Skip to main content

Security Directory

Explore comprehensive security analyses from websites around the world. Filter by industry, location, risk level, and more.

Live Guard activity

Security teams are checking their sites with Guard right now

Run your domain before the queue fills up

0
Websites
0
Industries
0
Countries
0
Avg Score
Page 1 of 1|Showing 1-35 of 35
cybusinessonline.co.uk favicon

Virgin Money UK

cybusinessonline.co.uk

0
bankingUKlargeLOW

The website demonstrates a generally strong technical security foundation with high scores in email security, SSL/TLS, DNS health, and network security. However, significant gaps exist in compliance and governance areas, particularly related to GDPR and NIS2 regulations, which pose notable legal and operational risks. The absence of a cookie policy, consent banner, and incomplete privacy documentation expose the business to potential regulatory penalties and customer trust issues. Critical deficiencies in information security framework, incident response, and security policy documentation under NIS2 further elevate the risk of unmanaged security incidents and business disruption. While no critical vulnerabilities were identified, the combination of high and medium severity findings indicates an urgent need to address compliance and governance controls. Proactively remediating these issues will reduce regulatory exposure, improve stakeholder confidence, and strengthen the overall security posture. Immediate focus on policy implementation and GDPR compliance will deliver the greatest business value and risk mitigation. Ongoing monitoring of SSL certificates and DNS configurations ensures continued protection of core infrastructure components.

85
43
25
100
95
90
100
business bankingVirgin Moneybusiness accountsfinanceSME banking+1 more
jQuery 3.5.1Visual Website Optimizer (VWO)Adobe DTM (Dynamic Tag Manager)CSS Custom Properties (with fallback)+7

Partner Domains:

virginmoneyukplc.com
subsidiary74
virginmoney.com.au
sister company67

+1 more partners

2025-06-13T21:51:18.215Z
barclayscorporate.com favicon

Barclays Bank PLC

barclayscorporate.com

0
bankingUnited KingdomenterpriseMEDIUM

The website exhibits a concerning security posture with no critical issues but multiple high and medium severity vulnerabilities, particularly in security headers, GDPR compliance, and NIS2 regulatory adherence. The absence of key security headers like Content-Security-Policy and X-Frame-Options exposes the site to clickjacking and content injection attacks, increasing the risk of data breaches and reputational damage. GDPR compliance gaps, including missing privacy and cookie policies along with the lack of a consent banner, expose the business to regulatory fines and customer trust erosion. NIS2-related deficiencies such as missing security frameworks, incident response procedures, and security documentation highlight significant operational risks and non-compliance with important EU cybersecurity regulations. While email security, SSL/TLS, DNS health, and network security are relatively strong, the overall low scores in governance and protective controls indicate urgent attention is needed. Addressing these issues will not only enhance security but also ensure regulatory compliance and protect the business’s brand reputation. Immediate remediation will reduce legal risks and improve stakeholder confidence in the company’s cybersecurity maturity.

35
40
30
85
97
90
100
bankingfinancial servicescorporate bankinginvestmentprivate banking
Adobe Helix RUM JSjQueryAdobe DTM (Dynamic Tag Manager)Modernizr+3

Partner Domains:

barclays.co.uk
subsidiarypending
barclayscard.co.uk
subsidiarypending

+3 more partners

2025-06-13T18:12:28.978Z
credit-agricole.com favicon

Crédit Agricole

credit-agricole.com

0
bankingFranceenterpriseMEDIUM

The website exhibits serious security deficiencies, particularly the complete absence of HTTPS encryption, which critically exposes data in transit and undermines user trust. Compliance with GDPR and NIS2 regulations is severely lacking, with missing cookie policies, consent mechanisms, and essential security governance documentation, posing significant legal and operational risks. While network security and email security demonstrate relatively strong postures, foundational issues around encryption and policy frameworks significantly elevate the organization's exposure to data breaches and regulatory penalties. Security headers and DNS configurations are suboptimal but less urgent relative to the critical gaps. Immediate remediation is necessary to protect customer data, maintain regulatory compliance, and uphold the organization's reputation. Without urgent action, the business remains vulnerable to interception, data leakage, and potential loss of customer confidence. Prioritizing HTTPS implementation alongside privacy and incident response policies will substantially improve the security stance. Overall, the current posture demands urgent attention to align with industry best practices and regulatory mandates.

80
18
5
85
-
85
100
bankingfinanceCrédit AgricoleFrancefinancial services+2 more
JavaScriptGoogle Maps APIAT Internettarteaucitron.js+3

Partner Domains:

credit-agricole.fr
subsidiarypending
2025-06-13T18:10:50.379Z
andbank.com favicon

GROUP Andbank

andbank.com

0
bankingAndorralargeHIGH

The website's overall security posture is currently poor, with critical vulnerabilities that pose significant risks to both the business and its users. The absence of HTTPS encryption is a severe issue, exposing data in transit to interception and undermining compliance with GDPR and NIS2 regulations. Key security headers are either missing or weakly configured, increasing susceptibility to common web attacks such as clickjacking and content injection. Privacy compliance is lacking, with no privacy or cookie policies and no consent mechanisms, risking regulatory penalties and reputational damage. Additionally, the organization lacks foundational security governance, including incident response, security policies, and vulnerability disclosure procedures, which impairs its ability to manage and respond to threats effectively. Email security is moderately strong but could be improved with stricter DMARC enforcement and reporting. DNS security measures like DNSSEC are not enabled, reducing protection against DNS spoofing. Network security itself is well managed, indicating some internal controls are in place. Immediate remediation is critical to prevent data breaches, regulatory fines, and erosion of customer trust.

50
-
5
85
-
85
100
bankingprivate bankingasset managementfinancial servicesinvestment+1 more
WordPressYoast SEO PremiumSimple Google reCAPTCHAjQuery+12

Partner Domains:

andbank.com.br
subsidiarypending
andbank.es
subsidiarypending

+2 more partners

2025-06-13T18:10:48.109Z