Badge
11,371 badges added since 01 January 2025
ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Essar, with an entrepreneurial track record spanning 50+ years, specialises in investing and developing assets to create value in core sectors such as Energy, Infrastructure, Metals & Mining, and Technology & Retail. With a presence in eight countries, Essar generates revenues of US$15 billion and provides employment for over 7,000 people. Over the past five years, Essar has strategically rebalanced its portfolio by monetising some world-class assets. Essar is now positioned to transition its existing assets to a greener regime and invest in businesses driving the transformation of sector landscapes from carbon-centric to a clean energy ecosystem, both nationally and globally. The Group is developing sustainable assets and industry ecosystems, with a particular focus on hydrogen, green mobility, and green steel. Essar Foundation, the CSR arm of Essar, has a rich 50-year heritage of service across India, focusing on areas such as health, education, livelihood, women empowerment, sports, environment, and infrastructure.

Essar A.I CyberSecurity Scoring

Essar

Company Details

Linkedin ID:

essar

Employees number:

10,565

Number of followers:

334,742

NAICS:

5239

Industry Type:

Investment Management

Homepage:

essar.com

IP Addresses:

0

Company ID:

ESS_3514152

Scan Status:

In-progress

AI scoreEssar Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/essar.jpeg
Essar Investment Management
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreEssar Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/essar.jpeg
Essar Investment Management
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Essar Company CyberSecurity News & History

Past Incidents
0
Attack Types
0
No data available
Ailogo

Essar Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Essar

Incidents vs Investment Management Industry Average (This Year)

No incidents recorded for Essar in 2026.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Essar in 2026.

Incident Types Essar vs Investment Management Industry Avg (This Year)

No incidents recorded for Essar in 2026.

Incident History — Essar (X = Date, Y = Severity)

Essar cyber incidents detection timeline including parent company and subsidiaries

Essar Company Subsidiaries

SubsidiaryImage

Essar, with an entrepreneurial track record spanning 50+ years, specialises in investing and developing assets to create value in core sectors such as Energy, Infrastructure, Metals & Mining, and Technology & Retail. With a presence in eight countries, Essar generates revenues of US$15 billion and provides employment for over 7,000 people. Over the past five years, Essar has strategically rebalanced its portfolio by monetising some world-class assets. Essar is now positioned to transition its existing assets to a greener regime and invest in businesses driving the transformation of sector landscapes from carbon-centric to a clean energy ecosystem, both nationally and globally. The Group is developing sustainable assets and industry ecosystems, with a particular focus on hydrogen, green mobility, and green steel. Essar Foundation, the CSR arm of Essar, has a rich 50-year heritage of service across India, focusing on areas such as health, education, livelihood, women empowerment, sports, environment, and infrastructure.

Loading...
similarCompanies

Essar Similar Companies

Odebrecht

Founded in 1944, Odebrecht is a Brazilian group with diverse businesses and world-class standards of quality. Its Members, guided by the Group’s own philosophy, the Odebrecht Entrepreneurial Technology (TEO), provide services and manufacture products for clients on five continents. As part of their

Pudur Corporation

On any given day, Sixty Million people use Pudur products and services to get more out of life. With more than twenty business verticals focused on innovation,technology, health, wellbeing, environment, investments, natural resources, trading, energy, agro, real estate, telecom, defense, banking

Sonae

Sonae exists to create a lasting positive impact on businesses, people, communities and on the planet. Managing a diverse portfolio of businesses in retail, financial services, technology, investments, real estate and telecommunications, Sonae makes the most of its expertise and pushes itself to c

Ackermans & van Haaren

Ackermans & van Haaren is a diversified group active in 4 core sectors: Marine Engineering & Contracting (DEME, one of the largest dredging companies in the world - CFE, a construction group with headquarters in Belgium), Private Banking (Delen Private Bank, one of the largest independent private as

Sabanci Holding

Sabancı Holding is one of Turkey’s leading conglomerate, engaged in a wide variety of business activities through its subsidiaries and affiliates, mainly in the banking, financial services, energy, industrials, building materials and retail sectors. Our Group companies most of which are leaders i

Entekhab Group

Entekhab Group is one of the largest Iranian international holdings which seeks to impact industry and economy of Iran and the world. The impact which more than anything, is derived from updated and localized knowledge and technology which has so far been implemented in most Iranian economic fields.

newsone

Essar CyberSecurity News

May 05, 2025 07:00 AM
Essar Group firm Black Box earmarks Rs 100 cr to ramp up India presence

Essar Group firm Black Box, a global digital infrastructure integrator, has earmarked about Rs 100 crore to fuel its India expansion,...

January 30, 2025 08:00 AM
Black Box continues to power Next-Gen Digital Infrastructure with order wins across industry verticals

Black Box Limited (BSE: 500463) (NSE: BBOX), Essar's technology arm, today announced its order wins across industry verticals.

September 06, 2024 07:00 AM
Black Box targets tripling sales over next 4 yrs on US networking demand

The company is seeking to capitalise on a global quest for artificial intelligence that's prompting customers to invest in computing and...

June 06, 2024 07:00 AM
Ankur Kumar: CEO, Essar Power’s Renewables Division

Ankur Kumar has over 24 years of extensive experience in sectors such as renewable energy and public infrastructure. He currently serves as chief executive...

June 01, 2017 07:00 AM
The leap from CIO to CEO: Jayantha Prabhu, Business Head-India, AGC Networks

Jayantha Prabhu did things that CIOs are supposed to do—be strategic, be game-changing, and to transcend IT. So when he was offered the...

April 30, 2017 07:00 AM
Essar Group CIO Jayantha Prabhu to also Head India Business for AGC Networks

Essar Group CIO Jayantha Prabhu has picked up the additional responsibility of heading the India business of AGC Networks, a global solution integrator.

May 10, 2007 07:00 AM
Vodafone Completes Hutchison Essar Deal

British cellular giant Vodafone on Wednesday said it had completed the acquisition of a majority stake in India's Hutchison Essar.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Essar CyberSecurity History Information

Official Website of Essar

The official website of Essar is http://www.essar.com.

Essar’s AI-Generated Cybersecurity Score

According to Rankiteo, Essar’s AI-generated cybersecurity score is 774, reflecting their Fair security posture.

How many security badges does Essar’ have ?

According to Rankiteo, Essar currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Has Essar been affected by any supply chain cyber incidents ?

According to Rankiteo, Essar has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.

Does Essar have SOC 2 Type 1 certification ?

According to Rankiteo, Essar is not certified under SOC 2 Type 1.

Does Essar have SOC 2 Type 2 certification ?

According to Rankiteo, Essar does not hold a SOC 2 Type 2 certification.

Does Essar comply with GDPR ?

According to Rankiteo, Essar is not listed as GDPR compliant.

Does Essar have PCI DSS certification ?

According to Rankiteo, Essar does not currently maintain PCI DSS compliance.

Does Essar comply with HIPAA ?

According to Rankiteo, Essar is not compliant with HIPAA regulations.

Does Essar have ISO 27001 certification ?

According to Rankiteo,Essar is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Essar

Essar operates primarily in the Investment Management industry.

Number of Employees at Essar

Essar employs approximately 10,565 people worldwide.

Subsidiaries Owned by Essar

Essar presently has no subsidiaries across any sectors.

Essar’s LinkedIn Followers

Essar’s official LinkedIn profile has approximately 334,742 followers.

NAICS Classification of Essar

Essar is classified under the NAICS code 5239, which corresponds to Other Financial Investment Activities.

Essar’s Presence on Crunchbase

No, Essar does not have a profile on Crunchbase.

Essar’s Presence on LinkedIn

Yes, Essar maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/essar.

Cybersecurity Incidents Involving Essar

As of January 23, 2026, Rankiteo reports that Essar has not experienced any cybersecurity incidents.

Number of Peer and Competitor Companies

Essar has an estimated 5,173 peer or competitor companies worldwide.

Essar CyberSecurity History Information

How many cyber incidents has Essar faced ?

Total Incidents: According to Rankiteo, Essar has faced 0 incidents in the past.

What types of cybersecurity incidents have occurred at Essar ?

Incident Types: The types of cybersecurity incidents that have occurred include .

Incident Details

What are the most common types of attacks the company has faced ?

Additional Questions

cve

Latest Global CVEs (Not Company-Specific)

Description

Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0, the `FetchUrlReader` component, used by the catalog and other plugins to fetch content from URLs, followed HTTP redirects automatically. This allowed an attacker who controls a host listed in `backend.reading.allow` to redirect requests to internal or sensitive URLs that are not on the allowlist, bypassing the URL allowlist security control. This is a Server-Side Request Forgery (SSRF) vulnerability that could allow access to internal resources, but it does not allow attackers to include additional request headers. This vulnerability is fixed in `@backstage/backend-defaults` version 0.12.2, 0.13.2, 0.14.1, and 0.15.0. Users should upgrade to this version or later. Some workarounds are available. Restrict `backend.reading.allow` to only trusted hosts that you control and that do not issue redirects, ensure allowed hosts do not have open redirect vulnerabilities, and/or use network-level controls to block access from Backstage to sensitive internal endpoints.

Risk Information
cvss3
Base: 3.5
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Description

Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath` utility function in `@backstage/backend-plugin-api`, which is used to prevent path traversal attacks, failed to properly validate symlink chains and dangling symlinks. An attacker could bypass the path validation via symlink chains (creating `link1 → link2 → /outside` where intermediate symlinks eventually resolve outside the allowed directory) and dangling symlinks (creating symlinks pointing to non-existent paths outside the base directory, which would later be created during file operations). This function is used by Scaffolder actions and other backend components to ensure file operations stay within designated directories. This vulnerability is fixed in `@backstage/backend-plugin-api` version 0.1.17. Users should upgrade to this version or later. Some workarounds are available. Run Backstage in a containerized environment with limited filesystem access and/or restrict template creation to trusted users.

Risk Information
cvss3
Base: 6.3
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Description

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets); delete arbitrary files via the `fs:delete` action by creating symlinks pointing outside the workspace, and write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks. This affects any Backstage deployment where users can create or execute Scaffolder templates. This vulnerability is fixed in `@backstage/backend-defaults` versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0; `@backstage/plugin-scaffolder-backend` versions 2.2.2, 3.0.2, and 3.1.1; and `@backstage/plugin-scaffolder-node` versions 0.11.2 and 0.12.3. Users should upgrade to these versions or later. Some workarounds are available. Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.

Risk Information
cvss3
Base: 7.1
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L
Description

FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-channel vulnerability in verify_key(). The method applied a random delay only on verification failures, allowing an attacker to statistically distinguish valid from invalid API keys by measuring response latencies. With enough repeated requests, an adversary could infer whether a key_id corresponds to a valid key, potentially accelerating brute-force or enumeration attacks. All users relying on verify_key() for API key authentication prior to the fix are affected. Users should upgrade to version 1.1.0 to receive a patch. The patch applies a uniform random delay (min_delay to max_delay) to all responses regardless of outcome, eliminating the timing correlation. Some workarounds are available. Add an application-level fixed delay or random jitter to all authentication responses (success and failure) before the fix is applied and/or use rate limiting to reduce the feasibility of statistical timing attacks.

Risk Information
cvss3
Base: 3.7
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Description

The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in version 0.36.0 and prior to version 0.40.0, a privilege escalation vulnerability exists in the Flux Operator Web UI authentication code that allows an attacker to bypass Kubernetes RBAC impersonation and execute API requests with the operator's service account privileges. In order to be vulnerable, cluster admins must configure the Flux Operator with an OIDC provider that issues tokens lacking the expected claims (e.g., `email`, `groups`), or configure custom CEL expressions that can evaluate to empty values. After OIDC token claims are processed through CEL expressions, there is no validation that the resulting `username` and `groups` values are non-empty. When both values are empty, the Kubernetes client-go library does not add impersonation headers to API requests, causing them to be executed with the flux-operator service account's credentials instead of the authenticated user's limited permissions. This can result in privilege escalation, data exposure, and/or information disclosure. Version 0.40.0 patches the issue.

Risk Information
cvss3
Base: 5.3
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=essar' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge