Comparison Overview

EPAM Systems

VS

Orange Business

EPAM Systems

41 University Drive Suite 202, Newtown, PA, US, 18940
Last Update: 2026-01-19
Between 750 and 799

Since 1993, EPAM Systems, Inc. (NYSE: EPAM) has used its software engineering expertise to become a leading global provider of digital engineering, cloud and AI-enabled transformation services, and a leading business and experience consulting partner for global enterprises and ambitious startups. We address our clients’ transformation challenges by fusing EPAM Continuum’s integrated strategy, experience and technology consulting with our 30+ years of engineering execution to speed our clients’ time to market and drive greater value from their innovations and digital investments. We leverage AI and GenAI to deliver transformative solutions that accelerate our clients’ digital innovation and enhance their competitive edge. Through platforms like EPAM AI/RUN™ and initiatives like DIALX Lab, we integrate advanced AI technologies into tailored business strategies, driving significant industry impact and fostering continuous innovation. We deliver globally, but engage locally with our expert teams of consultants, architects, designers and engineers, making the future real for our clients, our partners and our people around the world. We believe the right solutions are the ones that improve people’s lives and fuel competitive advantage for our clients across diverse industries. Our thinking comes to life in the experiences, products and platforms we design and bring to market. Added to the S&P 500 and the Forbes Global 2000 in 2021 and recognized by Glassdoor and Newsweek as Most Loved Workplace, our multidisciplinary teams serve customers across six continents. We are proud to be among the top 15 companies in Information Technology Services in the Fortune 1000 and to be recognized as a leader in the IDC MarketScapes for Worldwide Experience Build Services, Worldwide Experience Design Services and Worldwide Software Engineering Services. Learn more at www.epam.com.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 63,943
Subsidiaries: 4
12-month incidents
0
Known data breaches
0
Attack type number
0

Orange Business

La Plaine Saint Denis, Paris, FR, 93457 Cedex
Last Update: 2026-01-24

At Orange Business, our ambition is to become the leading european Network and Digital Integrator by leveraging our proven expertise in next-generation connectivity solutions, the cloud and cybersecurity. Our 30,000 women and men are present in 65 countries, where every voice counts. Together, we are driven by the same determination and the same team spirit, to build the digital solutions of today and tomorrow and create a positive impact for our customers, for their employees and for the planet. We offer exciting opportunities through innovative projects in data and digital, cloud, AI, cybersecurity, IoT, or digital workspace and big data. Join us and be part of this adventure!

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 28,320
Subsidiaries: 0
12-month incidents
0
Known data breaches
1
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/epam-systems.jpeg
EPAM Systems
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/orange-business.jpeg
Orange Business
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
EPAM Systems
100%
Compliance Rate
0/4 Standards Verified
Orange Business
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for EPAM Systems in 2026.

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for Orange Business in 2026.

Incident History — EPAM Systems (X = Date, Y = Severity)

EPAM Systems cyber incidents detection timeline including parent company and subsidiaries

Incident History — Orange Business (X = Date, Y = Severity)

Orange Business cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/epam-systems.jpeg
EPAM Systems
Incidents

No Incident

https://images.rankiteo.com/companyimages/orange-business.jpeg
Orange Business
Incidents

Date Detected: 1/2022
Type:Breach
Blog: Blog

FAQ

EPAM Systems company demonstrates a stronger AI Cybersecurity Score compared to Orange Business company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Orange Business company has historically faced a number of disclosed cyber incidents, whereas EPAM Systems company has not reported any.

In the current year, Orange Business company and EPAM Systems company have not reported any cyber incidents.

Neither Orange Business company nor EPAM Systems company has reported experiencing a ransomware attack publicly.

Orange Business company has disclosed at least one data breach, while EPAM Systems company has not reported such incidents publicly.

Neither Orange Business company nor EPAM Systems company has reported experiencing targeted cyberattacks publicly.

Neither EPAM Systems company nor Orange Business company has reported experiencing or disclosing vulnerabilities publicly.

Neither EPAM Systems nor Orange Business holds any compliance certifications.

Neither company holds any compliance certifications.

EPAM Systems company has more subsidiaries worldwide compared to Orange Business company.

EPAM Systems company employs more people globally than Orange Business company, reflecting its scale as a IT Services and IT Consulting.

Neither EPAM Systems nor Orange Business holds SOC 2 Type 1 certification.

Neither EPAM Systems nor Orange Business holds SOC 2 Type 2 certification.

Neither EPAM Systems nor Orange Business holds ISO 27001 certification.

Neither EPAM Systems nor Orange Business holds PCI DSS certification.

Neither EPAM Systems nor Orange Business holds HIPAA certification.

Neither EPAM Systems nor Orange Business holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Description

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘options’ parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. NOTE: Successful exploitation of this vulnerability requires that the PDFCrowd API key is blank (also known as "demo mode", which is the default configuration when the plugin is installed) or known.

Risk Information
cvss3
Base: 6.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Description

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires an admin to grant Hustle module permissions (or module edit access) to the low-privileged user so they can access the Hustle admin page and obtain the required nonce.

Risk Information
cvss3
Base: 7.5
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Description

The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description

The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Risk Information
cvss3
Base: 4.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N