Skip to main content
All Industries

EU Industry Benchmark

Regulatory

Anonymized security posture data for the regulatory sector across the EU. Based on 348 monitored sites.

49.3

Avg. Score /100

D

Avg. Grade

348

Sites Tracked

+10.0

vs. EU Average

Critical findings in this industry

158 of 348 without HTTPS redirect

45.0%

339 of 348 with unencrypted email (no STARTTLS)

97.0%

348 of 348 without DMARC protection (spoofable)

100.0%

109 of 348 missing 3+ critical security headers

31.0%

249 of 348 without DNSSEC (vulnerable to DNS spoofing)

72.0%

295 of 348 without CAA records (unrestricted certificate issuance)

85.0%

331 of 348 without MTA-STS (email downgrade attacks possible)

95.0%

Grade Distribution

A
0 (0.0%)
B
6 (2.0%)
C
74 (21.0%)
D
192 (55.0%)
F
76 (22.0%)

Security across Europe

Average security score by country — hover for details, click to explore.

Hosting & Data Residency

29%

EU-headquartered provider

71%

Non-EU provider (CLOUD Act / Schrems II)

Cloudflare (US) 49 35.5%
Amazon Web Services (US) 25 18.1%
Microsoft Azure (US) 17 12.3%
Hetzner (DE) 12 8.7%
OVHcloud (FR) 9 6.5%

Server location via IP geolocation (MaxMind GeoLite2). Company HQ from ASN registry. A site may be physically hosted in the EU but use a US-headquartered provider subject to the CLOUD Act — per Schrems II (CJEU C-311/18), this requires SCCs with supplementary measures. · GDPR Art. 44–49

How does your site compare?

Run a free security scan and see your grade instantly.

Scan your site

All data is anonymized. No individual sites are identified. Statistics updated weekly.