Comparison Overview

Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH

VS

John Swire & Sons (H.K.) Ltd.

Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH

Friedrich-Ebert-Allee 32+36, Bonn, 53113, DE
Last Update: 2025-12-14
Between 750 and 799

As a service provider in the field of international cooperation for sustainable development and international education work, we are dedicated to shaping a future worth living around the world. GIZ has over 50 years of experience in a wide variety of areas, including economic development and employment promotion, energy and the environment, and peace and security. The diverse expertise of our federal enterprise is in demand around the globe – from the German Government, European Union institutions, the United Nations, the private sector and governments of other countries. We work with businesses, civil society actors and research institutions, fostering successful interaction between development policy and other policy fields and areas of activity. Our main commissioning party is the German Federal Ministry for Economic Cooperation and Development (BMZ). The commissioning parties and cooperation partners all place their trust in GIZ, and we work with them to generate ideas for political, social and economic change, to develop these into concrete plans and to implement them. Since we are a public-benefit federal enterprise, German and European values are central to our work. Together with our partners in national governments worldwide and cooperation partners from the worlds of business, research and civil society, we work flexibly to deliver effective solutions that offer people better prospects and sustainably improve their living conditions. The registered offices of GIZ are in Bonn and Eschborn (Germany). Our video: DE: https://youtu.be/KCb9XVCZzWQ?si=Cwm0ArGKq6VQD83q EN: https://youtu.be/XIMLHv17Pns?si=UrRGg8WANlZ-j8og Registration information: https://www.giz.de/en/html/registration_information.html Our netiquette: https://www.giz.de/en/mediacenter/93951.html Data privacy statement: https://www.giz.de/en/html/data_protection.html

NAICS: 522293
NAICS Definition: International Trade Financing
Employees: 26,244
Subsidiaries: 29
12-month incidents
0
Known data breaches
0
Attack type number
0

John Swire & Sons (H.K.) Ltd.

Hong Kong, HK
Last Update: 2025-12-18
Between 750 and 799

Swire is a highly diversified global business group which has been in operation for over 200 years. It employs over 121,000 people across the world. Swire Group’s businesses span Property, Beverages & Food Chain, Aviation, Marine Services, Trading & Industrial, as well as Healthcare. Whilst Swire operates globally, its main sphere of operations is in Asia and to a lesser, but nevertheless significant, extent in North America and Europe. Swire’s wholly owned shipping businesses trade worldwide, but the major sphere of their activity is in the Pacific and Australasia.

NAICS: 522293
NAICS Definition: International Trade Financing
Employees: 24,468
Subsidiaries: 16
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/gizgmbh.jpeg
Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/jsshk.jpeg
John Swire & Sons (H.K.) Ltd.
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH
100%
Compliance Rate
0/4 Standards Verified
John Swire & Sons (H.K.) Ltd.
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs International Trade and Development Industry Average (This Year)

No incidents recorded for Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH in 2025.

Incidents vs International Trade and Development Industry Average (This Year)

No incidents recorded for John Swire & Sons (H.K.) Ltd. in 2025.

Incident History — Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH (X = Date, Y = Severity)

Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH cyber incidents detection timeline including parent company and subsidiaries

Incident History — John Swire & Sons (H.K.) Ltd. (X = Date, Y = Severity)

John Swire & Sons (H.K.) Ltd. cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/gizgmbh.jpeg
Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH
Incidents

No Incident

https://images.rankiteo.com/companyimages/jsshk.jpeg
John Swire & Sons (H.K.) Ltd.
Incidents

No Incident

FAQ

Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH company demonstrates a stronger AI Cybersecurity Score compared to John Swire & Sons (H.K.) Ltd. company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, John Swire & Sons (H.K.) Ltd. company has disclosed a higher number of cyber incidents compared to Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH company.

In the current year, John Swire & Sons (H.K.) Ltd. company and Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH company have not reported any cyber incidents.

Neither John Swire & Sons (H.K.) Ltd. company nor Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH company has reported experiencing a ransomware attack publicly.

Neither John Swire & Sons (H.K.) Ltd. company nor Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH company has reported experiencing a data breach publicly.

Neither John Swire & Sons (H.K.) Ltd. company nor Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH company has reported experiencing targeted cyberattacks publicly.

Neither Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH company nor John Swire & Sons (H.K.) Ltd. company has reported experiencing or disclosing vulnerabilities publicly.

Neither Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH nor John Swire & Sons (H.K.) Ltd. holds any compliance certifications.

Neither company holds any compliance certifications.

Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH company has more subsidiaries worldwide compared to John Swire & Sons (H.K.) Ltd. company.

Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH company employs more people globally than John Swire & Sons (H.K.) Ltd. company, reflecting its scale as a International Trade and Development.

Neither Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH nor John Swire & Sons (H.K.) Ltd. holds SOC 2 Type 1 certification.

Neither Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH nor John Swire & Sons (H.K.) Ltd. holds SOC 2 Type 2 certification.

Neither Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH nor John Swire & Sons (H.K.) Ltd. holds ISO 27001 certification.

Neither Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH nor John Swire & Sons (H.K.) Ltd. holds PCI DSS certification.

Neither Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH nor John Swire & Sons (H.K.) Ltd. holds HIPAA certification.

Neither Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH nor John Swire & Sons (H.K.) Ltd. holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulnerability where authentication middleware is not properly applied to API endpoints. This results in certain API endpoints being accessible without valid session credentials. This is dangerous for those who have exposed Zerobyte to be used outside of their internal network. A fix has been applied in both version 0.19.0 and 0.18.5. If immediate upgrade is not possible, restrict network access to the Zerobyte instance to trusted networks only using firewall rules or network segmentation. This is only a temporary mitigation; upgrading is strongly recommended.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter configuration. The CSRF protection mechanism was **explicitly disabled**, allowing the application to process state-changing requests (POST) without verifying a valid CSRF token. An unauthenticated remote attacker can exploit this by hosting a malicious web page. If a logged-in administrator visits this page, their browser is forced to send unauthorized requests to the application. A successful exploit allows the attacker to silently create a new Administrator account with full privileges, leading to a complete takeover of the system and loss of confidentiality, integrity, and availability. The vulnerability has been patched in version 3.4.2. The fix re-enables the CSRF filter in `app/Config/Filters.php` and resolves associated AJAX race conditions by adjusting token regeneration settings. As a workaround, administrators can manually re-enable the CSRF filter in `app/Config/Filters.php` by uncommenting the protection line. However, this is not recommended without applying the full patch, as it may cause functionality breakage in the Sales module due to token synchronization issues.

Risk Information
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Model Context Protocol (MCP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A malicious MCP configuration can contain arbitrary shell commands that run on the host system with the privileges of the user running the IDE. This can be triggered automatically without any user interaction besides opening the project in the IDE. Version 0.218.2-pre fixes the issue by implementing worktree trust mechanism. As a workaround, users should carefully review the contents of project settings files (`./zed/settings.json`) before opening new projects in Zed.

Risk Information
cvss3
Base: 7.7
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Description

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Language Server Protocol (LSP) configurations from the `settings.json` file located within a project’s `.zed` subdirectory. A malicious LSP configuration can contain arbitrary shell commands that run on the host system with the privileges of the user running the IDE. This can be triggered when a user opens project file for which there is an LSP entry. A concerted effort by an attacker to seed a project settings file (`./zed/settings.json`) with malicious language server configurations could result in arbitrary code execution with the user's privileges if the user opens the project in Zed without reviewing the contents. Version 0.218.2-pre fixes the issue by implementing worktree trust mechanism. As a workaround, users should carefully review the contents of project settings files (`./zed/settings.json`) before opening new projects in Zed.

Risk Information
cvss3
Base: 7.7
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Description

Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present starting in versions 7.0.0 and prior to versions 7.6.21, 8.6.15, 9.1.17, and 10.1.10 relates to Storybook’s handling of environment variables defined in a `.env` file, which could, in specific circumstances, lead to those variables being unexpectedly bundled into the artifacts created by the `storybook build` command. When a built Storybook is published to the web, the bundle’s source is viewable, thus potentially exposing those variables to anyone with access. For a project to potentially be vulnerable to this issue, it must build the Storybook (i.e. run `storybook build` directly or indirectly) in a directory that contains a `.env` file (including variants like `.env.local`) and publish the built Storybook to the web. Storybooks built without a `.env` file at build time are not affected, including common CI-based builds where secrets are provided via platform environment variables rather than `.env` files. Storybook runtime environments (i.e. `storybook dev`) are not affected. Deployed applications that share a repo with your Storybook are not affected. Users should upgrade their Storybook—on both their local machines and CI environment—to version .6.21, 8.6.15, 9.1.17, or 10.1.10 as soon as possible. Maintainers additionally recommend that users audit for any sensitive secrets provided via `.env` files and rotate those keys. Some projects may have been relying on the undocumented behavior at the heart of this issue and will need to change how they reference environment variables after this update. If a project can no longer read necessary environmental variable values, either prefix the variables with `STORYBOOK_` or use the `env` property in Storybook’s configuration to manually specify values. In either case, do not include sensitive secrets as they will be included in the built bundle.

Risk Information
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L