Comparison Overview

Kavika Oy

VS

Natuzzi

Kavika Oy

Tempo 4, Järvenpää, 04430, FI
Last Update: 2025-11-21
Between 750 and 799

Kavika Oy provides rustproof professional competence since 1945 For over 70 years, Kavika Oy has designed and manufactured stainless steel products for demanding applications. Kavika Oy on jo yli 70 vuotta suunnitellut ja valmistanut rst-tuotteita vaativaan käyttöön. Kalusteiden suunnittelussa lähtökohtana ovat aina asiakkaan tarpeet: minkälaiseen tilaan ja mihin käyttöön kalusteita tarvitaan. Kavikan ammattitaito näkyy lopputuotteiden tarkkuudessa, kestävyydessä ja loppuun asti ajatelluissa yksityiskohdissa.

NAICS: 337
NAICS Definition: Furniture and Related Product Manufacturing
Employees: 16
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Natuzzi

Via Iazzitiello, 47, Santeramo in Colle, 70029, IT
Last Update: 2025-11-21
Between 750 and 799

Founded in 1959 by Pasquale Natuzzi, Natuzzi is one of the world’s leading players in the production and distribution of design and luxury furniture. Natuzzi products are the embodiment of Italian design and craftmanship, expressing the “Made in Italy” tradition at its best. With a global retail network of 678 mono-brand stores and 456 galleries, Natuzzi distributes its collections worldwide. Natuzzi represents a unique production reality with its supply chain covering the entire process. Production takes place in the Italian hub and in the Natuzzi factories in China, Brazil and Romania. The Natuzzi company DNA flows into two brands that embody Natuzzi's core values: Natuzzi Italia and Natuzzi Editions. Natuzzi Italia is rooted in the Mediterranean lifestyle to design harmonious spaces through a collection of made in Italy luxury furniture. Natuzzi Editions comprises collections that satisfy any need of versatility thanks to high-quality options and comfort. Alongside Natuzzi Editions is Divani&Divani by Natuzzi, the Italian chain of franchising stores specialized in sofas, armchairs and accessories created in 1990.

NAICS: 337
NAICS Definition: Furniture and Related Product Manufacturing
Employees: 1,432
Subsidiaries: 1
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/kavika-oy.jpeg
Kavika Oy
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/natuzzi.jpeg
Natuzzi
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Kavika Oy
100%
Compliance Rate
0/4 Standards Verified
Natuzzi
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Furniture and Home Furnishings Manufacturing Industry Average (This Year)

No incidents recorded for Kavika Oy in 2025.

Incidents vs Furniture and Home Furnishings Manufacturing Industry Average (This Year)

No incidents recorded for Natuzzi in 2025.

Incident History — Kavika Oy (X = Date, Y = Severity)

Kavika Oy cyber incidents detection timeline including parent company and subsidiaries

Incident History — Natuzzi (X = Date, Y = Severity)

Natuzzi cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/kavika-oy.jpeg
Kavika Oy
Incidents

No Incident

https://images.rankiteo.com/companyimages/natuzzi.jpeg
Natuzzi
Incidents

No Incident

FAQ

Kavika Oy company demonstrates a stronger AI Cybersecurity Score compared to Natuzzi company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, Natuzzi company has disclosed a higher number of cyber incidents compared to Kavika Oy company.

In the current year, Natuzzi company and Kavika Oy company have not reported any cyber incidents.

Neither Natuzzi company nor Kavika Oy company has reported experiencing a ransomware attack publicly.

Neither Natuzzi company nor Kavika Oy company has reported experiencing a data breach publicly.

Neither Natuzzi company nor Kavika Oy company has reported experiencing targeted cyberattacks publicly.

Neither Kavika Oy company nor Natuzzi company has reported experiencing or disclosing vulnerabilities publicly.

Neither Kavika Oy nor Natuzzi holds any compliance certifications.

Neither company holds any compliance certifications.

Natuzzi company has more subsidiaries worldwide compared to Kavika Oy company.

Natuzzi company employs more people globally than Kavika Oy company, reflecting its scale as a Furniture and Home Furnishings Manufacturing.

Neither Kavika Oy nor Natuzzi holds SOC 2 Type 1 certification.

Neither Kavika Oy nor Natuzzi holds SOC 2 Type 2 certification.

Neither Kavika Oy nor Natuzzi holds ISO 27001 certification.

Neither Kavika Oy nor Natuzzi holds PCI DSS certification.

Neither Kavika Oy nor Natuzzi holds HIPAA certification.

Neither Kavika Oy nor Natuzzi holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.

Risk Information
cvss4
Base: 6.2
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).

Risk Information
cvss3
Base: 9.9
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

Description

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.