Comparison Overview

ICONICS

VS

SAP

ICONICS

2 Hampshire St, Foxborough (Foxboro), Massachusetts, 02035, US
Last Update: 2025-12-25
Between 750 and 799

Founded in 1986, ICONICS is an award-winning global software provider offering real-time visualization, HMI/SCADA, energy management, fault detection, manufacturing intelligence, IoT, and a suite of analytics solutions for building automation and operational excellence. ICONICS solutions are installed in 70% of Global 500 companies around the world, helping customers to be more profitable, agile, efficient, and sustainable. ICONICS promotes an international culture of innovation, creativity and excellence in product design, development, technical support, training, sales and consulting services for end users, system integrators, OEMs and channel partners. ICONICS has over 375,000 applications installed in multiple industries worldwide. #AutomatingtheWorld #MaketheInvisibleVisible #AutomationSoftware #Technology #SmartSolutions

NAICS: 5112
NAICS Definition: Software Publishers
Employees: 237
Subsidiaries: 4
12-month incidents
0
Known data breaches
0
Attack type number
1

SAP

Dietmar-Hopp-Allee 16, None, Walldorf, BW, DE, 69190
Last Update: 2025-12-19
Between 750 and 799

SAP is the leading enterprise application and business AI company. We stand at the intersection of business and technology, where our innovations are designed to directly address real business challenges and produce real-world impacts. Our solutions are the backbone for the world’s most complex and demanding processes. SAP’s integrated portfolio unites the elements of modern organizations — from workforce and financials to customers and supply chains — into a unified ecosystem that drives progress. SAP privacy statement for followers: www.sap.com/sps Our Community Guidelines At SAP, we're committed to fostering meaningful conversations that respect everyone in our community. To maintain a positive environment, we moderate comments that: • Target individuals personally, including our employees, customers, or partners • Contain discriminatory, harassing, or threatening language/content • Share personal information without consent • Promote misinformation or spam or 3rd-party links We believe in open dialogue and constructive feedback, but we will remove content that violates these guidelines without notice. We appreciate your understanding and contribution to a respectful community. For questions about our moderation practices, please DM or contact us at [email protected].

NAICS: 5112
NAICS Definition: Software Publishers
Employees: 133,175
Subsidiaries: 17
12-month incidents
5
Known data breaches
1
Attack type number
3

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/iconics.jpeg
ICONICS
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/sap.jpeg
SAP
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
ICONICS
100%
Compliance Rate
0/4 Standards Verified
SAP
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Software Development Industry Average (This Year)

No incidents recorded for ICONICS in 2025.

Incidents vs Software Development Industry Average (This Year)

SAP has 719.67% more incidents than the average of same-industry companies with at least one recorded incident.

Incident History — ICONICS (X = Date, Y = Severity)

ICONICS cyber incidents detection timeline including parent company and subsidiaries

Incident History — SAP (X = Date, Y = Severity)

SAP cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/iconics.jpeg
ICONICS
Incidents

Date Detected: 6/2024
Type:Vulnerability
Attack Vector: Phantom DLL Hijacking, Lateral Movement
Blog: Blog
https://images.rankiteo.com/companyimages/sap.jpeg
SAP
Incidents

Date Detected: 8/2025
Type:Vulnerability
Attack Vector: Network, RFC-Exposed Function Module, ABAP Code Injection
Motivation: Data Theft, Data Manipulation, Privilege Escalation, Credential Theft, Operational Disruption, Potential Financial Gain
Blog: Blog

Date Detected: 6/2025
Type:Vulnerability
Attack Vector: Network (RMI-P4 module), Path Traversal (SAP Print Service), File Upload (SAP Supplier Relationship Management)
Blog: Blog

Date Detected: 4/2025
Type:Vulnerability
Attack Vector: Unauthenticated upload of executable binaries
Blog: Blog

FAQ

SAP company demonstrates a stronger AI Cybersecurity Score compared to ICONICS company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

SAP company has faced a higher number of disclosed cyber incidents historically compared to ICONICS company.

In the current year, SAP company has reported more cyber incidents than ICONICS company.

SAP company has confirmed experiencing a ransomware attack, while ICONICS company has not reported such incidents publicly.

SAP company has disclosed at least one data breach, while ICONICS company has not reported such incidents publicly.

Neither SAP company nor ICONICS company has reported experiencing targeted cyberattacks publicly.

Both ICONICS company and SAP company have disclosed vulnerabilities.

Neither ICONICS nor SAP holds any compliance certifications.

Neither company holds any compliance certifications.

SAP company has more subsidiaries worldwide compared to ICONICS company.

SAP company employs more people globally than ICONICS company, reflecting its scale as a Software Development.

Neither ICONICS nor SAP holds SOC 2 Type 1 certification.

Neither ICONICS nor SAP holds SOC 2 Type 2 certification.

Neither ICONICS nor SAP holds ISO 27001 certification.

Neither ICONICS nor SAP holds PCI DSS certification.

Neither ICONICS nor SAP holds HIPAA certification.

Neither ICONICS nor SAP holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

Risk Information
cvss3
Base: 8.9
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Description

Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server.

Risk Information
cvss3
Base: 9.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 9.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality, integrity, and availability.

Risk Information
cvss3
Base: 5.6
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Description

ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

Risk Information
cvss3
Base: 6.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N