Skip to main content
All Benchmarks
61078 sites · March 2026

EU Website Security Benchmark — March 2026

Security posture snapshot for March 2026 across 61078 monitored European websites.

49.0/100

Average score

71%

Email spoofable

86%

No DNSSEC

71%

Missing security headers

How does your industry compare?

Security posture by industry — sorted by average score. Click an industry to see its detailed breakdown.

Industry Sites Score Unprotected Spoofable Insecure Grade distribution
construction 129
38.5
87% 79% 16%
D
F
professional-services 93
41.7
80% 63% 9%
D
F
pets 47
42.9
72% 57% 17%
D
F
beauty 477
43.0
76% 80% 10%
D
F
home-garden 476
44.3
70% 75% 9%
D
F
Hospitality 5194
44.8
79% 81% 9%
D
F
Food & Delivery 12054
45.1
77% 81% 8%
D
F
culture 902
45.5
73% 77% 9%
D
F
Sports 3160
45.9
80% 81% 8%
D
F
Healthcare 3147
46.8
78% 77% 10%
D
F
Automotive 2781
47.1
73% 78% 10%
D
F
Travel 1623
47.2
75% 75% 9%
D
F
Real Estate 1745
47.8
78% 75% 8%
D
F
Education 4352
48.4
72% 77% 7%
C
D
F
NGO & Nonprofit 1876
48.7
80% 76% 8%
C
D
F
Fashion 2520
49.1
65% 76% 7%
D
F
Adult 298
49.5
78% 73% 6%
C
D
F
Logistics 955
49.5
76% 68% 7%
C
D
Pharma 3517
49.8
62% 69% 6%
C
D
Media 2481
52.0
78% 59% 2%
C
D
Energy 934
53.3
65% 59% 8%
C
D
Insurance 1208
54.2
63% 60% 7%
C
D
Gambling 282
54.7
68% 49% 10%
C
D
Technology 2340
55.1
64% 50% 6%
C
D
E-Commerce 4265
55.2
65% 46% 5%
C
D
Transport 464
55.9
59% 49% 7%
C
D
Regulatory 339
56.9
53% 53% 6%
C
D
Telecom 368
57.1
57% 47% 7%
C
D
Government 1395
58.1
54% 52% 6%
C
D
Banking 1655
62.6
32% 48% 4%
C
D

Click a column header to sort. Column explanations: Unprotected = missing 3+ critical HTTP headers. Spoofable = no or weak DMARC. Insecure = no HTTPS redirect.

A B C D F

What we found

The most common security gaps across 61078 European websites — and the regulations they violate.

71%

Missing Security Headers

Visitors are exposed to clickjacking, XSS, and content injection because critical HTTP headers are missing.

NIS2 Art. 21

71%

Weak Email Authentication

Emails from these domains can be spoofed — invoices, password resets, anything. No DMARC enforcement.

NIS2 Art. 21 / DORA Art. 9

86%

No DNSSEC

DNS responses are unsigned. Attackers can redirect visitors to fake sites without detection.

NIS2 Art. 21

Where does your website fit in this picture?

Run a free security scan — no account needed. See your score, grade, and how you compare to your industry.

Scan your website now

This data is also available as JSON via the Benchmark API.