevent unauthorized spoofing of donation receipts."
      ]
    },
    {
      "sector_id": "financial-services",
      "sector_name": "Financial Services",
      "total_businesses": 39,
      "pct_of_sample": 4.8,
      "scores": {
        "mean": 73.5,
        "median": 75.0,
        "benchmark_delta_vs_community": 7.3
      },
      "grade_distribution": {
        "A_plus": 8,
        "A": 1,
        "B": 11,
        "C": 13,
        "D": 2,
        "F": 4
      },
      "adoption_metrics": {
        "dmarc_enforced_n": 18,
        "dmarc_enforced_pct": 46.2,
        "dmarc_monitoring_n": 10,
        "dmarc_monitoring_pct": 25.6,
        "dmarc_missing_n": 11,
        "dmarc_missing_pct": 28.2,
        "open_to_spoof_n": 21,
        "open_to_spoof_pct": 53.8,
        "dkim_present_n": 22,
        "dkim_present_pct": 56.4,
        "missing_dkim_n": 17,
        "missing_dkim_pct": 43.6,
        "spf_published_n": 35,
        "spf_published_pct": 89.7,
        "spf_strict_hardfail_n": 0,
        "spf_strict_hardfail_pct": 0.0,
        "dnsbl_blacklisted_n": 9,
        "dnsbl_blacklisted_pct": 23.1
      },
      "why_it_matters": "Financial advisors, CPAs, lenders, and wealth managers are high-priority targets for wire fraud and account takeover schemes. A single spoofed invoice or wire-instruction email can cause catastrophic, unrecoverable capital loss for local clients. SEC, FINRA, and FTC Safeguards Rules mandate strict domain and message authentication for customer data protection.",
      "sector_insights": "Highest commercial enforcement rate in the county (46.2% — 18 of 39 firms) driven by enterprise broker-dealer mandates. Highest telemetry adoption in the study, with 61.5% (24 of 39 firms) publishing active DMARC RUA aggregate reporting. 11 of 39 boutique firms still publish no DMARC policy, creating a bifurcated risk landscape between branch offices and independents.",
      "remediation_playbook": [
        "Enable DKIM signing keys in Microsoft 365 Defender / Google Workspace to seal all financial statements.",
        "Advance remaining monitoring policies (p=none) to full enforcement (p=reject).",
        "Implement DMARC RUA reporting to maintain continuous audit telemetry for regulatory compliance."
      ]
    },
    {
      "sector_id": "hospitality-dining-and-retail",
      "sector_name": "Hospitality, Dining & Retail",
      "total_businesses": 37,
      "pct_of_sample": 4.5,
      "scores": {
        "mean": 61.4,
        "median": 62.0,
        "benchmark_delta_vs_community": -4.8
      },
      "grade_distribution": {
        "A_plus": 2,
        "A": 0,
        "B": 5,
        "C": 16,
        "D": 6,
        "F": 8
      },
      "adoption_metrics": {
        "dmarc_enforced_n": 5,
        "dmarc_enforced_pct": 13.5,
        "dmarc_monitoring_n": 9,
        "dmarc_monitoring_pct": 24.3,
        "dmarc_missing_n": 23,
        "dmarc_missing_pct": 62.2,
        "open_to_spoof_n": 32,
        "open_to_spoof_pct": 86.5,
        "dkim_present_n": 17,
        "dkim_present_pct": 45.9,
        "missing_dkim_n": 20,
        "missing_dkim_pct": 54.1,
        "spf_published_n": 27,
        "spf_published_pct": 73.0,
        "spf_strict_hardfail_n": 0,
        "spf_strict_hardfail_pct": 0.0,
        "dnsbl_blacklisted_n": 8,
        "dnsbl_blacklisted_pct": 21.6
      },
      "why_it_matters": "Restaurants, event venues, boutique retailers, and hospitality operators manage large customer contact lists and private event bookings. Spoofed banquet and catering deposit invoices directly defraud event clients and damage local brand goodwill. Customer trust is fragile: recipient mail gateways increasingly route unauthenticated promotional emails directly to spam folders.",
      "sector_insights": "Lowest-scoring sector in the region (61.4 mean), with 62% of storefronts (23 of 37) publishing no DMARC record at all. 86% of hospitality businesses (32 of 37) are open to spoofing, with only 5 storefronts (14%) enforcing DMARC. Storefronts manage marketing separate from core operations, creating unaligned transactional sending services on DIY website builders.",
      "remediation_playbook": [
        "Unify customer booking channels under authenticated corporate domain email (@brand.com).",
        "Publish basic SPF and DMARC (p=none) records to immediately gain visibility into brand spoofing.",
        "Migrate from consumer webmail to managed business suites (Google Workspace / Microsoft 365)."
      ]
    },
    {
      "sector_id": "professional-services-legal-and-cpa",
      "sector_name": "Professional Services: Legal & CPA",
      "total_businesses": 15,
      "pct_of_sample": 1.8,
      "scores": {
        "mean": 73.5,
        "median": 75.0,
        "benchmark_delta_vs_community": 7.3
      },
      "grade_distribution": {
        "A_plus": 2,
        "A": 0,
        "B": 6,
        "C": 6,
        "D": 1,
        "F": 0
      },
      "adoption_metrics": {
        "dmarc_enforced_n": 4,
        "dmarc_enforced_pct": 26.7,
        "dmarc_monitoring_n": 3,
        "dmarc_monitoring_pct": 20.0,
        "dmarc_missing_n": 8,
        "dmarc_missing_pct": 53.3,
        "open_to_spoof_n": 11,
        "open_to_spoof_pct": 73.3,
        "dkim_present_n": 7,
        "dkim_present_pct": 46.7,
        "missing_dkim_n": 8,
        "missing_dkim_pct": 53.3,
        "spf_published_n": 15,
        "spf_published_pct": 100.0,
        "spf_strict_hardfail_n": 0,
        "spf_strict_hardfail_pct": 0.0,
        "dnsbl_blacklisted_n": 2,
        "dnsbl_blacklisted_pct": 13.3
      },
      "why_it_matters": "Attorneys, legal practices, title companies, and CPAs handle confidential client privileged communications and escrow/settlement funds. Real estate closing wire fraud represents one of the fastest-growing cybercrime categories targeting legal settlement coordinators. State bar ethics rules require reasonable technical measures to protect confidential client data in transit.",
      "sector_insights": "Strong 73.5 mean score, but 53.3% of firms (8 of 15) publish no DMARC record and 53.3% lack DKIM cryptographic signatures. Only 4 of 15 practices (26.7%) enforce anti-spoofing policies despite handling high-risk financial and escrow transactions. Practices assume standard cloud setups (Microsoft 365: 9, Google Workspace: 3) automatically enforce protection without manual DNS activation.",
      "remediation_playbook": [
        "Publish DMARC records to establish corporate identity governance.",
        "Configure DKIM cryptographic signatures in primary email hosting providers.",
        "Delist blacklisted sending IPs and migrate to dedicated cloud mail delivery."
      ]
    },
    {
      "sector_id": "technology-and-defense",
      "sector_name": "Technology & Defense",
      "total_businesses": 2,
      "pct_of_sample": 0.2,
      "scores": {
        "mean": 75.0,
        "median": 75.0,
        "benchmark_delta_vs_community": 8.8
      },
      "grade_distribution": {
        "A_plus": 0,
        "A": 0,
        "B": 1,
        "C": 1,
        "D": 0,
        "F": 0
      },
      "adoption_metrics": {
        "dmarc_enforced_n": 1,
        "dmarc_enforced_pct": 50.0,
        "dmarc_monitoring_n": 0,
        "dmarc_monitoring_pct": 0.0,
        "dmarc_missing_n": 1,
        "dmarc_missing_pct": 50.0,
        "open_to_spoof_n": 1,
        "open_to_spoof_pct": 50.0,
        "dkim_present_n": 1,
        "dkim_present_pct": 50.0,
        "missing_dkim_n": 1,
        "missing_dkim_pct": 50.0,
        "spf_published_n": 2,
        "spf_published_pct": 100.0,
        "spf_strict_hardfail_n": 0,
        "spf_strict_hardfail_pct": 0.0,
        "dnsbl_blacklisted_n": 1,
        "dnsbl_blacklisted_pct": 50.0
      },
      "why_it_matters": "Defense, aerospace, and government IT contractors operate under strict DFARS / NIST SP 800-171 and CMMC mandates. Contractors handle Controlled Unclassified Information (CUI) and defense logistics where domain spoofing represents a national security threat. Prime contractors and DoD agencies increasingly require verified SPF, DKIM, and DMARC before issuing subcontractor task orders.",
      "sector_insights": "100% Microsoft 365 cloud email deployments with 50.0% enforcement rate. Unconfigured secondary domains lower what should otherwise be a uniform A-grade defense-adjacent posture.",
      "remediation_playbook": [
        "Attain 100% DMARC enforcement (p=reject) with 100% DKIM key rotation across all primary and secondary defense domains.",
        "Deploy MTA-STS (RFC 8461) and TLS-RPT to enforce TLS encryption in transit for defense correspondence.",
        "Audit SPF CIDR scopes to eliminate shared or overly broad subnet delegations."
      ]
    }
  ]
}
