Comparison Overview

CMOC

VS

Alcoa

CMOC

Au Nord De Yihe, Route Huamei Shan Luanchuan, Henan 471500, CN
Last Update: 2025-12-17
Between 800 and 849

CMOC or CMOC Group Limited is a public holding company created in 1969, engaged in the mining, processing, and trading of base and rare metals. Its main mining assets are located in the Democratic Republic of the Congo (DRC), China and Brazil, and its metal trading business spanned 80 countries, making CMOC one of the world’s largest producers of tungsten, cobalt, niobium and molybdenum, as well as a leading copper producer. CMOC’s vision is to ensure a responsible supply of metals for the sustainable energy sector in order to meet the needs of the global energy transition, as it advocates a more sustainable development for the mining industry and the well-being of humanity. As a key player in the mining industry, CMOC is committed towards the environment - through its innovation to support the ecological transition or its carbon-neutral strategy -, the community - by conducting activities that promotes positive and open relationships with local communities and its support of the United Nations Sustainable Development Goals - and to a responsible governance based on equality respect for international standards and transparency.

NAICS: 212
NAICS Definition: Mining (except Oil and Gas)
Employees: 10,001
Subsidiaries: 1
12-month incidents
0
Known data breaches
0
Attack type number
0

Alcoa

201 Isabella St., Pittsburgh, PA, 15212, US
Last Update: 2025-12-17
Between 750 and 799

Alcoa (NYSE: AA) is a global industry leader in bauxite, alumina and aluminum products with a vision to reinvent the aluminum industry for a sustainable future. With a values-based approach that encompasses integrity, operating excellence, care for people and courageous leadership, our purpose is to Turn Raw Potential into Real Progress. Since developing the process that made aluminum an affordable and vital part of modern life, our talented Alcoans have developed breakthrough innovations and best practices that have led to greater efficiency, safety, sustainability and stronger communities wherever we operate.

NAICS: 212
NAICS Definition: Mining (except Oil and Gas)
Employees: 16,336
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/cmocinternational.jpeg
CMOC
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/alcoa.jpeg
Alcoa
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
CMOC
100%
Compliance Rate
0/4 Standards Verified
Alcoa
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Mining Industry Average (This Year)

No incidents recorded for CMOC in 2025.

Incidents vs Mining Industry Average (This Year)

No incidents recorded for Alcoa in 2025.

Incident History — CMOC (X = Date, Y = Severity)

CMOC cyber incidents detection timeline including parent company and subsidiaries

Incident History — Alcoa (X = Date, Y = Severity)

Alcoa cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/cmocinternational.jpeg
CMOC
Incidents

No Incident

https://images.rankiteo.com/companyimages/alcoa.jpeg
Alcoa
Incidents

No Incident

FAQ

CMOC company demonstrates a stronger AI Cybersecurity Score compared to Alcoa company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, Alcoa company has disclosed a higher number of cyber incidents compared to CMOC company.

In the current year, Alcoa company and CMOC company have not reported any cyber incidents.

Neither Alcoa company nor CMOC company has reported experiencing a ransomware attack publicly.

Neither Alcoa company nor CMOC company has reported experiencing a data breach publicly.

Neither Alcoa company nor CMOC company has reported experiencing targeted cyberattacks publicly.

Neither CMOC company nor Alcoa company has reported experiencing or disclosing vulnerabilities publicly.

Neither CMOC nor Alcoa holds any compliance certifications.

Neither company holds any compliance certifications.

CMOC company has more subsidiaries worldwide compared to Alcoa company.

Alcoa company employs more people globally than CMOC company, reflecting its scale as a Mining.

Neither CMOC nor Alcoa holds SOC 2 Type 1 certification.

Neither CMOC nor Alcoa holds SOC 2 Type 2 certification.

Neither CMOC nor Alcoa holds ISO 27001 certification.

Neither CMOC nor Alcoa holds PCI DSS certification.

Neither CMOC nor Alcoa holds HIPAA certification.

Neither CMOC nor Alcoa holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool allows Stored XSS.This issue affects TempTool: from n/a through 1.3.1.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tormorten WP Microdata allows Stored XSS.This issue affects WP Microdata: from n/a through 1.0.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Description

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool allows Retrieve Embedded Sensitive Data.This issue affects TempTool: from n/a through 1.3.1.

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Risk Information
cvss2
Base: 9.0
Severity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 7.4
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X