Comparison Overview

Coty

VS

The Estée Lauder Companies Inc.

Coty

Buitenveldertselaan 3-5, Amsterdam, 1082, NL
Last Update: 2026-04-03
Between 750 and 799

Since 1904, Coty has fearlessly pioneered innovation across the beauty industry. We have a reputation for breaking new ground; a history of ‘firsts’ and ‘bests’ that has laid the foundation for the industry as we know it today. For over a century, our brands have been empowering people to express themselves and create their own vision of beauty. It’s a legacy we’re proud to own and grow. We work hand-in-hand with our people, our partners and our customers. Together, we unleash every vision of beauty. We stand for the beauty of diversity and the diversity of beauty - celebrating and inspiring all the expressions of beauty that exist and that will exist. We honor you, and we honor our planet. We create Beauty That Lasts. A beauty that is both good to people and the world. Our mission is to create a forward thinking beauty; Products that provide new, innovative and simply better science based solutions. Let’s keep making over the beauty world TOGETHER.

NAICS: 32562
NAICS Definition: Toilet Preparation Manufacturing
Employees: 12,568
Subsidiaries: 0
12-month incidents
0
Known data breaches
1
Attack type number
1

The Estée Lauder Companies Inc.

767 5th Ave, New York, NY, US, 10153
Last Update: 2026-04-04
Between 650 and 699

The Estée Lauder Companies Inc. is one of the world’s leading manufacturers, marketers, and sellers of quality skin care, makeup, fragrance, and hair care products, and is a steward of outstanding luxury and prestige brands globally. The company’s products are sold in approximately 150 countries and territories under brand names including: Estée Lauder, Aramis, Clinique, Lab Series, Origins, M·A·C, La Mer, Bobbi Brown Cosmetics, Aveda, Jo Malone London, Bumble and bumble, Darphin Paris, TOM FORD, Smashbox, AERIN Beauty, Le Labo, Editions de Parfums Frédéric Malle, GLAMGLOW, KILIAN PARIS, Too Faced, Dr.Jart+, the DECIEM family of brands, including The Ordinary and NIOD, and BALMAIN Beauty. To explore our current job openings, go to www.elcompanies.com

NAICS: 32562
NAICS Definition: Toilet Preparation Manufacturing
Employees: 52,420
Subsidiaries: 0
12-month incidents
1
Known data breaches
2
Attack type number
3

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/coty.jpeg
Coty
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/the-estee-lauder-companies-inc.jpeg
The Estée Lauder Companies Inc.
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Coty
100%
Compliance Rate
0/4 Standards Verified
The Estée Lauder Companies Inc.
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Personal Care Product Manufacturing Industry Average (This Year)

No incidents recorded for Coty in 2026.

Incidents vs Personal Care Product Manufacturing Industry Average (This Year)

The Estée Lauder Companies Inc. has 66.67% fewer incidents than the average of same-industry companies with at least one recorded incident.

Incident History — Coty (X = Date, Y = Severity)

Coty cyber incidents detection timeline including parent company and subsidiaries

Incident History — The Estée Lauder Companies Inc. (X = Date, Y = Severity)

The Estée Lauder Companies Inc. cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/coty.jpeg
Coty
Incidents

Date Detected: 1/2018
Type:Breach
Attack Vector: Phishing
Blog: Blog
https://images.rankiteo.com/companyimages/the-estee-lauder-companies-inc.jpeg
The Estée Lauder Companies Inc.
Incidents

Date Detected: 3/2026
Type:Cyber Attack
Blog: Blog

Date Detected: 6/2025
Type:Ransomware
Attack Vector: Zero-Day Exploit (CVE-2025-61882, CVE-2025-21884), Unauthenticated HTTP Requests, Data Exfiltration
Motivation: Financial Gain (Ransomware Extortion)
Blog: Blog

Date Detected: 7/2023
Type:Breach
Attack Vector: Unauthorized Access
Blog: Blog

FAQ

Coty company demonstrates a stronger AI Cybersecurity Score compared to The Estée Lauder Companies Inc. company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

The Estée Lauder Companies Inc. company has faced a higher number of disclosed cyber incidents historically compared to Coty company.

In the current year, The Estée Lauder Companies Inc. company has reported more cyber incidents than Coty company.

The Estée Lauder Companies Inc. company has confirmed experiencing a ransomware attack, while Coty company has not reported such incidents publicly.

Both The Estée Lauder Companies Inc. company and Coty company have disclosed experiencing at least one data breach.

The Estée Lauder Companies Inc. company has reported targeted cyberattacks, while Coty company has not reported such incidents publicly.

Neither Coty company nor The Estée Lauder Companies Inc. company has reported experiencing or disclosing vulnerabilities publicly.

Neither Coty nor The Estée Lauder Companies Inc. holds any compliance certifications.

Neither company holds any compliance certifications.

Neither Coty company nor The Estée Lauder Companies Inc. company has publicly disclosed detailed information about the number of their subsidiaries.

The Estée Lauder Companies Inc. company employs more people globally than Coty company, reflecting its scale as a Personal Care Product Manufacturing.

Neither Coty nor The Estée Lauder Companies Inc. holds SOC 2 Type 1 certification.

Neither Coty nor The Estée Lauder Companies Inc. holds SOC 2 Type 2 certification.

Neither Coty nor The Estée Lauder Companies Inc. holds ISO 27001 certification.

Neither Coty nor The Estée Lauder Companies Inc. holds PCI DSS certification.

Neither Coty nor The Estée Lauder Companies Inc. holds HIPAA certification.

Neither Coty nor The Estée Lauder Companies Inc. holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, two peer-facing consensus request handlers assume that the history index is always available and call blockchain.history_store.history_index().unwrap() directly. That assumption is false by construction. HistoryStoreProxy::history_index() explicitly returns None for the valid HistoryStoreProxy::WithoutIndex state. when a full node is syncing or otherwise running without the history index, a remote peer can send RequestTransactionsProof or RequestTransactionReceiptsByAddress and trigger an Option::unwrap() panic on the request path. This issue has been patched in version 1.3.0.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

PraisonAI is a multi-agent teams system. Prior to version 1.5.95, FileTools.download_file() in praisonaiagents validates the destination path but performs no validation on the url parameter, passing it directly to httpx.stream() with follow_redirects=True. An attacker who controls the URL can reach any host accessible from the server including cloud metadata services and internal network services. This issue has been patched in version 1.5.95.

Risk Information
cvss3
Base: 8.6
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access to all registered tools and agent capabilities. This issue has been patched in version 4.5.97.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any network client can connect, enumerate registered agents, and send arbitrary messages to agents and their tool sets. This issue has been patched in version 4.5.97.

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied string directly as a Python regular expression with no validation, sanitization, or timeout. A crafted regex causes catastrophic backtracking in the re engine, blocking the Python thread for hundreds of seconds and causing a complete service outage. This issue has been patched in version 4.5.90.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H