Skip to main content

High-risk security reports

Browse 43,501 Guard analyses across this slice of the directory — NIS2 / GDPR readiness, SSL/TLS, DNS hygiene and email authentication.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

148819
Websites
130
Industries
113
Countries
52
Avg Score
Page 806 of 871|Showing 40251-40300 of 43501
poesis.at favicon

Poesis Consulting GmbH

poesis.at

40
OtherAustriasmallHIGH

Poesis Consulting GmbH is a small, dynamic consulting firm specializing in strategy, project management, process management, and training services. The company targets businesses requiring tailored consulting solutions, particularly in complex projects where internal resources or expertise are limited. Their market position is regional with offices in Vorarlberg and Liechtenstein, emphasizing a personalized and deep consulting approach. The website reflects a professional and consistent brand image with clear service offerings and client testimonials, supporting their credibility. Technically, the website is built on the Webflow platform, leveraging modern web technologies such as Google Fonts, Google Tag Manager, and Cookiebot for consent management. Hosting is via Cloudflare CDN with DNS managed by United Hoster. However, the site lacks a valid SSL certificate and does not support HTTPS, which is a significant technical and security deficiency. Performance is rated slow due to missing optimization metrics, but mobile responsiveness and SEO basics are adequately addressed. From a security perspective, the absence of HTTPS and TLS protocols severely undermines the site's security posture. While some security headers and best practices like HttpOnly cookies and reCAPTCHA are implemented, critical vulnerabilities exist including no DNSSEC, no certificate transparency compliance, and no session resumption. Privacy compliance is reasonably addressed with a privacy policy, cookie consent, and GDPR indicators, but no explicit security or incident response policies are published. Overall, the website presents a moderate risk profile primarily due to missing HTTPS and related security controls. Strategic recommendations include immediate SSL/TLS deployment, enhancement of DNS security, and publication of security policies. These improvements will bolster trust, compliance, and protect both the business and its clients from potential threats.

30
18
25
50
-
85
100
unternehmensberatungstrategieprojektmanagementprozessmanagementtrainings+4 more
WebflowGoogle FontsGoogle Tag ManagerGoogle reCAPTCHA+2
2025-06-15T21:59:06.165Z
O

OTP Bank

otpbank.hu

40
FinanceHungaryenterpriseHIGH

OTP Bank is a leading Hungarian financial institution with a strong regional presence in Central and Eastern Europe. Founded in 1949, it offers a comprehensive range of banking services including retail and corporate banking, loans, savings, insurance, and digital banking solutions. The website reflects a mature and professional digital presence with excellent content quality, clear navigation, and strong branding consistency. The bank leverages modern web technologies such as Vue.js and integrates multiple analytics and marketing tools to enhance user experience and business intelligence. From a technical perspective, the website employs robust security headers and content security policies, but suffers from critical SSL/TLS configuration issues including an invalid SSL certificate and lack of modern TLS protocol support. These issues significantly impact the security posture score and should be addressed promptly to ensure secure communications and user trust. Privacy compliance is well handled with clear GDPR-aligned privacy and cookie policies, supported by a consent mechanism. Overall, OTP Bank's website demonstrates high business credibility and professionalism, with comprehensive contact information and trust indicators such as awards and certifications. The domain registration data aligns well with the business history and legitimacy. Strategic improvements in SSL/TLS configuration and ongoing security audits are recommended to enhance the security posture and maintain customer confidence.

75
-
17
50
-
50
100
bankingfinanceretailbankingcorporatebankingdigitalbanking+4 more
Vue.jsGoogle Tag ManagerGoogle AnalyticsHotjar+4
2025-06-15T21:59:04.368Z
hellermanntyton.at favicon

HellermannTyton

hellermanntyton.at

40
ManufacturingAustrialargeHIGH

HellermannTyton is a well-established manufacturer and provider of cable management and connectivity products, serving industrial sectors such as manufacturing, energy, and transportation. The website presents comprehensive product information, industry solutions, and sustainability initiatives, targeting professional and industrial customers primarily in Austria and surrounding regions. The company maintains a strong brand presence with consistent design and multiple social media channels. Technically, the website uses a modern tech stack including Apache, jQuery, Google Tag Manager, and Usercentrics for consent management, hosted behind Cloudflare DNS services. However, the SSL/TLS configuration is outdated, supporting only TLS 1.1 without TLS 1.2 or 1.3, which is a security concern. Security headers are well implemented, including a strict Content Security Policy and HSTS header, though HSTS is not fully enabled in SSL configuration. Privacy compliance is strong with clear privacy and cookie policies and active consent mechanisms. No critical vulnerabilities or exposed sensitive data were detected. Overall, the website is professional, trustworthy, and compliant, but would benefit from modernizing its TLS support and enhancing SSL configurations.

45
18
9
50
77
85
100
cablemanagementindustrialproductsmanufacturingconnectivitysustainability
ApachejQueryGoogle Tag ManagerUsercentrics Consent Management+2

Partner Domains:

hellermanntyton.com
partnerpending
hellermanntyton.de
partnerpending

+1 more partners

2025-06-15T21:58:57.166Z
mac.de favicon

mac. brand spaces GmbH

mac.de

40
OtherGermanymediumHIGH

mac. brand spaces GmbH is a medium-sized company specializing in sustainable and innovative brand space design and live communication services. They offer comprehensive full-service solutions for events, trade shows, roadshows, and digital live communication, targeting businesses seeking to create immersive brand experiences. The company has an international presence with offices in Germany, China, Singapore, and Austria, emphasizing sustainability as a core value. Technically, the website is built using modern web technologies including React, Gatsby, and Chakra UI, hosted on Netlify. The site demonstrates excellent performance, mobile optimization, and accessibility. SEO practices are well implemented with proper meta tags and structured data. From a security perspective, the site enforces HTTPS with strong security headers such as HSTS, X-Frame-Options, and X-Content-Type-Options. OCSP stapling is enabled, and no vulnerabilities or exposed sensitive data were detected. However, improvements such as enabling HSTS for subdomains and DNSSEC could further enhance security. Overall, the website presents a professional and trustworthy digital presence with good privacy compliance, including GDPR-aligned cookie consent and privacy policies. The company provides clear contact information and maintains active social media channels, supporting strong business credibility.

65
18
17
50
77
80
20
brandingsustainabilityeventmanagementlivecommunicationdigitaltransformation
ReactGatsbyChakra UINetlify
2025-06-15T21:58:42.537Z
jvi.org favicon

Joint Vienna Institute

jvi.org

28
EducationAustriamediumHIGH

The Joint Vienna Institute (JVI) is a well-established regional training center founded in 1992, providing policy-oriented training primarily to public officials and selected private sector executives from Central, Eastern, and Southeastern Europe, the Caucasus, and Central Asia. Supported by international organizations such as the IMF, Austrian Finance Ministry, EBRD, and others, JVI offers a broad range of courses, webinars, and special events focused on economics, financial sector management, trade policy, and governance. The website reflects a professional and consistent brand with good content quality and clear navigation, targeting a specialized audience in the education and government sectors. Technically, the site is built on TYPO3 CMS with PHP 7.4, uses Bootstrap and jQuery for frontend, and integrates Matomo and Google Analytics for user tracking. The site is hosted likely by Telekom Austria based on DNS records. While the site is mobile-optimized and SEO-friendly, it lacks HTTPS support, which is a critical security shortfall. The absence of SSL/TLS encryption exposes users to potential data interception risks. Privacy compliance is well addressed with a comprehensive privacy policy and cookie consent mechanism. Security posture is weak due to missing HTTPS, lack of HSTS, and minimal security headers. No incident response or vulnerability disclosure information is provided. Business credibility is strong, supported by clear contact information, partner logos, and active social media presence. Overall, the site is trustworthy but requires urgent security improvements to protect user data and enhance trust. Recommendations include immediate implementation of HTTPS with a valid SSL certificate, enabling security headers, publishing a security policy and vulnerability disclosure, and upgrading PHP to a supported version to improve security and compliance.

25
43
9
50
-
85
20
educationtrainingfinancepolicyinternational+3 more
PHP 7.4.33TYPO3 CMSBootstrap CSSjQuery 1.11.0+4
2025-06-15T21:58:38.717Z