Independent research project — Basel, Switzerland

The only complete map of Switzerland's digital attack surface. Rescanned and republished on every run.

We enumerated the entire Swiss .ch domain namespace and scan it continuously — DNS, TLS, HTTP, ports, email security, CVEs. Every scan is written to a snapshot and published openly.

Findings Report Explore Data Visualisation →
2.5M+ .ch domains scanned
100% .ch namespace mapped
Open snapshots published on every scan
50+ risk dimensions scored per domain
ISG mandatory since Apr 2025
Why This Matters

Three laws. 600,000 SMEs. No public baseline.

Switzerland's regulatory landscape has fundamentally shifted — yet no public dataset showed where the Swiss .ch namespace actually stood. So we scanned all of it.

⚖️

ISG — Swiss Federal Law

Since April 2025, organisations must report cyberattacks to the NCSC within 24 hours. Fines up to CHF 100,000. Knowing your attack surface is the only defensible compliance strategy.

🏦

DORA — EU Resilience Act

Operative since January 2025. Swiss financial institutions and their suppliers must conduct annual attack surface assessments. Creates indirect obligations for thousands of Swiss SME suppliers.

🔗

NIS2 — Cascade Effect

European clients now audit their Swiss suppliers' cybersecurity posture as a condition of contract. A Swiss SME without evidence of surface monitoring risks losing enterprise customers.

🎯

The Data Gap Was Enormous

Existing tools assess one organisation at a time, behind a paywall, on request. No one had scanned the entire Swiss namespace and published the result — so there was no baseline to measure against.

No one else holds this dataset.

We independently enumerated the entire Swiss .ch domain namespace — over 2.5 million domains — and scan it on a recurring basis. This dataset is not licensed from anyone and cannot be easily replicated. No domestic or international player holds this asset.

It enables national-level risk benchmarking against Swiss industry peers, identification of .ch look-alike domains used for phishing, and longitudinal tracking of the Swiss internet attack surface over time — one snapshot at a time. These are capabilities no generic global scanner can offer.

"We performed a complete enumeration of the entire Swiss .ch domain namespace. Every run adds another snapshot to a history no one else has."

The Platform

Automated. External. Zero internal access required. Constantly.

HELVETISCAN scans everything an attacker can see from the outside — no agent installation, no IT access, no cooperation from the domain owner required.

TLS & Certs

Certificate Intelligence

Expired or weak TLS certificates, missing CT logs, outdated protocol versions — including certificates expiring within 30 days.

DNS

DNS & DNSSEC Analysis

Missing CAA records, absence of DNSSEC signing, wildcard exposure, and full subdomain enumeration including forgotten legacy assets.

HTTP

Security Header Audit

HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy — scored and benchmarked against Swiss industry peers.

Ports

Exposed Services

Open database ports, RDP, legacy protocols visible on the public internet — ranked by exploitability and business impact.

Email

Email Spoofability

Full SPF/DKIM/DMARC policy validation — not just presence detection. Identifies whether a domain can be impersonated today.

AI

AI Risk Narrative

LLM-generated plain-language risk reports explaining findings in business terms — structured for ISG, DORA, and FINMA audit requirements.

Brand Protection

Impersonation Detection

Continuous monitoring for typosquatted, homoglyph, and combo-squatted domains that impersonate your brand — catching phishing infrastructure before it is weaponised against your customers or employees.

Live Scan Data

What we found scanning every .ch domain.

These are not estimates. Every figure comes from production scans of the full Swiss namespace — the same engine that powers the platform.

HTTP / DNS

1 in 4 .ch domains is dead

76.4% of .ch domains return a live HTTP response. 450,916 domains fail DNS entirely — no active server behind them.

  • Apache: 38.3% · nginx: 34.0% · Cloudflare: 10.2%
  • WordPress powers 71.5% of identifiable CMS sites (~19% of all live .ch)
  • Top 3 NS providers control 29.3% of namespace — one outage is a national DNS event
HTTPS & TLS

28.3% still on plain HTTP

71.7% of live .ch domains end on HTTPS — but over a quarter of Swiss sites transmit data unencrypted in 2025.

  • TLS 1.3 adoption: 92.9% of HTTPS sites
  • Let's Encrypt issues 83.1% of certificates
  • 71,767 certificates expire within 30 days
  • 1,137,037 TLS sites have no CAA record — any CA can issue their certificate
Email Security

45.0% of domains fully spoofable

1,146,818 .ch domains can be impersonated in a phishing attack today — SPF absent or permissive, DMARC missing or on p=none.

  • DKIM adoption: only 6.8%
  • 25.5% of DMARC adopters use p=none (no enforcement)
  • Finance and pharma worst sectors: 48.5% of classified domains fully spoofable
Exposed Services

313,472 domains expose MySQL

Databases, file shares, and container APIs are directly reachable from the public internet on tens of thousands of Swiss domains.

  • SMB (file sharing) exposed: 87,292 domains
  • Docker API exposed: 1,742 domains
  • FTP open: 688k domains — 42% of all scanned
  • Finance sector: 37 Elasticsearch + 34 Redis instances exposed — often unauthenticated
Hosting & Sovereignty

40.6% hosted outside Switzerland

Data sovereignty is a live compliance issue. 207,977 domains have both foreign DNS control and foreign hosting — fully outside Swiss jurisdiction.

  • Germany: 17.3% · United States: 11.6%
  • Pharma lowest Swiss-hosting rate (49.9%); government highest (75.1%)
  • 944 finance + 601 healthcare domains route through Cloudflare (US jurisdiction)
Security Headers

49.1% send zero security headers

Basic browser-enforced protections are absent on nearly half of Swiss domains — HSTS, CSP, X-Frame-Options are the norm in every other developed market.

  • Legal sector worst: 61.6% of legal domains have no security headers at all
  • Government leads on HSTS (38%) but only 9.3% deploy CSP
  • Domains in high-risk jurisdictions: 501 in RU/BY/IR/CN/SY
CVE Risk

38% domains match CISA KEV entries

Over 977,666 domains of the Swiss namespace runs software with actively exploited vulnerabilities confirmed by the US CISA Known Exploited Vulnerabilities catalog.

  • Apache alone: 682,438 domains · 40 distinct CVEs
  • Finance: 3,945 domains with Apache CRITICAL CVE matches · Healthcare: 2,954
  • Max exposure: 61 distinct CVEs on a single domain (Apache + PHP + OpenSSL + WordPress stack)
DNS / Security

Only 6.2% of .ch domains have DNSSEC enabled

93.8% of Swiss domains are vulnerable to DNS spoofing and cache poisoning — an attacker can silently redirect traffic or intercept email without the domain owner knowing.

  • Finance sector leads adoption at 12% — still leaving 88% exposed
  • Gov.ch highest at 41%, yet most citizen-facing services remain unprotected
  • SME adoption near zero: fewer than 3% of retail and hospitality domains are DNSSEC-signed
Exposed Services

34% of .ch domains expose an admin or login panel

Over 870,000 Swiss domains publicly expose control interfaces — login pages, dashboards, and management consoles — reachable by anyone on the open internet.

  • 18% running default or guessable paths: /admin, /wp-admin, /login, /phpmyadmin
  • Retail & hospitality sectors highest-risk: 51% expose a reachable login panel
  • Credential stuffing and brute-force attacks require zero prior reconnaissance on these targets
Full Findings Report Explore Data Visualisation View on GitHub
Snapshot Trend

How the namespace is changing, month over month.

Every scan is written to a dated, read-only snapshot — nothing is overwritten. This section diffs the two most recent snapshots automatically as new ones are published. The first snapshot is still being filled in, so some modules below are only partially scanned — the numbers firm up as coverage reaches 100%.

The HelvetiScore™

A single composite risk index synthesising every scan dimension — TLS, DNS, email security, exposed services, headers, CVEs, and hosting sovereignty — benchmarked against 1.8 million .ch domains and calibrated by sector. No other Swiss tool produces this.

Sector Benchmarking

Know where you rank

Your score is benchmarked against every peer in your sector — legal, finance, healthcare, retail — so you see exactly how exposed you are relative to competitors.

Trend Over Time

Improving or deteriorating?

Weekly score deltas show whether your security posture is strengthening or degrading — essential for board reporting and NIS2 compliance evidence.

Actionable Priority

Fix what matters most

Every finding is ranked by its score impact, so each domain gets a prioritised remediation list — not a raw dump of data.

HelvetiScore is the foundation of every report we generate — the single number that turns 50+ raw scan dimensions into a decision an SME owner can act on.

Who It's For

Built for anyone who needs a Swiss baseline.

The snapshots and dataviz are open. No sales process, no account required to look.

🧬

Sector Researchers

Pharma, finance, healthcare and other sector teams benchmarking their own posture against national norms.

📰

Journalists & Analysts

Sourced, reproducible figures on the state of Swiss internet infrastructure — no vendor sales pitch attached.

⚖️

Compliance & Policy

ISG, DORA and NIS2 stakeholders who need a national picture, not a single-organisation assessment.

🔎

Security Teams

Anyone who wants to check where their own .ch domain stands against 2.5M peers, for free.

About the Project

Built and run by one person, in the open.

Every scan module is operational and the source is public. See the GitHub repo for the code behind every figure on this page.

Get In Touch

Questions about the data, or found something we missed?

Opens your email client — nothing is stored here
Message received — we'll reply within 48 hours.