Skip to main content
All Industries

EU Industry Benchmark

Regulatory

Anonymized security posture data for the regulatory sector across the EU. Based on 349 monitored sites.

47.5

Avg. Score /100

D

Avg. Grade

349

Sites Tracked

+4.0

vs. EU Average

Critical findings in this industry

317 of 349 without HTTPS redirect

91.0%

225 of 349 with unencrypted email (no STARTTLS)

64.0%

234 of 349 without DMARC protection (spoofable)

67.0%

27 of 349 missing 3+ critical security headers

8.0%

249 of 349 without DNSSEC (vulnerable to DNS spoofing)

71.0%

296 of 349 without CAA records (unrestricted certificate issuance)

85.0%

333 of 349 without MTA-STS (email downgrade attacks possible)

95.0%

Grade Distribution

A
0 (0.0%)
B
4 (1.0%)
C
43 (12.0%)
D
218 (62.0%)
F
84 (24.0%)

Security across Europe

Average security score by country — hover for details, click to explore.

Hosting & Data Residency

29%

EU-headquartered provider

71%

Non-EU provider (CLOUD Act / Schrems II)

Cloudflare (US) 49 35.5%
Amazon Web Services (US) 25 18.1%
Microsoft Azure (US) 17 12.3%
Hetzner (DE) 12 8.7%
OVHcloud (FR) 9 6.5%

Server location via IP geolocation (MaxMind GeoLite2). Company HQ from ASN registry. A site may be physically hosted in the EU but use a US-headquartered provider subject to the CLOUD Act — per Schrems II (CJEU C-311/18), this requires SCCs with supplementary measures. · GDPR Art. 44–49

How does your site compare?

Run a free security scan and see your grade instantly.

Scan your site

All data is anonymized. No individual sites are identified. Statistics updated weekly.