ImmuniWeb Launches Free Website Security and GDPR Compliance Test
May 29, 2019The non-intrusive online test quickly verifies relevant GDPR and PCI DSS requirements, checks CMS security and runs a privacy check.
ImmuniWeb, a global provider of web, mobile and API security testing and risk ratings, has now added a GDPR compliance check to its website security test, one of the most popular free tests provided within ImmuniWeb’s community offering.
The test is initially designed for SMEs and organizations with nascent application security testing programs. Large organizations with mature DevSecOps programs can also benefit from the service to quickly run hundreds of daily GDPR scans ensuring essential security and compliance of their external web applications.
The free security test will:
- Verify PCI DSS requirements 6.2, 6.5 and 6.6.
- Verify GDPR requirements mentioned in Articles 5, 6, 7, 25, 32 and 35 applicable to websites and web applications.
- Fingerprint versions of over 100 most popular CMS, web frameworks and over 167,000 of their plugins.
- Run a comprehensive but non-intrusive vulnerability scan for all known vulnerabilities in the fingerprinted software.
- Check over 20 HTTP headers related to security, encryption or privacy for strong configurations in line with industry best practices, including ones from OWASP.
- Assess Content Security Policy (CSP) to prevent some XSS and CSRF exploitation vectors, as well as variations of ransomware and Cryptojacking attacks.
One year ago, the EU GDPR was officially enforced as a law and imposed a considerable set of data protection and privacy requirements on all organizations handling PII (personally identifiable information) of European residents.
So far, 144,376 complaints were filed for various violations of GDPR, while companies have reported 89,271 data breaches, which they're obligated to report within 72 hours of discovery. A Brussels report finds that €56 million of fines have been handed out since GDPR was enacted.
To test how largest European websites adhere to GDPR requirements related to web applications, we selected the 100 most visited websites (excluding local versions of global brands e.g. Google or Facebook) of the 28 European member states and ran the following non-intrusive checks:
- Missing or hard-to-get (not easily visible and accessible from the main page) privacy policy (51.50%)
- Nonconsensual (no cookie notice/disclaimer) or insecure usage of cookies (e.g. missing secure flag) handling sensitive or tracking data (78.25%)
- Outdated and vulnerable CMS or CMS components (not counting just outdated software) (6.75%)
- No HTTPS encryption by default or serious security SSL/TLS flaws (e.g. usage of SSLv3) (5.96%)
Below are the results per county:
Widespread GDPR Issues on Websites | |||||
---|---|---|---|---|---|
Total | Issues Found from Total | ||||
Member Country | GDPR Issue(s) Found (%) | Privacy Policy Issues (%) | Cookie Protection or Usage Issues (%) | Website Security Issues (%) | HTTPS Encryption Issues (%) |
Germany | 50 | 40 | 100 | 0 | 0 |
Italy | 50 | 14 | 86 | 0 | 14 |
Austria | 67 | 0 | 100 | 0 | 0 |
Spain | 75 | 67 | 56 | 11 | 11 |
Greece | 81 | 54 | 69 | 38 | 0 |
Poland | 82 | 67 | 67 | 11 | 11 |
Belgium | 83 | 70 | 70 | 0 | 10 |
Bulgaria | 83 | 40 | 73 | 7 | 7 |
Cyprus | 83 | 60 | 80 | 0 | 0 |
France | 83 | 50 | 80 | 0 | 10 |
Netherlands | 85 | 18 | 91 | 0 | 0 |
Portugal | 85 | 73 | 82 | 0 | 0 |
Luxembourg | 86 | 33 | 100 | 0 | 17 |
UK | 86 | 17 | 100 | 0 | 0 |
Denmark | 87 | 54 | 85 | 8 | 8 |
Slovenia | 91 | 70 | 90 | 20 | 10 |
Estonia | 92 | 67 | 67 | 0 | 8 |
Latvia | 93 | 64 | 79 | 0 | 0 |
Finland | 94 | 88 | 50 | 0 | 6 |
Lithuania | 94 | 67 | 67 | 0 | 7 |
Romania | 94 | 60 | 87 | 20 | 13 |
Sweden | 94 | 60 | 87 | 0 | 0 |
Hungary | 95 | 83 | 44 | 11 | 0 |
Croatia | 100 | 60 | 80 | 0 | 0 |
Czechia | 100 | 83 | 44 | 11 | 6 |
Ireland | 100 | 0 | 88 | 25 | 0 |
Malta | 100 | 14 | 100 | 14 | 29 |
Slovakia | 100 | 69 | 69 | 13 | 0 |
Average: | 86,18 | 51,50 | 78,25 | 6,75 | 5,96 |
Ilia Kolochenko, CEO and Founder of ImmuniWeb, comments: “We can see laudable efforts aimed to improve web application security and adhere to GDPR requirements amid European companies. However, there is a long road before the majority of organizations start valuing actual security above paper-based compliance thereby providing users with the privacy and security they truly deserve.
To help companies comply with the intricate requirements of GDPR, most of which are quite far from being crystal-clear today, we are happy to enhance our community offering with the new free test. More cool features are coming soon, please stay tuned.”
The GDPR test is now also integrated with ImmuniWeb® Discovery to quickly build a comprehensive inventory of your organization’s web, mobile and cloud assets, providing an ultimate asset visibility.
ImmuniWeb Named a Key Player on the AI in Cybersecurity Global Market
ImmuniWeb Launches Partner Portal
ImmuniWeb Launches Free Website Security and PCI DSS Compliance Test
Webinar: Transform Penetration Testing Costs into an Investment
Webinar and Live Booth at the ISF World Congress
Webinar: “Top 10 Cybercrime and Cybersecurity Trends in 2021”