SECURITY RESEARCH · 2026

The State of Zimbabwe Web Security 2026

What we found assessing 17 Harare businesses across 5 sectors — and what every Zimbabwean business owner should take from it.

Download the PDF

17

Businesses assessed

5

Sectors covered

16/17

Had a fixable vulnerability

57

Findings logged in total

Over the past months we ran passive, no-touch security assessments of 17 businesses across Harare — hospitality, healthcare, legal, education and the NGO sector. We never logged in, scanned ports, or touched a live system. Everything below comes from publicly available information any attacker could see. The picture is consistent, and it's fixable.

What we found

The most common issues, by share of the businesses assessed:

Missing one or more critical security headers15 of 17 · 88%
No privacy policy (Data Protection Act 2021 gap)12 of 17 · 71%
Running outdated software / CMS / plugins11 of 17 · 65%
No HTTP→HTTPS redirect or weak TLS configuration8 of 17 · 47%
No SPF/DMARC — email can be spoofed from their domain7 of 17 · 41%
Exposed admin panel or sensitive endpoint4 of 17 · 24%

Sectors we looked at

HospitalityHealthcareLaw firmsSchoolsNGOs

What it means

None of these are exotic, nation-state problems. They're the basics — security headers, software updates, a privacy policy, email anti-spoofing — and the overwhelming majority of the businesses we assessed were missing at least one. Each is cheap to fix once you know it's there, and each is something a motivated attacker (or an automated bot) finds in minutes.

The privacy-policy gap matters twice over: it's a Data Protection Act (2021) compliance exposure as well as a trust signal. And the email anti-spoofing gap means a stranger can send mail that looks like it came from these businesses — a direct phishing risk to their own customers.

What to do about it

  • Add the core security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options).
  • Update your CMS, plugins, and server software — and keep them updated.
  • Publish a privacy policy and make sure HTTP redirects to HTTPS.
  • Set SPF and DMARC records so no one can spoof email from your domain.
  • Get a passive assessment so you know exactly where you stand — it's free.

Methodology: passive assessment only — public DNS, certificate transparency, HTTP response headers, and open-source reconnaissance. No authentication, port scanning, or exploitation. Figures are aggregated and anonymised; no individual business is identified.

Where does your business stand?

Get a free passive assessment of your own site — no obligation, no cost.