EU Industry Benchmark
Hospitality
Anonymized security posture data for the hospitality sector across the EU. Based on 110519 monitored sites.
38.3
Avg. Score /100
F
Avg. Grade
110519
Sites Tracked
-1.0
vs. EU Average
Critical findings in this industry
99614 of 110519 without HTTPS redirect
108552 of 110519 with unencrypted email (no STARTTLS)
110283 of 110519 without DMARC protection (spoofable)
25477 of 110519 missing 3+ critical security headers
95301 of 110519 without DNSSEC (vulnerable to DNS spoofing)
107829 of 110519 without CAA records (unrestricted certificate issuance)
110351 of 110519 without MTA-STS (email downgrade attacks possible)
Grade Distribution
Security across Europe
Average security score by country — hover for details, click to explore.
/100 · sites
Score by Country
Hosting & Data Residency
62%
EU-headquartered provider
38%
Non-EU provider (CLOUD Act / Schrems II)
Server location via IP geolocation (MaxMind GeoLite2). Company HQ from ASN registry. A site may be physically hosted in the EU but use a US-headquartered provider subject to the CLOUD Act — per Schrems II (CJEU C-311/18), this requires SCCs with supplementary measures. · GDPR Art. 44–49
All data is anonymized. No individual sites are identified. Statistics updated weekly.