EU Industry Benchmark
Travel
Anonymized security posture data for the travel sector across the EU. Based on 23323 monitored sites.
38.9
Avg. Score /100
F
Avg. Grade
23323
Sites Tracked
0.0
vs. EU Average
Critical findings in this industry
21291 of 23323 without HTTPS redirect
22931 of 23323 with unencrypted email (no STARTTLS)
23289 of 23323 without DMARC protection (spoofable)
5212 of 23323 missing 3+ critical security headers
19061 of 23323 without DNSSEC (vulnerable to DNS spoofing)
22643 of 23323 without CAA records (unrestricted certificate issuance)
23210 of 23323 without MTA-STS (email downgrade attacks possible)
Grade Distribution
Security across Europe
Average security score by country — hover for details, click to explore.
/100 · sites
Score by Country
Hosting & Data Residency
65%
EU-headquartered provider
35%
Non-EU provider (CLOUD Act / Schrems II)
Server location via IP geolocation (MaxMind GeoLite2). Company HQ from ASN registry. A site may be physically hosted in the EU but use a US-headquartered provider subject to the CLOUD Act — per Schrems II (CJEU C-311/18), this requires SCCs with supplementary measures. · GDPR Art. 44–49
All data is anonymized. No individual sites are identified. Statistics updated weekly.