Comparison Overview

JCPenney

VS

EXPRESS

JCPenney

6502 Legacy Drive, Plano, 75024, US
Last Update: 2026-04-02
Between 800 and 849

As we reinvent ourselves to fit the diversity of America, we are looking for motivated, talented people who can emerge as Warriors in our organization. JCPenney offers an inclusive environment and culture where you can find and define yourself - your style, your purpose and your career. We know success is built from the inside out, and our associates are the heartbeat of our Company! JCPenney is now part of Catalyst Brands.

NAICS: 43
NAICS Definition: Retail Trade
Employees: 40,106
Subsidiaries: 7
12-month incidents
0
Known data breaches
1
Attack type number
2

EXPRESS

1 Express Drive, Columbus, 43230, US
Last Update: 2026-04-02
Between 750 and 799

EXPRESS is a multichannel fashion brand dedicated to creating confidence and inspiring self-expression. Since its launch in 1980, the brand has embraced a design philosophy rooted in modern, confident and effortless style. Whether dressing for work, everyday or special occasions, EXPRESS ensures you look and feel your best, wherever life takes you. Customers can experience our brand in over 400 Express retail stores, Express Factory Outlet stores and online at www.express.com.

NAICS: 43
NAICS Definition: Retail Trade
Employees: 11,644
Subsidiaries: 2
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/jcpenney.jpeg
JCPenney
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/express-llc.jpeg
EXPRESS
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
JCPenney
100%
Compliance Rate
0/4 Standards Verified
EXPRESS
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Retail Industry Average (This Year)

No incidents recorded for JCPenney in 2026.

Incidents vs Retail Industry Average (This Year)

No incidents recorded for EXPRESS in 2026.

Incident History — JCPenney (X = Date, Y = Severity)

JCPenney cyber incidents detection timeline including parent company and subsidiaries

Incident History — EXPRESS (X = Date, Y = Severity)

EXPRESS cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/jcpenney.jpeg
JCPenney
Incidents

Date Detected: 05/2017
Type:Breach
Blog: Blog

Date Detected: 4/2016
Type:Cyber Attack
Attack Vector: Malicious Software
Blog: Blog

Date Detected: 1/2016
Type:Cyber Attack
Attack Vector: Malware
Blog: Blog
https://images.rankiteo.com/companyimages/express-llc.jpeg
EXPRESS
Incidents

No Incident

FAQ

JCPenney company demonstrates a stronger AI Cybersecurity Score compared to EXPRESS company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

JCPenney company has historically faced a number of disclosed cyber incidents, whereas EXPRESS company has not reported any.

In the current year, EXPRESS company and JCPenney company have not reported any cyber incidents.

Neither EXPRESS company nor JCPenney company has reported experiencing a ransomware attack publicly.

JCPenney company has disclosed at least one data breach, while the other EXPRESS company has not reported such incidents publicly.

JCPenney company has reported targeted cyberattacks, while EXPRESS company has not reported such incidents publicly.

Neither JCPenney company nor EXPRESS company has reported experiencing or disclosing vulnerabilities publicly.

Neither JCPenney nor EXPRESS holds any compliance certifications.

Neither company holds any compliance certifications.

JCPenney company has more subsidiaries worldwide compared to EXPRESS company.

JCPenney company employs more people globally than EXPRESS company, reflecting its scale as a Retail.

Neither JCPenney nor EXPRESS holds SOC 2 Type 1 certification.

Neither JCPenney nor EXPRESS holds SOC 2 Type 2 certification.

Neither JCPenney nor EXPRESS holds ISO 27001 certification.

Neither JCPenney nor EXPRESS holds PCI DSS certification.

Neither JCPenney nor EXPRESS holds HIPAA certification.

Neither JCPenney nor EXPRESS holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X