Products Services Automation About Contact

Research · 8 September 2026

State of Bermuda on the Web

On one day in September we looked at every .bm name we could find that was alive on the internet, and wrote down how it was set up. 1,385 websites and 1,305 mail domains. Nothing was broken into, guessed at, or tested for weaknesses: everything below is what a domain already publishes to anyone who asks. How that was done.

Every figure on this page prints the count it came from, so you can check any of it against the evidence table at the foot. No cybersecurity background is assumed and every term is explained where it first appears.

Two kinds of security, and Bermuda is only good at one

The basic plumbing of a secure website is in good shape here, because free automated certificates and services like Wix, Squarespace and Shopify give it to you without your having to think about it. Everything a domain's owner has to switch on deliberately is a different story. Both columns below read the same way, the share of domains that have the protection, so higher is better on both sides.

Handled for you

A platform or a certificate authority switches these on. Bermuda's whole national population sits close to a benchmark drawn from the world's best-resourced websites.

websites, or mail domains where stated

Offers an encrypted connection 90% · 1,253 of 1,385
Sends the browser a Strict-Transport-Security header 43% · 600 of 1,385
Publishes a DMARC record 49% · 645 of 1,305

Of the 1,305 mail domains.

Needs you to act

These live in settings only the domain's owner controls. No platform can do them for you, and mostly they have not been done.

websites, or mail domains where stated

DMARC actually set to stop forged mail 28% · 360 of 1,305

Of the 1,305 mail domains.

Publishes a security.txt contact 0.8% · 11 of 1,385
Signed with DNSSEC 0.2% · 3 of 1,385

If an organisation only ever does one thing from this whole report, it should be the first row on the right: get DMARC to an enforcing setting. It protects the most people against the most common kind of attack, and for most domains it is a single change.

What was actually looked at

1,385 is the number nearly everything on this page divides by, so it is worth knowing what it leaves out. Open any step to see what dropped and why.

1,561 live .bm domains

Names that resolve or accept mail, found from two independent public sources: the certificate transparency logs, and a large public catalogue of the web. Between them these hold 2,939 live hostnames.

1,475 serving a website

86 of the live domains answer on the internet without serving a web page. Most of these are mail-only: a registered name that carries email for an organisation whose website lives somewhere else.

1,385 websites assessed

90 more were removed as parked pages with no real content, or domains whose public address points at an internal, unreachable location. That second case is a configuration error rather than a website, so counting it as one would have understated every share on this page.

Separately, 1,305 of the live names accept email and were checked for that. Those are the domains every email figure on this page divides by.

What this is not

It is not a census of Bermuda's digital economy. Many organisations here, particularly in international business, run on .com and are simply out of scope, and holding a .bm name does not prove a company is Bermudian. Read this as the observable .bm web, not every Bermuda business online.

What Bermuda's web is built on

Two thirds of sites do not say what they are built with, which is unremarkable. Of those that do, one name dominates, and it happens to be the one that needs its owner to keep it updated.

What the page says it was built with

of 1,385 assessed websites

Nothing disclosed 67% · 926 of 1,385

Unremarkable. Modern site builders and hand-built sites often say nothing about themselves.

WordPress 22% · 307 of 1,385
Wix 7.7% · 106 of 1,385
Other disclosed platform 2.2% · 31 of 1,385
Joomla 1.1% · 15 of 1,385
Who issued the security certificate

of 1,260 certificates read

Let's Encrypt 65% · 815 of 1,260

Free, and renews itself. The single clearest reason the encryption figures below look as healthy as they do.

Google Trust Services 18% · 232 of 1,260

What Google-hosted and Squarespace sites use.

Sectigo 4.4% · 55 of 1,260
DigiCert 3.7% · 47 of 1,260
GoDaddy 3.3% · 41 of 1,260
Amazon 1.8% · 23 of 1,260

The certificates are the more reliable view of who supplies Bermuda's infrastructure, because a certificate names its issuer and cannot be hidden the way a platform banner can. Paid commercial certificates are now a small minority. That is the clearest single reason the encryption figures in the next section look as healthy as they do: good security here is free and automatic, and Bermuda has taken it up.

An earlier stage of this work estimated which hosting companies carry the most Bermuda sites. That estimate could not be checked against anything we kept, so it is left out rather than published unverified. The two charts above can be, and they stand on their own.

How well connections are protected

When you see a padlock, your connection is encrypted and nobody in between can read or change what passes. Whether a site offers that, and whether the protection is any good, are two different questions. Bermuda answers the second one better than the first.

Does the encrypted version actually get used

of 1,385 assessed websites

Completed a secure connection and presented a certificate 90% · 1,253 of 1,385
Sends every visitor to the encrypted version 81% · 1,116 of 1,385
Serves its home page over plain HTTP, no redirect 15% · 202 of 1,385

The padlock exists. The front door is left open.

Redirects, but lands the visitor back on an unencrypted page 4.8% · 67 of 1,385
Is the encryption itself modern

of 1,260 hosts that completed a handshake

Supports the still-safe TLS 1.2 99.5% · 1,254 of 1,260
Supports the current TLS 1.3 92% · 1,160 of 1,260
Still also accepts the outdated TLS 1.0 or 1.1 12% · 146 of 1,260

Every one of these also offers modern encryption, so no ordinary visitor is forced onto the weak version. On any site that handles card details it is still a failure of the card-payment standard, which no longer allows these versions.

Accepts only outdated versions 0% · 0 of 1,260

Not one site we checked. This is the result that would have been the emergency, and it did not happen.

Where the certificates go wrong

of 1,385 assessed websites

Certificate does not match the site’s own name 4.5% · 63 of 1,385
Certificate a browser cannot verify 2.5% · 35 of 1,385
Certificate has expired 1.2% · 16 of 1,385
Undersized encryption key 0% · 0 of 1,385

Nor a single SHA-1 signature. Where Bermuda certificates go wrong it is through misconfiguration, never weak cryptography.

Any of the first three shows the visitor a browser security warning, which both looks alarming and trains people to click through warnings they should not. The cryptography underneath is uniformly modern: not one undersized key and not one broken SHA-1 signature on any site we checked.

The extra locks a site can fit

Beyond encryption, a website can send the visitor's browser a set of instructions that harden the page against common attacks. They are invisible, optional, and each closes one specific risk. This is where Bermuda looks weakest at first glance, and it is also where that first glance is most misleading.

Security headers present

of 1,385 assessed websites

Strict-Transport-Security 43% · 600 of 1,385

Stops a first visit being downgraded to an insecure one.

Content-type protection 42% · 583 of 1,385

Stops the browser being tricked about a file’s type.

Framing protection 30% · 414 of 1,385

Stops the site being hidden inside a fake page to trick clicks.

Content-Security-Policy 22% · 304 of 1,385

Limits what scripts a page will run.

Referrer control 20% · 273 of 1,385

Stops leaking which page a visitor came from.

Permissions control 16% · 215 of 1,385

Limits access to camera, location and similar.

Protections that live in the domain's settings

of 1,385 assessed websites

IPv6 13% · 184 of 1,385

Supports the newer internet addressing scheme.

CAA 1.9% · 26 of 1,385

Limits who is allowed to issue certificates for the domain.

DNSSEC 0.2% · 3 of 1,385

Stops visitors being silently sent to a fake copy of the site. Three of the 1,385 sites checked. At most providers it is one switch.

Read alone, "only 22 percent of sites have a content-security-policy" sounds like a crisis. It is not, and presenting it that way would be misleading: the same gaps exist across most of the world's websites, including well-resourced ones. They are worth adding, and their absence is the global norm rather than a Bermuda failing.

DNSSEC is the one that stands out, and it is not a header. Three of the 1,385 sites we checked are signed. Low DNSSEC adoption is common worldwide too, but at essentially zero Bermuda sits below even that low bar, and for most domains it is a single switch at the DNS provider. That makes it a matter of awareness rather than effort.

How well website software is kept up to date

This section is only about WordPress, because it is the one common platform that reveals its version and that the site's owner is responsible for updating. Wix and Squarespace update themselves, so they do not appear here. WordPress issues security fixes for older lines too, so the fair test is not how old a version is but whether it has applied the fixes that exist for it.

Is this site running the latest security fix for its line

of 195 sites that disclosed a version

On the current release 45% · 88 of 195
On the latest fix for an older but still-supported line 35% · 69 of 195
Behind on security fixes that already exist 18% · 36 of 195
On a line no longer supported at all 1.0% · 2 of 195

38 of the 195 WordPress sites that show their version, 19%, are running a version that is missing security fixes which already exist. Every one of the 38 is on a version with at least one known, published flaw. Across the 21 versions involved the counts run from 1 to 100, with a middle value of 13.

These are flaws known to affect a version, looked up in the WPScan database. They are not proof that any of them can be exploited on a particular site, which depends on that site’s plug-ins, settings and other defences. None of that was tested. The narrower, still useful statement: these sites have not applied security updates that exist.

These counts overlap. A flaw in an old version usually affected the versions before it too, so adding them up would count the same flaw again and again. That is why there is no total anywhere on this page.

The practical message is simple and old. WordPress sites need their updates applied, and a fifth of Bermuda's visible ones are behind.

How well email is protected against impersonation

Email has a design flaw: by default, anyone can put your domain in the "from" line of a message. Three settings close it. SPF lists which mail servers may send for you. DKIM signs your genuine messages. DMARC ties the two together and tells the world's mail systems what to do when a message fails the checks. DMARC is the keystone, and it is where Bermuda is furthest behind.

  1. 1. Anyone can write your name in the From line

    Email was designed without a check on who a message says it is from. Nothing stops a stranger sending an invoice that appears to come from your company.

  2. 2. SPF and DKIM give the receiving system something to check

    SPF lists which mail servers may send for your domain. DKIM adds a signature to your genuine messages. Between them the receiver can tell a real message from a forged one.

  3. 3. The forged message fails both checks

    It came from a server your SPF record does not list, and it carries no valid signature. The receiver now knows it is not from you.

  4. 4. DMARC is what decides the outcome

    Without a DMARC record, or with one set to monitor only, the receiver is left to decide for itself, and forged mail often gets through. Set to quarantine or reject, the domain tells the receiver to stop it. That single setting is the difference, and 72 percent of Bermuda mail domains have not made it.

What Bermuda's DMARC records actually say

of 1,305 domains that accept mail

No DMARC record at all 51% · 660 of 1,305
Has one, set to monitor only 21% · 274 of 1,305

Watches, blocks nothing.

Has one, but it is broken 0.8% · 11 of 1,305

A record with no policy in it, two records where only one is allowed, or a policy receivers do not recognise, such as a misspelt "quaratine". Receivers ignore all three.

Actively enforcing: quarantine or reject 28% · 360 of 1,305
The supporting records

of 1,305 domains that accept mail

A DKIM signing key was found 48% · 630 of 1,305

Treat this as a minimum. DKIM keys can be named anything and there is no way to list them all, so "not found" here does not prove a domain never signs its mail. This is the one email check that cannot be read as an absence.

No SPF record at all 14% · 178 of 1,305
Neither SPF nor DMARC 12% · 162 of 1,305
SPF record needs more look-ups than the standard permits 1.5% · 19 of 1,305

Which makes the record fail.

Mail server named in DNS no longer resolves 0.9% · 12 of 1,305

A strong prediction that inbound mail is failing, derived from the domain’s own configuration. A handful were confirmed by hand. Nobody watched a message bounce, so it is reported only as strongly as that method supports.

Duplicate SPF records 0.4% · 5 of 1,305

Which cancels them out.

Put the DMARC lines together and 945 of 1,305 mail domains, 72 percent, publish no enforced anti-impersonation policy. Just over half publish nothing at all, and another fifth publish one set to monitor only, which watches but blocks nothing. This is the most consequential and most fixable finding in the study: the fix is usually a single line added to a domain's settings, and it directly reduces the risk of someone sending convincing fake invoices in a Bermuda organisation's name.

Two further mail settings, MTA-STS and TLS-RPT, which harden server-to-server delivery, are absent on 99 percent of domains. As with the website headers, that is rare everywhere and is noted for completeness rather than concern.

How Bermuda compares with the wider world

Carefully, because these do not measure the same population. Most of the global figures come from a crawl of the top one million most-visited websites, counted over the roughly 819,000 that responded: the best-resourced sites on the internet. Bermuda's 1,385 is a whole national long tail, corner shops and clubs included, and a long tail should look weaker than a top-sites benchmark. This is context, not a scoreboard, and no claim is made that Bermuda is ahead or behind overall.

Bermuda measurements beside published global benchmarks
Measure Bermuda Benchmark Source
Enforces HTTPS
81%

1,116 of 1,385

80% of the top-1M sites that responded Scott Helme, crawl of 13 Jun 2026
Strict-Transport-Security present
43%

600 of 1,385

31% of the top-1M sites that responded Scott Helme, crawl of 13 Jun 2026
Content-Security-Policy present
22%

304 of 1,385

21% of the top-1M sites that responded Scott Helme, crawl of 13 Jun 2026
Has a DMARC record
49%

645 of 1,305

48% of the top 1.8M domains; 15% of 73M domains EasyDMARC 2025; Red Sift, Dec 2025
DMARC actually enforcing
28%

360 of 1,305

about 24% of the top-1M sites that responded Scott Helme, crawl of 13 Jun 2026
Signed with DNSSEC
0.2%

3 of 1,385

about 9% of the top-1M sites that responded; about 5% of .com Scott Helme, crawl of 13 Jun 2026; SIDN, Jan 2025

The pattern is the same one the whole report describes. On the settings commercial platforms handle automatically, Bermuda's whole-population numbers sit close to a benchmark drawn from the world's best sites, most plausibly because free, automatic certificates do that work here: Let's Encrypt alone issued 815 of the 1,260 certificates we read. On the one setting in that list no platform switches on for you, DNSSEC, Bermuda falls well below even the modest global level.

The benchmarks come from different studies with different dates and definitions, so a small difference between a Bermuda figure and a benchmark is not meaningful. Read "close to the top million" as platform defaults having lifted the floor, not as a ranking win.

What to do about it

A suggested order of priorities, not a timetable. Because nearly all of these settings live with individual domain owners, the biggest island-wide gain comes from many owners each making a few small changes rather than from any single central action.

First priority

Usually achievable quickly, and between them these help the most people for the least work.

Publish a DMARC policy, then set it to enforce

Stops mail forged in your name being delivered. For most domains it is a single line.

How you know it is done. A DMARC record exists and says quarantine or reject, not none.

Add an SPF record where it is missing, and fix broken ones

Lets receiving systems tell your genuine mail from a forgery.

How you know it is done. One valid SPF record, and only one.

Send all web traffic to HTTPS

Every visitor gets the encrypted version by default, not just the ones who type it.

How you know it is done. Typing the plain address lands you on the secure one.

Replace mismatched and expired certificates

Removes the browser security warning visitors currently see, which trains people to click through warnings.

How you know it is done. The site loads with no warning.

Check that the mail server named in your DNS still exists

Twelve domains name one that does not. Their inbound mail is very likely failing to arrive.

How you know it is done. The mail server in your DNS resolves and accepts mail.

Second priority

A little more setup, and some of it depends on who runs your server.

Turn on DNSSEC

Stops visitors being sent to a fake copy of your site. Three of the 1,385 sites we checked have it.

How you know it is done. Your DNS provider shows DNSSEC as enabled.

Update WordPress

Closes flaws that are already known and already fixed. The 38 sites behind are running versions with published, catalogued problems.

How you know it is done. The site reports the current version for its line.

Switch off TLS 1.0 and 1.1

Retires obsolete encryption, which the card-payment standard no longer allows on any site that handles card details.

How you know it is done. Only TLS 1.2 and 1.3 are accepted.

Add the main security headers

Reduces what a common web attack can do. Worth having, though their absence is the global norm rather than a Bermuda failing.

How you know it is done. A content-security-policy and framing protection are present.

Ongoing priority

The part that stops the backlog coming back.

Publish a security.txt contact

Gives a researcher who spots a fault somewhere to send it. Eleven Bermuda sites have one, so at the moment there is usually nowhere.

How you know it is done. The file is reachable at /.well-known/security.txt and names a contact.

Keep software and certificates current

Prevents the backlog returning, which is the only way any of the above stays fixed.

How you know it is done. Updates and renewals happen automatically, or on a schedule somebody owns.

What we still do not know

One snapshot, and deliberately cautious about what it claims.

It cannot show change over time

One day of data. No honest claim can be made that anything is improving or worsening. Repeating the same measurements later, and only then, would allow that.

It cannot confirm anything is exploitable

A missing setting or an outdated version is a risk indicator, not proof a site can be broken into. Confirming that needs permission-based testing of an individual site, which this study did not do and was never designed to do.

Detection has blind spots

Software versions can be hidden or misreported, DKIM keys cannot be exhaustively found, and a site behind certain infrastructure looks different from the outside than it is. Some failed connections may be a filter between the observer and the site rather than a fault at the site.

It covers the .bm web only

Many Bermuda organisations, particularly in international business, operate on .com and are simply not in scope. And holding a .bm name does not prove an organisation is Bermudian. Read this as the observable .bm web, not every Bermuda business online.

One estimate we could not check

We looked at which hosting companies carry the most .bm sites, then could not check that answer against anything we had kept, so it is not here. The certificate issuers above cover the same ground and can be checked.

A repeat study, run the same way on a later date, would let Bermuda track real progress on the two things that matter most and are most within owners' control: enforced email protection and basic DNS security.

Every figure on this page, and where it came from

Every figure, what it was counted out of, and which check it came from, all observed on 8 September 2026. The checks were: WEB is the website sweep, TLS the dedicated encryption pass, MAIL the mail-domain checks, DNS the domain record depth check, DISC the discovery files.

Every headline figure with its count, denominator, share, category and source dataset.
Live .bm domains Coverage · DISC Names that answer on the internet, or accept email, or both. 1,561
Live hostnames Coverage · DISC 2,939
Websites assessed Coverage · DISC / WEB After removing 90 parked pages and addresses that could not be reached. 1,385
Mail domains assessed Coverage · MAIL Separate domains, each counted once. 1,305
Offers HTTPS 1,253 of 1,385 · Encryption · WEB Answered securely and presented a certificate. 90%
No HTTPS redirect 202 of 1,385 · Encryption · WEB The home page arrives unencrypted. 15%
Supports TLS 1.3 1,160 of 1,260 · Encryption · TLS Of the hosts that answered the encryption check. 92%
Accepts TLS 1.0 or 1.1 146 of 1,260 · Encryption · TLS Every one of them also offers a modern version. 12%
RSA keys under 2048-bit 0 of 1,260 · Encryption · TLS 0%
SHA-1 signatures 0 of 1,260 · Encryption · TLS 0%
Let's Encrypt certificates 815 of 1,260 · Encryption · TLS 65%
Certificate name mismatch 63 of 1,385 · Encryption · WEB 4.5%
Expired certificate 16 of 1,385 · Encryption · WEB 1.2%
No Content-Security-Policy 1,081 of 1,385 · Headers · WEB 78%
No framing protection 971 of 1,385 · Headers · WEB 70%
No Strict-Transport-Security 785 of 1,385 · Headers · WEB 57%
Publishes security.txt 11 of 1,385 · Headers · WEB 0.8%
DNSSEC signed 3 of 1,385 · DNS · DNS 0.2%
CAA record 26 of 1,385 · DNS · DNS 1.9%
IPv6 184 of 1,385 · DNS · DNS 13%
Discloses a WordPress version 195 of 1,385 · Software · WEB 14%
WordPress behind on fixes 38 of 195 · Software · WEB 36 behind on available fixes, and 2 on a line no longer supported at all. 19%
Known WordPress flaws, by version Software · WEB 21 versions, each carrying between 1 and 100 known flaws. The same flaw recurs across versions, so these cannot be added together. 21
No DMARC record 660 of 1,305 · Email · MAIL 51%
No enforced DMARC 945 of 1,305 · Email · MAIL No record at all, set to monitor only, or published but broken. 72%
DMARC enforcing 360 of 1,305 · Email · MAIL Set to quarantine or reject forged mail. 28%
No SPF record 178 of 1,305 · Email · MAIL 14%
Neither SPF nor DMARC 162 of 1,305 · Email · MAIL 12%
Mail server that no longer exists 12 of 1,305 · Email · MAIL Predicted from the domain’s settings rather than from a message that bounced. 0.9%
Sites with at least one serious problem 389 of 1,385 · Severity · WEB Each site counted once, at its most serious finding. 28%

Two counting rules that matter

A finding is one observation about one site, and most of what we recorded is a check that passed, so the number of records is not a number of problems and is never presented as one. A site with several problems is counted once, at its most serious. And the WordPress flaw counts are given per version and never added up, because the same flaw affects several versions and a total would count it repeatedly.

The high-severity count includes sites running a WordPress version that is missing security fixes, which is why it is 389 and not the 360 you would get from the website checks alone.

Every share here is worked out from the two numbers beside it, so any of it can be checked without taking our word for it.

Is your domain in here?

Probably, if it ends in .bm. We do not publish per-domain results and we never will, but if you want to know what we saw for your own domain, ask and we will send it. There is no charge and nothing to buy. If you would rather not be looked at again, that takes one email and no explanation.