Skip to main content

United Kingdom security reports

Browse 6,589 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155884
Websites
130
Industries
113
Countries
52
Avg Score
Page 129 of 132|Showing 6401-6450 of 6589
nhm.ac.uk favicon

The Natural History Museum

nhm.ac.uk

40
EducationUnited KingdomlargeHIGH

The Natural History Museum website serves as a comprehensive digital portal for one of the UK's leading educational and cultural institutions. It offers extensive information on exhibitions, scientific research, educational resources, and visitor services, targeting a broad audience including the general public, educators, and researchers. The site is well-branded, professionally designed, and provides clear navigation and rich content relevant to its mission. Technically, the website leverages modern web technologies such as React with Next.js and Adobe Experience Manager as its CMS, hosted on Microsoft Azure. While the site is mobile-optimized and accessible, performance is currently hindered by an invalid SSL certificate and lack of enabled TLS protocols, which also impacts the security posture. Security-wise, the site implements some security headers like HSTS and X-Frame-Options but lacks a valid SSL certificate and proper TLS support, which are critical for secure communications. Privacy and cookie policies are comprehensive and GDPR compliant, with a clear consent mechanism in place. Social media integration and tracking tools like Google Tag Manager and Adobe DTM are used responsibly with privacy considerations. Overall, the website is trustworthy and professional but requires urgent remediation of SSL and TLS issues to ensure secure user interactions and improve its security score. Strategic improvements in SSL management and security best practices will enhance user trust and compliance.

45
-
5
50
-
85
100
museumeducationsciencenaturalhistoryuk+1 more
React (Next.js)Adobe Experience Manager (AEM)Google Tag ManagerAdobe DTM (Dynamic Tag Management)+3
2025-06-15T22:12:49.186Z
I

Identity Protection Service

humandynamics.org

23
OtherUnited KingdomsmallCRITICAL

The website humandynamics.org currently serves only the default Apache2 Debian welcome page, indicating that the web server is operational but no actual business content or services are presented. The domain is mature, registered since 1998, and protected by an identity protection service based in Great Britain. However, the lack of any meaningful content, contact information, or policies on the site suggests it is either under maintenance or parked. From a technical perspective, the site runs on Apache 2.4.38 on Debian Linux but lacks HTTPS support, security headers, and modern web practices. Performance data is unavailable, and the site is not optimized for mobile or accessibility. No analytics or tracking technologies are detected. Security posture is weak due to the absence of SSL/TLS encryption and security headers. The domain registration is stable and protected, but the lack of active content and contact details reduces trustworthiness. There are no privacy or cookie policies, and no incident response or vulnerability disclosure information is present. Overall, the site scores very low on content quality, security, privacy compliance, and business credibility. It is recommended to immediately secure the site with HTTPS, add relevant policies, and publish meaningful business content to improve trust and compliance.

15
15
-
50
-
85
20
defaultapachedebianplaceholderno-content+1 more
Apache/2.4.38DebianLinux/Debian
2025-06-15T21:58:31.303Z
ic-resources.com favicon

IC Resources

ic-resources.com

40
TechnologyUnited KingdommediumHIGH

IC Resources is a well-established technology recruitment agency specializing in deep tech sectors such as software, semiconductor, electronics, and manufacturing. Founded in 1999, it operates globally with offices in the UK, Germany, and the USA. The company connects innovative organizations with highly skilled technology professionals, offering services including job search assistance, CV advice, and talent acquisition for clients. The website reflects a professional and comprehensive digital presence with rich content and client testimonials, positioning IC Resources as a trusted partner in the technology recruitment market. Technically, the website is built on WordPress with modern plugins like Yoast SEO and Contact Form 7, supported by a PHP 8.2 backend and hosted via StackCDN. While the site is mobile-optimized and SEO-friendly, performance metrics are not available, and accessibility is basic. The absence of a valid SSL certificate and HTTPS support is a critical security shortfall, exposing users to potential risks. Security headers are present but insufficient to compensate for the lack of encryption. Privacy compliance is partially met with a privacy policy present, but no cookie consent mechanism is detected. Overall, the security posture is weak due to missing HTTPS and TLS protocols, which should be addressed urgently. The business credibility is strong, supported by consistent WHOIS data and transparent contact information. Strategic recommendations include immediate SSL/TLS implementation, enhanced security headers, and improved privacy and cookie consent mechanisms to align with GDPR requirements and user trust expectations.

15
43
9
82
-
85
100
technologyrecruitmentdeeptechjobsearchrecruitmentagencytechnologyjobs+6 more
PHP 8.2.28ApacheWordPress 6.7.2Yoast SEO plugin+6
2025-06-15T21:56:56.566Z
impactory.org favicon

Identity Protection Service

impactory.org

31
OtherUnited KingdomsmallHIGH

The website impactory.org represents a digital presence with minimal visible content and lacks explicit business descriptions or contact information. The domain is registered to 'Identity Protection Service' in Great Britain and has a mature registration age of 6 years, indicating a stable domain ownership. The site uses common marketing and analytics technologies such as Google Tag Manager, Google Analytics, Stripe.js for payments, and Drift for live chat, suggesting some level of digital maturity. However, the absence of visible business content, privacy policies, and contact details limits the site's transparency and user trust. Technically, the site is served via Apache but lacks a valid SSL/TLS certificate, resulting in no HTTPS support. This is a critical security deficiency that severely impacts the site's security posture and user trust. The HTTP headers do not include modern security headers, and no DNSSEC or domain protection mechanisms are enabled, which further reduces the security robustness. Performance metrics are unavailable, but the lack of optimization and minimal content suggest a slow and basic user experience. From a security perspective, the absence of HTTPS and security headers exposes users to risks such as data interception and man-in-the-middle attacks. No privacy or cookie policies are present, indicating poor compliance with GDPR and other privacy regulations. No incident response or vulnerability disclosure information is available, which is a concern for security transparency. The domain WHOIS data is consistent and legitimate but lacks protective measures like domain locks or DNSSEC. Overall, the website's risk profile is elevated due to critical security gaps and lack of transparency. Strategic recommendations include immediate implementation of HTTPS with a valid SSL certificate, addition of privacy and cookie policies to comply with regulations, enhancement of security headers, and publication of contact and security incident response information to improve trust and compliance.

15
25
25
50
50
70
-
technologyanalyticsmarketingchatapache
ApacheGoogle Tag ManagerGoogle AnalyticsStripe.js+1
2025-06-15T21:56:44.308Z
J

Jacobs Douwe Egberts

jacobsdouweegberts.com

22
RetailUnited KingdomenterpriseCRITICAL

Jacobs Douwe Egberts is an established enterprise-level company operating in the retail sector, specializing in coffee and related consumer goods. The website presents a professional corporate image with clear branding and content focused on product portfolio, sustainability, careers, and corporate responsibility. The target audience includes consumers, job seekers, and stakeholders interested in corporate responsibility. The business model centers on product sales and brand reputation in the global coffee market. Technically, the website uses a modern CMS platform (Episerver) and integrates analytics and tag management tools such as Microsoft Application Insights and Google Tag Manager. However, the site suffers from slow load times and lacks a valid SSL certificate, which impacts user trust and security. Mobile optimization and SEO are adequately addressed, but accessibility is basic. From a security perspective, the absence of HTTPS and security headers is a critical vulnerability. The DNS configuration lacks DNSSEC and CAA records, and no advanced security policies or incident response contacts are published. Cookie consent is implemented via OneTrust, indicating some privacy compliance efforts. Overall, the website is functional and professional but requires urgent improvements in security infrastructure, particularly enabling HTTPS and adding security headers. Performance optimization is also recommended to enhance user experience and trust.

20
-
-
50
-
80
-
corporatecoffeeconsumergoodsprivacycookieconsent+2 more
jQueryMicrosoft Application InsightsOneTrust Cookie ConsentGoogle Tag Manager+1

Partner Domains:

jdepeets.com
partnerpending
2025-06-15T21:53:52.645Z
cmcmarkets.com favicon

CMC Markets

cmcmarkets.com

40
FinanceUnited KingdomlargeHIGH

CMC Markets is a well-established global online trading platform founded in 1989, offering leveraged trading on a wide range of financial instruments including forex, indices, commodities, cryptocurrencies, shares, ETFs, and bonds. The company operates multiple trading platforms such as MetaTrader 4, MetaTrader 5, TradingView integration, and its proprietary web and mobile platforms, serving over 1.5 million global clients. It is a FTSE 250 listed company with a strong market position and multiple regulatory licenses, including in Bermuda and the UK. The website is professionally designed, content-rich, and targets retail and institutional traders worldwide. Technically, the website is built on modern frameworks like Next.js and hosted on Vercel, with good mobile optimization and SEO practices. The platform supports multiple device types and integrates third-party services for enhanced user experience and marketing. However, the SSL certificate is currently invalid or missing, which is a critical security concern. Security headers are partially implemented, and there is no evidence of advanced security policies or incident response information on the site. The security posture is moderate with room for improvement, especially in SSL configuration and additional security headers. Privacy and cookie policies are present and indicate GDPR compliance, with clear consent mechanisms. Contact information is comprehensive, including phone, email, and physical addresses in multiple countries. The company demonstrates strong business credibility through trust indicators such as awards, Trustpilot reviews, and regulatory compliance. Overall, CMC Markets presents a professional and trustworthy online trading service with a mature digital presence. Addressing the SSL certificate issue and enhancing security headers would significantly improve the security posture and user trust.

30
33
5
50
-
90
100
financetradingforexcfdcryptocurrency+5 more
React (Next.js)Vercel hostingMetaTrader 4 and 5 platformsTradingView integration+5

Partner Domains:

partner-portal.cmcmarkets.com
partner
signup.cmcmarkets.com
service

+2 more partners

2025-06-15T21:53:36.496Z
T

Trūata Limited

truata.com

40
TechnologyUnited KingdommediumHIGH

Trūata Limited is a UK-based technology company specializing in privacy-enhancing data analytics solutions. Their offerings include anonymization services, privacy risk assessments, and privacy-compliant analytics platforms designed to help businesses extract value from data while maintaining compliance with global data protection regulations. The company targets enterprises and organizations seeking to leverage data securely and ethically, positioning itself as a leader in privacy technology with notable partnerships including IBM, Microsoft Azure, and Mastercard. The website is professionally designed, content-rich, and well-structured, supporting a positive user experience and clear navigation. Technically, the site is built on WordPress with integrations of marketing and analytics tools such as Adobe Analytics and HubSpot, and hosted on Microsoft Azure infrastructure. However, the security posture is weakened by the absence of a valid SSL certificate and lack of enabled TLS protocols, which is a critical vulnerability that undermines secure communications and user trust. Privacy compliance is well addressed with comprehensive privacy and cookie policies and GDPR-aligned consent mechanisms. WHOIS data confirms the domain's legitimacy and consistent registration history. Overall, while the business and content quality are strong, urgent improvements in SSL/TLS security are necessary to elevate the site's security and trustworthiness.

65
30
5
50
-
80
100
privacydataanalyticsdataanonymizationgdprb2b+1 more
WordPressjQueryAdobe AnalyticsOneTrust Cookie Consent+1

Partner Domains:

ibm.com
partner72
microsoft.com
partner69

+1 more partners

2025-06-15T21:51:43.345Z