Skip to main content
Updated weekly · 17591 sites

EU Website Security Benchmark

We scan 17591 European websites every week — banking, pharma, e-commerce, government, tech. No individual sites are named. The question isn't who failed. It's which industries are exposed.

53.9/100

Average score

50%

Email spoofable

83%

No DNSSEC

66%

Missing security headers

19%

High-risk pre-consent transfers

60.1/100

Accessibility score

5.0

Pre-consent cookies avg

How does your industry compare?

Security posture by industry — sorted by average score. Click an industry to see its detailed breakdown.

Industry Sites Score Unprotected Spoofable Pre-Consent Grade distribution
Sports 395
41.5
83% 75% 29%
D
F
Hospitality 518
42.7
79% 70% 23%
C
D
F
Logistics 305
45.4
74% 50% 13%
C
D
F
Adult 295
46.1
81% 76% 12%
D
F
NGO & Nonprofit 345
47.9
73% 68% 23%
C
D
F
Media 2432
51.9
79% 59% 22%
C
D
Travel 227
52.1
64% 57% 11%
B
C
D
F
Fashion 269
52.6
57% 48% 22%
C
D
F
Gambling 272
53.0
68% 52% 13%
C
D
Food & Delivery 222
53.2
66% 54% 12%
C
D
F
Real Estate 354
53.4
69% 52% 21%
C
D
Healthcare 541
54.1
67% 50% 18%
C
D
E-Commerce 4320
54.6
65% 47% 16%
C
D
Transport 416
55.2
60% 49% 19%
C
D
Technology 2064
55.7
64% 49% 22%
C
D
Automotive 367
55.8
59% 51% 15%
C
D
Pharma 292
55.9
59% 39% 22%
C
D
Regulatory 332
55.9
55% 55% 36%
C
D
Education 926
56.4
69% 62% 23%
C
D
Telecom 364
56.9
58% 47% 19%
C
D
Energy 389
57.0
55% 42% 20%
C
D
Government 989
57.6
57% 50% 24%
C
D
Banking 623
61.0
44% 27% 11%
C
D
Insurance 334
61.5
46% 29% 13%
C
D

Sorted by average security score (lowest first). Column explanations: Unprotected = missing 3+ critical HTTP headers. Spoofable = no or weak DMARC.

A B C D F

Where does your website fit in this picture?

Run a free security scan — no account needed. See your score, grade, and how you compare to your industry.

Scan your website now

What we found

The most common security gaps across 17591 European websites — and the regulations they violate.

66%

Missing Security Headers

Visitors are exposed to clickjacking, XSS, and content injection because critical HTTP headers are missing.

NIS2 Art. 21

50%

Weak Email Authentication

Emails from these domains can be spoofed — invoices, password resets, anything. No DMARC enforcement.

NIS2 Art. 21 / DORA Art. 9

83%

No DNSSEC

DNS responses are unsigned. Attackers can redirect visitors to fake sites without detection.

NIS2 Art. 21
Show all findings
96%
No MTA-STS
Inbound emails can be downgraded to plaintext by an attacker — the server doesn't enforce TLS.
NIS2 Art. 21
14%
No SMTP Encryption
Email is transmitted in cleartext. Anyone on the network can read it.
GDPR Art. 32
85%
No security.txt
No public vulnerability disclosure contact — security researchers have nowhere to report issues.
CRA Art. 11
85%
No CAA Records
Any certificate authority can issue certificates for this domain — no restrictions.
NIS2 Art. 21
6%
No HTTPS Redirect
Visitors connect over unencrypted HTTP. Credentials and data are visible on the network.
GDPR Art. 32
95%
No DANE/TLSA
No certificate pinning for email transport — vulnerable to man-in-the-middle on SMTP.
NIS2 Art. 21

Accessibility, Performance & Cookie Compliance

Beyond security — how Europe's websites perform on accessibility, Core Web Vitals, and cookie consent.

Accessibility (WCAG 2.2)

17019 sites scanned · EAA / BFSG

60.1

Avg score

5.3

Avg violations

13244

Critical total

Government
71.2
Insurance
69.2
Banking
67.4
Regulatory
67.2
Pharma
66.3
Education
65.7
Automotive
63.2
Telecom
62.8
Healthcare
62.6
Technology
62.2
Energy
61.1
E-Commerce
59.3
Food & Delivery
59.2
Fashion
58.9
Travel
57.8
Transport
57.5
Adult
57.3
Real Estate
57.2
NGO & Nonprofit
56.3
Gambling
55.1
Media
54.1
Logistics
53.4
Hospitality
50.0
Sports
49.7

Cookie Compliance

16917 sites scanned · ePrivacy / TTDSG

5.0

Pre-consent avg

7212

No banner

3369

No reject btn

Regulatory
2.2
Education
2.9
Logistics
2.9
Government
3.0
Pharma
3.7
Energy
3.9
NGO & Nonprofit
4.0
Sports
4.1
Healthcare
4.2
Technology
4.3
Hospitality
4.5
Automotive
4.6
Gambling
4.8
Real Estate
5.0
Transport
5.0
Adult
5.1
Food & Delivery
5.4
Media
5.6
Banking
5.7
E-Commerce
6.0
Insurance
6.0
Telecom
6.4
Travel
7.4
Fashion
11.5

Core Web Vitals

16581 sites scanned

92.9

Perf score

1.8s

LCP

0.083

CLS

1.5s

FCP

80.0ms

TBT

0ms

TTFB

Real Estate
94.7
Adult
94.6
Media
94.0
Technology
93.9
Insurance
93.7
Automotive
93.6
Transport
93.3
Banking
93.1
E-Commerce
93.0
Healthcare
92.7
Government
92.3
Education
92.2
Hospitality
92.1
Gambling
92.0
Pharma
91.8
Food & Delivery
91.7
Energy
91.5
Travel
91.5
Logistics
91.3
Regulatory
91.3
NGO & Nonprofit
91.2
Telecom
91.1
Fashion
90.5
Sports
90.4

Methodology & Scoring

How we scan, what we measure, how scores are computed.

Every site is scanned weekly across these security dimensions. Scores are computed on a 100-point scale.

Security Headers 25 pts

HSTS, CSP, X-Frame-Options, X-Content-Type, Referrer-Policy, Permissions-Policy

SSL/TLS Certificate 20 pts

Key strength, signature algorithm, chain depth, TLS version, forward secrecy

HTTPS Enforcement 10 pts

HTTP-to-HTTPS redirect for all visitors

Email Authentication 15 pts

SPF, DKIM (key strength), DMARC (policy enforcement)

DNS Security 15 pts

DNSSEC signing, CAA records, DoH consistency, DANE/TLSA

security.txt 5 pts

Vulnerability disclosure contact per RFC 9116

MTA-STS 3 pts

Inbound email TLS enforcement (enforce vs. testing mode)

TLS-RPT 2 pts

SMTP TLS failure reporting endpoint

Server Privacy 5 pts

No server version disclosure, no X-Powered-By, restricted CORS

Data based on automated weekly scans of publicly accessible websites.

No individual site names are disclosed. All statistics are anonymised by industry.

Regulatory references indicate which requirements relate to each finding. They do not assert non-compliance of any specific organisation.

Your competitors are in this data. Are you better or worse?

Run a free security scan and see your score, your grade, and how you compare — in 30 seconds, no account needed.

This data is also available as JSON via the Benchmark API.