web-hardening · severity medium
Security headers
Share of web-serving domains missing HSTS and Content-Security-Policy response headers.
Measured every Thursday · last updated
How it is measured
Tier 3a; check Strict-Transport-Security, Content-Security-Policy, X-Frame-Options on the homepage response. Denominator: has_web.
Why it matters
HSTS is what stops the first, downgradeable request; CSP is what limits the damage of injected script. Both are one-line changes, and both are commonly switched off silently by a framework upgrade or a proxy change.
The base rate
Two independent populations. The global, domain-anchored figure is unbiased; the company-anchored figures are built by matching company names to domains and skew toward more digitally-mature firms. Both are published, so the gap is visible.
By company size band
Company-anchored cuts (national registries with a size proxy), split by size band. Right-hand figure is the share not meeting the control.
Every segment
Pick one to see the citable answer for a company like yours, with its trend and methodology.
Show the remaining 62 segments
From the newsletter
Where this base rate turned up as a real, fixable exposure.
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.