Comparison Overview

Red Eléctrica

VS

Duke Energy Corporation

Red Eléctrica

Paseo del Conde de los Gaitanes, Alcobendas, Madrid, 28109, ES
Last Update: 2025-12-09
Between 750 and 799

Red Eléctrica fue la primera empresa en el mundo dedicada en exclusividad al transporte de electricidad y a la operación de sistemas eléctricos. Pionera en su clase, mantiene hoy una posición de liderazgo en estas actividades. Desde su creación en 1985, se hizo cargo de la red de transporte y de la operación del sistema eléctrico español adelantándose a las recientes tendencias mundiales hacia la segregación de actividades, estableciendo al transporte como una actividad separada de la generación y de la distribución. Este hecho supuso un cambio radical en el funcionamiento del sector eléctrico español y ha sido uno de los modelos que ha permitido a otros países establecer sistemas liberalizados.

NAICS: 22
NAICS Definition: Utilities
Employees: 1,164
Subsidiaries: 0
12-month incidents
1
Known data breaches
0
Attack type number
1

Duke Energy Corporation

525 S Tryon St, Charlotte, North Carolina, 28202, US
Last Update: 2025-12-11
Between 800 and 849

Duke Energy, a Fortune 150 company headquartered in Charlotte, N.C., is one of America’s largest energy holding companies. The company’s electric utilities serve 8.4 million customers in North Carolina, South Carolina, Florida, Indiana, Ohio and Kentucky, and collectively own 54,800 megawatts of energy capacity. Its natural gas utilities serve 1.7 million customers in North Carolina, South Carolina, Tennessee, Ohio and Kentucky. Duke Energy is executing an ambitious clean energy transition, keeping reliability, affordability and accessibility at the forefront as the company works toward net-zero methane emissions from its natural gas business by 2030 and net-zero carbon emissions from electricity generation by 2050. The company is investing in major electric grid upgrades and cleaner generation, including expanded energy storage, renewables, natural gas and nuclear. Our team is available Monday to Friday from 8 a.m. to 5 p.m. EST. If you suspect an emergency, please call 911.

NAICS: 22
NAICS Definition: Utilities
Employees: 24,627
Subsidiaries: 1
12-month incidents
0
Known data breaches
0
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/ree.jpeg
Red Eléctrica
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/duke-energy-corporation.jpeg
Duke Energy Corporation
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Red Eléctrica
100%
Compliance Rate
0/4 Standards Verified
Duke Energy Corporation
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Utilities Industry Average (This Year)

Red Eléctrica has 25.0% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs Utilities Industry Average (This Year)

No incidents recorded for Duke Energy Corporation in 2025.

Incident History — Red Eléctrica (X = Date, Y = Severity)

Red Eléctrica cyber incidents detection timeline including parent company and subsidiaries

Incident History — Duke Energy Corporation (X = Date, Y = Severity)

Duke Energy Corporation cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/ree.jpeg
Red Eléctrica
Incidents

Date Detected: 4/2025
Type:Cyber Attack
Blog: Blog
https://images.rankiteo.com/companyimages/duke-energy-corporation.jpeg
Duke Energy Corporation
Incidents

Date Detected: 10/2024
Type:Cyber Attack
Motivation: Strategic dependencies and potential exploitation
Blog: Blog

FAQ

Duke Energy Corporation company demonstrates a stronger AI Cybersecurity Score compared to Red Eléctrica company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Red Eléctrica and Duke Energy Corporation have experienced a similar number of publicly disclosed cyber incidents.

In the current year, Red Eléctrica company has reported more cyber incidents than Duke Energy Corporation company.

Neither Duke Energy Corporation company nor Red Eléctrica company has reported experiencing a ransomware attack publicly.

Neither Duke Energy Corporation company nor Red Eléctrica company has reported experiencing a data breach publicly.

Both Duke Energy Corporation company and Red Eléctrica company have reported experiencing targeted cyberattacks.

Neither Red Eléctrica company nor Duke Energy Corporation company has reported experiencing or disclosing vulnerabilities publicly.

Neither Red Eléctrica nor Duke Energy Corporation holds any compliance certifications.

Neither company holds any compliance certifications.

Duke Energy Corporation company has more subsidiaries worldwide compared to Red Eléctrica company.

Duke Energy Corporation company employs more people globally than Red Eléctrica company, reflecting its scale as a Utilities.

Neither Red Eléctrica nor Duke Energy Corporation holds SOC 2 Type 1 certification.

Neither Red Eléctrica nor Duke Energy Corporation holds SOC 2 Type 2 certification.

Neither Red Eléctrica nor Duke Energy Corporation holds ISO 27001 certification.

Neither Red Eléctrica nor Duke Energy Corporation holds PCI DSS certification.

Neither Red Eléctrica nor Duke Energy Corporation holds HIPAA certification.

Neither Red Eléctrica nor Duke Energy Corporation holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Risk Information
cvss3
Base: 8.1
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Risk Information
cvss3
Base: 2.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this issue. You should upgrade the affected component. The vendor confirms that this is "[f]ixed in version 4.10.2". Furthermore, that "[b]ackports for older versions in process and will be out as soon as their respective CI pipelines complete."

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Risk Information
cvss3
Base: 4.5
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Risk Information
cvss3
Base: 5.8
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N