Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Johnson Controls

Johnson Controls Vendor Cyber Rating & Cyber Score

johnsoncontrols.com

At Johnson Controls, we transform the environments where people live, work, learn and play. As the global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Building on a proud history of 140 years of innovation, we deliver the blueprint of the future for industries such as healthcare, schools, data centers, airports, stadiums, manufacturing and beyond through OpenBlue, our comprehensive digital offering. Today, Johnson Controls offers the world`s largest portfolio of building technology and software as well as service solutions from some of the most trusted names in the industry. Visit www.johnsoncontrols.com for more information.


Johnson Controls A.I CyberSecurity Scoring

Johnson Controls
Company Information
Website:http://www.johnsoncontrols.com
Employees number:60,211
Number of followers:1,690,218
NAICS:3332
Industry Type:Industrial Machinery Manufacturing
Homepage:johnsoncontrols.com
Johnson Controls Risk Score (AI oriented)
Between 750 and 799
logo
Johnson ControlsIndustrial Machinery Manufacturing
Updated:
01/04/2026
783/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Johnson Controls Global Score (TPRM)
xxxx
logo
Johnson ControlsIndustrial Machinery Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Johnson Controls
Johnson ControlsFair
Current Score
783Baa (FAIR)
01000
2 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
787Before Incident
MAY 2026
786Before Incident
APRIL 2026
786Before Incident
MARCH 2026
785Before Incident
FEBRUARY 2026
784Before Incident
JANUARY 2026
784Before Incident
DECEMBER 2025
778Before Incident
NOVEMBER 2025
782Before Incident
OCTOBER 2025
781Before Incident
SEPTEMBER 2025
780Before Incident
AUGUST 2025
779Before Incident
JULY 2025
778Before Incident
JUNE 2025
778Before Incident
Vulnerability
16 Jun 2025Johnson Controls
Johnson Controls

Mass Exposure of Industrial Control Systems to the Open Internet

775After Incident
CRITICAL-3
JOH4502045100625
Johnson Controls, a critical infrastructure provider, faced severe exposure of its industrial control systems (ICS) due to unpatched vulnerabilities and misconfigurations. The systems, integral to power grids, water treatment plants, and manufacturing operations, were left accessible online with default credentials or known flaws. This negligence enabled potential cyber intrusions capable of triggering catastrophic outcomes—such as blackouts, chemical contamination (e.g., tampering with chlorine levels in water utilities), or operational shutdowns in energy and healthcare sectors. The 2025 CISA advisory highlighted these vulnerabilities as high-severity risks, emphasizing the systemic failure to enforce air-gapping or zero-trust security models. The lapse not only jeopardized public safety but also invited state-sponsored or criminal exploitation, amplifying threats to national security. The company’s delayed mitigation efforts, coupled with regulatory gaps and legacy system dependencies, exacerbated the exposure, leaving critical infrastructure defenseless against attacks with life-threatening or war-escalating potential.
INCIDENT DETAILS -
TYPE
Exposure of Critical InfrastructureMisconfigurationUnpatched VulnerabilitiesLack of Network Segmentation
IMPACT
Industrial Control Systems (ICS)Programmable Logic Controllers (PLCs)Water treatment control systemsEnergy sector devices (oil pipelines, electrical substations)Transportation infrastructureHealthcare infrastructurePotential blackoutsChemical spillsManipulation of critical processes (e.g., chlorine levels in water treatment)Cascading failures in interconnected systemsErosion of public trust in critical infrastructure securityPerception of negligence in safeguarding essential services
DATA BREACH
Lack of encryption in exposed systems
SEPTEMBER 2023
813Before Incident
Ransomware
01 Sep 2023Johnson Controls
johnson-controls

Massive Ransomware Attack on Johnson Controls International

755After Incident
HIGH-58
JOH174511023
A'massive ransomware attack' reportedly affected Johnson Controls International, encrypting many company devices, including VMware ESXi servers, and negatively affecting the business operations of both the parent corporation and its subsidiaries. Development and production of industrial control systems, security tools, air conditioners, and fire safety gear are all activities of the international company Johnson Controls. However, the incident has disrupted some of the Company's business operations and is anticipated to continue doing so. The Company is evaluating the incident's potential effects on its ability to deliver its financial results for the entire fiscal year and the fourth quarter on schedule.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial Gain
IMPACT
Financial Loss: Potential delay in reporting financial resultsVMware ESXi serverscompany devicesDowntime: Ongoing disruption of business operationsOperational Impact: Significant

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Johnson Controls ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Johnson Controls's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Johnson Controls's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Johnson Controls ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Johnson Controls's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?