Research · 8 September 2026
State of Bermuda on the Web
On one day in September we looked at every .bm name we could find that
was alive on the internet, and wrote down how it was set up. 1,385 websites and 1,305 mail domains.
Nothing was broken into, guessed at, or tested for weaknesses: everything below is what a domain already
publishes to anyone who asks. How that was done.
Every figure on this page prints the count it came from, so you can check any of it against the evidence table at the foot. No cybersecurity background is assumed and every term is explained where it first appears.
Two kinds of security, and Bermuda is only good at one
The basic plumbing of a secure website is in good shape here, because free automated certificates and services like Wix, Squarespace and Shopify give it to you without your having to think about it. Everything a domain's owner has to switch on deliberately is a different story. Both columns below read the same way, the share of domains that have the protection, so higher is better on both sides.
Handled for you
A platform or a certificate authority switches these on. Bermuda's whole national population sits close to a benchmark drawn from the world's best-resourced websites.
websites, or mail domains where stated
Of the 1,305 mail domains.
Needs you to act
These live in settings only the domain's owner controls. No platform can do them for you, and mostly they have not been done.
websites, or mail domains where stated
Of the 1,305 mail domains.
If an organisation only ever does one thing from this whole report, it should be the first row on the right: get DMARC to an enforcing setting. It protects the most people against the most common kind of attack, and for most domains it is a single change.
What was actually looked at
1,385 is the number nearly everything on this page divides by, so it is worth knowing what it leaves out. Open any step to see what dropped and why.
1,561 live .bm domains
Names that resolve or accept mail, found from two independent public sources: the certificate transparency logs, and a large public catalogue of the web. Between them these hold 2,939 live hostnames.
1,475 serving a website
86 of the live domains answer on the internet without serving a web page. Most of these are mail-only: a registered name that carries email for an organisation whose website lives somewhere else.
1,385 websites assessed
90 more were removed as parked pages with no real content, or domains whose public address points at an internal, unreachable location. That second case is a configuration error rather than a website, so counting it as one would have understated every share on this page.
Separately, 1,305 of the live names accept email and were checked for that. Those are the domains every email figure on this page divides by.
What this is not
It is not a census of Bermuda's digital economy. Many organisations here, particularly in international business, run on .com and are simply out of scope, and holding a .bm name does not prove a company is Bermudian. Read this as the observable .bm web, not every Bermuda business online.
What Bermuda's web is built on
Two thirds of sites do not say what they are built with, which is unremarkable. Of those that do, one name dominates, and it happens to be the one that needs its owner to keep it updated.
of 1,385 assessed websites
Unremarkable. Modern site builders and hand-built sites often say nothing about themselves.
of 1,260 certificates read
Free, and renews itself. The single clearest reason the encryption figures below look as healthy as they do.
What Google-hosted and Squarespace sites use.
The certificates are the more reliable view of who supplies Bermuda's infrastructure, because a certificate names its issuer and cannot be hidden the way a platform banner can. Paid commercial certificates are now a small minority. That is the clearest single reason the encryption figures in the next section look as healthy as they do: good security here is free and automatic, and Bermuda has taken it up.
An earlier stage of this work estimated which hosting companies carry the most Bermuda sites. That estimate could not be checked against anything we kept, so it is left out rather than published unverified. The two charts above can be, and they stand on their own.
How well connections are protected
When you see a padlock, your connection is encrypted and nobody in between can read or change what passes. Whether a site offers that, and whether the protection is any good, are two different questions. Bermuda answers the second one better than the first.
of 1,385 assessed websites
The padlock exists. The front door is left open.
of 1,260 hosts that completed a handshake
Every one of these also offers modern encryption, so no ordinary visitor is forced onto the weak version. On any site that handles card details it is still a failure of the card-payment standard, which no longer allows these versions.
Not one site we checked. This is the result that would have been the emergency, and it did not happen.
of 1,385 assessed websites
Nor a single SHA-1 signature. Where Bermuda certificates go wrong it is through misconfiguration, never weak cryptography.
Any of the first three shows the visitor a browser security warning, which both looks alarming and trains people to click through warnings they should not. The cryptography underneath is uniformly modern: not one undersized key and not one broken SHA-1 signature on any site we checked.
The extra locks a site can fit
Beyond encryption, a website can send the visitor's browser a set of instructions that harden the page against common attacks. They are invisible, optional, and each closes one specific risk. This is where Bermuda looks weakest at first glance, and it is also where that first glance is most misleading.
of 1,385 assessed websites
Stops a first visit being downgraded to an insecure one.
Stops the browser being tricked about a file’s type.
Stops the site being hidden inside a fake page to trick clicks.
Limits what scripts a page will run.
Stops leaking which page a visitor came from.
Limits access to camera, location and similar.
of 1,385 assessed websites
Supports the newer internet addressing scheme.
Limits who is allowed to issue certificates for the domain.
Stops visitors being silently sent to a fake copy of the site. Three of the 1,385 sites checked. At most providers it is one switch.
Read alone, "only 22 percent of sites have a content-security-policy" sounds like a crisis. It is not, and presenting it that way would be misleading: the same gaps exist across most of the world's websites, including well-resourced ones. They are worth adding, and their absence is the global norm rather than a Bermuda failing.
DNSSEC is the one that stands out, and it is not a header. Three of the 1,385 sites we checked are signed. Low DNSSEC adoption is common worldwide too, but at essentially zero Bermuda sits below even that low bar, and for most domains it is a single switch at the DNS provider. That makes it a matter of awareness rather than effort.
How well website software is kept up to date
This section is only about WordPress, because it is the one common platform that reveals its version and that the site's owner is responsible for updating. Wix and Squarespace update themselves, so they do not appear here. WordPress issues security fixes for older lines too, so the fair test is not how old a version is but whether it has applied the fixes that exist for it.
of 195 sites that disclosed a version
38 of the 195 WordPress sites that show their version, 19%, are running a version that is missing security fixes which already exist. Every one of the 38 is on a version with at least one known, published flaw. Across the 21 versions involved the counts run from 1 to 100, with a middle value of 13.
These are flaws known to affect a version, looked up in the WPScan database. They are not proof that any of them can be exploited on a particular site, which depends on that site’s plug-ins, settings and other defences. None of that was tested. The narrower, still useful statement: these sites have not applied security updates that exist.
These counts overlap. A flaw in an old version usually affected the versions before it too, so adding them up would count the same flaw again and again. That is why there is no total anywhere on this page.
The practical message is simple and old. WordPress sites need their updates applied, and a fifth of Bermuda's visible ones are behind.
How well email is protected against impersonation
Email has a design flaw: by default, anyone can put your domain in the "from" line of a message. Three settings close it. SPF lists which mail servers may send for you. DKIM signs your genuine messages. DMARC ties the two together and tells the world's mail systems what to do when a message fails the checks. DMARC is the keystone, and it is where Bermuda is furthest behind.
-
1. Anyone can write your name in the From line
Email was designed without a check on who a message says it is from. Nothing stops a stranger sending an invoice that appears to come from your company.
-
2. SPF and DKIM give the receiving system something to check
SPF lists which mail servers may send for your domain. DKIM adds a signature to your genuine messages. Between them the receiver can tell a real message from a forged one.
-
3. The forged message fails both checks
It came from a server your SPF record does not list, and it carries no valid signature. The receiver now knows it is not from you.
-
4. DMARC is what decides the outcome
Without a DMARC record, or with one set to monitor only, the receiver is left to decide for itself, and forged mail often gets through. Set to quarantine or reject, the domain tells the receiver to stop it. That single setting is the difference, and 72 percent of Bermuda mail domains have not made it.
of 1,305 domains that accept mail
Watches, blocks nothing.
A record with no policy in it, two records where only one is allowed, or a policy receivers do not recognise, such as a misspelt "quaratine". Receivers ignore all three.
of 1,305 domains that accept mail
Treat this as a minimum. DKIM keys can be named anything and there is no way to list them all, so "not found" here does not prove a domain never signs its mail. This is the one email check that cannot be read as an absence.
Which makes the record fail.
A strong prediction that inbound mail is failing, derived from the domain’s own configuration. A handful were confirmed by hand. Nobody watched a message bounce, so it is reported only as strongly as that method supports.
Which cancels them out.
Put the DMARC lines together and 945 of 1,305 mail domains, 72 percent, publish no enforced anti-impersonation policy. Just over half publish nothing at all, and another fifth publish one set to monitor only, which watches but blocks nothing. This is the most consequential and most fixable finding in the study: the fix is usually a single line added to a domain's settings, and it directly reduces the risk of someone sending convincing fake invoices in a Bermuda organisation's name.
Two further mail settings, MTA-STS and TLS-RPT, which harden server-to-server delivery, are absent on 99 percent of domains. As with the website headers, that is rare everywhere and is noted for completeness rather than concern.
How Bermuda compares with the wider world
Carefully, because these do not measure the same population. Most of the global figures come from a crawl of the top one million most-visited websites, counted over the roughly 819,000 that responded: the best-resourced sites on the internet. Bermuda's 1,385 is a whole national long tail, corner shops and clubs included, and a long tail should look weaker than a top-sites benchmark. This is context, not a scoreboard, and no claim is made that Bermuda is ahead or behind overall.
The pattern is the same one the whole report describes. On the settings commercial platforms handle automatically, Bermuda's whole-population numbers sit close to a benchmark drawn from the world's best sites, most plausibly because free, automatic certificates do that work here: Let's Encrypt alone issued 815 of the 1,260 certificates we read. On the one setting in that list no platform switches on for you, DNSSEC, Bermuda falls well below even the modest global level.
The benchmarks come from different studies with different dates and definitions, so a small difference between a Bermuda figure and a benchmark is not meaningful. Read "close to the top million" as platform defaults having lifted the floor, not as a ranking win.
What to do about it
A suggested order of priorities, not a timetable. Because nearly all of these settings live with individual domain owners, the biggest island-wide gain comes from many owners each making a few small changes rather than from any single central action.
Show what applies to me
Wix, Squarespace, Shopify or similar. The platform handles the website half and does it well. Everything left on your plate lives in your domain settings, which is exactly where Bermuda is weakest.
You or your IT provider control the server, so nothing here is switched on for you. That includes the update backlog: a fifth of Bermuda’s visible WordPress sites are missing security fixes that already exist.
A centrally-run estate gets none of the automatic defaults that carry so much of the private sector. Everything on this page has to be done deliberately rather than arriving switched on with the platform.
First priority
Usually achievable quickly, and between them these help the most people for the least work.
Publish a DMARC policy, then set it to enforce
Stops mail forged in your name being delivered. For most domains it is a single line.
How you know it is done. A DMARC record exists and says quarantine or reject, not none.
Add an SPF record where it is missing, and fix broken ones
Lets receiving systems tell your genuine mail from a forgery.
How you know it is done. One valid SPF record, and only one.
Send all web traffic to HTTPS
Every visitor gets the encrypted version by default, not just the ones who type it.
How you know it is done. Typing the plain address lands you on the secure one.
Replace mismatched and expired certificates
Removes the browser security warning visitors currently see, which trains people to click through warnings.
How you know it is done. The site loads with no warning.
Check that the mail server named in your DNS still exists
Twelve domains name one that does not. Their inbound mail is very likely failing to arrive.
How you know it is done. The mail server in your DNS resolves and accepts mail.
Nothing in this group applies to you.
Second priority
A little more setup, and some of it depends on who runs your server.
Turn on DNSSEC
Stops visitors being sent to a fake copy of your site. Three of the 1,385 sites we checked have it.
How you know it is done. Your DNS provider shows DNSSEC as enabled.
Update WordPress
Closes flaws that are already known and already fixed. The 38 sites behind are running versions with published, catalogued problems.
How you know it is done. The site reports the current version for its line.
Switch off TLS 1.0 and 1.1
Retires obsolete encryption, which the card-payment standard no longer allows on any site that handles card details.
How you know it is done. Only TLS 1.2 and 1.3 are accepted.
Add the main security headers
Reduces what a common web attack can do. Worth having, though their absence is the global norm rather than a Bermuda failing.
How you know it is done. A content-security-policy and framing protection are present.
Nothing in this group applies to you.
Ongoing priority
The part that stops the backlog coming back.
Publish a security.txt contact
Gives a researcher who spots a fault somewhere to send it. Eleven Bermuda sites have one, so at the moment there is usually nowhere.
How you know it is done. The file is reachable at /.well-known/security.txt and names a contact.
Keep software and certificates current
Prevents the backlog returning, which is the only way any of the above stays fixed.
How you know it is done. Updates and renewals happen automatically, or on a schedule somebody owns.
Nothing in this group applies to you.
What we still do not know
One snapshot, and deliberately cautious about what it claims.
It cannot show change over time
One day of data. No honest claim can be made that anything is improving or worsening. Repeating the same measurements later, and only then, would allow that.
It cannot confirm anything is exploitable
A missing setting or an outdated version is a risk indicator, not proof a site can be broken into. Confirming that needs permission-based testing of an individual site, which this study did not do and was never designed to do.
Detection has blind spots
Software versions can be hidden or misreported, DKIM keys cannot be exhaustively found, and a site behind certain infrastructure looks different from the outside than it is. Some failed connections may be a filter between the observer and the site rather than a fault at the site.
It covers the .bm web only
Many Bermuda organisations, particularly in international business, operate on .com and are simply not in scope. And holding a .bm name does not prove an organisation is Bermudian. Read this as the observable .bm web, not every Bermuda business online.
One estimate we could not check
We looked at which hosting companies carry the most .bm sites, then could not check that answer against anything we had kept, so it is not here. The certificate issuers above cover the same ground and can be checked.
A repeat study, run the same way on a later date, would let Bermuda track real progress on the two things that matter most and are most within owners' control: enforced email protection and basic DNS security.
Every figure on this page, and where it came from
Every figure, what it was counted out of, and which check it came from, all observed on 8 September 2026. The checks were: WEB is the website sweep, TLS the dedicated encryption pass, MAIL the mail-domain checks, DNS the domain record depth check, DISC the discovery files.
Two counting rules that matter
A finding is one observation about one site, and most of what we recorded is a check that passed, so the number of records is not a number of problems and is never presented as one. A site with several problems is counted once, at its most serious. And the WordPress flaw counts are given per version and never added up, because the same flaw affects several versions and a total would count it repeatedly.
The high-severity count includes sites running a WordPress version that is missing security fixes, which is why it is 389 and not the 360 you would get from the website checks alone.
Every share here is worked out from the two numbers beside it, so any of it can be checked without taking our word for it.
Is your domain in here?
Probably, if it ends in .bm. We do not publish per-domain results and we never will, but if you want to know what we saw for your own domain, ask and we will send it. There is no charge and nothing to buy. If you would rather not be looked at again, that takes one email and no explanation.