Skip to main content

United States security reports

Browse 10,659 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

155884
Websites
130
Industries
113
Countries
52
Avg Score
Page 213 of 214|Showing 10601-10650 of 10659
freddiemac.com favicon

Freddie Mac

freddiemac.com

74
housing financeUnited StatesenterpriseMEDIUM

The website demonstrates a generally solid technical security foundation with no critical vulnerabilities detected and strong scores in email security, network security, SSL/TLS, and DNS health. However, significant gaps exist in regulatory compliance and governance, particularly regarding GDPR and NIS2 mandates, which present substantial legal and operational risks. The absence of essential policies such as cookie consent, incident response, and security frameworks exposes the organization to potential regulatory penalties and undermines customer trust. Missing key security headers and mixed content issues indicate areas where the website’s resilience against common web attacks can be improved. While foundational network and protocol configurations are strong, the low scores in compliance reflect a need for urgent attention to documentation, privacy, and incident management. Overall, the security posture is functional but incomplete, with business-critical exposure due to compliance shortcomings. Addressing these gaps will enhance legal compliance, customer confidence, and incident readiness, thereby reducing potential financial and reputational damage.

70
43
25
100
87
85
100
housing financemortgagehomeownershipfinancial servicesgovernment-sponsored enterprise+3 more
DrupalGoogle Tag ManagerVisual Website Optimizer (VWO)Cloudflare Email Protection+3

Partner Domains:

gcs-web.com
serviceanalyzing...
onetrust.com
service72
2025-06-13T20:19:09.744Z
djreprints.com favicon

Dow Jones

djreprints.com

68
media and publishingUnited StatesmediumMEDIUM

The website exhibits a concerning security posture with no critical issues but multiple high and medium severity vulnerabilities, primarily related to missing security headers, GDPR compliance gaps, and lack of foundational NIS2 security documentation. The absence of key HTTP security headers such as Strict-Transport-Security, X-Frame-Options, and Content-Security-Policy exposes the site to common web-based attacks like clickjacking, content injection, and downgrade attacks. GDPR compliance deficiencies, including missing cookie consent and incomplete privacy policies, present legal and reputational risks. Furthermore, the lack of an information security framework, incident response procedures, and security policy documentation indicates immature security governance. While email security, SSL/TLS, DNS health, and network security show relatively strong scores, the overall low NIS2 compliance score signals significant gaps in regulatory adherence and operational readiness. Immediate focus on governance, policy implementation, and security header configuration will mitigate business risks and enhance trust. Addressing these issues is critical to safeguarding customer data, ensuring regulatory compliance, and maintaining brand reputation.

15
58
25
85
85
85
100
reprintslicensingmediapublishingDow Jones
WordPressGenesis Blocks PluginAstra ThemejQuery+2

Partner Domains:

dowjones.com
subsidiary93
wsj.com
sister companyanalyzing...

+1 more partners

2025-06-13T20:15:22.289Z
R

Restoration Hardware

restorationhardware.com

69
home furnishingsUnited StateslargeMEDIUM

The website demonstrates a mixed security posture with no critical vulnerabilities but several high and medium-risk issues that could expose the business to significant threats. Major gaps exist in security headers, GDPR compliance, and adherence to the NIS2 directive, particularly around incident response and information security frameworks. The absence of essential security headers like Content-Security-Policy and X-Frame-Options increases the risk of web-based attacks such as clickjacking and cross-site scripting. GDPR compliance weaknesses, including missing cookie consent and privacy policy concerns, expose the business to regulatory penalties and reputational damage. Key NIS2 deficiencies highlight a lack of documented security policies and incident management, which could impair response to cyber incidents. SSL/TLS weaknesses and missing DNS security measures further elevate risk by potentially allowing interception or manipulation of data. Positively, email security and network security postures are strong, reducing some risks related to email spoofing and network-based attacks. Overall, urgent remediation is needed to protect the business, customer data, and ensure regulatory compliance while maintaining stakeholder trust.

30
58
25
90
72
85
100
Restoration Hardwarefurniturehome accessorieslightingluxury+1 more
ReactGoogle Analytics

Partner Domains:

rh.com
servicepending
adyen.com
payment68

+2 more partners

2025-06-13T18:10:51.514Z
fmssolutions.com favicon

FMS Solutions

fmssolutions.com

60
Profit maximization, technology, outsourcingUnited StatesmediumMEDIUM

The website demonstrates significant security weaknesses, particularly in critical HTTP security headers, GDPR compliance, and adherence to NIS2 cybersecurity requirements. No critical vulnerabilities were found, but twelve high-severity issues indicate substantial risk exposure, especially related to missing security headers and lack of privacy policies. The absence of key headers like Strict-Transport-Security, X-Frame-Options, and Content-Security-Policy increases susceptibility to common web attacks such as clickjacking, man-in-the-middle, and cross-site scripting. GDPR compliance gaps, including missing privacy and cookie policies and consent mechanisms, expose the business to regulatory penalties and reputational damage. Additionally, the lack of documented information security frameworks, incident response, and business continuity plans under NIS2 requirements presents operational risks. SSL/TLS implementation is weak due to expiring certificates, weak key lengths, and mixed content, which may undermine user trust and data confidentiality. DNS and network security are relatively strong, but DNSSEC and CAA records should be configured to enhance domain integrity. Immediate remediation is necessary to protect customer data, maintain compliance, and safeguard business continuity.

25
25
25
100
50
85
100
profit maximizationtechnologyoutsourcingBPOtax management+2 more
WordPress 6.8.1jQuery 3.7.1Google Tag Manager (gtag.js)Formsite embed+5
2025-06-13T18:10:51.492Z
johnsoncontrols.com favicon

Johnson Controls

johnsoncontrols.com

68
Building Automation and ControlsUnited StatesenterpriseMEDIUM

The website demonstrates a moderate security posture with no critical vulnerabilities found; however, several high and medium-risk issues significantly impact compliance and risk management. Key deficiencies exist in GDPR compliance, including the absence of privacy and cookie policies and lack of user consent mechanisms, exposing the business to regulatory penalties and reputational damage. The absence of a documented information security framework, incident response procedures, and security policies under NIS2 guidance further increases organizational risk and may hinder regulatory adherence. Security headers are inconsistently implemented, reducing protection against common web threats like XSS and content sniffing. SSL/TLS configurations are generally strong but require timely certificate renewal and elimination of mixed content to maintain secure communications. DNS settings are mostly healthy but can be improved by enabling DNSSEC to prevent domain spoofing. Positively, email and network security postures are robust, mitigating some external attack vectors. Overall, urgent attention to compliance and governance-related controls is critical to safeguard the business and maintain trust with users and regulators.

60
25
25
100
80
85
100
OpenBlueArtificial IntelligenceHealthy BuildingsAI in Building ManagementNet Zero Buildings+4 more
jQueryBootstrap 4Coveo SearchGoogle Maps API+15
2025-06-13T18:10:48.990Z