Comparison Overview

Deutsche Börse

VS

KBC Bank & Verzekering

Deutsche Börse

Mergenthalerallee 61, Eschborn, undefined, 65760, DE
Last Update: 2025-11-27

As one of the world’s leading exchange organisations, Deutsche Börse Group provides investors, financial institutions and companies access to global capital markets. Our business covers the entire financial market transaction process chain, ranging from securities and derivatives trading, clearing, settlement and custody, to market data and the development and operation of electronic trading systems. As a technology company, we develop state-of-the-art IT solutions and offer IT systems all over the world. Our reliable systems and our integrity as a neutral market infrastructure provider form the basis of our business philosophy. We operate to the most exacting standards to create products and services which meet the needs of international financial markets. As a listed company we work to create value for our customers and our shareholders. Privacy notice: https://deutsche-boerse.com/social-media-privacy Imprint: https://deutsche-boerse.com/imprint

NAICS: 52
NAICS Definition: Finance and Insurance
Employees: 3,865
Subsidiaries: 6
12-month incidents
0
Known data breaches
0
Attack type number
0

KBC Bank & Verzekering

Havenlaan 2, 1000 Brussel, Brussels, undefined, 1080, BE
Last Update: 2025-11-27
Between 750 and 799

Welkom op de officiële LinkedIn-pagina van KBC! Bekijk onze vacatures op de tab ‘Vacatures’. KBC is een geïntegreerde bank-verzekeraar die zich hoofdzakelijk richt op particulieren en privatebankingcliënten, en op kleine en middelgrote ondernemingen. KBC heeft een leidende positie in zijn thuismarkten in België en Centraal- en Oost-Europa, en is selectief aanwezig in de rest van de wereld.

NAICS: 52
NAICS Definition: Finance and Insurance
Employees: 13,115
Subsidiaries: 3
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/deutscheboerse.jpeg
Deutsche Börse
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/kbc-bank-en-verzekering.jpeg
KBC Bank & Verzekering
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Deutsche Börse
100%
Compliance Rate
0/4 Standards Verified
KBC Bank & Verzekering
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Financial Services Industry Average (This Year)

No incidents recorded for Deutsche Börse in 2025.

Incidents vs Financial Services Industry Average (This Year)

No incidents recorded for KBC Bank & Verzekering in 2025.

Incident History — Deutsche Börse (X = Date, Y = Severity)

Deutsche Börse cyber incidents detection timeline including parent company and subsidiaries

Incident History — KBC Bank & Verzekering (X = Date, Y = Severity)

KBC Bank & Verzekering cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/deutscheboerse.jpeg
Deutsche Börse
Incidents

No Incident

https://images.rankiteo.com/companyimages/kbc-bank-en-verzekering.jpeg
KBC Bank & Verzekering
Incidents

No Incident

FAQ

Deutsche Börse company demonstrates a stronger AI Cybersecurity Score compared to KBC Bank & Verzekering company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, KBC Bank & Verzekering company has disclosed a higher number of cyber incidents compared to Deutsche Börse company.

In the current year, KBC Bank & Verzekering company and Deutsche Börse company have not reported any cyber incidents.

Neither KBC Bank & Verzekering company nor Deutsche Börse company has reported experiencing a ransomware attack publicly.

Neither KBC Bank & Verzekering company nor Deutsche Börse company has reported experiencing a data breach publicly.

Neither KBC Bank & Verzekering company nor Deutsche Börse company has reported experiencing targeted cyberattacks publicly.

Neither Deutsche Börse company nor KBC Bank & Verzekering company has reported experiencing or disclosing vulnerabilities publicly.

Neither Deutsche Börse nor KBC Bank & Verzekering holds any compliance certifications.

Neither company holds any compliance certifications.

Deutsche Börse company has more subsidiaries worldwide compared to KBC Bank & Verzekering company.

KBC Bank & Verzekering company employs more people globally than Deutsche Börse company, reflecting its scale as a Financial Services.

Neither Deutsche Börse nor KBC Bank & Verzekering holds SOC 2 Type 1 certification.

Neither Deutsche Börse nor KBC Bank & Verzekering holds SOC 2 Type 2 certification.

Neither Deutsche Börse nor KBC Bank & Verzekering holds ISO 27001 certification.

Neither Deutsche Börse nor KBC Bank & Verzekering holds PCI DSS certification.

Neither Deutsche Börse nor KBC Bank & Verzekering holds HIPAA certification.

Neither Deutsche Börse nor KBC Bank & Verzekering holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.

Risk Information
cvss4
Base: 7.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H