Comparison Overview

AlmavivA Group

VS

TELUS Digital

AlmavivA Group

Via di Casal Boccone, 188-190, Roma, IT, 00137
Last Update: 2026-03-22
Between 750 and 799

Almaviva is the Italian digital innovation group that supports the country’s growth by helping enterprises meet the challenges of staying competitive in the digital age. The Group helps organizations transform their business models, operational structures, corporate culture, and ICT systems. Building on strong Made in Italy expertise, the Almaviva Group has developed a global network of 41,000 professionals, 30 companies, and 80 offices worldwide, with a significant presence in Latin America (Brazil, Colombia, and the Dominican Republic), as well as in the United States, Belgium, Spain, Finland, Saudi Arabia, the United Arab Emirates, Egypt, and Tunisia.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 51,293
Subsidiaries: 15
12-month incidents
0
Known data breaches
0
Attack type number
0

TELUS Digital

510 West Georgia Street, Vancouver, V6B 0M3, CA
Last Update: 2026-03-25

TELUS Digital crafts unique and enduring experiences for customers and employees, and creates future-focused digital transformations that stand the test of time. We are the brand behind the brands. Our global team members are both passionate ambassadors of our clients’ products and services, and visionary technology experts resolute in our pursuit to elevate their end customer journeys, solve business challenges, mitigate risks, and drive continuous innovation. Our portfolio of end-to-end, integrated capabilities include digital IT services, such as cloud solutions and AI-fueled automation, trust and safety services, AI data solutions, including expertise in computer vision, and front-end digital design and consulting services. Fuel iX™ is TELUS Digital’s proprietary GenAI engine at the heart of our innovation, helping enterprises advance their GenAI pilots to working prototypes and production at scale, quickly, securely and responsibly across multiple environments, applications and clouds. Powered by purpose, TELUS Digital leverages technology, human ingenuity and compassion to fuel remarkable outcomes and create inclusive, thriving communities in the regions where we operate around the world. Guided by our Humanity-in-the-loop principles, we take a responsible approach to the transformational technologies we develop and deploy by proactively considering and addressing the broader impacts of our work.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 39,811
Subsidiaries: 16
12-month incidents
2
Known data breaches
3
Attack type number
2

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/almaviva-group.jpeg
AlmavivA Group
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/telus-digital.jpeg
TELUS Digital
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
AlmavivA Group
100%
Compliance Rate
0/4 Standards Verified
TELUS Digital
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for AlmavivA Group in 2026.

Incidents vs IT Services and IT Consulting Industry Average (This Year)

TELUS Digital has 19.76% more incidents than the average of same-industry companies with at least one recorded incident.

Incident History — AlmavivA Group (X = Date, Y = Severity)

AlmavivA Group cyber incidents detection timeline including parent company and subsidiaries

Incident History — TELUS Digital (X = Date, Y = Severity)

TELUS Digital cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/almaviva-group.jpeg
AlmavivA Group
Incidents

No Incident

https://images.rankiteo.com/companyimages/telus-digital.jpeg
TELUS Digital
Incidents

Date Detected: 3/2026
Type:Cyber Attack
Blog: Blog

Date Detected: 2/2026
Type:Breach
Attack Vector: Compromised credentials (Google Cloud Platform)
Motivation: Extortion, data theft for resale on dark web
Blog: Blog

Date Detected: 7/2025
Type:Breach
Attack Vector: Compromised Okta SSO account via malware on a support agent's device
Motivation: Extortion (ransom demand of $5 million)
Blog: Blog

FAQ

AlmavivA Group company demonstrates a stronger AI Cybersecurity Score compared to TELUS Digital company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

TELUS Digital company has historically faced a number of disclosed cyber incidents, whereas AlmavivA Group company has not reported any.

In the current year, TELUS Digital company has reported more cyber incidents than AlmavivA Group company.

Neither TELUS Digital company nor AlmavivA Group company has reported experiencing a ransomware attack publicly.

TELUS Digital company has disclosed at least one data breach, while AlmavivA Group company has not reported such incidents publicly.

TELUS Digital company has reported targeted cyberattacks, while AlmavivA Group company has not reported such incidents publicly.

Neither AlmavivA Group company nor TELUS Digital company has reported experiencing or disclosing vulnerabilities publicly.

Neither AlmavivA Group nor TELUS Digital holds any compliance certifications.

Neither company holds any compliance certifications.

TELUS Digital company has more subsidiaries worldwide compared to AlmavivA Group company.

AlmavivA Group company employs more people globally than TELUS Digital company, reflecting its scale as a IT Services and IT Consulting.

Neither AlmavivA Group nor TELUS Digital holds SOC 2 Type 1 certification.

Neither AlmavivA Group nor TELUS Digital holds SOC 2 Type 2 certification.

Neither AlmavivA Group nor TELUS Digital holds ISO 27001 certification.

Neither AlmavivA Group nor TELUS Digital holds PCI DSS certification.

Neither AlmavivA Group nor TELUS Digital holds HIPAA certification.

Neither AlmavivA Group nor TELUS Digital holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulation of the argument ID can lead to HTML injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible to be carried out remotely.

Risk Information
cvss2
Base: 4.0
Severity: LOW
AV:N/AC:L/Au:S/C:N/I:P/A:N
cvss3
Base: 3.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid password reset token for the currently logged-in user viewing the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to craft a malicious pending post that, when previewed by an Administrator, generates a password reset token for the Administrator and exfiltrates it to an attacker-controlled server, leading to full account takeover.

Risk Information
cvss3
Base: 8.0
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Description

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the `jwk2key` tool to check for validity of a JWK file. Likewise, if possible, do not use JWK files with RSA-PSS keys.

Risk Information
cvss4
Base: 5.8
Severity: HIGH
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25, a prototype pollution vulnerability exists in the `parse_str` function of the npm package locutus. An attacker can pollute `Object.prototype` by overriding `RegExp.prototype.test` and then passing a crafted query string to `parse_str`, bypassing the prototype pollution guard. This vulnerability stems from an incomplete fix for CVE-2026-25521. The CVE-2026-25521 patch replaced the `String.prototype.includes()`-based guard with a `RegExp.prototype.test()`-based guard. However, `RegExp.prototype.test` is itself a writable prototype method that can be overridden, making the new guard bypassable in the same way as the original — trading one hijackable built-in for another. Version 3.0.25 contains an updated fix.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X