Company Details
d--e--systems-ltd-
25
405
56192
desystems.com
0
D. _2382954
In-progress

D. E. Systems Ltd. Company CyberSecurity Posture
desystems.comD.E. Systems Ltd. has been providing technology solutions in Ontario and Quebec for over 46 years. Our range of services includes Computer Rentals and Event Technology Services, Computer Network Sales, Service and Support along with the development of software solutions for the events industry. D.E. Systems' commitment to provide innovative information technology solutions to industry and government has made us one of the largest and most respected Computer Rental Service organizations serving all areas of Canada and the U.S. through its business partners. D. E. Systems' latest product offerings include Navori digital signage solutions, ERS 2.0, our enhanced on-line event registration solution and Proactive ITcare Program, providing remote monitoring, server configuration management, pc heath and performance monitoring.
Company Details
d--e--systems-ltd-
25
405
56192
desystems.com
0
D. _2382954
In-progress
Between 650 and 699

DESL Global Score (TPRM)XXXX

Description: **ERS Data Breach Exposes Payment Card and Personal Information in Cybersecurity Incident** On December 15, 2025, Event Rental Systems (ERS) disclosed a cybersecurity breach involving unauthorized access to customer data. The incident occurred when an attacker injected malicious code into certain modules of ERS’s customer websites, potentially compromising sensitive information. Affected data includes personally identifiable information (PII) such as contact details, payment card numbers, CVV codes, and expiration dates. The exact number of impacted individuals remains undisclosed. Lynch Carpenter LLP, a national class action law firm, is investigating potential legal claims against ERS on behalf of those affected. The firm, which specializes in data privacy litigation, has urged individuals who received breach notifications in the past 30 days to seek legal review. ERS has not provided further details on the breach’s scope, timeline, or remediation efforts. The incident highlights ongoing risks to payment processing systems and third-party integrations in the events industry.


D. E. Systems Ltd. has 0.0% fewer incidents than the average of same-industry companies with at least one recorded incident.
D. E. Systems Ltd. has 28.21% more incidents than the average of all companies with at least one recorded incident.
D. E. Systems Ltd. reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.
DESL cyber incidents detection timeline including parent company and subsidiaries

D.E. Systems Ltd. has been providing technology solutions in Ontario and Quebec for over 46 years. Our range of services includes Computer Rentals and Event Technology Services, Computer Network Sales, Service and Support along with the development of software solutions for the events industry. D.E. Systems' commitment to provide innovative information technology solutions to industry and government has made us one of the largest and most respected Computer Rental Service organizations serving all areas of Canada and the U.S. through its business partners. D. E. Systems' latest product offerings include Navori digital signage solutions, ERS 2.0, our enhanced on-line event registration solution and Proactive ITcare Program, providing remote monitoring, server configuration management, pc heath and performance monitoring.


Encore is your full-service event production partner with more than 80 years of experience. Each year, Encore delivers more than 350,000 events in 20 countries across North America, Europe, the Middle East, Australia and Asia Pacific. Through event technology, rigging infrastructure, production an
.png)
A cybersecurity report warns of serious vulnerabilities in V16 beacons mandatory from 2026 and opens doubts about their reliability in...
This AI survey shows how AI investments are turning into business productivity gains and significant financial performance.
Cybersecurity Ventures expects global cybercrime costs to grow by 15 percent per year over the next five years, reaching $10.5 trillion USD annually by 2025.
The global cybersecurity market size is projected to grow from $218.98 billion in 2025 to $562.77 billion by 2032, at a CAGR of 14.4% during...
A lawsuit filed by Nebraska Attorney General Mike Hilgers over the 2024 Change Healthcare data breach has been allowed to proceed after...
In 2023, 725 data breaches were reported to OCR and across those breaches, more than 133 million records were exposed or impermissibly disclosed.
Take this security awareness training quiz to test your knowledge of common cybersecurity threats and best practices, from secure file...
Ransomware is expected to attack a business every 11 seconds by the end of 2021.
Cybersecurity is entering uncharted waters. A rapidly shifting world order and threat environment ― powered by recent, exponential leaps in...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of D. E. Systems Ltd. is http://www.desystems.com.
According to Rankiteo, D. E. Systems Ltd.’s AI-generated cybersecurity score is 691, reflecting their Weak security posture.
According to Rankiteo, D. E. Systems Ltd. currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, D. E. Systems Ltd. is not certified under SOC 2 Type 1.
According to Rankiteo, D. E. Systems Ltd. does not hold a SOC 2 Type 2 certification.
According to Rankiteo, D. E. Systems Ltd. is not listed as GDPR compliant.
According to Rankiteo, D. E. Systems Ltd. does not currently maintain PCI DSS compliance.
According to Rankiteo, D. E. Systems Ltd. is not compliant with HIPAA regulations.
According to Rankiteo,D. E. Systems Ltd. is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
D. E. Systems Ltd. operates primarily in the Events Services industry.
D. E. Systems Ltd. employs approximately 25 people worldwide.
D. E. Systems Ltd. presently has no subsidiaries across any sectors.
D. E. Systems Ltd.’s official LinkedIn profile has approximately 405 followers.
D. E. Systems Ltd. is classified under the NAICS code 56192, which corresponds to Convention and Trade Show Organizers.
No, D. E. Systems Ltd. does not have a profile on Crunchbase.
Yes, D. E. Systems Ltd. maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/d--e--systems-ltd-.
As of December 16, 2025, Rankiteo reports that D. E. Systems Ltd. has experienced 1 cybersecurity incidents.
D. E. Systems Ltd. has an estimated 7,592 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with lynch carpenter llp (legal investigation), and communication strategy with public disclosure via press release..
Title: ERS Cybersecurity Incident and Data Breach
Description: An unauthorized person inserted unauthorized code into certain modules of ERS’s customers’ websites and may have acquired records containing personally identifiable information (PII), including contact information, payment card numbers, CVV, and expiration dates.
Date Publicly Disclosed: 2025-12-15
Type: Data Breach
Attack Vector: Unauthorized code insertion
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through ERS customers’ websites.

Data Compromised: Personally identifiable information (PII), payment card details (number, CVV, expiration date)
Systems Affected: ERS customers’ websites
Identity Theft Risk: High
Payment Information Risk: High
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Contact Information, Payment Card Number, Cvv, Expiration Date and .

Entity Name: Event Rental Systems (ERS)
Entity Type: Company
Industry: Event Rental Software
Location: Pittsburgh, USA
Customers Affected: Unknown number of individuals

Third Party Assistance: Lynch Carpenter LLP (legal investigation)
Communication Strategy: Public disclosure via press release
Third-Party Assistance: The company involves third-party assistance in incident response through Lynch Carpenter LLP (legal investigation).

Type of Data Compromised: Contact information, Payment card number, Cvv, Expiration date
Sensitivity of Data: High
Data Exfiltration: Possible
Personally Identifiable Information: Yes

Legal Actions: Potential class action investigation by Lynch Carpenter LLP
Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through Potential class action investigation by Lynch Carpenter LLP.

Source: Globe Newswire
URL: https://eventrentalsystems.com/
Date Accessed: 2025-12-15
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Globe NewswireUrl: https://eventrentalsystems.com/Date Accessed: 2025-12-15.

Investigation Status: Ongoing (Lynch Carpenter LLP investigation)
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Public disclosure via press release.

Customer Advisories: Individuals impacted may be entitled to compensation; advised to contact Lynch Carpenter LLP.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Individuals impacted may be entitled to compensation; advised to contact Lynch Carpenter LLP..

Entry Point: ERS customers’ websites
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Lynch Carpenter LLP (legal investigation).
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-12-15.
Most Significant Data Compromised: The most significant data compromised in an incident were Personally identifiable information (PII), payment card details (number, CVV and expiration date).
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was Lynch Carpenter LLP (legal investigation).
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Personally identifiable information (PII), payment card details (number, CVV and expiration date).
Most Significant Legal Action: The most significant legal action taken for a regulatory violation was Potential class action investigation by Lynch Carpenter LLP.
Most Recent Source: The most recent source of information about an incident is Globe Newswire.
Most Recent URL for Additional Resources: The most recent URL for additional resources on cybersecurity best practices is https://eventrentalsystems.com/ .
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing (Lynch Carpenter LLP investigation).
Most Recent Customer Advisory: The most recent customer advisory issued was an Individuals impacted may be entitled to compensation; advised to contact Lynch Carpenter LLP.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an ERS customers’ websites.
.png)
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.
Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.
A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php of the component Backend System Configuration Module. The manipulation of the argument Cj_Add/Cj_Edit results in code injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.