Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Connective - a Nitro company

Connective - a Nitro company Vendor Cyber Rating & Cyber Score

connective.eu

Connective helps every organization, no matter the size or industry, to do business any place and anytime – in a fully digital way. With our Identity Hub, eSignatures and Smart Documents solutions, our customers can streamline their digital transactions across borders and transform any paper-based customer journey (e.g. digital onboarding, KYC and contract management) into an unparalleled digital user experience. Increase operational efficiency, offer the best-in-class user experience and obtain easy-as-can-be compliance to national and international regulations (e.g. eIDAS, GDPR, UETA, eSIGN Act, …). More than 1.000 clients all over the world choose for a flawless digital, yet secure customer journey and complete more than 100 million


CNC A.I CyberSecurity Scoring

CNC
Company Information
Website:http://www.connective.eu
Employees number:8
Number of followers:0
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:connective.eu
CNC Risk Score (AI oriented)
Between 750 and 799
logo
CNCIT Services and IT Consulting
Updated:
10/08/2026
799/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
CNC Global Score (TPRM)
xxxx
logo
CNCIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CNCFair
Current Score
799Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
799Before Incident
AUGUST 2026
799Before Incident
JULY 2026
799Before Incident
JUNE 2026
799Before Incident
MAY 2026
798Before Incident
APRIL 2026
798Before Incident
MARCH 2026
798Before Incident
Vulnerability
17 Mar 2026 • CNC
Nitro Software Belgium: Connective eID Extension Flaws Let Attackers Steal Belgian ID PINs and Trigger Drive-By RCE

Critical Vulnerabilities in Belgium’s Connective Signing Extension Exposed Millions to Fraud and RCE

798After Incident
CRITICAL0
CON1786357491
Critical Vulnerabilities in Belgium’s Connective Signing Extension Exposed Millions to Fraud and RCE Security researchers uncovered severe flaws in the Connective Signing Extension, a browser component used by over 2 million people in Belgium for accessing electronic identity (eID) cards and Maestro payment cards. The now-patched vulnerabilities could have enabled attackers to steal eID PINs, harvest card data, forge signing requests, and execute malicious code on Windows devices all with minimal user interaction. ### How the Flaws Worked The extension acts as a bridge between websites, a browser plugin, and a native application that communicates with smart-card readers. However, researchers from Have I Been Pwned identified multiple critical weaknesses: 1. Token Replay Attacks – The extension failed to properly validate the origin of requests, allowing malicious websites to replay tokens issued to legitimate services. This could let attackers interact with the native host and extract data from connected eID or Maestro cards without the user’s knowledge. 2. PIN Phishing via Fake Dialogs – Attackers could display native-looking PIN prompts with custom titles and messages, impersonating trusted banking or government services. The stolen PIN, combined with access to an eID card, could enable unauthorized authentication or document signing. 3. Drive-By Remote Code Execution (RCE) – A command in the native host could load a library from an attacker-controlled path. By tricking users into downloading a malicious file, attackers could execute arbitrary code at the current user’s privilege level, even without an eID card connected. ### Broader Impact Belgium’s eID system is integral to banking, public services, and legally binding electronic signatures under the EU’s eIDAS regulation. A compromised signing capability could facilitate account takeovers, fraudulent identity verification, or large-scale identity theft. Researchers demonstrated an account takeover involving Belgium’s CSAM (Child Abuse Material) reporting system, though impacts on other platforms depended on additional security controls. ### Remediation Timeline Nitro Software Belgium, the company behind Connective and an EU-listed Qualified Trust Service Provider, deployed fixes in stages: - Disabled the risky library-loading feature. - Modified PIN-token handling to prevent decryption by malicious sites. - Enforced origin checks for all requests. The final patch was released 146 days after the initial report, though no CVEs were assigned at the time of disclosure. The vulnerabilities highlight the risks of third-party identity and payment integrations, particularly in high-trust environments like government and financial services.
INCIDENT DETAILS -
TYPE
Data BreachRemote Code Execution (RCE)Phishing
MOTIVATION
FraudIdentity TheftUnauthorized Access
IMPACT
eID PINsMaestro payment card dataElectronic signaturesWindows devices with Connective Signing ExtensionUnauthorized authenticationFraudulent document signingBrand Reputation Impact: High (trust in eID and payment systems)Potential violations of EU eIDAS regulationIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
eID PINsMaestro payment card dataElectronic signaturesSensitivity Of Data: High (PII, payment information, legally binding signatures)Personally Identifiable Information: Yes (eID data, payment card details)
FEBRUARY 2026
798Before Incident
JANUARY 2026
798Before Incident
DECEMBER 2025
798Before Incident
NOVEMBER 2025
798Before Incident
OCTOBER 2025
798Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CNC ?
?
What was CNC's A.I Rankiteo Cyber Score in August 2026 ?
?
What was CNC's A.I Rankiteo Cyber Score in July 2026 ?
?
What was CNC's A.I Rankiteo Cyber Score in June 2026 ?
?
What was CNC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CNC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CNC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CNC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CNC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CNC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CNC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CNC's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on CNC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CNC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CNC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?