Securva · Research EnginePrivate preview

The research is
the edge.

What securva.net/research actually gives us, why it's an advantage almost nobody has, and what the numbers mean in plain English.

In one line: it turns "trust me, you need security" into "here's the measured proof you're exposed, and exactly who's worst." That's the difference between a salesman and a doctor showing you the X-ray.

274
orgs mapped
17,446
live hosts
22
sectors
monthly
refreshed

1What the findings mean (plain English)

2Who's strong, who's weak

Higher % = safer (more sites force a secure connection). Lower = exposed. Real measured numbers.
SectorHSTS %Read
e-commerce62.7%strongest
fintech59.3%strong (money + regulated)
banking54.6%strong
oil-gas48.2%middling
insurance35.9%weak-ish (regulated PII)
healthcare31.0%weak · biggest exposed surface (1,790 hosts)
government34.2%weak (citizen data)
edtech28.3%weak (student data)
power / DisCos21.5%very weak · critical infra + billing PII
telecom16.0%WEAKEST · serves tens of millions
The ones that should worry everyone — weak AND touching millions, where a breach gets ugly if nothing changes: telecom (16%), power (21.5%), healthcare (31%). The gut-punch: the infrastructure Nigerians depend on most — their phone, their power, their hospital — is the least secured.

3Our target audience

The weakest giants (telecom, power) are huge but slow to sell. The sweet spot for real near-term business = sectors that are measurably exposed + regulated under NDPA + can pay: insurance, fintech, banking, and healthcare. That's exactly why the insurance campaign is already our first move (19 insurers, exposed, regulated, reachable). The research hands us the specific weak orgs in each — so every pitch is warm, not cold.

4The edge this gives us

Why owning this data is an advantage competitors don't have.
1
Proof, not talk. Everyone says "you're at risk." We SHOW measured exposure, by sector, with receipts. Credibility nobody else brings.
2
A warm lead list, pre-qualified. The data names exactly which orgs are weakest. We know their gap before we ever contact them, so outreach is specific and warm, not cold.
3
A credible door-opener. "Here's how your sector scores, and where you stand vs peers" starts a conversation like a helpful expert, not a salesman.
4
Authority / own the narrative. Whoever holds the numbers becomes the name the market, press, and regulators reference. First-mover on the data = the go-to.
5
It arms the compliance angle. Weak posture = NDPA / data-protection risk = regulatory pressure = a concrete reason to buy the audit. The data quantifies the risk.
6
It compounds. Monthly refresh = a trend ("is Nigeria getting more secure or less?") = ongoing content, authority, and a reason for everyone to keep watching Securva.

5Why it holds up (so it's safe to show anyone)

It's passive measurement of publicly-observable data — DNS, which hosts are live, and the security headers each returns. Anyone can verify any single org themselves (curl -I their-domain and look at the HSTS header). Every number is computed from our stored per-org data, not asserted — re-run the method, get the same result. We measure what's publicly checkable; nobody has to take our word for it. We never publish a number we can't prove.

6How it's measured (the method, briefly)

Per sector, all passive: pick the real commercial orgs → enumerate their public DNS → probe which hosts are live → measure each one's security headers / HSTS → classify + aggregate per org → store in the database with a timestamp → prune junk rows → re-check the sanity-gate (a number must reproduce or it doesn't ship) → log a dated record. Commercial only (government excluded); no intrusive testing, ever.

7Where the proof lives (the evidence trail)

ArtifactWhat it proves
The database phase-intel.dbEvery org: sector, host count, HSTS %, timestamp — the raw data behind every number
Scan scriptsThe exact reproducible method — re-run, reproduce the data
Run logs + DB snapshotsTimestamped evidence each scan ran, point-in-time proof
Dated phase recordsThe audit trail of every expansion step
The sanity-gateHard rule: no number publishes unless it reproduces from the database
Publishing discipline: the live page shows only the validated core sectors (203 orgs). The 22-sector / 274-org expansion stays internal until a monthly refresh validates it. We publish proven, not eager.
Securva internal · 2026-10-01 · private, noindex · your-eyes-only preview. Full methodology + evidence doc on the box. Companion to the Securva Positioning + AI Security Engine pages.