Skip to main content
All Benchmarks
985 sites · May 2025

EU Website Security Benchmark — May 2025

Security posture snapshot for May 2025 across 985 monitored European websites.

57.9/100

Average score

52%

Email spoofable

78%

No DNSSEC

56%

Missing security headers

How does your industry compare?

Security posture by industry — sorted by average score. Click an industry to see its detailed breakdown.

Industry Sites Score Unprotected Spoofable Insecure Grade distribution
Pharma 39
49.1
54% 87% 13%
C
D
F
Automotive 19
51.8
58% 68% 21%
B
C
D
F
Banking 120
54.9
53% 56% 28%
C
D
F
Media 140
55.1
71% 66% 11%
C
D
E-Commerce 175
55.2
59% 61% 25%
C
D
F
Government 95
58.1
48% 61% 19%
C
D
F
Insurance 42
61.2
43% 45% 24%
B
C
D
F
Technology 265
61.9
52% 37% 14%
B
C
D
Regulatory 90
63.5
51% 28% 13%
B
C
D

Sorted by average security score (lowest first). Column explanations: Unprotected = missing 3+ critical HTTP headers. Spoofable = no or weak DMARC. Insecure = no HTTPS redirect.

A B C D F

What we found

The most common security gaps across 985 European websites — and the regulations they violate.

56%

Missing Security Headers

Visitors are exposed to clickjacking, XSS, and content injection because critical HTTP headers are missing.

NIS2 Art. 21

52%

Weak Email Authentication

Emails from these domains can be spoofed — invoices, password resets, anything. No DMARC enforcement.

NIS2 Art. 21 / DORA Art. 9

78%

No DNSSEC

DNS responses are unsigned. Attackers can redirect visitors to fake sites without detection.

NIS2 Art. 21

Where does your website fit in this picture?

Run a free security scan — no account needed. See your score, grade, and how you compare to your industry.

Scan your website now

This data is also available as JSON via the Benchmark API.