Skip to content

Services, Wiki-Artikel, Blog-Beiträge und Glossar-Einträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen
Every second company website is at risk!
Consulting

Every second company website is at risk!

Digitalisation with certainty a miss - every second company website is at risk! The eco - Association of the Internet Industry reports that about half of the we...

Chris Wojzechowski Chris Wojzechowski Geschäftsführender Gesellschafter
Updated: October 7, 2024 3 min read read
IT-Grundschutz-Praktiker (TÜV) IT Risk Manager (DGI) § 8a BSIG Prüfverfahrenskompetenz Ausbilderprüfung (IHK)

TL;DR

A scan of 1,406 German company websites by eco's SIWECOS project found that around 39% still lack HTTPS encryption, 8% are vulnerable to the POODLE attack, and 5.6% are susceptible to Padding Oracle attacks. A quarter of sites expose their CMS version, with a third of those overdue for security updates. The free SIWECOS scanner helps SMEs identify these issues without requiring in-house IT security expertise, though it does not replace a professional penetration test.

Table of Contents (3 sections)

Digitalisation with certainty a miss - every second company website is at risk! The eco - Association of the Internet Industry reports that about half of the websites in German corporate websites are badly configured. A resulting potential security risk is accepted by the companies. Data theft, defacement and missing customers are dangers that threaten a company if serious security gaps threaten its own infrastructure.

SIWECO scans websites and gives recommendations for action

According to its own information, around 1,406 websites were scanned. An alarming 39% of the sample still do not use encryption 1 1/2 years after the introduction of the DSGVO. Before the lack of confidentiality, users inside have already been notified in numerous browsers. Subtle hints such as “not secure” draw the surfer’s attention to a problem. However, there are also ways of overriding the existing encryption on many websites. For example, about 8% of websites are vulnerable to the “POODLE” vulnerability. Another 5.6% can be attacked with a “Padding Oracle”. Vulnerabilities that should no longer appear in the broad masses.

Lack of update readiness - every second company website is vulnerable!

A quarter of the websites checked reveal the version of the content management system used. A third of this sample should update as quickly as possible - to close the known and above all critical security gaps. Who is affected and to what extent can be checked by the SIWECOS scanner free of charge. SIWECOS is an acronym for “Secure websites and content management systems”. The project started in autumn 2016 and is a helpful tool for companies that do not have their own IT security competence but want to know what to do. SIWECOS does not replace a penetration test. In the latter case interfaces and web applications are also examined to a larger and deeper extent. However, for those who operate a website as a GALABAU company, the scanner provided by eco is sufficient in the first step.

SIWECOS is supported, developed by experts and offered free of charge!

The joint project is supported by the eco - Association of the Internet Industry, as well as by the Ruhr-Universität Bochum. Furthermore, CMS Garden e.V. is also involved. The IT-Security Startup Hackmanit also makes a contribution. The project is sponsored by the Federal Ministry of Economics and Energy (BMWi). The goal to increase the SME website security in the long run includes the fact to know where the weak points are lurking. The project, the association and the companies involved are therefore on the right track - but the companies concerned now also have a lot of work ahead of them.

Next Step

Our certified security experts will advise you on the topics covered in this article — free and without obligation.

Free · 30 minutes · No obligation

Share this article

About the author

About the Author

Chris Wojzechowski
Chris Wojzechowski

Geschäftsführender Gesellschafter

E-Mail

Geschäftsführender Gesellschafter der AWARE7 GmbH mit langjähriger Expertise in Informationssicherheit, Penetrationstesting und IT-Risikomanagement. Absolvent des Masterstudiengangs Internet-Sicherheit an der Westfälischen Hochschule (if(is), Prof. Norbert Pohlmann). Bestseller-Autor im Wiley-VCH Verlag und Lehrbeauftragter der ASW-Akademie. Einschätzungen zu Cybersecurity und digitaler Souveränität erschienen u.a. in Welt am Sonntag, WDR, Deutschlandfunk und Handelsblatt.

10 Publikationen
  • Einsatz von elektronischer Verschlüsselung - Hemmnisse für die Wirtschaft (2018)
  • Kompass IT-Verschlüsselung - Orientierungshilfen für KMU (2018)
  • IT Security Day 2025 - Live Hacking: KI in der Cybersicherheit (2025)
  • Live Hacking - Credential Stuffing: Finanzrisiken jenseits Ransomware (2025)
  • Keynote: Live Hacking Show - Ein Blick in die Welt der Cyberkriminalität (2025)
  • Analyse von Angriffsflächen bei Shared-Hosting-Anbietern (2024)
  • Gänsehaut garantiert: Die schaurigsten Funde aus dem Leben eines Pentesters (2022)
  • IT Security Zertifizierungen — CISSP, T.I.S.P. & Co (Live-Webinar) (2023)
  • Sicherheitsforum Online-Banking — Live Hacking (2021)
  • Nipster im Netz und das Ende der Kreidezeit (2017)
IT-Grundschutz-Praktiker (TÜV) IT Risk Manager (DGI) § 8a BSIG Prüfverfahrenskompetenz Ausbilderprüfung (IHK)
Certified ISO 27001ISO 9001AZAVBSI

Cookielose Analyse via Matomo (selbst gehostet, kein Tracking-Cookie). Datenschutzerklärung