Comparison Overview

CSS Pension Plan (Co-operative Superannuation Society)

VS

Discover

CSS Pension Plan (Co-operative Superannuation Society)

333 3rd Ave N, Saskatoon, S7K, CA
Last Update: 2026-04-02
Between 750 and 799

The Co-operative Superannuation Society (CSS) Pension Plan provides competitive, value-added retirement products and services exclusively to co-operative and credit union employees. Pioneered in Saskatchewan in 1939, we are one of the oldest and largest defined contribution (DC) pension plans in Canada with over $5.4B in assets. Today we’ve grown to serve approximately 300 employers and over 56,000 current and past co-operative and credit union employees across eight provinces and territories, including nearly 9,000 retirees who draw a retirement income from CSS.

NAICS: 52
NAICS Definition: Finance and Insurance
Employees: 36
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Discover

2500 Lake Cook Road, Riverwoods, IL, US, 60015
Last Update: 2026-04-01
Between 600 and 649

Discover® is now part of Capital One. Together, we’ll continue to deliver exceptional financial products and experiences, drive innovation, and serve customers. Find the latest updates at https://capitalonediscover.com. Discover is one of the most recognized brands in the U.S. with the Discover® card, America's cash rewards pioneer, and offers personal loans, home loans, checking and savings accounts and certificates of deposit. The Discover Global Network® is comprised of Discover Network, with millions of merchants and cash access locations; PULSE®, one of the nation's leading ATM/debit networks; and Diners Club International®, a global payments network with acceptance around the world.

NAICS: 52
NAICS Definition: Finance and Insurance
Employees: 19,187
Subsidiaries: 0
12-month incidents
0
Known data breaches
33
Attack type number
2

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/css-pension-plan.jpeg
CSS Pension Plan (Co-operative Superannuation Society)
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/discover.jpeg
Discover
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
CSS Pension Plan (Co-operative Superannuation Society)
100%
Compliance Rate
0/4 Standards Verified
Discover
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Financial Services Industry Average (This Year)

No incidents recorded for CSS Pension Plan (Co-operative Superannuation Society) in 2026.

Incidents vs Financial Services Industry Average (This Year)

No incidents recorded for Discover in 2026.

Incident History — CSS Pension Plan (Co-operative Superannuation Society) (X = Date, Y = Severity)

CSS Pension Plan (Co-operative Superannuation Society) cyber incidents detection timeline including parent company and subsidiaries

Incident History — Discover (X = Date, Y = Severity)

Discover cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/css-pension-plan.jpeg
CSS Pension Plan (Co-operative Superannuation Society)
Incidents

No Incident

https://images.rankiteo.com/companyimages/discover.jpeg
Discover
Incidents

Date Detected: 9/2020
Type:Breach
Attack Vector: Inadvertent Disclosure
Blog: Blog

Date Detected: 8/2018
Type:Breach
Blog: Blog

Date Detected: 1/2018
Type:Breach
Blog: Blog

FAQ

CSS Pension Plan (Co-operative Superannuation Society) company demonstrates a stronger AI Cybersecurity Score compared to Discover company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Discover company has historically faced a number of disclosed cyber incidents, whereas CSS Pension Plan (Co-operative Superannuation Society) company has not reported any.

In the current year, Discover company and CSS Pension Plan (Co-operative Superannuation Society) company have not reported any cyber incidents.

Neither Discover company nor CSS Pension Plan (Co-operative Superannuation Society) company has reported experiencing a ransomware attack publicly.

Discover company has disclosed at least one data breach, while CSS Pension Plan (Co-operative Superannuation Society) company has not reported such incidents publicly.

Discover company has reported targeted cyberattacks, while CSS Pension Plan (Co-operative Superannuation Society) company has not reported such incidents publicly.

Neither CSS Pension Plan (Co-operative Superannuation Society) company nor Discover company has reported experiencing or disclosing vulnerabilities publicly.

Neither CSS Pension Plan (Co-operative Superannuation Society) nor Discover holds any compliance certifications.

Neither company holds any compliance certifications.

Neither CSS Pension Plan (Co-operative Superannuation Society) company nor Discover company has publicly disclosed detailed information about the number of their subsidiaries.

Discover company employs more people globally than CSS Pension Plan (Co-operative Superannuation Society) company, reflecting its scale as a Financial Services.

Neither CSS Pension Plan (Co-operative Superannuation Society) nor Discover holds SOC 2 Type 1 certification.

Neither CSS Pension Plan (Co-operative Superannuation Society) nor Discover holds SOC 2 Type 2 certification.

Neither CSS Pension Plan (Co-operative Superannuation Society) nor Discover holds ISO 27001 certification.

Neither CSS Pension Plan (Co-operative Superannuation Society) nor Discover holds PCI DSS certification.

Neither CSS Pension Plan (Co-operative Superannuation Society) nor Discover holds HIPAA certification.

Neither CSS Pension Plan (Co-operative Superannuation Society) nor Discover holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, two peer-facing consensus request handlers assume that the history index is always available and call blockchain.history_store.history_index().unwrap() directly. That assumption is false by construction. HistoryStoreProxy::history_index() explicitly returns None for the valid HistoryStoreProxy::WithoutIndex state. when a full node is syncing or otherwise running without the history index, a remote peer can send RequestTransactionsProof or RequestTransactionReceiptsByAddress and trigger an Option::unwrap() panic on the request path. This issue has been patched in version 1.3.0.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but performs no validation on the url parameter, passing it directly to httpx.stream() with follow_redirects=True. An attacker who controls the URL can reach any host accessible from the server including cloud metadata services and internal network services. This issue has been patched in version 1.5.95.

Risk Information
cvss3
Base: 8.6
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access to all registered tools and agent capabilities. This issue has been patched in version 4.5.97.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any network client can connect, enumerate registered agents, and send arbitrary messages to agents and their tool sets. This issue has been patched in version 4.5.97.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the re engine, blocking the Python thread for hundreds of seconds and causing a complete service outage. This issue has been patched in version 4.5.90.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H