Securva · Research EnginePrivate preview
The research is
the edge.
What securva.net/research actually gives us, why it's an advantage almost nobody has, and what the numbers mean in plain English.
In one line: it turns "trust me, you need security" into "here's the measured proof you're exposed, and exactly who's worst." That's the difference between a salesman and a doctor showing you the X-ray.
1What the findings mean (plain English)
- "HSTS coverage %" = the share of a sector's websites that force a secure (HTTPS) connection. Low number = lots of sites where traffic can be intercepted and users are exposed.
- Example: healthcare sits around 18%. In plain terms: most Nigerian hospital websites don't even enforce a secure connection, so patient data is exposed in transit. That's not an opinion, it's measured.
- "Weak-posture orgs" (0% HSTS, legacy stack) = the specific businesses most exposed right now. These are the ones who most need help, and our warmest leads.
- "274 orgs / 17,446 hosts" = how much of the Nigerian business internet we've actually mapped. Scale = authority.
2Who's strong, who's weak
Higher % = safer (more sites force a secure connection). Lower = exposed. Real measured numbers.
| Sector | HSTS % | Read |
| e-commerce | 62.7% | strongest |
| fintech | 59.3% | strong (money + regulated) |
| banking | 54.6% | strong |
| oil-gas | 48.2% | middling |
| insurance | 35.9% | weak-ish (regulated PII) |
| healthcare | 31.0% | weak · biggest exposed surface (1,790 hosts) |
| government | 34.2% | weak (citizen data) |
| edtech | 28.3% | weak (student data) |
| power / DisCos | 21.5% | very weak · critical infra + billing PII |
| telecom | 16.0% | WEAKEST · serves tens of millions |
The ones that should worry everyone — weak AND touching millions, where a breach gets ugly if nothing changes: telecom (16%), power (21.5%), healthcare (31%). The gut-punch: the infrastructure Nigerians depend on most — their phone, their power, their hospital — is the least secured.
3Our target audience
The weakest giants (telecom, power) are huge but slow to sell. The sweet spot for real near-term business = sectors that are measurably exposed + regulated under NDPA + can pay: insurance, fintech, banking, and healthcare. That's exactly why the insurance campaign is already our first move (19 insurers, exposed, regulated, reachable). The research hands us the specific weak orgs in each — so every pitch is warm, not cold.
4The edge this gives us
Why owning this data is an advantage competitors don't have.
1
Proof, not talk. Everyone says "you're at risk." We SHOW measured exposure, by sector, with receipts. Credibility nobody else brings.
2
A warm lead list, pre-qualified. The data names exactly which orgs are weakest. We know their gap before we ever contact them, so outreach is specific and warm, not cold.
3
A credible door-opener. "Here's how your sector scores, and where you stand vs peers" starts a conversation like a helpful expert, not a salesman.
4
Authority / own the narrative. Whoever holds the numbers becomes the name the market, press, and regulators reference. First-mover on the data = the go-to.
5
It arms the compliance angle. Weak posture = NDPA / data-protection risk = regulatory pressure = a concrete reason to buy the audit. The data quantifies the risk.
6
It compounds. Monthly refresh = a trend ("is Nigeria getting more secure or less?") = ongoing content, authority, and a reason for everyone to keep watching Securva.
5Why it holds up (so it's safe to show anyone)
It's passive measurement of publicly-observable data — DNS, which hosts are live, and the security headers each returns. Anyone can verify any single org themselves (curl -I their-domain and look at the HSTS header). Every number is computed from our stored per-org data, not asserted — re-run the method, get the same result. We measure what's publicly checkable; nobody has to take our word for it. We never publish a number we can't prove.
6How it's measured (the method, briefly)
Per sector, all passive: pick the real commercial orgs → enumerate their public DNS → probe which hosts are live → measure each one's security headers / HSTS → classify + aggregate per org → store in the database with a timestamp → prune junk rows → re-check the sanity-gate (a number must reproduce or it doesn't ship) → log a dated record. Commercial only (government excluded); no intrusive testing, ever.
7Where the proof lives (the evidence trail)
| Artifact | What it proves |
| The database phase-intel.db | Every org: sector, host count, HSTS %, timestamp — the raw data behind every number |
| Scan scripts | The exact reproducible method — re-run, reproduce the data |
| Run logs + DB snapshots | Timestamped evidence each scan ran, point-in-time proof |
| Dated phase records | The audit trail of every expansion step |
| The sanity-gate | Hard rule: no number publishes unless it reproduces from the database |
Publishing discipline: the live page shows only the validated core sectors (203 orgs). The 22-sector / 274-org expansion stays internal until a monthly refresh validates it. We publish proven, not eager.