Nixeny Dijital - Mersin / Cyber Hygiene & KVKK 2026
The response headers and home pages of 4,167 business websites in Mersin were examined. 60.9% of the reachable sites send none of the six basic security headers; 69.3% link to no privacy text at all from their home page.
What this study is not
This report is not a security test. The only thing measured is the configuration any visitor also sees: response headers, cookie flags, and the links and scripts on the home page. The six points below hold for the whole report, and not one of them has been softened.
No vulnerability scan, port scan, directory scan, login attempt or attack-surface probe was performed. A missing header is a missing header; it does not mean “this site can be broken into”.
Every input is a response header the parent study had already downloaded and a home-page HTML already in its cache. No site was touched a second time for this report. What is measured is the configuration any visitor would also see.
If a site’s privacy notice is not linked from the home page it appears here as “absent”; it may exist on an inner page. Every rate in the KVKK section is therefore a floor.
No published file contains a business name or a domain; site rows carry a salted pseudonym. This report describes the state of a sector, a district or a platform — not of a business.
KVKK compliance is a legal assessment and this study does not make one. What is measured is the configuration visible on the home page: whether a link exists, whether a tool is loaded.
Every detection runs on regular expressions, and the patterns are listed openly in the study’s configuration. Pattern-based detection produces both false positives and false negatives; the rates should be read as orders of magnitude, not as point values.
4,167 domains were audited. 3,395 of them returned a response at the time of the audit; 3,509 had a readable home-page HTML; 3,429 could be given a score. All four are the same order of magnitude and easy to confuse with one another — which is why every figure names its own base in its header.
Glossary · every term explained once
- Cyber hygiene
- The subject of this report: the basic security and transparency settings of a website, as visible to a visitor. Not whether the site can be broken into, but which standard protections are switched on.
- Base
- This report uses four separate bases: 4,167 audited domains, 3,395 reachable sites, 3,509 sites with a readable home page, and 3,429 scorable sites. Every rate names which one it is over.
- Reachable site
- A site that returned an HTTP response at the time of the audit. Unreachable sites enter no rate at all; they are recorded as not measured, not as bad.
- HTTPS
- Encryption of the traffic between visitor and site. Without it, everyone on the same network can read what is typed into a form. Whether the certificate validates is a separate measure.
- HSTS
- The Strict-Transport-Security header: it tells the browser “always connect to this site encrypted from now on”. It is not the same as turning on HTTPS; it also closes off the unencrypted attempt.
- Content-Security-Policy
- The header that limits which sources a page may run scripts from. It is the hardest to set up and the broadest in effect, which is why adoption is low.
- Framing protection
- X-Frame-Options or CSP frame-ancestors: it stops the page from being embedded invisibly inside another site. Without it, a visitor can be made to click something other than what they think they are clicking.
- Secure / HttpOnly / SameSite
- Cookie flags. Secure sends the cookie only over an encrypted connection, HttpOnly hides it from scripts on the page, SameSite withholds it on requests coming from other sites.
- Consent management tool
- Software that asks for and records the visitor’s cookie preference. Showing a cookie notice and recording a preference are not the same thing; the report measures them separately.
- Privacy notice (KVKK)
- The disclosure required by Turkey’s data protection law. What is measured here is whether the home page links to such a text — not its content or its legal sufficiency.
- Third-party host
- Every domain outside the site’s own that the home page loads a resource from. Each is a separate party that receives the visitor’s IP address and browser string.
- Cyber Hygiene Score
- A weighted 0-100 score from six components: encrypted transport 30, security headers 25, transparency and consent 15, cookie hygiene 10, information disclosure 10, form security 10. A component that cannot be measured is dropped from both the numerator and the denominator.
- Risk level
- A summary of missing controls, not a vulnerability assessment. Critical = no HTTPS and a password, identity or payment field on the page. High = no HTTPS, a certificate that will not validate, or mixed content together with a form that collects data.
- Floor
- Because only the home page was examined, the KVKK and form rates are the worst case of the real situation. A text on an inner page is invisible to this study — so the real rates can be higher than what is written here, not lower.
Encrypted transport: good, but unfinished
91.8% of the reachable sites are served over HTTPS. Behind the remaining 279 sites stand 299 businesses, and everything typed into a form on those sites travels in a form everyone on the same network can read.
Four rows, four different bases. The redirect rate looks only at sites that answered over http://, the certificate check only at those serving HTTPS. Dividing all four by the same number would misstate three of them.
60.9% of sites send not one security header
There are six response headers a browser acts on directly. 60.9% of the reachable sites send none of them; the share sending all six is 2.6%.
All six over the same base. This is the one figure in the report whose rows can be compared directly.
The same six headers, this time counted per site. The horizontal axis is the number of headers coming from one site.
Two thirds of session cookies are unprotected
Of the 534 sites that set a session cookie, 67.2% send it without the HttpOnly flag and 34.6% without the Secure flag.
A three-layer base: the first row is all reachable sites, the middle rows the sites that set a cookie, the last two those that set a session cookie. Each row prints its own base beside it.
Sites announce what they are running
57.0% of sites announce, unprompted, the software or the version they run. This is not a vulnerability: a version number in a header is something the visitor’s browser already receives. The report says only that it is being sent.
The fourth row's base is the sites with a readable home-page HTML; the others are reachable sites. The difference between the two is 114 sites.
The first word of the Server header, normalised. This is not a market-share measurement; only what the sites that do send the header say.
No privacy notice is visible on the home page
69.3% of the sites with a readable home page — 2,432 sites — carry no link at all on that page to a privacy notice, a privacy policy or a cookie policy.
This is not a compliance audit. KVKK compliance is a legal assessment and it cannot be read off a home page. The only thing measured is whether a visitor arriving at the site can reach those texts — and because only the home page was examined, this rate is a floor: the text may exist on an inner page.
All six rows over the same base. The last row is the complement of the first five: sites linking to no policy text at all.
Tracking spread; consent infrastructure did not
40.8% of sites run at least one tracker, but only 7.7% use a consent management tool. The gap between the two collects into a single metric: 29.1%.
Trackers detected on the home page, most common first. The category comes from the study’s own classification: analytics, advertising, session recording.
The fourth row is this section’s subject: a tracker is loaded but there is neither a consent tool nor a cookie policy.
The eight most common of the 14 platforms detected. The axis ends at 5%; none of them comes near that line.
Opening one site means connecting to seven companies
A Mersin business site’s home page loads resources from a median of 7 distinct external domains (p90: 15, highest: 289). Each host is a separate party that receives the visitor’s IP address and browser string.
Hosts are counted, not requests: twenty requests to one CDN is one party, one request each to twenty hosts is twenty.
The fourteen most common of the 25 hosts detected. A host being on this list does not mean it is tracking; it shows only that a connection is made.
Half the forms that collect data carry no notice at all
Of the 982 sites that collect personal data on their home page, 57.2% offer no privacy or notice link on the same page. 41 of them do it over an unencrypted connection.
The first two rows are over 3,509 readable home pages; rows 3, 4 and 6 over the 982 sites collecting personal data; row 5 over the 125 sites with a password field.
Detected by field name and label pattern. False positives are possible; these numbers must be verified by hand before being repeated in a story.
Cyber Hygiene Score: median 51
A weighted 0-100 score from six components. Median 51.0, p25 46.4, p90 73.6. A component that cannot be measured is dropped from both the numerator and the denominator; if the remaining weight falls below 60% no score is published — 738 sites are unscored for that reason.
Buckets of twenty points. Sites without a score are not in this distribution; they were not counted as zero.
Each component’s median sub-score and its weight. The number of sites that could be measured differs by component, because a component that cannot be measured is dropped from both the numerator and the denominator for that site.
A hundred squares, each about 34 sites. The squares were allocated by largest remainder, so they sum to exactly 100.
What decides this is not the business, it is the platform
The median score is 77.1 on sites running IdeaSoft and 48.4 on those whose platform could not be identified. That gap is wider than the widest gap between sectors and the widest gap between districts — and it is not something the business chose directly.
The percentages on each row are over that platform’s own site count. A platform’s high score does not show that the businesses using it are more careful; it shows that its defaults are better.
| Platform | Sites | Median score | HTTPS | HSTS | CSP | Privacy notice |
|---|---|---|---|---|---|---|
| IdeaSoft | 37 | 77.1 | 100.0% | 91.9% | 89.2% | 40.5% |
| Ticimax | 48 | 69.9 | 100.0% | 97.9% | 6.3% | 77.1% |
| Wix | 122 | 65.4 | 100.0% | 100.0% | 0.0% | 10.7% |
| Next.js | 146 | 65.0 | 98.0% | 71.9% | 36.3% | 41.1% |
| WooCommerce | 386 | 50.5 | 96.1% | 3.9% | 8.6% | 20.8% |
| custom build | 1,913 | 50.4 | 88.8% | 22.8% | 11.8% | 20.4% |
| WordPress | 559 | 49.5 | 95.3% | 7.9% | 9.5% | 18.5% |
| not identified | 799 | 48.4 | 51.7% | 21.9% | 20.7% | 0.0% |
The business types in the study’s own headline tier, by median score. The 17 sectors below the threshold are not in the table: a median over nine sites is not a sector finding.
| Sector | Sites | Median score | HTTPS | Privacy notice | Tracking, no consent |
|---|---|---|---|---|---|
| Clothing shop | 75 | 69.6 | 96.4% | 47.0% | 28.8% |
| Café | 55 | 60.4 | 95.3% | 26.1% | 19.6% |
| Phone / electronics shop | 131 | 59.6 | 89.7% | 36.5% | 29.6% |
| Car rental | 79 | 59.1 | 95.2% | 28.8% | 24.2% |
| Furniture shop | 92 | 55.7 | 87.3% | 42.9% | 25.7% |
| Catering company | 59 | 55.7 | 98.0% | 17.7% | 19.6% |
| Agrochemical / farm supplier | 51 | 55.2 | 85.1% | 23.4% | 29.8% |
| Air-conditioning service | 76 | 53.2 | 95.5% | 11.8% | 35.3% |
| Tutoring centre | 79 | 49.0 | 92.4% | 7.4% | 50.0% |
| International shipping / freight forwarder | 92 | 48.6 | 90.7% | 21.6% | 12.5% |
| Guest house | 89 | 48.6 | 89.3% | 15.8% | 25.0% |
| Spa / massage centre | 53 | 48.6 | 97.1% | 24.3% | 54.1% |
| Removals company | 68 | 48.6 | 94.9% | 11.9% | 44.1% |
| Cleaning company | 76 | 48.5 | 94.8% | 4.8% | 41.3% |
| Warehouse / storage | 93 | 48.1 | 86.4% | 22.6% | 34.5% |
| Customs brokerage | 74 | 46.4 | 78.8% | 7.5% | 11.9% |
Each row’s base is the number of sites in that district. The axis runs 0-70; no district is above 60.
345 sites, 387 businesses
In the study’s risk classification 345 sites fall into the “high” or “critical” category (8.3%); those sites represent 387 businesses. The classification is not a vulnerability assessment but a summary of missing controls.
Critical = no HTTPS and a password, identity or payment field on the page. High = no HTTPS, a certificate that will not validate, or mixed content together with a form that collects data. Medium = tracking without consent, data collection without a notice, or a session cookie without flags.
A site can carry more than one reason; the rows do not sum. Every reason is a missing control, not a hole.
A missing control is not an open door
Every line of this report measures an absence: a header not sent, a link not given, a flag not set. None of them means a site will be broken into, and none of them means a business has acted against the law.
The sentence “there is no Content-Security-Policy” is true and verifiable. The sentence “this site can be broken into” does not follow from this data: saying it would require knowing what the site runs, how it handles which inputs and which version it is on — this study tested none of the three and did not set out to. In the same way, the distance between “no privacy notice is linked from the home page” and “the disclosure obligation has not been met” is a legal distance this report cannot close.
- That on most reachable Mersin business sites the basic browser security headers are switched off, and that this is read directly from the response headers.
- That the share of sites linking to a privacy or disclosure text from the home page is low, and that this share is a floor.
- That tracker use is markedly more widespread than consent infrastructure.
- That the largest difference in cyber hygiene score is not between sectors but between the platforms in use.
- That any site can be broken into — this study performs no vulnerability testing.
- That any business has acted against KVKK — compliance is a legal assessment and cannot be read off a home page.
- That a site has no privacy notice — what is measured is whether the home page links to one.
- That the rates are point values — detection is pattern-based and should be read as an order of magnitude.
Limitations
- A single cross-section.
- Headers and HTML were measured as they stood at the time of the audit. A site switching on CSP the next day does not appear in this table.
- The home page only.
- A privacy notice, form or tracker on an inner page is not seen. Every rate in the KVKK section is a floor for that reason — the real rate can be higher, not lower.
- Some “sites” are not the business’s own.
- A few businesses gave a platform address as their website on their Google profile — an Instagram profile, a Google search link. Those addresses are in the audited list too, and they reflect the configuration of their own platform, not of the business.
- Cookie flags are measured incompletely.
- Only the cookies sent in the first response are known. Cookies written by JavaScript never enter this measurement; the cookie rates are a floor for that reason too.
- Consent tool detection is pattern-based.
- Sites that wrote their own banner can appear as “no consent tool”. A separate “banner hint” measure is therefore published as well, and the difference between the two is shown in the report.
- CSP quality was not measured.
- Content-Security-Policy was assessed only at the level of presence and unsafe-inline. No full policy analysis was performed; “there is a CSP” does not mean “the CSP works”.
- Sensitive field detection can produce false positives.
- National ID, health and card fields are found by field-name and label pattern. These numbers must be verified by hand before being used in a story.
- The risk classification is not a vulnerability assessment.
- It is a summary of missing controls. “High risk” does not mean a site will be broken into; which control is missing is written on every row.
Citation rules
These six rules are not a matter of style. Framing a number wrongly in this report does something it would not do in the other three: it leaves a business under suspicion.
- 01No business or domain is published; site rows are pseudonymous.
- 02Do not say “this site can be broken into”; say “this control is absent”.
- 03Because only the home page was measured, every KVKK rate is a floor.
- 04Unreachable sites and sites without HTML are not counted as zero; they drop out of the base.
- 05The numbers are not a compliance audit; KVKK compliance is a legal assessment.
- 06Pattern-based detection rates are not presented as point values.
The method, briefly
- 01UniverseThe 4,167 domains audited in the Mersin / State of Digital 2026 study. Behind those addresses stand 4,773 businesses; one domain can belong to more than one business, which is why the site count and the business count are reported separately.
- 02InputThe HTTP response headers, Set-Cookie lines and home-page HTML in the parent study’s cache. No new request was made for this report; no site was touched a second time.
- 03The base ruleUnreachable sites are not counted as zero, they drop out of the base. The transport layer is calculated over 3,395 reachable sites, the KVKK and tracking layer over the 3,509 sites whose home-page HTML was in the cache.
- 04DetectionEvery detection runs on regular expressions, and the patterns are listed openly in the study’s configuration file. Pattern-based detection produces both false positives and false negatives.
- 05ScoreA weighted 0-100 score from six components. A component that cannot be measured is dropped from both the numerator and the denominator and the remaining weight ratio is recorded; if that ratio is below 60% the site gets no score. 738 sites are unscored for that reason.
- 06Sector thresholdSector comparisons are limited to the 39 business types in the study’s own “headline” tier. Sectors with fewer sites do not appear in the table; a median over nine sites is not a sector finding.
Sources
- 01Mersin Digital Report Card 2026 · response headers and home-page HTML cacheThe primary data source. The HTTP response headers, cookies and home-page HTML the parent study had already downloaded during its audit. Fieldwork 2026·08·25. No new network request was made for this report.
- 02Nixeny Dijital · Mersin / State of Digital 2026The same universe, the same field date. The 4,167 audited domains, the 4,773 businesses behind them and the district/sector assignment come from that study. What was measured there was speed and mobile fitness; here it is security and transparency configuration.nixeny.com
- 03MDN · HTTP security headers referenceThe definition and browser behaviour of the six headers measured. Which header counts as “present” was decided against these definitions.developer.mozilla.org
- 04OWASP · Secure Headers ProjectThe source of the six-header checklist. The report uses that list as a “good practice” yardstick, not as a compliance standard.owasp.org
- 05Turkish Personal Data Protection Law (6698)The basis of the disclosure obligation and the data subject’s right to apply. This report does not audit how the law is applied; it only counts whether the home page links to these texts.www.mevzuat.gov.tr
The numbers in this report were not compared with a measurement of another province, country or sector. A “world average” produced with a different scope, a different method and a different base looks, when placed side by side, as though both numbers measure the same thing. All that is shared with Mersin / State of Digital 2026 is the universe and the field date.
Colophon
Conducted and published by Nixeny Dijital, Mersin. Measurement, scoring and report design are Nixeny’s own. The universe and the site list are shared with the Mersin / State of Digital 2026 study. No new request was sent to any site for this report.
If a business wants to know its own site’s row in this study, writing in the domain name is enough: the pseudonym mapping is held only by us and shared only with the site owner. The method, the detection patterns and the verification logs are also shared on request: info@nixeny.com