Baseline cybersecurity configuration patterns in Italian public healthcare web portals
Abstract The progressive digitalisation of public healthcare services has made institutional web portals a critical access point for citizens and professionals alike. This study presents a nation-wide, comparative assessment of Italian regional and provincial healthcare portals, focusing on the presence of baseline security weaknesses observable through passive, non-intrusive scanning. Using OWASP ZAP in baseline mode, we analysed all institutional portals within a single temporal window, collecting severity-labelled vulnerability categories and technology fingerprinting information. To avoid biases related to portal size or content volume, each vulnerability category was counted at most once per portal. The resulting dataset therefore captures configuration and hardening patterns rather than vulnerability frequency or exploitability. Results show a heterogeneous but recurrent set of low- and medium-severity issues across regions and macro-areas, alongside a limited presence of high-severity findings. Several vulnerability classes related to HTTP security headers, cookie attributes, and request-handling mechanisms appear widespread, suggesting uneven adoption of well-established defensive measures. While the analysis does not assess exploitability or operational risk, it provides a reproducible empirical snapshot of baseline security configurations across the Italian public healthcare web ecosystem. The findings support comparative analysis and longitudinal monitoring, offering a reference point for future studies on the evolution of security practices in institutional digital services.
Authors
- Lerina Aversano (ORCID: https://orcid.org/0000-0003-2436-6835)
- Giuseppe Pirlo (ORCID: https://orcid.org/0000-0002-7305-2210)
- Alessandro Caniglia (ORCID: https://orcid.org/0000-0002-3180-5835)
- Stefano Galantucci (ORCID: https://orcid.org/0000-0002-3955-0478)
Institutions
- University of Foggia (IT)
- University of Bari Aldo Moro (IT)
Publication Details
- Journal
- International Journal of Information Security
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1007/s10207-026-01331-0
- Primary Topic
- Web Application Security Vulnerabilities
- Type
- article
- Field-Weighted Citation Impact
- 0.00