Skip to main content

Norway security reports

Browse 1,098 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

157327
Websites
130
Industries
113
Countries
52
Avg Score
Page 22 of 22|Showing 1051-1098 of 1098
nilu.no favicon

Norsk institutt for luftforskning

nilu.no

54
OtherNorwaymediumMEDIUM

NILU (Norsk institutt for luftforskning) is a well-established Norwegian non-profit research institute specializing in climate and environmental research. Founded in 1969, it holds a strong market position as an internationally leading institute in its field. The website reflects a professional and content-rich platform targeting researchers, policymakers, and environmental stakeholders. NILU offers a range of services including atmospheric research, urban air quality studies, environmental toxin analysis, and laboratory services. The organization is ISO 9001 and ISO 14001 certified, reinforcing its credibility and commitment to quality and environmental management. Technically, the website is built on WordPress with modern libraries such as jQuery, Bootstrap, and Select2, hosted behind Cloudflare. The site demonstrates good mobile optimization, accessibility, and SEO practices. However, performance metrics are unavailable, and some technical debt exists in the form of missing or invalid SSL/TLS configuration, which is a critical security concern. Security posture is weakened by the absence of a valid SSL certificate and disabled TLS protocols, exposing users to potential risks. While security headers are present, the lack of HTTPS and HSTS reduces overall security. Privacy compliance is good with a comprehensive GDPR-compliant privacy policy, but the absence of a cookie consent mechanism is a gap. Contact information is complete and transparent, including email, phone, and physical addresses, alongside active social media channels. Overall, NILU's website is professional and trustworthy but requires urgent security improvements to protect user data and maintain trust. Strategic recommendations include implementing a valid SSL certificate, enabling modern TLS protocols, and adding cookie consent mechanisms to enhance privacy compliance.

65
25
25
50
50
90
100
environmentresearchclimatenon-profitnorway+2 more
WordPress 6.8.1jQuery 3.7.1Bootstrap 4.1.1Select2 4.0.5+5

Partner Domains:

norin.no
partnerpending
ciens.no
partnerpending

+2 more partners

2025-06-15T13:19:43.585Z
kystverket.no favicon

Kystverket

kystverket.no

60
GovernmentNorwaylargeMEDIUM

Kystverket is a Norwegian government agency responsible for maritime safety, navigation, and environmental protection along the Norwegian coast. The website serves as a portal for digital maritime services, including navigation aids, real-time ship tracking, and environmental alerts. It targets maritime professionals, coastal communities, and the general public interested in maritime affairs. The agency holds a strong national position as the authoritative maritime body in Norway. Technically, the website leverages Microsoft Azure infrastructure, ASP.NET Core framework, and integrates advanced analytics and consent management tools such as Microsoft Application Insights, Google Tag Manager, and Cookie Information. The site uses Episerver CMS and Cloudflare for CDN services. Despite a rich technical stack, the site suffers from critical SSL/TLS misconfigurations, lacking a valid certificate and disabling all TLS protocols, which severely impacts security posture. Security-wise, while the site implements HSTS with preload and includes no known major vulnerabilities like Heartbleed or POODLE, the absence of a valid SSL certificate and TLS support is a critical flaw. Cookie consent and privacy policies are comprehensive and GDPR compliant, reflecting good privacy practices. Contact information and social media presence enhance trust and transparency. Overall, the site is professionally designed with good content quality and user experience but requires urgent remediation of SSL/TLS issues to ensure secure communications. Strategic recommendations include fixing the SSL certificate, enabling modern TLS protocols, and improving OCSP stapling and session resumption. These steps will significantly enhance the security posture and user trust.

30
25
25
80
100
90
85
governmentmaritimenorwaynavigationenvironment+4 more
Microsoft AzureASP.NET CorePower BICloudflare+3
2025-06-15T13:19:43.146Z
dsa.no favicon

Direktoratet for strålevern og atomsikkerhet

dsa.no

74
GovernmentNorwaymediumMEDIUM

Direktoratet for strålevern og atomsikkerhet (DSA) is a Norwegian government directorate responsible for radiation protection and nuclear safety. The organization operates as a national authority providing regulatory oversight, monitoring radioactive emissions, and disseminating information to the public and relevant sectors such as veterinary and medical fields. The website serves as an official communication channel offering news, regulatory information, publications, and contact resources. It targets Norwegian citizens, government agencies, and professional sectors involved with radiation safety. Technically, the website is built on the Enonic CMS platform, hosted on Fastly CDN, and employs modern web technologies including jQuery and Google Tag Manager. The site supports TLS 1.3 and 1.2 with strong cipher suites, ensuring secure communications. However, performance is suboptimal with a slow load time and a large page size. Accessibility and SEO optimizations are well implemented, and the site is mobile responsive. From a security perspective, the site enforces HTTPS with valid certificates and implements SPF and DMARC email authentication policies with strict reject rules, reducing email spoofing risks. The absence of HSTS and DNSSEC are notable gaps. No critical vulnerabilities or exposed sensitive data were detected. Privacy and cookie policies are present and GDPR compliant, with a consent mechanism implemented. Overall, the website demonstrates a strong security posture and credible business presence consistent with a government agency. Recommendations include enabling HSTS, DNSSEC, and OCSP stapling to further harden security. Performance improvements would enhance user experience. The domain registration data aligns well with the organization's identity, supporting high trustworthiness.

75
25
25
80
87
85
100
governmentradiationnuclearsafetynorwaypublicservice+1 more
jQueryGoogle Tag ManagerPiwik PRO analyticsTLS 1.3+1
2025-06-15T13:19:43.026Z
framforum.com favicon

Framsenteret Drift AS

framforum.com

40
Non-profitNorwaysmallHIGH

Framforum is a specialized online publication operated by Framsenteret Drift AS, focusing on climate, environment, and people in the High North, particularly the Arctic region. The website serves as a communication platform for research notes, profiles, retrospectives, and editorials related to Arctic environmental research, targeting researchers, journalists, and interested public. The business operates as a non-profit entity with a clear affiliation to the Fram Centre, a recognized research center in Norway. Technically, the website is built on WordPress, utilizing common web technologies such as jQuery, Font Awesome, and Google Fonts, with Matomo and Google Tag Manager for analytics. However, the site suffers from a critical security shortfall: it lacks a valid SSL certificate and does not serve content over HTTPS, which undermines user trust and data security. While HSTS is enabled, it is ineffective without proper SSL/TLS configuration. Privacy compliance is minimal, with a privacy policy present but no cookie consent mechanism or GDPR compliance indicators. Contact information is clearly provided, enhancing business credibility. Overall, the site is content-rich and professionally designed but requires urgent security improvements to protect users and enhance trust.

70
43
17
50
82
70
-
arcticclimateenvironmentresearchnon-profit+1 more
WordPressPHPjQueryMatomo Analytics+3

Partner Domains:

framsenteret.no
partner40
2025-06-15T13:19:42.681Z
nersc.no favicon

Nansensenteret

nersc.no

56
GovernmentNorwaymediumMEDIUM

Nansensenteret (NERSC) is a Norwegian government-affiliated research center specializing in climate, ocean, sea ice, and atmospheric studies in the North Atlantic and Arctic regions. The website presents comprehensive information about ongoing research projects, publications, and organizational structure, targeting researchers, students, and stakeholders interested in climate and environmental sciences. The business model focuses on scientific research, data provision, and collaboration within the climate science community. Technically, the website is built on WordPress with modern plugins for SEO and multilingual support, delivering a moderate performance and good mobile optimization. However, the site lacks a valid SSL certificate, which critically impacts its security posture. The absence of HTTPS and security headers exposes the site to potential risks. Privacy compliance is weak due to missing privacy and cookie policies. Security evaluation reveals significant vulnerabilities, including invalid SSL, disabled TLS protocols, and missing security headers. These issues reduce trust and expose users to risks. The domain is mature and consistent with the organization's profile, enhancing business credibility despite technical shortcomings. Overall, the site is professionally designed with good content quality but requires urgent security improvements to protect users and comply with privacy regulations. Strategic recommendations include obtaining a valid SSL certificate, enabling modern TLS protocols, implementing security headers, and publishing privacy and cookie policies.

15
40
25
70
75
90
100
climateresearcharcticenvironmentnorway+2 more
WordPress 6.8.1WPBakery Page BuilderjQuery 3.7.1Rank Math SEO plugin+6
2025-06-15T13:19:19.398Z
diku.no favicon

Direktoratet for høyere utdanning og kompetanse

diku.no

49
EducationNorwaymediumHIGH

Direktoratet for høyere utdanning og kompetanse (HK-dir) is a Norwegian government agency responsible for national administration and policy implementation in higher education, vocational education, and competence development. Established in 2021 through a merger of several agencies, it serves as a key authority in Norway's education sector, providing services such as career guidance, foreign education recognition, funding programs, and statistical reporting. The website targets professionals and stakeholders in education and workforce development within Norway. Technically, the website is built using modern web technologies including Next.js and Sanity CMS, with integration of Google Fonts and Siteimprove Analytics. The site is well-structured, mobile-optimized, and provides good accessibility and SEO features. However, performance is moderate with a load time of approximately 5.8 seconds. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical vulnerability. No security headers or advanced TLS configurations are present, exposing the site to potential risks. Privacy compliance is strong, with a comprehensive GDPR-compliant privacy policy and clear contact information. No cookie consent mechanism or terms of service were found. Overall, while the business and content aspects are solid and trustworthy, the lack of HTTPS and proper SSL configuration significantly lowers the security posture and overall risk rating. Immediate remediation of SSL/TLS issues is recommended to protect user data and enhance trust.

35
25
25
55
50
85
100
educationgovernmenthighereducationcompetencenorway+1 more
React (Next.js)Google FontsSiteimprove AnalyticsNext.js
2025-06-15T13:19:10.365Z
arvenetternansen.com favicon

The Nansen Legacy

arvenetternansen.com

59
EducationNorwaymediumMEDIUM

The Nansen Legacy website represents a collaborative Arctic research project focused on the Barents Sea and related environmental studies. It serves as an information portal for research activities, team members, publications, and events. The project is supported by multiple Norwegian academic and governmental institutions, indicating a strong presence in the education and research sector. The website targets researchers, early career scientists, and stakeholders interested in Arctic science. Technically, the site is built on WordPress with Elementor and hosted on WordPress.com infrastructure. While the site uses HTTPS and modern web technologies, its performance is slow with a high number of resources loaded. Accessibility and SEO are basic to good, but there is room for improvement in security headers and advanced SSL configurations. Security posture is moderate with valid SSL but lacking HSTS and OCSP stapling. No explicit privacy or cookie policies were found, which is a compliance gap especially under GDPR. Contact information is limited to an email address, with no phone numbers or detailed business registration data visible. Social media presence is active on major platforms. Overall, the site is a credible academic project portal but would benefit from enhanced privacy compliance, improved security headers, and performance optimizations to strengthen trust and user experience.

30
25
25
50
67
80
100
arcticresearchscienceeducationenvironmentalstudiesresearchconsortium
WordPressElementorPHPjQuery+2

Partner Domains:

forskningsradet.no
partnerpending
regjeringen.no
partnerpending

+3 more partners

2025-06-15T13:10:49.588Z
framsenteret.no favicon

Framsenteret Drift AS

framsenteret.no

40
GovernmentNorwaymediumHIGH

Framsenteret Drift AS operates as a Norwegian Arctic research center focused on interdisciplinary climate and environmental research of high international standard. The organization collaborates with numerous research institutions and partners, positioning itself as a key player in Arctic research and policy support. The website serves as a platform for disseminating research findings, hosting events, and providing information about ongoing projects and collaborations. The target audience includes researchers, policymakers, environmental stakeholders, and the general public interested in Arctic issues. Technically, the website is built on WordPress with a modern tech stack including jQuery, Font Awesome, and Matomo analytics for privacy-conscious user tracking. The site is well-structured with good SEO metadata and accessibility features, though performance is slow with a load time exceeding 12 seconds. Mobile optimization is good, and navigation is clear and professional. From a security perspective, the site lacks a valid SSL certificate and does not support HTTPS, which is a critical vulnerability. No modern TLS protocols are enabled, and advanced security features like OCSP stapling and session resumption are missing. The site does implement HSTS but without HTTPS, this is ineffective. No explicit security or incident response policies are found, indicating gaps in security governance. Overall, the site is trustworthy and professionally maintained with strong business credibility and content quality. However, the lack of HTTPS and security policies significantly lowers its security posture and overall risk profile. Strategic improvements in SSL/TLS deployment and security governance are recommended to enhance trust and compliance.

70
25
17
60
82
85
-
researchclimateenvironmentarcticnorway+2 more
WordPressjQueryFont AwesomeMatomo Analytics+2

Partner Domains:

framforum.com
partnerpending
ifram.no
partnerpending

+3 more partners

2025-06-15T13:10:49.353Z
S

Store Norske Spitsbergen Kulkompani AS

snsk.no

39
EnergyNorwaymediumHIGH

Store Norske Spitsbergen Kulkompani AS is a historic Norwegian company with over 100 years of industrial activity in the Arctic region, primarily focused on coal mining, real estate, logistics, and energy production including renewable energy initiatives. The company maintains a strong local presence in Longyearbyen, Svalbard, and serves a diverse audience including industry partners, local residents, and tourists. The website reflects a professional and consistent brand image with good content quality and clear navigation. Technically, the site uses modern frameworks such as Nuxt.js and Craft CMS, hosted on DigitalOcean, but suffers from slow performance and lacks HTTPS, which is a critical security concern. Security posture is weak due to absence of SSL/TLS, security headers, and modern protocols. Privacy compliance is good with a clear cookie consent mechanism and a comprehensive privacy policy. Contact information and social media presence are clearly provided, enhancing business credibility. The domain is very recently registered, which is inconsistent with the company's long history, suggesting a recent domain acquisition or migration. Overall, the website is functional and informative but requires urgent security improvements to protect users and enhance trust.

15
-
5
85
-
85
100
energyminingrealestatelogisticstourism+2 more
Vue.jsNuxt.jsGoogle FontsYouTube embed

Partner Domains:

teamtailor.com
partner76
2025-06-15T13:07:01.189Z
nhn.no favicon

Norsk helsenett SF

nhn.no

40
HealthcareNorwaylargeHIGH

Norsk helsenett SF is a Norwegian state-owned enterprise responsible for delivering and maintaining national ICT infrastructure and e-health solutions for the healthcare sector. The organization is well-established with a domain age of 25 years and operates under the Ministry of Health and Care Services. Their services include healthcare registers, videoconferencing, electronic death notifications, and membership in the national health network, targeting healthcare professionals and Norwegian citizens. The website content is rich, professionally designed, and well-structured, providing clear navigation and relevant information about their offerings and events. Technically, the website uses modern frontend technologies such as Tailwind CSS and Matomo for analytics, hosted on Azure and served via Fastly CDN. The site is mobile-optimized and accessible, though performance is moderate with a page load time of approximately 4.8 seconds. SEO and metadata are well implemented, including Open Graph tags for social sharing. From a security perspective, the website currently lacks a valid SSL certificate, resulting in no HTTPS availability, which is a critical issue. Additionally, no security headers or HSTS are implemented, and TLS protocols are disabled, exposing the site to potential risks. The SPF DNS record is properly configured, and no subdomain takeover vulnerabilities were found. Privacy compliance is good, with a comprehensive privacy policy and cookie policy present, though no explicit cookie consent mechanism is implemented. Contact information is available via a contact page, but no direct emails or phone numbers are exposed on the site. Overall, the website is trustworthy and credible, reflecting its government ownership and mature domain registration. However, the lack of HTTPS and proper SSL configuration significantly impacts its security posture and user trust. Strategic improvements in SSL deployment, security headers, and cookie consent mechanisms are recommended to enhance security and compliance.

70
-
5
50
-
90
100
healthcaregovernmentnorwaye-healthictinfrastructure+2 more
Tailwind CSSSimpleBarMatomo AnalyticsAzure Web Apps (prod-nhn-no.azurewebsites.net)+1
2025-06-15T13:07:01.162Z
vegvesen.no favicon

Statens vegvesen

vegvesen.no

38
TransportationNorwaylargeHIGH

Statens vegvesen is the Norwegian government agency responsible for road infrastructure, traffic information, vehicle registration, and driver licensing services across Norway. The website serves as a comprehensive portal for citizens to access traffic updates, vehicle information, and licensing services, targeting Norwegian residents and road users. The business model is that of a public service provider with a national mandate, positioning itself as the authoritative source for transportation-related information and services in Norway. Technically, the website employs modern web technologies including Microsoft Application Insights for telemetry and Boost.ai for chat services, indicating a moderate level of digital maturity. The site is hosted likely on Microsoft Azure infrastructure and features responsive design and accessibility considerations. However, performance metrics were not available, and no CMS was explicitly detected. From a security perspective, the site suffers from critical SSL/TLS misconfigurations, lacking a valid certificate and proper HTTPS support, which significantly undermines user trust and security. While some security headers like Strict-Transport-Security are present, they are not fully enabled. No major vulnerabilities like Heartbleed or POODLE were detected, but the absence of proper encryption is a critical issue. Privacy compliance is strong with clear privacy and cookie policies, though no explicit security or incident response policies were found. Overall, the website is professionally designed and content-rich, serving its public service role well, but the lack of valid SSL/TLS is a major risk. Strategic improvements in security infrastructure and transparency around security policies are recommended to enhance trust and compliance.

25
15
5
50
-
90
100
governmenttransportationnorwayroadtraffic+3 more
Microsoft Application InsightsBoost.ai chat integrationCSS frameworks (custom)JavaScript+1
2025-06-15T13:07:00.742Z