Comparison Overview

LexisNexis

VS

Iron Mountain

LexisNexis

230 Park Avenue, Suite 7, New York City, NY, US, 10017
Last Update: 2025-12-09

LexisNexis Legal & Professional is a leading global provider of legal, regulatory and business information and analytics that help customers increase productivity, improve decision-making and outcomes, and advance the rule of law around the world. We help lawyers win cases, manage their work more efficiently, serve their clients better and grow their practices. We assist corporations in better understanding their markets, monitoring their brands and competition, and in mitigating business risk. We collaborate with universities to educate students, and we support nation-building with governments and courts by making laws accessible and strengthening legal infrastructures. We partner with leading global associations and customers to collect evidence against war criminals and provide tools to combat human trafficking. LexisNexis Legal & Professional, which serves customers in more than 130 countries with 10,000 employees worldwide, is part of RELX Group, a global provider of information and analytics for professional and business customers across industries.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 10,523
Subsidiaries: 91
12-month incidents
0
Known data breaches
0
Attack type number
0

Iron Mountain

1 Federal Street, Boston, Massachusetts, 02110, US
Last Update: 2025-12-09
Between 750 and 799

For over 70 years, Iron Mountain Incorporated (NYSE: IRM) has been your strategic partner to care for your information and assets. A global leader in storage and information management services and trusted by more than 225,000 organizations around the world, including 95% of the Fortune 1000, we protect, unlock, and extend the value of your work—whatever it is, wherever it is, however it’s stored. We create the framework necessary to bridge the gaps between paper, digital, media, and physical data and extract value along its lifecycle, helping to build your organizational resilience. And all this with a commitment to sustainability at our core. Our relationship is a true partnership where you trust us not only to preserve institutional knowledge and enhance efficiency, security, and access but to make your work mean more. Because in that work is the power to not only accelerate your business, but elevate it. Elevate the power of your work.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 19,962
Subsidiaries: 4
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/lexisnexis.jpeg
LexisNexis
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/iron-mountain.jpeg
Iron Mountain
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
LexisNexis
100%
Compliance Rate
0/4 Standards Verified
Iron Mountain
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for LexisNexis in 2025.

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for Iron Mountain in 2025.

Incident History — LexisNexis (X = Date, Y = Severity)

LexisNexis cyber incidents detection timeline including parent company and subsidiaries

Incident History — Iron Mountain (X = Date, Y = Severity)

Iron Mountain cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/lexisnexis.jpeg
LexisNexis
Incidents

No Incident

https://images.rankiteo.com/companyimages/iron-mountain.jpeg
Iron Mountain
Incidents

No Incident

FAQ

Iron Mountain company demonstrates a stronger AI Cybersecurity Score compared to LexisNexis company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, Iron Mountain company has disclosed a higher number of cyber incidents compared to LexisNexis company.

In the current year, Iron Mountain company and LexisNexis company have not reported any cyber incidents.

Neither Iron Mountain company nor LexisNexis company has reported experiencing a ransomware attack publicly.

Neither Iron Mountain company nor LexisNexis company has reported experiencing a data breach publicly.

Neither Iron Mountain company nor LexisNexis company has reported experiencing targeted cyberattacks publicly.

Neither LexisNexis company nor Iron Mountain company has reported experiencing or disclosing vulnerabilities publicly.

Neither LexisNexis nor Iron Mountain holds any compliance certifications.

Neither company holds any compliance certifications.

LexisNexis company has more subsidiaries worldwide compared to Iron Mountain company.

Iron Mountain company employs more people globally than LexisNexis company, reflecting its scale as a IT Services and IT Consulting.

Neither LexisNexis nor Iron Mountain holds SOC 2 Type 1 certification.

Neither LexisNexis nor Iron Mountain holds SOC 2 Type 2 certification.

Neither LexisNexis nor Iron Mountain holds ISO 27001 certification.

Neither LexisNexis nor Iron Mountain holds PCI DSS certification.

Neither LexisNexis nor Iron Mountain holds HIPAA certification.

Neither LexisNexis nor Iron Mountain holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Risk Information
cvss3
Base: 8.1
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Risk Information
cvss3
Base: 2.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this issue. You should upgrade the affected component. The vendor confirms that this is "[f]ixed in version 4.10.2". Furthermore, that "[b]ackports for older versions in process and will be out as soon as their respective CI pipelines complete."

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Risk Information
cvss3
Base: 4.5
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Risk Information
cvss3
Base: 5.8
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N