Company Details
almaviva-group
51,293
145,169
5415
almaviva.it
0
ALM_2225197
In-progress


AlmavivA Group Vendor Cyber Rating & Cyber Score
almaviva.itAlmaviva is the Italian digital innovation group that supports the country’s growth by helping enterprises meet the challenges of staying competitive in the digital age. The Group helps organizations transform their business models, operational structures, corporate culture, and ICT systems. Building on strong Made in Italy expertise, the Almaviva Group has developed a global network of 41,000 professionals, 30 companies, and 80 offices worldwide, with a significant presence in Latin America (Brazil, Colombia, and the Dominican Republic), as well as in the United States, Belgium, Spain, Finland, Saudi Arabia, the United Arab Emirates, Egypt, and Tunisia.
Company Details
almaviva-group
51,293
145,169
5415
almaviva.it
0
ALM_2225197
In-progress
Between 750 and 799

AlmavivA Group Global Score (TPRM)XXXX



No incidents recorded for AlmavivA Group in 2026.
No incidents recorded for AlmavivA Group in 2026.
No incidents recorded for AlmavivA Group in 2026.
AlmavivA Group cyber incidents detection timeline including parent company and subsidiaries

Almaviva is the Italian digital innovation group that supports the country’s growth by helping enterprises meet the challenges of staying competitive in the digital age. The Group helps organizations transform their business models, operational structures, corporate culture, and ICT systems. Building on strong Made in Italy expertise, the Almaviva Group has developed a global network of 41,000 professionals, 30 companies, and 80 offices worldwide, with a significant presence in Latin America (Brazil, Colombia, and the Dominican Republic), as well as in the United States, Belgium, Spain, Finland, Saudi Arabia, the United Arab Emirates, Egypt, and Tunisia.


At Ricoh, we bring people, processes, and technology together to make information work for you. We unlock the power of information so organizations can unlock the full potential of their people. We're a leader in information management and digital services, creating competitive advantage for over 1.

Tata Elxsi is amongst the world’s leading providers of design and technology services across industries, including Automotive, Media & Entertainment, Communications, and Healthcare. Tata Elxsi is helping customers reimagine their products and services through design thinking and the application of d

TELUS Digital crafts unique and enduring experiences for customers and employees, and creates future-focused digital transformations that stand the test of time. We are the brand behind the brands. Our global team members are both passionate ambassadors of our clients’ products and services, and vis

Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialized skills across more than 40 industries, we offer Strategy and Consulting, Interactive, Technology and Operations services — all powered by the w

NTT DATA, Inc. is a trusted global innovator of business and technology services. We're committed to helping clients innovate, optimize and transform for long-term success. Our R&D investments help organizations and society move confidently and sustainably into the digital future. As a Global Top Em

At Orange Business, our ambition is to become the leading european Network and Digital Integrator by leveraging our proven expertise in next-generation connectivity solutions, the cloud and cybersecurity. Our 30,000 women and men are present in 65 countries, where every voice counts. Together, we a

Unisys is a global technology solutions company that powers breakthroughs for the world’s leading organizations. Our solutions – cloud, AI, digital workplace, logistics and enterprise computing – help our clients challenge the status quo and unlock their full potential. To learn how we have been hel

Apex Systems is a leading global technology services firm that incorporates industry insights and experience to deliver solutions that fulfill our clients’ digital visions. We offer a continuum of services, specializing in strategy, transformation, and managed services across application development

We get you. You want more out of a career. A place to share your ideas freely — even if they’re daring or different. Where the true you can learn, grow, and thrive. You’ll find all that here. Because we empower you. We power and empower how people live, work and play by connecting them to what bri
.png)
Eviden and Almaviva join Forces to Secure Deployments of Cooperative Intelligent Transport Systems in Italy....
A security incident at IT provider Almaviva resulted in the compromise of sensitive information tied to Italy's national railway operator,...
Ferrovie dello Stato Italiane (FS) data leaked after a breach at IT provider Almaviva. A hacker claims the theft of 2.3 TB of sensitive...
Italian state-owned railway operator FS Italiane Group had 2.3 TB of data pilfered and exposed following a purported attack against its...
Data from Italy's national railway operator, the FS Italiane Group, has been exposed after a threat actor breached the organization's IT...
Iteris, Inc. announced it has acquired ThruGreen's technology, enhancing their position as the leading provider of comprehensive traffic...
The group is at the helm of Q-Arm with ten partners from seven European countries.
Italian company Almaviva, which operates in digital services and customer relationship management, has acquired 100% of Brazilian technology firm Tivit.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of AlmavivA Group is http://www.almaviva.it.
According to Rankiteo, AlmavivA Group’s AI-generated cybersecurity score is 785, reflecting their Fair security posture.
According to Rankiteo, AlmavivA Group currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, AlmavivA Group has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, AlmavivA Group is not certified under SOC 2 Type 1.
According to Rankiteo, AlmavivA Group does not hold a SOC 2 Type 2 certification.
According to Rankiteo, AlmavivA Group is not listed as GDPR compliant.
According to Rankiteo, AlmavivA Group does not currently maintain PCI DSS compliance.
According to Rankiteo, AlmavivA Group is not compliant with HIPAA regulations.
According to Rankiteo,AlmavivA Group is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
AlmavivA Group operates primarily in the IT Services and IT Consulting industry.
AlmavivA Group employs approximately 51,293 people worldwide.
AlmavivA Group presently has no subsidiaries across any sectors.
AlmavivA Group’s official LinkedIn profile has approximately 145,169 followers.
AlmavivA Group is classified under the NAICS code 5415, which corresponds to Computer Systems Design and Related Services.
No, AlmavivA Group does not have a profile on Crunchbase.
Yes, AlmavivA Group maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/almaviva-group.
As of March 28, 2026, Rankiteo reports that AlmavivA Group has not experienced any cybersecurity incidents.
AlmavivA Group has an estimated 39,816 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, AlmavivA Group has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulation of the argument ID can lead to HTML injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible to be carried out remotely.
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid password reset token for the currently logged-in user viewing the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to craft a malicious pending post that, when previewed by an Administrator, generates a password reset token for the Administrator and exfiltrates it to an attacker-controlled server, leading to full account takeover.
LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the `jwk2key` tool to check for validity of a JWK file. Likewise, if possible, do not use JWK files with RSA-PSS keys.
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25, a prototype pollution vulnerability exists in the `parse_str` function of the npm package locutus. An attacker can pollute `Object.prototype` by overriding `RegExp.prototype.test` and then passing a crafted query string to `parse_str`, bypassing the prototype pollution guard. This vulnerability stems from an incomplete fix for CVE-2026-25521. The CVE-2026-25521 patch replaced the `String.prototype.includes()`-based guard with a `RegExp.prototype.test()`-based guard. However, `RegExp.prototype.test` is itself a writable prototype method that can be overridden, making the new guard bypassable in the same way as the original — trading one hijackable built-in for another. Version 3.0.25 contains an updated fix.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.