Company Details
thoughtworks
11,241
650,966
None
thoughtworks.com
0
THO_9968339
In-progress

Thoughtworks Company CyberSecurity Posture
thoughtworks.comThoughtworks is a pioneering global technology consultancy, leading the charge in custom software development and technology innovation. We empower ambitious businesses to thrive in a constantly evolving world. We integrate the best of strategy, design, and software engineering to provide our clients with the foundations they need to excel. Our 30+ years of hands-on experience enables us to help our clients navigate change effectively, harness the power of data and AI to unlock new sources of value, and create adaptable technology platforms that align seamlessly with their business objectives. We are a team of 10,500 talented Thoughtworkers across 19 countries. Here, computer science grads come together with seasoned technologists, self-taught developers, midlife career changers and more to learn from and challenge each other. Career journeys flourish with the strength of our cultivation culture, which has won awards around the world.
Company Details
thoughtworks
11,241
650,966
None
thoughtworks.com
0
THO_9968339
In-progress
Between 750 and 799

Thoughtworks Global Score (TPRM)XXXX



No incidents recorded for Thoughtworks in 2025.
No incidents recorded for Thoughtworks in 2025.
No incidents recorded for Thoughtworks in 2025.
Thoughtworks cyber incidents detection timeline including parent company and subsidiaries

Thoughtworks is a pioneering global technology consultancy, leading the charge in custom software development and technology innovation. We empower ambitious businesses to thrive in a constantly evolving world. We integrate the best of strategy, design, and software engineering to provide our clients with the foundations they need to excel. Our 30+ years of hands-on experience enables us to help our clients navigate change effectively, harness the power of data and AI to unlock new sources of value, and create adaptable technology platforms that align seamlessly with their business objectives. We are a team of 10,500 talented Thoughtworkers across 19 countries. Here, computer science grads come together with seasoned technologists, self-taught developers, midlife career changers and more to learn from and challenge each other. Career journeys flourish with the strength of our cultivation culture, which has won awards around the world.

Exela is a business process automation (BPA) leader, leveraging a global footprint and proprietary technology to provide digital transformation solutions enhancing quality, productivity, and end-user experience. With decades of expertise operating mission-critical processes, Exela serves a growing
AKKA is a European leader in engineering consulting and R&D services. Our comprehensive portfolio of digital solutions combined with our expertise in engineering, uniquely positions us to support our clients by leveraging the power of connected data to accelerate innovation and drive the future of s

A Fujitsu é a companhia líder japonesa de tecnologias de informação e comunicação (TIC) disponibilizando um leque completo de produtos tecnológicos, soluções e serviços. Cerca de 132.000 colaboradores da Fujitsu prestam suporte a clientes em mais de 100 países. Utilizamos a nossa experiência e o pod

Computacenter is a leading independent technology and services provider, trusted by large corporate and public sector organisations. We are a responsible business that believes in winning together for our people and our planet. We help our customers to Source, Transform and Manage their technol

We are at the forefront of digital transformation in the Americas, positively impacting the lives of over 500 million people. As a key player in emerging industries, we drive innovation and change through ambitious modernization projects and cutting-edge solutions. By understanding the region's chal

In a world undergoing constant change, VINCI Energies contributes to the environmental transition by helping bring about major trends in the digital landscape and energy sector. VINCI Energies’ teams roll out technologies and integrate customised multi-technical solutions, from design to implement
.png)
A complete list of all the known layoffs in tech, from Big Tech to startups, broken down by month throughout 2024 and 2025.
A groundbreaking AI-controlled cyber espionage incident, revealed by Anthropic, signals a major shift in cybersecurity landscapes.
Award recognizes Thoughtworks Global CISO's leadership in the mid-cap category of organizations with less than $4B in revenue.
US-based global technology consultancy firm Thoughtworks has seen a rise in its customer base seeking advice on how to implement AI...
In this Help Net Security interview, Thomas Squeo, CTO for the Americas at Thoughtworks, discusses why traditional security architectures...
As more artificial intelligence (AI) and large language models pop up in the market, including open source alternatives, organisations will...
As the cyber security landscape has become increasingly complex, Check Point's UK partners have helped customers navigate the challenges of...
Ecuador's tech scene is booming in 2025, with internet access reaching 60% nationwide and significant growth in AI, cloud computing,...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Thoughtworks is http://www.thoughtworks.com.
According to Rankiteo, Thoughtworks’s AI-generated cybersecurity score is 790, reflecting their Fair security posture.
According to Rankiteo, Thoughtworks currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Thoughtworks is not certified under SOC 2 Type 1.
According to Rankiteo, Thoughtworks does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Thoughtworks is not listed as GDPR compliant.
According to Rankiteo, Thoughtworks does not currently maintain PCI DSS compliance.
According to Rankiteo, Thoughtworks is not compliant with HIPAA regulations.
According to Rankiteo,Thoughtworks is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Thoughtworks operates primarily in the Information Technology & Services industry.
Thoughtworks employs approximately 11,241 people worldwide.
Thoughtworks presently has no subsidiaries across any sectors.
Thoughtworks’s official LinkedIn profile has approximately 650,966 followers.
Thoughtworks is classified under the NAICS code None, which corresponds to Others.
Yes, Thoughtworks has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/thoughtworks.
Yes, Thoughtworks maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/thoughtworks.
As of December 01, 2025, Rankiteo reports that Thoughtworks has not experienced any cybersecurity incidents.
Thoughtworks has an estimated 10,071 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, Thoughtworks has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipulation of the argument First Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.
By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the default configuration of this MCP server at the affected version (as of commit 2f3a5512 in September of 2025).
A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
A security flaw has been discovered in Qualitor 8.20/8.24. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing manipulation of the argument passageiros results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.