EU Industry Benchmark
Regulatory
Anonymized security posture data for the regulatory sector across the EU. Based on 348 monitored sites.
49.3
Avg. Score /100
D
Avg. Grade
348
Sites Tracked
+10.0
vs. EU Average
Critical findings in this industry
158 of 348 without HTTPS redirect
339 of 348 with unencrypted email (no STARTTLS)
348 of 348 without DMARC protection (spoofable)
109 of 348 missing 3+ critical security headers
249 of 348 without DNSSEC (vulnerable to DNS spoofing)
295 of 348 without CAA records (unrestricted certificate issuance)
331 of 348 without MTA-STS (email downgrade attacks possible)
Grade Distribution
Security across Europe
Average security score by country — hover for details, click to explore.
/100 · sites
Score by Country
Hosting & Data Residency
29%
EU-headquartered provider
71%
Non-EU provider (CLOUD Act / Schrems II)
Server location via IP geolocation (MaxMind GeoLite2). Company HQ from ASN registry. A site may be physically hosted in the EU but use a US-headquartered provider subject to the CLOUD Act — per Schrems II (CJEU C-311/18), this requires SCCs with supplementary measures. · GDPR Art. 44–49
All data is anonymized. No individual sites are identified. Statistics updated weekly.