Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

B&QB&Q
VS
H&MH&M
B&Q

B&Q

undefined, Southampton, undefined, undefined, GB

Last Update: 02/04/2026

View Profile
791/1000Fair

We are the UK’s leading home improvement and garden living retailer with over 300 stores throughout the UK and Ireland, offering great prices, with over 100,000 products available to order at diy.com for home delivery or click and collect. We launched the UK’s first ho...

NAICS:43
NAICS Definition:Retail Trade
Employees:12,936
Subsidiaries:10
12-month incidents
0
Known data breaches
0
Attack type number
0
H&M

H&M

Vasagatan 7, Stockholm, Stockholm County, SE, 111 20

Last Update: 13/08/2026

View Profile
Between 800 and 849
https://career.hm.com/
818/1000Good

At H&M, we welcome you to be yourself and feel like you truly belong. Help us reimagine the future of an entire industry by making everyone look, feel, and do good. We take pride in our history of making fashion accessible to everyone and led by our values we strive to...

NAICS:43
NAICS Definition:Retail Trade
Employees:67,647
Subsidiaries:11
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Ranges Comparison

Based On Specific Ai Models Category
B&Q

B&Q

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
H&M

H&M

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Retail Industry Avg (This Year)

No incidents recorded for B&Q in 2026.

Incidents

Incidents vs Retail Industry Avg (This Year)

No incidents recorded for H&M in 2026.

Incidents

Incident History - B&Q (X = Date, Y = Severity)

B&Q cyber incidents detection timeline including parent company and subsidiaries.

No timeline data available
R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - H&M (X = Date, Y = Severity)

H&M cyber incidents detection timeline including parent company and subsidiaries.

No timeline data available
R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
B&Q

B&Q

Incidents
No explicit notable incidents reported.
H&M

H&M

Incidents
No explicit notable incidents reported.

FAQ

Between B&Q company and H&M company, which one has the best AI Cybersecurity Score ?
Between B&Q company and H&M company, which one has experienced more cyber incidents in the past ?
Between B&Q company and H&M company, which one has experienced more cyber incidents this year ?
Between B&Q company and H&M company, which one has experienced at least one ransomware attack ?
Between B&Q company and H&M company, which one has experienced at least one data breach ?
Between B&Q company and H&M company, which one has experienced at least one targeted cyberattack ?
Between B&Q company and H&M company, which one has experienced at least one vulnerability ?
Between B&Q company and H&M company, which one holds the most compliance certifications ?
Between B&Q company and H&M company, which one holds the fewest compliance certifications ?
Between B&Q company and H&M company, which one has the most subsidiaries ?
Between B&Q company and H&M company, which one has the largest number of employees ?
Between B&Q and H&M, which company holds both SOC 2 Type 1 certifications ?
Between B&Q and H&M, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - B&Q or H&M ?
Which company is PCI DSS compliant - B&Q or H&M ?
Between B&Q and H&M, which company complies with HIPAA regulations for healthcare data ?
Between B&Q and H&M, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-9693
SUMMARY

Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682

PUBLISHED
Date2026-08-17
UPDATED
Date2026-08-17
RISK INFORMATION (Score: 3.5)
CVSS3
Base Score: 3.5
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
IMPACT SCORE
1.4
EXPLOITABILITY
2.1
CVE-2026-75587
SUMMARY

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716

PUBLISHED
Date2026-08-17
UPDATED
Date2026-08-17
RISK INFORMATION (Score: 3.6)
CVSS3
Base Score: 3.6
Complexity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
IMPACT SCORE
1.4
EXPLOITABILITY
1.8
CVE-2026-75078
SUMMARY

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Date2026-08-17
UPDATED
Date2026-08-17
RISK INFORMATION (Score: 4.3)
CVSS2
Base Score: 5.0
Complexity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
CVSS3
Base Score: 4.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS4
Base Score: 2.1
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
1.4
EXPLOITABILITY
2.8
CVE-2026-67961
SUMMARY

An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

PUBLISHED
Date2026-08-17
UPDATED
Date2026-08-17
IMPACT SCORE
NA
EXPLOITABILITY
NA
CVE-2026-67919
SUMMARY

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

PUBLISHED
Date2026-08-17
UPDATED
Date2026-08-17
IMPACT SCORE
NA
EXPLOITABILITY
NA