SunuBarometer: Africa Cybersecurity

This barometer relies solely on our real operational data, aggregated at continental scale — no modeling, no extrapolation.

Methodology

Loading real data…

Trend over time
Loading real data…
Missing or misconfigured HSTS

Without this header, visitors remain exposed to HTTPS downgrade attacks on their first connection.

DMARC absent

Without DMARC, nothing prevents an attacker from spoofing the domain for phishing campaigns targeting customers or partners.

SPF absent

Missing SPF makes it easier to send fraudulent emails impersonating the analyzed domain.

No CDN/WAF in front of the infrastructure

The server's real IP address is exposed directly on the internet, allowing any application-layer filtering to be bypassed.

Publicly exposed SSH port

An admin access point reachable from the internet is a prime target for brute-force attempts.

Database exposed on the Internet

MySQL, MongoDB, or Elasticsearch reachable with no authentication from the outside — the equivalent of leaving the door wide open on customer, financial, or operational data.

Invalid or expired SSL/TLS certificate

An invalid certificate exposes users to man-in-the-middle attacks and undermines trust.

Where does your organization stand?

A free scan is all it takes to compare your exposure to these numbers, in minutes.

Free scan

These numbers are recalculated continuously over a rolling 90-day window — not a static study, not a statistical extrapolation of the whole continent, just what we actually observe on the ground, updated in real time.