Skip to main content

Finland security reports

Browse 1,714 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155885
Websites
130
Industries
113
Countries
52
Avg Score
Page 4 of 35|Showing 151-200 of 1714
aurinkomatkat.fi favicon

Aurinkomatkat Oy

aurinkomatkat.fi

66
HospitalityFinlandlargeMEDIUM

Aurinkomatkat Oy is a prominent Finnish travel agency specializing in package holidays, last-minute deals, city breaks, and family vacations. The company offers a comprehensive range of travel services including flights, hotels, car rentals, and travel insurance, targeting Finnish travelers seeking reliable and convenient holiday solutions. The website reflects a mature business with a strong market position in Finland, supported by clear branding and trust indicators such as the Avainlippu certification and partnerships with Finnair and CarTrawler. Technically, the website is built using modern web technologies including React and integrates Google Tag Manager and Salesforce Chat for analytics and customer support. The site is well-optimized for mobile devices, accessible, and SEO-friendly, providing a smooth user experience. The content is rich, professionally designed, and structured for easy navigation. From a security perspective, the site enforces HTTPS, implements standard security headers, and provides cookie consent mechanisms aligned with GDPR requirements. However, explicit security policies and incident response information are not published, and there is no visible vulnerability disclosure or security.txt file. No vulnerabilities or exposed sensitive data were detected. Overall, Aurinkomatkat.fi demonstrates a high level of professionalism, security, and compliance suitable for its business domain. Strategic recommendations include publishing detailed security policies, establishing a vulnerability disclosure program, and enhancing transparency on data retention to further strengthen trust and security posture.

75
10
17
80
72
85
100
travelholidaypackagetoursfinnishtravelagencyvacation+3 more
ReactGoogle Tag ManagerSalesforce ChatProxima Nova fonts+1

Partner Domains:

aurinkomatkat.cartrawler.com
partner
www.finnair.com
partner

+1 more partners

2025-10-23T11:37:20.750Z
palta.fi favicon

Palvelualojen työnantajat PALTA ry

palta.fi

70
OtherFinlandlargeMEDIUM

Palvelualojen työnantajat PALTA ry is a prominent Finnish employer association representing service sector employers. The organization acts as a key influencer and negotiator in labor market agreements, serving approximately 2600 members and holding a significant position as the second largest member union in the Confederation of Finnish Industries (EK). Their website reflects a professional and well-structured digital presence, offering comprehensive information about their sectors, services, and events, targeting employers and decision-makers in Finland's service industries. The site is bilingual, primarily in Finnish with English alternatives, enhancing accessibility for international visitors. Technically, the website is built on WordPress with modern JavaScript frameworks like React and uses analytics tools such as Matomo and Google Tag Manager. The site employs hCaptcha for bot protection and demonstrates good mobile optimization and accessibility standards. While the site uses HTTPS and some security best practices, explicit security headers and a formal security policy are not evident, indicating room for improvement in security posture. Security-wise, the site shows no signs of vulnerabilities or exposed sensitive data. However, it lacks a published incident response or vulnerability disclosure policy, which could enhance trust and preparedness. Privacy compliance is partially addressed with a privacy and cookie policy present, though no active cookie consent mechanism is detected. Contact information is primarily via contact forms, with no direct emails or phone numbers visible on the main page. Overall, the website is trustworthy, professional, and well-aligned with the organization's business objectives. Strategic recommendations include enhancing security headers, publishing security and vulnerability disclosure policies, implementing cookie consent mechanisms, and providing clearer direct contact channels for security and privacy inquiries.

80
10
17
87
95
85
100
employerassociationservicesectorworkplacetradeunionfinland+3 more
WordPressReactMatomo AnalyticsGoogle Tag Manager+1

Partner Domains:

www.paltapalvelu.fi
service
palta.creamailer.fi
service
2025-10-23T10:33:15.456Z
stiga.com favicon

STIGA Oy

stiga.com

72
ManufacturingFinlandlargeMEDIUM

STIGA Oy is a well-established Finnish company specializing in manufacturing and retailing garden machinery such as lawn mowers, garden tractors, brush cutters, and chainsaws. The company targets both consumers and professionals seeking quality garden equipment. Their website reflects a mature digital presence with a Magento-based e-commerce platform, integrating advanced analytics and marketing tools to optimize user experience and business operations. The site is professionally designed, mobile-optimized, and provides clear contact and privacy information, enhancing user trust. From a technical perspective, the website employs modern web technologies including RequireJS, jQuery, Google Tag Manager, and New Relic monitoring. The integration of Cookiebot ensures compliance with cookie consent regulations, and the site uses HTTPS with implied security headers, indicating a good security posture. However, explicit security policies and vulnerability disclosure mechanisms are not publicly available, representing an area for improvement. Security-wise, the site demonstrates strong practices such as encrypted connections, cookie consent management, and monitoring tools. No critical vulnerabilities or exposed sensitive data were detected. The absence of WHOIS data is a minor concern but does not detract significantly from the site's legitimacy given the professional presentation and comprehensive privacy compliance. Overall, STIGA Oy's website is a robust digital asset supporting their business operations effectively. Strategic recommendations include publishing explicit security policies, implementing vulnerability disclosure channels, and enhancing accessibility compliance to further strengthen their security and compliance posture.

55
95
17
80
62
85
100
e-commercegardenmachinerylawnmowersprivacycookieconsent+3 more
Magento eCommerce platformRequireJSjQueryGoogle Tag Manager+3

Partner Domains:

www.salesforce.com
partner
www.klarna.com
partner

+2 more partners

2025-10-23T07:36:50.246Z
misterspex.com favicon

Mister Spex SE

misterspex.com

11
RetailFinlandlargeCRITICAL

Mister Spex SE is a leading European omnichannel eyewear retailer founded in 2007, specializing in the sale of prescription glasses, sunglasses, and contact lenses. The company operates multiple online stores across Europe and physical retail locations, serving over 7.1 million customers. Their business model focuses on digital innovation, including virtual try-on and home trial services, positioning them as a market leader in digital eyewear retail. The website is professionally designed, mobile-optimized, and provides comprehensive product and service information in Finnish, targeting Finnish consumers. Technically, the site leverages modern frameworks such as Next.js and React, uses CDN services like CloudFront, and integrates advanced personalization and consent management tools, reflecting a mature digital infrastructure. Security-wise, the site enforces HTTPS, implements strong security headers, and uses cookie consent mechanisms, though it lacks publicly available security policies or incident response details. Overall, the site demonstrates a high level of professionalism, trustworthiness, and compliance with privacy regulations, making it a reliable platform for consumers. Strategic recommendations include publishing explicit security and incident response policies and adding vulnerability disclosure information to enhance transparency and trust.

-
-
-
-
-
-
-
eyewearopticsecommerceglassescontactlenses+4 more
ReactNext.jsCloudinary (image hosting)Google Tag Manager+2
2025-10-23T05:25:15.644Z
bimobject.com favicon

BIMobject

bimobject.com

73
TechnologyFinlandlargeMEDIUM

BIMobject is a leading technology platform specializing in providing free BIM (Building Information Modeling) objects and content for architects, engineers, and construction professionals. The website offers a comprehensive catalog of BIM objects from over 2,000 manufacturers, supporting multiple design software platforms such as Revit, SketchUp, and ArchiCAD. The platform also enables manufacturers to publish their products, positioning BIMobject as a key player in the digital construction ecosystem. Technically, the website is built on a modern Angular framework with integrations for Google Tag Manager and OneTrust for privacy compliance, reflecting a mature digital infrastructure. Security posture is strong with HTTPS enforcement and standard security headers, although explicit security policies and incident response contacts are not publicly detailed. Overall, the site demonstrates high professionalism, good privacy compliance, and a trustworthy user experience, though the absence of WHOIS registration data slightly reduces transparency. Strategic recommendations include publishing detailed security policies, adding vulnerability disclosure mechanisms, and providing direct contact channels for security and business inquiries.

55
80
2
80
100
85
100
bimbuildinginformationmodelingarchitectureengineeringconstruction+4 more
Angular 19.2.8Google Tag ManagerOneTrust Cookie ConsentWebmanifest+1

Partner Domains:

business.bimobject.com
partner
account.bimobject.com
service
2025-10-21T13:52:52.062Z
wicona.com favicon

WICONA

wicona.com

65
ManufacturingFinlandlargeMEDIUM

WICONA is a well-established company specializing in architectural aluminum systems, serving primarily the construction and architectural sectors. The website reflects a professional B2B business model with a focus on product offerings such as facades, windows, doors, and sliding systems. The company is a subsidiary of Hydro, a global aluminum company, which supports its market position and credibility. The website is targeted at architects, builders, and construction professionals, providing detailed product information and resources. Technically, the site employs modern web technologies including jQuery, Google Tag Manager, Cookiebot for consent management, and Microsoft Azure services for hosting and telemetry, indicating a mature digital infrastructure. The site is mobile-optimized and accessible, with good SEO practices evident from meta tags and structured cookie consent mechanisms. Security-wise, the website enforces HTTPS and includes a Content Security Policy header, but lacks some additional security headers and explicit privacy and terms of service pages. The cookie consent mechanism is comprehensive and GDPR compliant, with detailed cookie categorization and user control. However, the absence of visible contact information and WHOIS data inconsistency slightly reduce trustworthiness. Overall, the website is professional, secure, and compliant, but could improve transparency and contact accessibility to enhance user trust and compliance posture.

15
83
2
70
100
70
100
architecturealuminumsystemsfacadeswindowsdoors+6 more
jQueryGoogle Tag ManagerCookiebotMicrosoft Azure Application Insights+1

Partner Domains:

wictip.wicona.com
partner
bs.hydro.com
parent
2025-10-21T12:47:23.503Z
tietoevry.com favicon

Tietoevry

tietoevry.com

81
TechnologyFinlandenterpriseLOW

Tietoevry is a leading global software and digital engineering services company specializing in digital transformation, IT, ICT, data, and AI solutions. The company targets enterprise clients seeking to leverage technology for business advantage. Their website reflects a mature digital presence with comprehensive service offerings and a strong market position in the technology sector. The site is professionally designed, mobile-optimized, and well-structured for user experience. Technically, the website employs modern technologies including Azure Application Insights for monitoring, Google Tag Manager for analytics, and OneTrust for cookie consent management, indicating a high level of digital maturity. Hosting appears to be on Microsoft Azure, supporting scalability and performance. The site demonstrates good SEO and accessibility practices. From a security perspective, the site enforces HTTPS, uses multiple security headers, and integrates consent mechanisms for privacy compliance. No obvious vulnerabilities or exposed sensitive data were detected. However, the absence of WHOIS registration data raises questions about domain registration transparency, though the website content and certifications strongly support legitimacy. Overall, Tietoevry's website presents a low-risk profile with strong business credibility and security posture. Strategic recommendations include enhancing transparency around domain registration, publishing incident response procedures, and maintaining vigilant third-party script audits to sustain security and trust.

75
88
47
83
85
85
100
digitaltransformationsoftwareservicesitservicesaidata+1 more
JavaScriptAzure Application InsightsGoogle Tag ManagerOneTrust Consent Management+1
2025-10-21T06:28:34.363Z
chiesirarediseases.com favicon

Chiesi Global Rare Diseases

chiesirarediseases.com

10
HealthcareFinlandmediumCRITICAL

Chiesi Global Rare Diseases is a family-owned biopharmaceutical company specializing in rare disease therapeutics. The company positions itself as a Certified B Corporation committed to providing innovative treatments and support to patients with rare diseases. Their market position is niche but well-established, supported by a clear business model focused on research, development, and patient advocacy. The website reflects a medium-sized enterprise with a global presence and a parent company, Chiesi Farmaceutici S.p.A., which recently acquired Amryt Pharma, expanding its portfolio. Technically, the website uses modern frameworks such as Bootstrap and integrates Google Tag Manager for analytics. Hosting is managed via EasyDNS, and the site is mobile-optimized with good SEO practices. Accessibility is basic but present. Security posture is adequate with HTTPS enforced, though some improvements like enabling DNSSEC and adding security headers are recommended. Privacy compliance is strong with clear privacy and cookie policies and GDPR adherence. Overall, the security posture is solid with no critical vulnerabilities detected, but the absence of a public security policy or incident response information is a gap. The domain WHOIS data is consistent with the business claims, showing transparency and legitimacy. The website content is safe for general audiences, focusing on healthcare and patient support without any adult or explicit content. Strategic recommendations include enhancing security headers, publishing a security policy, and implementing a vulnerability disclosure program to further strengthen trust and compliance.

-
-
-
-
-
-
-
rarediseasebiopharmaceuticalhealthcarepatientsupportfamily-owned+1 more
Bootstrap 4.6.0jQueryFontAwesome 5.10.0Google Tag Manager+2

Partner Domains:

chiesiusa.com
partner
chiesi.com
parent

+1 more partners

2025-10-20T17:07:21.491Z
ferrero.com favicon

Ferrero Group

ferrero.com

71
RetailFinlandenterpriseMEDIUM

Ferrero Group is a globally recognized Italian family-owned confectionery company founded in 1946, with a strong presence in over 170 countries and a portfolio of more than 35 iconic brands including Nutella®, Kinder®, Tic Tac®, and Ferrero Rocher®. The company emphasizes quality, tradition, and sustainability, supported by a workforce of approximately 47,000 employees. The website reflects a mature digital presence with comprehensive content, multimedia integration, and multi-language support, targeting a broad consumer and business audience. Technically, the site is built on Drupal CMS, employs modern web technologies such as Google Tag Manager and lazy loading, and demonstrates good mobile optimization and accessibility standards. Security posture is solid with HTTPS enforced and no visible vulnerabilities, though explicit security headers and incident response contacts are not evident. Privacy and cookie policies are present with consent mechanisms, indicating GDPR compliance. The absence of WHOIS data is notable but likely due to privacy protection or query limitations, not detracting from the site's legitimacy. Overall, the site is professional, trustworthy, and well-maintained.

80
35
17
73
95
80
100
confectionerycorporatefamilybusinesssustainabilitybrands+2 more
Google Tag ManagerAddToAny sharingDrupal CMSGoogle Fonts+2

Partner Domains:

www.ferrerocareers.com
partner
www.ferrerosuppliers.com
partner

+3 more partners

2025-10-19T19:48:52.774Z
energiequelle.fi favicon

Energiequelle Oy

energiequelle.fi

50
EnergyFinlandlargeMEDIUM

Energiequelle Oy is a well-established renewable energy company founded in 1997, operating internationally with a strong presence in Finland and other European countries. The company specializes in the development, construction, and operation of renewable energy projects including wind power, solar power, energy storage, hydrogen, and P2X solutions. Their market position is strong as a leading player in the European renewable energy sector, employing over 600 professionals and having completed more than 850 power plants. The website reflects a professional and comprehensive digital presence with clear business information and international reach. Technically, the website is built on the Neos CMS platform using modern web technologies such as PHP, JavaScript, and various UI libraries. It is mobile-optimized, accessible, and SEO-friendly, with a cookie consent mechanism that complies with GDPR requirements. The site uses HTTPS with good SSL configuration, though explicit security headers could be improved. No critical vulnerabilities or exposed sensitive data were detected. From a security perspective, the site demonstrates good practices including encrypted communications and user consent management. However, it lacks publicly available security policies or incident response contacts, which could enhance trust and preparedness. The WHOIS data aligns well with the company’s stated history and location, supporting legitimacy. Overall, Energiequelle Oy’s website is a secure, professional, and trustworthy platform that effectively supports its business objectives in the renewable energy market. Strategic improvements in security transparency and policy publication would further strengthen its security posture and stakeholder confidence.

15
40
17
60
-
80
100
renewableenergywindpowersolarpowerenergystoragehydrogen+4 more
PHPJavaScriptjQueryOwl Carousel+5

Partner Domains:

energiequelle.com
partner
energiequelle.de
partner

+3 more partners

2025-10-19T07:50:10.354Z
nordhealth.com favicon

Nordhealth Ltd

nordhealth.com

74
HealthcareFinlandlargeMEDIUM

Nordhealth Ltd is a well-established healthcare technology company specializing in software and APIs for healthcare and veterinary professionals. With over 18 years of experience and a large user base of clinics and healthcare professionals worldwide, Nordhealth offers products such as Provet Cloud and Diarium that streamline practice management and improve patient care. The company has demonstrated growth through acquisitions and maintains a strong Nordic identity focused on innovation and modern design. Technically, the website is built using modern static site generation technology (Eleventy), hosted on AWS infrastructure, and employs privacy-conscious analytics (Fathom). The site is fast, mobile-optimized, and accessible, reflecting a mature digital presence. Security posture is solid with HTTPS enforced and no obvious vulnerabilities, though there is room for improvement in publishing explicit security policies and enabling DNSSEC. Overall, the domain registration and WHOIS data align well with the company's history and legitimacy. The website is professional, trustworthy, and compliant with GDPR, though direct contact emails and incident response contacts are not publicly listed. Strategic recommendations include enhancing security transparency and incident response readiness to further strengthen trust and compliance.

65
53
2
100
97
90
100
healthcareveterinarysoftwaresaasnordic+1 more
Eleventy (static site generator)AWS Route 53 DNSFathom AnalyticsService Worker+1

Partner Domains:

www.vetera.net
subsidiary
easypractice.net
subsidiary

+1 more partners

2025-10-18T19:39:43.640Z
nokia.com favicon

Nokia Corporation

nokia.com

82
TechnologyFinlandenterpriseLOW

Nokia Corporation is a globally recognized leader in telecommunications and technology infrastructure, providing mobile, fixed, and cloud network solutions. The company operates as a B2B technology provider serving enterprises, governments, and technology professionals worldwide. With a founding date of 1865 and a large enterprise size, Nokia maintains a strong market position supported by subsidiaries such as Nokia Networks and Nokia Bell Labs. The website reflects this stature with professional design, consistent branding, and comprehensive corporate information. Technically, the website is built on Drupal 10 CMS and integrates advanced marketing and analytics tools including Marketo, Google Tag Manager, Google Analytics, and New Relic. Performance is moderate with good mobile optimization and SEO practices. Accessibility is basic but functional. The site employs modern security headers and enforces HTTPS, indicating a strong security posture. However, explicit security policy pages and incident response contacts are not evident. Security-wise, the site demonstrates best practices such as content security policies and cookie consent mechanisms, with no visible vulnerabilities or exposed sensitive data. The absence of WHOIS data is noted but attributed to registry restrictions rather than suspicious activity. Overall, the site is trustworthy and professionally maintained. Strategically, Nokia should consider publishing explicit security policies and vulnerability disclosure information to enhance transparency and trust. Improving accessibility and regularly auditing third-party scripts will further strengthen the security and user experience. These steps will support Nokia's reputation as a secure and reliable technology leader.

75
73
55
85
100
80
100
technologytelecommunicationscorporateenterpriseb2b+3 more
Drupal 10 CMSMarketo marketing automationGoogle Tag ManagerGoogle Analytics+3

Partner Domains:

nokia-sbell.com
subsidiary
2025-10-18T08:19:04.119Z
nordhealth.design favicon

Nordhealth Oy

nordhealth.design

60
TechnologyFinlandsmallMEDIUM

Nordhealth Oy operates the Nord Design System website, providing a comprehensive design system tailored for healthcare and veterinary software development. The company, founded in 2021 and based in Finland, offers a suite of design tokens, web components, CSS frameworks, themes, iconography, and Figma toolkits to enable coherent and efficient software design and development. The website reflects a professional and modern digital presence, targeting software developers and designers in the healthcare sector. The market position is niche but well-defined, focusing on specialized design solutions for healthcare and veterinary applications. Technically, the website is built using the Eleventy static site generator, hosted likely on AWS infrastructure, and employs modern web technologies including JavaScript ES modules and service workers. The site is optimized for performance, mobile responsiveness, and accessibility, with good SEO practices. Analytics are implemented via Fathom Analytics, emphasizing minimal user tracking and privacy. From a security perspective, the site uses HTTPS with a good SSL configuration and domain registration protections such as client update, delete, and transfer prohibitions. However, DNSSEC is not enabled, and no explicit security headers were detected. Privacy compliance is lacking, with no visible privacy or cookie policies, which is a notable gap. No contact emails or phone numbers are explicitly provided, limiting direct communication channels. Overall, the website demonstrates a strong professional and trustworthy presence with a solid technical foundation. The main risks relate to privacy compliance and security header implementation. Strategic improvements in these areas would enhance trust and regulatory adherence.

15
50
2
70
95
65
100
designsystemhealthcareveterinaryuicomponentsstaticsite+2 more
Eleventy v2.0.1JavaScript ES ModulesAWS DNSFathom Analytics
2025-10-18T07:06:22.649Z
lego.com favicon

The LEGO® Group

lego.com

74
RetailFinlandenterpriseMEDIUM

The LEGO® Group is a globally recognized enterprise specializing in the design, manufacture, and retail of LEGO building toys and related merchandise. The website serves as an official e-commerce platform targeting a broad audience including children, families, and adult LEGO enthusiasts. It offers a comprehensive product catalog, digital content, and a loyalty program to enhance customer engagement. The company is a subsidiary of Kirkbi A/S and has a long-standing market presence since its founding in 1932. Technically, the website employs modern web technologies such as React and Next.js, optimized for performance and mobile responsiveness. It integrates analytics via New Relic and uses advanced image formats like WebP for efficient content delivery. The site demonstrates good SEO practices and accessibility features, ensuring a high-quality user experience. From a security perspective, the website enforces HTTPS, implements multiple security headers, and avoids exposing sensitive data. While no explicit incident response or vulnerability disclosure policies are publicly available, the overall security posture is strong. Privacy and cookie policies are comprehensive and GDPR compliant, reflecting a mature approach to data protection. Overall, the website is professional, trustworthy, and well-aligned with the LEGO brand. The absence of WHOIS data is likely due to registry restrictions and does not detract from the site's legitimacy. Strategic recommendations include enhancing transparency around security policies and incident response to further build user trust.

55
85
25
85
65
90
100
toyse-commercelegobuildingsetsfamily+1 more
ReactNext.jsNew RelicWebP images+2

Partner Domains:

www.kirkbi.com
parent
2025-10-17T15:19:41.316Z
icncongress.org favicon

International Council of Nurses

icncongress.org

70
HealthcareFinlandmediumMEDIUM

The ICN Congress 2025 website serves as the official platform for the 30th International Council of Nurses Congress, scheduled for June 2025 in Helsinki, Finland. It provides comprehensive information about the event, including scientific programs, speakers, photo galleries, and registration details. The site targets nursing professionals, students, and healthcare stakeholders globally, emphasizing nursing's role in shaping healthcare policy and delivery. The business model centers on event organization and professional development, supported by sponsorships and accreditation partnerships. Technically, the website is built on a Ruby on Rails framework with modern JavaScript libraries such as jQuery, Bootstrap, and Mapbox for interactive maps. It integrates third-party services like HelpScout for customer support and hCaptcha for bot mitigation. Hosting appears to be on AWS infrastructure, inferred from DNS records. The site is mobile-optimized with a responsive design and supports multiple languages, enhancing accessibility for an international audience. From a security perspective, the website enforces HTTPS and uses clientTransferProhibited status on the domain to prevent unauthorized transfers. However, DNSSEC is not enabled, and no explicit HTTP security headers were detected in the HTML content, indicating room for improvement. The site employs CSRF tokens and bot protection mechanisms but lacks publicly visible security or incident response policies. Privacy compliance is well addressed with clear privacy and cookie policies, including GDPR considerations. Overall, the website presents a professional and trustworthy front for a reputable international nursing organization. It effectively balances content richness, user experience, and basic security measures. Strategic enhancements in DNS security, HTTP headers, and documented security policies would further strengthen its posture and trustworthiness.

75
68
2
80
77
80
100
healthcarenursingeventconferenceprofessionaldevelopment+2 more
Ruby on RailsjQueryBootstrapMapbox GL JS+4

Partner Domains:

confedent.eventsair.com
partner
icn.ch
partner

+1 more partners

2025-10-17T07:44:22.319Z