Comparison Overview

Perfetti Van Melle

VS

JDE Peet's

Perfetti Van Melle

Stationsplein ZW 997, Tristar 3, SCHIPHOL OOST, AMSTERDAM, NL, 1117 CE
Last Update: 2025-12-09

Perfetti Van Melle is a privately owned company, producing and distributing candies and chewing gums in more than 150 countries worldwide. Employing over 17.000 people and operating 37 companies throughout the world, Perfetti Van Melle has a true global reach: it is present in the Asia Pacific Region, Europe, Middle East, Africa and the Americas The industrial adventure of Perfetti Van Melle began many years ago, but it was in March 2001 that the current Group was set up through the merger of Perfetti Spa and Van Melle N.V. In July 2006 the Group acquired the Spanish company Chupa Chups S.A., famous all over the world for its lollypops. Our brands convey the passion we have for our products. We continuously explore new ways of doing things and innovative ideas that will inspire and delight our consumers worldwide. Our global brands Mentos, Chupa Chups, Alpenliebe gratify, refresh, inspire consumers of all ages around the globe. Other brands are extremely popular in regional markets with innovative tastes that match local preferences.

NAICS: 722
NAICS Definition: Food Services and Drinking Places
Employees: 10,494
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

JDE Peet's

Oosterdoksstraat 80, Amsterdam, 1011 DK, NL
Last Update: 2025-12-09
Between 800 and 849

JDE Peet’s is the world’s leading pure-play coffee company, serving approximately 4,400 cups of coffee per second in more than 100 markets. Guided by our ‘Reignite the Amazing’ strategy, we are focusing on brand-led growth across three big bets: Peet’s, L’OR, and Jacobs, alongside a collection of 9 local icons. In 2024, JDE Peet’s generated total sales of EUR 8.8 billion and employed a global workforce of more than 21,000 employees. Discover more about our journey to deliver a coffee for every cup and a brand for every heart at www.jdepeets.com.

NAICS: 722
NAICS Definition: Food Services and Drinking Places
Employees: 10,453
Subsidiaries: 19
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/perfetti-van-melle.jpeg
Perfetti Van Melle
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/jdepeets.jpeg
JDE Peet's
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Perfetti Van Melle
100%
Compliance Rate
0/4 Standards Verified
JDE Peet's
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Food and Beverage Services Industry Average (This Year)

No incidents recorded for Perfetti Van Melle in 2025.

Incidents vs Food and Beverage Services Industry Average (This Year)

No incidents recorded for JDE Peet's in 2025.

Incident History — Perfetti Van Melle (X = Date, Y = Severity)

Perfetti Van Melle cyber incidents detection timeline including parent company and subsidiaries

Incident History — JDE Peet's (X = Date, Y = Severity)

JDE Peet's cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/perfetti-van-melle.jpeg
Perfetti Van Melle
Incidents

No Incident

https://images.rankiteo.com/companyimages/jdepeets.jpeg
JDE Peet's
Incidents

No Incident

FAQ

JDE Peet's company demonstrates a stronger AI Cybersecurity Score compared to Perfetti Van Melle company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, JDE Peet's company has disclosed a higher number of cyber incidents compared to Perfetti Van Melle company.

In the current year, JDE Peet's company and Perfetti Van Melle company have not reported any cyber incidents.

Neither JDE Peet's company nor Perfetti Van Melle company has reported experiencing a ransomware attack publicly.

Neither JDE Peet's company nor Perfetti Van Melle company has reported experiencing a data breach publicly.

Neither JDE Peet's company nor Perfetti Van Melle company has reported experiencing targeted cyberattacks publicly.

Neither Perfetti Van Melle company nor JDE Peet's company has reported experiencing or disclosing vulnerabilities publicly.

Neither Perfetti Van Melle nor JDE Peet's holds any compliance certifications.

Neither company holds any compliance certifications.

JDE Peet's company has more subsidiaries worldwide compared to Perfetti Van Melle company.

Perfetti Van Melle company employs more people globally than JDE Peet's company, reflecting its scale as a Food and Beverage Services.

Neither Perfetti Van Melle nor JDE Peet's holds SOC 2 Type 1 certification.

Neither Perfetti Van Melle nor JDE Peet's holds SOC 2 Type 2 certification.

Neither Perfetti Van Melle nor JDE Peet's holds ISO 27001 certification.

Neither Perfetti Van Melle nor JDE Peet's holds PCI DSS certification.

Neither Perfetti Van Melle nor JDE Peet's holds HIPAA certification.

Neither Perfetti Van Melle nor JDE Peet's holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. In versions 2.5.377 and below, an unchecked offset and size used in a memcpy operation inside PCSX2's CDVD SCMD 0x91 and SCMD 0x8F handlers allow a specially crafted disc image or ELF to cause an out-of-bounds read from emulator memory. Because the offset and size is controlled through MG header fields, a specially crafted ELF can read data beyond the bounds of mg_buffer and have it reflected back into emulated memory. This issue is fixed in version 2.5.378.

Risk Information
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions 3.3 and below, incorrect handling of malformed data in Java-based decompressor implementations for Snappy and LZ4 allow remote attackers to read previous buffer contents via crafted compressed input. With certain crafted compressed inputs, elements from the output buffer can end up in the uncompressed output, potentially leaking sensitive data. This is relevant for applications that reuse the same output buffer to uncompress multiple inputs. This can be the case of a web server that allocates a fix-sized buffer for performance purposes. There is similar vulnerability in GHSA-cmp6-m4wj-q63q. This issue is fixed in version 3.4.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=zone. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing manipulation of the argument photo can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X