RZIJZ Cybersecurity Survey: Key Findings


RZIJZ Cybersecurity Survey: Key Findings

RZIJZ Cybersecurity Survey: Key Findings

INFORMACIJSKA VARNOSTKIBERNETSKA VARNOSTSPOOFINGZINFV-1NIS-2

RZIJZ Cybersecurity Survey

Key Findings

Automated security scan of 1043 domain names associated with 1143 Slovenian public entities registered in RZIJZ (Register zavezancev za informacije javnega značaja — the mandatory register of entities obligated to provide public access to information under ZDIJZ). Schools and kindergartens excluded. Scanned: April 7, 2026.

Executive summary

The survey covers RZIJZ-registered entities (N=1143) with an identifiable web domain. The overall mean security score is 56.3/100 (median 55), indicating systemic underinvestment in basic cybersecurity hygiene across the Slovenian public sector.


Detailed Reports

Key Findings

Detailed Breakdowns

Domains

Press Release


Main risk factors

  1. Email spoofing exposure — only 18.6% of domains enforce DMARC (reject/quarantine). The remaining 81.4% can be trivially impersonated in phishing attacks targeting citizens and other public entities.

  2. CMS fingerprinting — 43.9% of domains run a detectable CMS (WordPress 41.6%, Drupal 2.3%), making the attack surface publicly known. 11.3% combine WordPress with no DMARC — a high-risk combination enabling both exploitation and phishing.

  3. Transport security gaps — 62.1% of domains lack HSTS, leaving users vulnerable to SSL stripping / downgrade attacks.

  4. No responsible disclosure channel — 94.2% of domains have no security.txt, meaning security researchers have no official route to report vulnerabilities.

  5. Hosting concentration — the top two ISPs (Webtasy and Pošta Slovenije) host nearly 30% of all public sector domains, creating systemic single points of failure.

  6. 5.2% of domains hosted outside the EU, with no GDPR guarantee on data processing location.

13.2% score below 40 (critical risk) and a further 43.7% score 40–59 (poor). Combined, 56.9% of all scanned public entities have inadequate baseline security.



Overall scorecard

Score distribution

MetricValue
Mean score56.3 / 100
Median score55 / 100
Min / Max10 / 100
Stdev16.9

Risk bands

BandCount%
Good (>=80)14512.7%
Moderate (60-79)34730.4%
Poor (40-59)50043.7%
Critical (<40)15113.2%

Security check pass rates

CheckPass %Risk if failing
DMARC (enforce/quarantine)18.6%Domain can be spoofed for phishing
DMARC (any policy)63.7%Includes monitoring-only
SPF (hard fail)54.2%Sender auth incomplete
DKIM60.2%Email integrity unverified
HTTPS redirect77.3%HTTP access possible
HSTS37.9%Downgrade attacks possible
security.txt5.8%No disclosure contact

Hosting sovereignty

Location%Note
Slovenia (SI)76.8%Data stays in Slovenia
EU (non-SI)11.5%GDPR applies
Outside EU5.2%No GDPR guarantee
Unknown6.6%Could not determine

CMS fingerprinting

CMS%Note
WordPress41.6%Attack surface publicly known
Drupal2.3%
Any detected43.9%

Risk combinations

Combination% of all domains
WordPress + no DMARC11.3%
Outside-EU + no HTTPS redirect7.8%

By sector (kategorija)

Kategorija classifies each entity by sector (healthcare, municipalities, utilities…). Sorted worst-first by mean score.

GroupNMeanMedianDMARC%DKIM%HSTS%SI%WP%
naravni_park1540.7420.0%33.3%33.3%66.7%53.3%
socialne_storitve1344.74515.4%38.5%15.4%76.9%61.5%
gledalisce_kultura1452.950.00.0%71.4%35.7%64.3%21.4%
drugo_javno44553.75522.0%60.4%31.7%69.0%45.6%
muzej_galerija3354.8559.1%54.5%21.2%87.9%51.5%
transport1354.95523.1%53.8%15.4%76.9%53.8%
zdravstvo18155.85514.4%63.5%24.3%81.2%54.1%
komunala7356.65524.7%63.0%26.0%80.8%50.7%
stanovanjski_sklad956.75022.2%55.6%44.4%55.6%44.4%
lekarna2059.258.520.0%70.0%45.0%80.0%40.0%
obcina20960.26012.9%46.9%63.6%89.5%22.0%
univerza_fakulteta6461.562.010.9%85.9%45.3%79.7%40.6%
voda_kanalizacija764.96528.6%100.0%28.6%71.4%14.3%
energetika3566.07045.7%80.0%62.9%68.6%22.9%
holding_infrastruktura869.875.037.5%50.0%75.0%87.5%25.0%

Oblika is the legal organisational form registered in RZIJZ (d.o.o., javni zavod, d.d.…). Larger commercially-oriented forms tend to score higher. Sorted worst-first.

GroupNMeanMedianDMARC%DKIM%HSTS%SI%WP%
Ustanova738.6450.0%42.9%14.3%42.9%71.4%
Izvršitelj5505520.0%60.0%0.0%80.0%60.0%
Zavod7454.055.025.7%60.8%25.7%77.0%52.7%
Družba z omejeno odgovornostjo d.o.o.52254.355.020.1%61.1%33.1%72.8%46.2%
Javni zavod25556.15517.3%64.3%25.5%76.1%47.8%
Javni sklad1157.86218.2%54.5%36.4%36.4%54.5%
Javna agencija758.96028.6%42.9%0.0%85.7%42.9%
Lokalne skupnosti19860.460.012.6%46.5%66.2%91.4%20.2%
Članica univerze1962.2650.0%100.0%89.5%94.7%5.3%
Organ, organizacija širše lokalne skupnosti363.35533.3%66.7%33.3%66.7%100.0%
Zbornica366.76533.3%100.0%0.0%100.0%66.7%
Skupnost zavodov368.3800.0%66.7%66.7%100.0%100.0%
Delniška družba d.d.2768.76540.7%70.4%59.3%63.0%22.2%

By region (region)

Region groups entities by administrative region codes. Regions with 3+ domains only. Sorted worst-first.

GroupNMeanMedianDMARC%DKIM%HSTS%SI%WP%
Zasavska2951.65013.8%69.0%34.5%69.0%41.4%
Goriška7054.655.015.7%58.6%27.1%81.4%34.3%
Savinjska13154.75519.8%60.3%36.6%77.1%44.3%
Posavska5155.25517.6%64.7%27.5%70.6%27.5%
Podravska15455.555.018.8%49.4%39.6%79.2%46.1%
Koroška3955.75517.9%56.4%38.5%74.4%30.8%
Jugovzhodna7955.85515.2%59.5%32.9%82.3%55.7%
Gorenjska11755.95520.5%52.1%41.9%76.1%39.3%
Obalno-kraška5656.055.012.5%71.4%32.1%80.4%53.6%
Pomurska6756.25513.4%61.2%40.3%73.1%35.8%
Primorsko-notranjska2758.26025.9%63.0%29.6%88.9%55.6%
Osrednjeslovenska32358.65521.1%65.3%42.7%74.6%39.0%

By municipality (obcina)

Obcina is the municipality of the entity’s registered office. Municipalities with 3+ domains only. Sorted worst-first.

GroupNMeanMedianDMARC%DKIM%HSTS%SI%WP%
Radlje Ob Dravi437.238.00.0%0.0%100.0%25.0%0.0%
Vojnik437.540.025.0%0.0%25.0%50.0%50.0%
Črnomelj639.240.016.7%16.7%0.0%100.0%50.0%
Tabor345450.0%100.0%0.0%100.0%0.0%
Brda345450.0%0.0%0.0%100.0%0.0%
Slovenske Konjice345.7400.0%100.0%33.3%66.7%33.3%
Gorišnica446.250.00.0%25.0%0.0%100.0%100.0%
Komenda346.74533.3%0.0%100.0%66.7%0.0%
Vrhnika64747.50.0%66.7%0.0%83.3%50.0%
Moravske Toplice347.3450.0%100.0%0.0%66.7%66.7%
Prevalje648.345.00.0%33.3%33.3%100.0%0.0%
Trbovlje7494514.3%42.9%57.1%57.1%28.6%
Lenart349450.0%66.7%66.7%66.7%0.0%
Ormož749.3550.0%42.9%57.1%71.4%42.9%
Litija749.75014.3%71.4%28.6%85.7%42.9%
Koper2149.8459.5%71.4%28.6%66.7%52.4%
Jesenice1850.245.011.1%44.4%11.1%88.9%55.6%
Tržič1250.350.00.0%66.7%0.0%66.7%33.3%
Velenje1350.55523.1%61.5%23.1%76.9%61.5%
Grad45151.00.0%0.0%50.0%50.0%0.0%
Domžale951.15511.1%33.3%22.2%77.8%22.2%
Šentjur951.15522.2%55.6%22.2%100.0%33.3%
Idrija751.15514.3%57.1%28.6%85.7%57.1%
Slovenj Gradec1051.245.010.0%80.0%10.0%60.0%60.0%
Tolmin851.652.50.0%62.5%25.0%87.5%50.0%
Škofljica351.77066.7%33.3%66.7%66.7%33.3%
Brežice1252.451.025.0%58.3%16.7%50.0%8.3%
Zagorje Ob Savi952.85511.1%77.8%33.3%66.7%33.3%
Krško1253.255.025.0%75.0%33.3%50.0%8.3%
Škofja Loka1053.357.520.0%80.0%20.0%90.0%50.0%
Majšperk353.3550.0%33.3%33.3%100.0%66.7%
Žalec953.6550.0%77.8%0.0%77.8%66.7%
Nazarje453.852.525.0%75.0%50.0%50.0%0.0%
Ivančna Gorica7545514.3%71.4%28.6%71.4%42.9%
Trebnje654.255.00.0%83.3%0.0%100.0%66.7%
Celje3854.450.018.4%63.2%42.1%68.4%50.0%
Novo Mesto2554.65020.0%60.0%28.0%72.0%68.0%
Maribor6854.755.025.0%54.4%26.5%72.1%48.5%
Nova Gorica2254.855.022.7%50.0%13.6%77.3%18.2%
Renče-Vogrsko355550.0%100.0%0.0%100.0%66.7%
Radovljica5555240.0%60.0%20.0%60.0%40.0%
Brezovica305550.016.7%83.3%16.7%100.0%100.0%
Hoče-Slivnica3553533.3%66.7%33.3%100.0%33.3%
Dobje45555.00.0%100.0%0.0%100.0%100.0%
Hrastnik15555820.0%80.0%20.0%60.0%60.0%
Radenci355550.0%100.0%0.0%66.7%33.3%
Rogaška Slatina855.255.025.0%50.0%25.0%87.5%37.5%
Ajdovščina955.35522.2%77.8%44.4%66.7%22.2%
Vodice45656.00.0%50.0%50.0%50.0%0.0%
Postojna1256.157.533.3%75.0%25.0%91.7%50.0%
Murska Sobota1856.255.016.7%55.6%38.9%50.0%16.7%
Logatec456.255.025.0%100.0%0.0%100.0%100.0%
Naklo1256.255.025.0%50.0%50.0%50.0%50.0%
Grosuplje456.257.50.0%25.0%50.0%75.0%75.0%
Ptuj2256.655.013.6%59.1%36.4%81.8%54.5%
Mozirje356.74533.3%66.7%33.3%100.0%33.3%
Ljutomer656.755.00.0%66.7%33.3%83.3%33.3%
Sevnica757.45514.3%85.7%28.6%85.7%14.3%
Žirovnica657.557.50.0%50.0%50.0%100.0%50.0%
Luče457.557.50.0%50.0%50.0%100.0%50.0%
Sežana105855.010.0%60.0%30.0%100.0%70.0%
Kočevje758.16014.3%57.1%28.6%85.7%28.6%
Bled958.25544.4%33.3%55.6%66.7%33.3%
Kranj3858.255.023.7%47.4%47.4%78.9%39.5%
Slovenska Bistrica858.959.525.0%50.0%37.5%50.0%25.0%
Ljubljana22959.55823.6%68.1%45.9%72.1%37.1%
Izola360650.0%33.3%33.3%100.0%33.3%
Markovci46060.00.0%50.0%100.0%100.0%50.0%
Straža360600.0%0.0%100.0%100.0%0.0%
Kamnik960.26011.1%55.6%44.4%88.9%44.4%
Mengeš360.75533.3%66.7%33.3%33.3%66.7%
Puconci46158.525.0%50.0%25.0%50.0%25.0%
Piran661.258.516.7%83.3%33.3%83.3%33.3%
Ilirska Bistrica462.562.525.0%25.0%25.0%100.0%75.0%
Šenčur462.565.00.0%100.0%75.0%75.0%25.0%
Šoštanj463.267.525.0%100.0%75.0%50.0%0.0%
Bovec363.36033.3%33.3%33.3%100.0%33.3%
Ravne Na Koroškem963.86033.3%77.8%11.1%77.8%55.6%
Dravograd664.563.550.0%66.7%50.0%83.3%16.7%
Kranjska Gora3656033.3%33.3%66.7%100.0%0.0%
Ruše66565.033.3%66.7%66.7%100.0%66.7%
Cerknica3656033.3%66.7%33.3%100.0%66.7%
Kidričevo366.77066.7%33.3%33.3%100.0%33.3%
Železniki667.377.033.3%100.0%66.7%0.0%66.7%
Cerklje Na Gorenjskem46866.050.0%50.0%75.0%75.0%0.0%
Gornja Radgona468.870.050.0%75.0%25.0%100.0%75.0%
Lendava47067.550.0%100.0%50.0%75.0%50.0%
Laško470.576.075.0%50.0%50.0%75.0%25.0%
Šentilj371.77066.7%33.3%33.3%100.0%33.3%
Ribnica1271.872.525.0%100.0%25.0%75.0%75.0%
Šempeter-Vrtojba373.38066.7%100.0%33.3%66.7%66.7%
Medvode573.46540.0%100.0%60.0%60.0%20.0%
Škocjan380800.0%100.0%100.0%100.0%0.0%

Hosting provider concentration (top 15)

Concentration in a few providers is a systemic risk: an incident at a dominant ISP affects many public entities simultaneously.

ISPDomains%
Webtasy, d.o.o.19417.0%
Posta Slovenije d.o.o.14412.6%
Optimus IT d.o.o.837.3%
(unknown)756.6%
Telemach d.o.o.585.1%
AVANT.SI d.o.o534.6%
Hetzner Online GmbH474.1%
SIEL, INFORMACIJSKE RESITVE, D.O.O.403.5%
ARNES provider393.4%
Hitrost.com Internet Storitve d.o.o.343.0%
Cloudflare, Inc.302.6%
Optimus IT d.o.o. sub of272.4%
ARCTUR d.o.o.221.9%
Avtenta.si191.7%
PERFTECH, podjetje za proizvodnjo in uvajanje novih tehnologij, d.o.o.191.7%

DomainScoreKategorijaCountrySPFDKIMDMARCHSTS
veterinarska-bolnica.si10drugo_javnoSIfailfailfailno
komunala-slb.si10komunalaUSwarnfailfailno
alba-ce.com10drugo_javnoCAwarnfailfailno
ircuo.si10drugo_javnoSIfailfailfailno
szf.si15drugo_javnoGBfailfailfailno
rcr-zasavje.si15drugo_javnoGBfailfailfailno
obcina.skofljica.si15obcinaUSfailfailfailyes
fizio-obala.si17drugo_javnoDEwarnokfailno
mc-litija.si18drugo_javnofailfailfailyes
olvidnja.si18drugo_javnofailfailfailyes
publicus.si18komunalafailfailfailyes
vdcvipava.si18socialne_storitvefailfailfailyes
lotusart.si18drugo_javnofailfailfailyes
sistemika.si18zdravstvofailfailfailyes
obcina-gup.si18energetikafailfailfailyes
zavodruj.si18drugo_javnofailfailfailyes
papilot.si18drugo_javnofailfailfailyes
i-ulfgg.si18holding_infrastrukturafailfailfailyes

Best scoring domains (best scores)

DomainScoreKategorijaCountrySPFDKIMDMARCHSTS
sava.si100drugo_javnoSIokokokyes
ir-rs.si100univerza_fakultetaSIokokokyes
sdh.si100holding_infrastrukturaSIokokokyes
gek.si100energetikaSIokokokyes
zd-ms.si95zdravstvoSIokokokyes
slo-zeleznice.si95transportSIokokokyes
domtaber.si95drugo_javnoSIokokokyes
b2.eu95drugo_javnoSIokokokyes
psih-klinika.si95zdravstvoSIokokokyes
komunala-nm.si95komunalaSIokokokyes
piran.si95obcinaSIokokokyes
talum.si95drugo_javnoSIokokokyes
siq.si95drugo_javnoSIokokokyes
hoce-slivnica.si95obcinaSIokokokyes
jkp-dravograd.si95komunalaSIokokokyes
petrol.si95drugo_javnoSIokokokyes
kraski-vodovod.si95voda_kanalizacijaSIokokokyes
rra-koroska.si95drugo_javnoSIokokokyes
prevozi-guliver.si95drugo_javnoSIokokokyes
slov-bistrica.si95obcinaSIokokokyes


Informacijski pooblaščenec in URSIV preverjata dokumentacijo, ne le sisteme. Ste pripravljeni?

ZInfV-1 zahteva dokazljivo usposabljanje zaposlenih — evidence udeležbe so med prvimi dokumenti, ki jih preveri inšpekcija. Naš praktičen tečaj (prilagojen vaši organizaciji) pokrije zakonsko obveznost in zgradi varnostno kulturo v enem koraku. Pridobite ponudbo za vašo organizacijo →

key_findings

RZIJZ Cybersecurity Survey: Domains

Kibernovarnostna raziskava RZIJZ: Ključne ugotovitve

Kibernovarnostna raziskava RZIJZ: Domene

Report: Over 80% of Slovenian Public Sector Domains Vulnerable to Spoofing, Cybersecurity Survey Finds

Kibernovarnostna raziskava RZIJZ: Celotna statistika po skupinah