EU Industry Benchmark
NGO & Nonprofit
Anonymized security posture data for the ngo & nonprofit sector across the EU. Based on 11774 monitored sites.
42.6
Avg. Score /100
D
Avg. Grade
11774
Sites Tracked
-0.0
vs. EU Average
Critical findings in this industry
6247 of 11774 without HTTPS redirect
10970 of 11774 with unencrypted email (no STARTTLS)
11596 of 11774 without DMARC protection (spoofable)
6650 of 11774 missing 3+ critical security headers
10235 of 11774 without DNSSEC (vulnerable to DNS spoofing)
11377 of 11774 without CAA records (unrestricted certificate issuance)
11631 of 11774 without MTA-STS (email downgrade attacks possible)
Grade Distribution
Security across Europe
Average security score by country — hover for details, click to explore.
/100 · sites
Score by Country
Hosting & Data Residency
66%
EU-headquartered provider
34%
Non-EU provider (CLOUD Act / Schrems II)
Server location via IP geolocation (MaxMind GeoLite2). Company HQ from ASN registry. A site may be physically hosted in the EU but use a US-headquartered provider subject to the CLOUD Act — per Schrems II (CJEU C-311/18), this requires SCCs with supplementary measures. · GDPR Art. 44–49
All data is anonymized. No individual sites are identified. Statistics updated weekly.