EU Industry Benchmark
Beauty
Anonymized security posture data for the beauty sector across the EU. Based on 73 monitored sites.
42.8
Avg. Score /100
D
Avg. Grade
73
Sites Tracked
-5.0
vs. EU Average
Critical findings in this industry
8 of 73 without HTTPS redirect
2 of 73 with unencrypted email (no STARTTLS)
21 of 73 without DMARC protection (spoofable)
51 of 73 missing 3+ critical security headers
28 of 73 without DNSSEC (vulnerable to DNS spoofing)
28 of 73 without CAA records (unrestricted certificate issuance)
28 of 73 without MTA-STS (email downgrade attacks possible)
Grade Distribution
Hosting & Data Residency
70%
EU-headquartered provider
30%
Non-EU provider (CLOUD Act / Schrems II)
Server location via IP geolocation (MaxMind GeoLite2). Company HQ from ASN registry. A site may be physically hosted in the EU but use a US-headquartered provider subject to the CLOUD Act — per Schrems II (CJEU C-311/18), this requires SCCs with supplementary measures. · GDPR Art. 44–49
All data is anonymized. No individual sites are identified. Statistics updated weekly.