ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Hassan Allam Holding is a leading group with a focus on engineering and construction, and investment and development. The Group operates in diverse sectors including infrastructure, energy, water, industrial, logistics, petrochemical, and complex large-scale projects in Egypt and the MENA region. The founders of Hassan Allam Holding commenced operations in 1936, making the oldest construction franchise in the MENA region with a solid reputation, superior technical capabilities, and a diversified portfolio. With a legacy of identifying and investing in attractive infrastructure projects, in the past five years, it has delivered over 70 projects and has a current backlog exceeding USD 5 billion. The Group is named among the Engineering News-Record (ENR) list of the top 250 global contractors. Today, we continue to lead our industry with a large dynamic business, employing more than 50,000 employees in Egypt and the MENA Region.

Hassan Allam Holding A.I CyberSecurity Scoring

HAH

Company Details

Linkedin ID:

hassan-allam-holding

Employees number:

11,537

Number of followers:

662,958

NAICS:

23

Industry Type:

Construction

Homepage:

hassanallam.com

IP Addresses:

0

Company ID:

HAS_2972923

Scan Status:

In-progress

AI scoreHAH Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/hassan-allam-holding.jpeg
HAH Construction
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreHAH Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/hassan-allam-holding.jpeg
HAH Construction
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

HAH Company CyberSecurity News & History

Past Incidents
0
Attack Types
0
No data available
Ailogo

HAH Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for HAH

Incidents vs Construction Industry Average (This Year)

No incidents recorded for Hassan Allam Holding in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Hassan Allam Holding in 2025.

Incident Types HAH vs Construction Industry Avg (This Year)

No incidents recorded for Hassan Allam Holding in 2025.

Incident History — HAH (X = Date, Y = Severity)

HAH cyber incidents detection timeline including parent company and subsidiaries

HAH Company Subsidiaries

SubsidiaryImage

Hassan Allam Holding is a leading group with a focus on engineering and construction, and investment and development. The Group operates in diverse sectors including infrastructure, energy, water, industrial, logistics, petrochemical, and complex large-scale projects in Egypt and the MENA region. The founders of Hassan Allam Holding commenced operations in 1936, making the oldest construction franchise in the MENA region with a solid reputation, superior technical capabilities, and a diversified portfolio. With a legacy of identifying and investing in attractive infrastructure projects, in the past five years, it has delivered over 70 projects and has a current backlog exceeding USD 5 billion. The Group is named among the Engineering News-Record (ENR) list of the top 250 global contractors. Today, we continue to lead our industry with a large dynamic business, employing more than 50,000 employees in Egypt and the MENA Region.

Loading...
similarCompanies

HAH Similar Companies

United Rentals

As North America’s largest equipment rental company, with 1500+ stores in the United States and Canada, we serve construction and industrial companies, utilities, municipalities, homeowners, and communities, with the goal of fulfilling customer needs and surpassing expectations. We go beyond equipm

REXEL USA

REXEL, LEADING DISTRIBUTOR WORLDWIDE OF ELECTRICAL SUPPLIES Rexel, a global leader in the distribution of electrical supplies and services, serves three main end markets: industrial, commercial and residential. The Group operates in 38 countries, with a network of some 2,200 branches, a distributio

Bouygues Construction

With 32,500 employees working in 60 countries, Bouygues Construction designs, builds and rehabilitates the infrastructures and buildings that are essential for a sustainable society. All over the world, the teams support the development of low-carbon energy production and public transport infrastruc

Taisei Corporation 大成建設株式会社

Taisei Corporation (大成建設株式会社) is one of the oldest and largest Japanese General Construction Contractors and a major International General Contractor. The main areas of business are building construction, civil engineering, and real estate development. Taisei Corporation's head office is in Shinj

VINCI

VINCI is a world leader in concessions, energy and construction, employing 280.000 people in some 120 countries. We design, finance, build and operate infrastructure and facilities that help improve daily life and mobility for all. Because we believe in all-round performance, above and beyond eco

Andrade Gutierrez S.A.

Fundada em Belo Horizonte, Minas Gerais, a Andrade Gutierrez tem reconhecida expertise no segmento de construção pesada. Na década de 1990 iniciou a diversificação dos negócios com investimentos nas áreas de Concessões e Telecomunicações. Hoje o Grupo Andrade Gutierrez é um dos maiores conglomer

Across decades, across disciplines, NCC Ltd has dedicated itself to building infrastructure of uncompromising standards. Infrastructure that is a constant reminder of the Company’s holistic construction expertise, which in turn is the result of relentless innovation and sheer dedication. Today, NCC

Mesa Holding

Mesa Holding, since its founding in 1969, has embraced innovation that values people while focusing on technology with a view of trust-oriented development and in line dynamics of the era. Mesa Holding’s vision aims to sustain its existing successes while believing in approaching every new project

KEC International Ltd.

KEC International Limited, the flagship company of RPG Enterprises is a diversified global infrastructure Engineering, Procurement & Construction (EPC) major, with a presence in the verticals of Power Transmission & Distribution, Railways, Civil, Urban Infrastructure, Oil & Gas Pipelines, Solar, Sma

newsone

HAH CyberSecurity News

August 09, 2023 07:00 AM
Digital Transformation Summit to happen on 9 to 10 August, 2023 at Cairo, Egypt

The 22nd Digital Transformation Summit, hosted in Egypt, is a prestigious event dedicated to in-depth discussions on the critical challenges that can be...

February 15, 2022 08:00 AM
Hassan Allam Holding partners with CrowdStrike to provide cybersecurity solutions

Hassan Allam Holding partners with CrowdStrike to provide cybersecurity solutions ... Hassan Allam Holding announced its partnership with...

February 15, 2022 08:00 AM
Egyptian tycoon Hassan Allam’s construction group partners with U.S.-based tech firm to provide cybersecurity solutions

Hassan Allam Holding is Egypt's largest privately held engineering, construction, and infrastructure firm.

June 07, 2021 07:00 AM
Hassan Allam Holding ushers in new era of productivity and security following its move to the intelligent Microsoft Cloud

Hassan Allam Holding (HAH) has significantly boosted both its productivity and security following its migration to the trusted, versatile, intelligent...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

HAH CyberSecurity History Information

Official Website of Hassan Allam Holding

The official website of Hassan Allam Holding is http://www.hassanallam.com.

Hassan Allam Holding’s AI-Generated Cybersecurity Score

According to Rankiteo, Hassan Allam Holding’s AI-generated cybersecurity score is 787, reflecting their Fair security posture.

How many security badges does Hassan Allam Holding’ have ?

According to Rankiteo, Hassan Allam Holding currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Hassan Allam Holding have SOC 2 Type 1 certification ?

According to Rankiteo, Hassan Allam Holding is not certified under SOC 2 Type 1.

Does Hassan Allam Holding have SOC 2 Type 2 certification ?

According to Rankiteo, Hassan Allam Holding does not hold a SOC 2 Type 2 certification.

Does Hassan Allam Holding comply with GDPR ?

According to Rankiteo, Hassan Allam Holding is not listed as GDPR compliant.

Does Hassan Allam Holding have PCI DSS certification ?

According to Rankiteo, Hassan Allam Holding does not currently maintain PCI DSS compliance.

Does Hassan Allam Holding comply with HIPAA ?

According to Rankiteo, Hassan Allam Holding is not compliant with HIPAA regulations.

Does Hassan Allam Holding have ISO 27001 certification ?

According to Rankiteo,Hassan Allam Holding is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Hassan Allam Holding

Hassan Allam Holding operates primarily in the Construction industry.

Number of Employees at Hassan Allam Holding

Hassan Allam Holding employs approximately 11,537 people worldwide.

Subsidiaries Owned by Hassan Allam Holding

Hassan Allam Holding presently has no subsidiaries across any sectors.

Hassan Allam Holding’s LinkedIn Followers

Hassan Allam Holding’s official LinkedIn profile has approximately 662,958 followers.

NAICS Classification of Hassan Allam Holding

Hassan Allam Holding is classified under the NAICS code 23, which corresponds to Construction.

Hassan Allam Holding’s Presence on Crunchbase

No, Hassan Allam Holding does not have a profile on Crunchbase.

Hassan Allam Holding’s Presence on LinkedIn

Yes, Hassan Allam Holding maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/hassan-allam-holding.

Cybersecurity Incidents Involving Hassan Allam Holding

As of November 27, 2025, Rankiteo reports that Hassan Allam Holding has not experienced any cybersecurity incidents.

Number of Peer and Competitor Companies

Hassan Allam Holding has an estimated 38,722 peer or competitor companies worldwide.

Hassan Allam Holding CyberSecurity History Information

How many cyber incidents has Hassan Allam Holding faced ?

Total Incidents: According to Rankiteo, Hassan Allam Holding has faced 0 incidents in the past.

What types of cybersecurity incidents have occurred at Hassan Allam Holding ?

Incident Types: The types of cybersecurity incidents that have occurred include .

Incident Details

What are the most common types of attacks the company has faced ?

Additional Questions

cve

Latest Global CVEs (Not Company-Specific)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.

Risk Information
cvss4
Base: 7.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=hassan-allam-holding' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge