Skip to main content
All Benchmarks
985 sites · December 2024

EU Website Security Benchmark — December 2024

Security posture snapshot for December 2024 across 985 monitored European websites.

58.3/100

Average score

49%

Email spoofable

78%

No DNSSEC

56%

Missing security headers

How does your industry compare?

Security posture by industry — sorted by average score. Click an industry to see its detailed breakdown.

Industry Sites Score Unprotected Spoofable Insecure Grade distribution
Pharma 39
48.5
56% 85% 15%
C
D
F
Automotive 19
51.8
58% 68% 21%
B
C
D
F
Banking 120
55.0
53% 55% 28%
C
D
F
Media 140
55.8
71% 61% 10%
C
D
E-Commerce 175
56.4
59% 53% 23%
C
D
F
Government 95
58.3
49% 54% 19%
B
C
D
F
Insurance 42
61.2
43% 45% 24%
B
C
D
F
Technology 265
62.1
52% 36% 14%
B
C
D
Regulatory 90
63.5
51% 28% 13%
B
C
D

Sorted by average security score (lowest first). Column explanations: Unprotected = missing 3+ critical HTTP headers. Spoofable = no or weak DMARC. Insecure = no HTTPS redirect.

A B C D F

What we found

The most common security gaps across 985 European websites — and the regulations they violate.

56%

Missing Security Headers

Visitors are exposed to clickjacking, XSS, and content injection because critical HTTP headers are missing.

NIS2 Art. 21

49%

Weak Email Authentication

Emails from these domains can be spoofed — invoices, password resets, anything. No DMARC enforcement.

NIS2 Art. 21 / DORA Art. 9

78%

No DNSSEC

DNS responses are unsigned. Attackers can redirect visitors to fake sites without detection.

NIS2 Art. 21

Where does your website fit in this picture?

Run a free security scan — no account needed. See your score, grade, and how you compare to your industry.

Scan your website now

This data is also available as JSON via the Benchmark API.