Comparison Overview

BNP Paribas Fortis

VS

Citizens

BNP Paribas Fortis

Rue Montagne du Parc 3, Brussels, 1000, BE
Last Update: 2026-04-02

For over 200 years, BNP Paribas Fortis has helped drive the growth and prosperity of Belgium’s economy and communities. The mission of our 12,000 colleagues is clear: be the trusted financial partner for four million individual customers, businesses and organisations. We do this by offering advice and solutions via the channels they prefer: digitally, by phone, via video call or in a bank or post office branch.

NAICS: 52211
NAICS Definition: Commercial Banking
Employees: 12,028
Subsidiaries: 28
12-month incidents
0
Known data breaches
0
Attack type number
0

Citizens

1 Citizens Plaza, Providence, 02903, US
Last Update: 2026-03-28
Between 700 and 749

At Citizens, we recognize that the journey to accomplishment is no longer linear and that individuals are made of all they have done and all they are going to do. As one of the oldest and largest financial services firms in the United States with a history dating back to 1828, we’re committed to providing solutions and expertise that support our customers, clients, colleagues, and communities in what’s next on their own unique journey. Whether you’re considering banking with us or looking to work with us, you’ll find a customer-centric culture and a supportive, collaborative workforce at Citizens. You’re made ready and so are we. #MadeReady

NAICS: 52211
NAICS Definition: Commercial Banking
Employees: 22,844
Subsidiaries: 4
12-month incidents
0
Known data breaches
1
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/bnpparibasfortis.jpeg
BNP Paribas Fortis
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/citizens-bank.jpeg
Citizens
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
BNP Paribas Fortis
100%
Compliance Rate
0/4 Standards Verified
Citizens
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Banking Industry Average (This Year)

No incidents recorded for BNP Paribas Fortis in 2026.

Incidents vs Banking Industry Average (This Year)

No incidents recorded for Citizens in 2026.

Incident History — BNP Paribas Fortis (X = Date, Y = Severity)

BNP Paribas Fortis cyber incidents detection timeline including parent company and subsidiaries

Incident History — Citizens (X = Date, Y = Severity)

Citizens cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/bnpparibasfortis.jpeg
BNP Paribas Fortis
Incidents

No Incident

https://images.rankiteo.com/companyimages/citizens-bank.jpeg
Citizens
Incidents

Date Detected: 1/2024
Type:Breach
Blog: Blog

FAQ

BNP Paribas Fortis company demonstrates a stronger AI Cybersecurity Score compared to Citizens company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Citizens company has historically faced a number of disclosed cyber incidents, whereas BNP Paribas Fortis company has not reported any.

In the current year, Citizens company and BNP Paribas Fortis company have not reported any cyber incidents.

Neither Citizens company nor BNP Paribas Fortis company has reported experiencing a ransomware attack publicly.

Citizens company has disclosed at least one data breach, while BNP Paribas Fortis company has not reported such incidents publicly.

Neither Citizens company nor BNP Paribas Fortis company has reported experiencing targeted cyberattacks publicly.

Neither BNP Paribas Fortis company nor Citizens company has reported experiencing or disclosing vulnerabilities publicly.

Neither BNP Paribas Fortis nor Citizens holds any compliance certifications.

Neither company holds any compliance certifications.

BNP Paribas Fortis company has more subsidiaries worldwide compared to Citizens company.

Citizens company employs more people globally than BNP Paribas Fortis company, reflecting its scale as a Banking.

Neither BNP Paribas Fortis nor Citizens holds SOC 2 Type 1 certification.

Neither BNP Paribas Fortis nor Citizens holds SOC 2 Type 2 certification.

Neither BNP Paribas Fortis nor Citizens holds ISO 27001 certification.

Neither BNP Paribas Fortis nor Citizens holds PCI DSS certification.

Neither BNP Paribas Fortis nor Citizens holds HIPAA certification.

Neither BNP Paribas Fortis nor Citizens holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X