Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...

The Rankiteo MCP server is now available.

Discover MCP
!

Top 25 Worst Companies in Sri Lanka

Identify the lowest-scoring most renowned companies in Sri Lanka. Understand where critical cyber risk exposure exists in this country. 32 companies scored.

110
Companies in Sri Lanka
32
Scored
764.4
Avg Score
0
Cyber Incidents
Bottom 25
Shown

Sri Lanka Cybersecurity Risk Assessment - Lowest-Scoring Companies in 2026

Out of 110 companies in Sri Lanka monitored by Rankiteo, this page highlights the Bottom 25 organizations with the weakest cybersecurity posture. These rankings are based on our proprietary Cyber Resilience Score, which integrates time-decayed incident exposure, sector-sensitive impact analysis, and market-cap-aware baseline and dampening to produce a single, interpretable score between 100 and 1,000.

Companies at the bottom of this ranking carry the heaviest accumulated cyber incident burden - including recent or severe ransomware attacks, data breaches with significant financial losses or records exposed, and repeated disclosure events. Understanding where these risk concentrations exist is essential for supply chain risk management, regulatory compliance, and competitive benchmarking within Sri Lanka.

The current average score for the most notable companies in Sri Lanka is 764.4 out of 1,000. Companies shown below score significantly lower than this average, falling far behind a country that generally maintains reasonable security standards.

Risk Highlights

768
Lowest Score
764.4
Country Average
0%
Scoring B or Below
0
Recorded Incidents

Score Distribution

Aaa
0 (0.0%)
Aa
0 (0.0%)
A
1 (3.1%)
Baa
31 (96.9%)
Ba
0 (0.0%)
B
0 (0.0%)
Caa
0 (0.0%)
Ca
0 (0.0%)
C
0 (0.0%)
#CompanyLabelScoreBandIncidentsScore Bar
1
Sunshine Holdings PLCsunshineholdings.lk
Other Financial Investment Activities750Baa0
2
EFL 3PL Globalefl3pl.global
Transportation and Warehousing751Baa0
3
LSEG Technologylseg.com
Computer Systems Design and Related Services752Baa0
4
AODaod.lk
-754Baa0
5
Surge Globalsurge.global
Management, Scientific, and Technical Consulting Services754Baa0
6
Tech One Global Ltdtechoneglobal.com
Computer Systems Design and Related Services754Baa0
7
Emapta Sri Lankaemapta.com
Others755Baa0
8
Twinery - Innovations by MAStwinery.co
-755Baa0
9
Airport & Aviation Services Sri Lankaairport.lk
-756Baa0
10
Hayleys Agriculture Holdings Limitedhayleysagriculture.com
Crop Production756Baa0
11
KAYJAY-Groupkayjay-group.com
-756Baa0
12
HNB Assurance PLChnbassurance.com
Insurance Carriers and Related Activities757Baa0
13
Sri Lanka Railwaysrailway.gov.lk
-757Baa0
14
Linea Aquamasholdings.com
Apparel Manufacturing758Baa0
15
MAS Kreedamasholdings.com
Apparel Manufacturing759Baa0
16
Sri Lanka Tourismsrilanka.travel
Travel Arrangement and Reservation Services760Baa0
17
Virtusa Sri Lankavirtusa.com
Computer Systems Design and Related Services761Baa0
18
Singer Sri Lanka PLCsingersl.com
-762Baa0
19
DFCC Bankdfcc.lk
-763Baa0
20
LOLC Holdings PLClolc.com
Finance and Insurance764Baa0
21
KPMG Sri Lankahome.kpmg
Management, Scientific, and Technical Consulting Services765Baa0
22
Lion Brewery (Ceylon) PLClionbeer.com
Food Services and Drinking Places766Baa0
23
Asiri Healthasirihealth.com
Health Care and Social Assistance767Baa0
24
Bank of Ceylonboc.lk
Commercial Banking767Baa0
25
MAS Activemasholdings.com
Clothing and Clothing Accessories Stores768Baa0

How Cyber Risk Scores Are Calculated

Rankiteo's Cyber Resilience Score produces a single value between 100 and 1,000 for each organization, where higher scores indicate lower estimated cyber risk. The framework integrates three principal components that together balance evidence, context, and comparability across industries and company sizes. Learn more in our AI Cyber Score methodology.

Understanding the Risk Bands

Each score maps to a letter-grade band. Companies appearing in this lowest-scoring ranking typically fall in the bottom bands:

  • Aaa (900-1,000): Exceptional cyber resilience - very few companies in a worst list reach this level.
  • Aa (800-899): Very strong security posture with minimal weaknesses.
  • A (700-799): Strong practices with some areas for improvement.
  • Baa (600-699): Adequate protection but notable security configuration gaps exist.
  • Ba (500-599): Below average - multiple risk areas require attention.
  • B (400-499): Weak security with significant exposure across categories.
  • Caa (300-399): Very weak with a high probability of exploitable vulnerabilities.
  • Ca (200-299): Critically poor with severe, widespread security gaps.
  • C (0-199): Extreme risk - immediate remediation is needed across all dimensions.

Why Monitoring Low-Scoring Companies in Sri Lanka Matters

Cybersecurity risk doesn't exist in isolation. If your organization works with, purchases from, or shares data with companies in Sri Lanka, their security weaknesses become your risk. Supply chain attacks - where adversaries compromise a less-secure vendor to reach a larger target - have become one of the most common and damaging attack vectors in recent years.

Rankiteo continuously monitors 110 companies in Sri Lanka, keeping these rankings up to date so you always have an accurate, current picture of the country's risk landscape.

Top 25 Worst Companies in Sri Lanka by Cybersecurity Score (2026) | Rankiteo | Rankiteo