Comparison Overview

Poste Italiane

VS

ZTO Express

Poste Italiane

Viale Europa 175, Rome, RM, IT, 00144
Last Update: 2025-12-09
Between 800 and 849

With our over 160-year history, approximately 120,000 employees and 12,800 post offices, total financial assets of €580 billion and 35 million customers, the Group occupies a unique position in terms of size, recognisability, reach and customer loyalty. Poste Italiane is Italy's largest service infrastructure and its services play an important role in society. We operate in three lines of business, in all of which we lead the market: Post and parcel sector, a business that has benefited from the rise of e-commerce and the dynamic nature of the parcels market; Financial Services, through BancoPosta; Insurance, where we lead the life market in Italy, and asset management, an area in which we are expanding. Our purpose: Grow responsibly thanks to the decisive contribution of its people to the sustainable success, innovation, digitisation and social cohesion of the country. Poste Italiane has issued shares listed on the Mercato Telematico Azionario (Electronic Stock Exchange - MTA) organised and managed by Borsa Italiana SpA as of 27 October 2015. At 31 December 2023, the Company is 29.26% owned by the Ministry of the Economy and Finance (MEF) and 35% owned by Cassa Depositi e Prestiti SpA (CDP), also controlled by the MEF. The remaining shares are held by institutional and retail investors. A total of 33.9%2 of the shares held by institutional investors of Poste Italiane SpA belong to investors who follow ESG (Environment, Social, Governance) criteria in their investment choices. Since May 2023, Silvia Maria Rovere is the Company’s Chairwoman. Since April 2017 Matteo Del Fante is Chief Executive Officer. Giuseppe Lasco was appointed General Manager in February 2024. More info https://www.posteitaliane.it/en/index.html (Last update March 2024)

NAICS: 47
NAICS Definition: Transportation and Warehousing
Employees: 17,738
Subsidiaries: 2
12-month incidents
0
Known data breaches
0
Attack type number
0

ZTO Express

1685 Huazhi Road, Qingpu District Shanghai, China 201708, CN
Last Update: 2025-12-09
Between 750 and 799

Founded on May 8, 2002, ZTO Express (“ZTO” or “the Company”) is one of the leading express delivery companies in China in terms of parcel volume, with a 20.4% market share in 2020. ZTO is both a key enabler and a direct beneficiary of China’s fast-growing e-commerce market, and has established itself as the trusted express delivery partner for millions of commerce customers, including online merchants and consumers selling and buying products on Chinese leading e-commerce sites, such as Alibaba, PDD, JD.com. ZTO operates a highly scalable network partner model that enables it to expand nationwide network quickly and provide e-commerce merchants with greater geographic reach at low cost. Under a network partner model, it operates the mission-critical line-haul transportation and sorting network within the express delivery service value chain, whereas its network partners operate the outlets that provide first-mile pickup and last-mile delivery services. Operational efficiency and economies of scale enable ZTO to achieve strong operating leverage which drives higher return on invested capital and equity. ZTO’s objective is to become a world-leading comprehensive logistical services provider.

NAICS: 47
NAICS Definition: Transportation and Warehousing
Employees: 10,001
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/poste-italiane.jpeg
Poste Italiane
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/ztoexpress.jpeg
ZTO Express
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Poste Italiane
100%
Compliance Rate
0/4 Standards Verified
ZTO Express
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Transportation, Logistics, Supply Chain and Storage Industry Average (This Year)

No incidents recorded for Poste Italiane in 2025.

Incidents vs Transportation, Logistics, Supply Chain and Storage Industry Average (This Year)

No incidents recorded for ZTO Express in 2025.

Incident History — Poste Italiane (X = Date, Y = Severity)

Poste Italiane cyber incidents detection timeline including parent company and subsidiaries

Incident History — ZTO Express (X = Date, Y = Severity)

ZTO Express cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/poste-italiane.jpeg
Poste Italiane
Incidents

No Incident

https://images.rankiteo.com/companyimages/ztoexpress.jpeg
ZTO Express
Incidents

No Incident

FAQ

Poste Italiane company demonstrates a stronger AI Cybersecurity Score compared to ZTO Express company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, ZTO Express company has disclosed a higher number of cyber incidents compared to Poste Italiane company.

In the current year, ZTO Express company and Poste Italiane company have not reported any cyber incidents.

Neither ZTO Express company nor Poste Italiane company has reported experiencing a ransomware attack publicly.

Neither ZTO Express company nor Poste Italiane company has reported experiencing a data breach publicly.

Neither ZTO Express company nor Poste Italiane company has reported experiencing targeted cyberattacks publicly.

Neither Poste Italiane company nor ZTO Express company has reported experiencing or disclosing vulnerabilities publicly.

Neither Poste Italiane nor ZTO Express holds any compliance certifications.

Neither company holds any compliance certifications.

Poste Italiane company has more subsidiaries worldwide compared to ZTO Express company.

Poste Italiane company employs more people globally than ZTO Express company, reflecting its scale as a Transportation, Logistics, Supply Chain and Storage.

Neither Poste Italiane nor ZTO Express holds SOC 2 Type 1 certification.

Neither Poste Italiane nor ZTO Express holds SOC 2 Type 2 certification.

Neither Poste Italiane nor ZTO Express holds ISO 27001 certification.

Neither Poste Italiane nor ZTO Express holds PCI DSS certification.

Neither Poste Italiane nor ZTO Express holds HIPAA certification.

Neither Poste Italiane nor ZTO Express holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be exploited.

Risk Information
cvss2
Base: 2.6
Severity: HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:N
cvss3
Base: 3.7
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
cvss4
Base: 6.3
Severity: HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown processing of the file /admin/update_student.php. This manipulation of the argument stud_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/save_user.php. The manipulation of the argument firstname results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php. The manipulation of the argument user_id leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X