This barometer relies solely on our real operational data, aggregated at continental scale — no modeling, no extrapolation.
Between June and August 2026, we analyzed 130 distinct African targets through our platform, across all sectors — banking, telecom, government, fintech, Mobile Money. The data is aggregated and anonymized; no organization is individually identifiable.
Without this header, visitors remain exposed to HTTPS downgrade attacks on their first connection.
Without DMARC, nothing prevents an attacker from spoofing the domain for phishing campaigns targeting customers or partners.
Missing SPF makes it easier to send fraudulent emails impersonating the analyzed domain.
The server's real IP address is exposed directly on the internet, allowing any application-layer filtering to be bypassed.
An admin access point reachable from the internet is a prime target for brute-force attempts.
MySQL, MongoDB, or Elasticsearch reachable with no authentication from the outside — the equivalent of leaving the door wide open on customer, financial, or operational data.
Measured on 91 targets that underwent an in-depth network audit.
An invalid certificate exposes users to man-in-the-middle attacks and undermines trust.
A free scan is all it takes to compare your exposure to these numbers, in minutes.
Next edition: Q4 2026. These numbers reflect the sample we actually analyzed over the stated period — not a statistically representative study of the entire continent, just what we observe on the ground.