Comparison Overview

Johnson Controls

VS

Wärtsilä

Johnson Controls

Milwaukee, Cork, Ireland, IE, T12 X8N6
Last Update: 2026-04-01

At Johnson Controls, we transform the environments where people live, work, learn and play. As the global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Building on a proud history of 140 years of innovation, we deliver the blueprint of the future for industries such as healthcare, schools, data centers, airports, stadiums, manufacturing and beyond through OpenBlue, our comprehensive digital offering. Today, Johnson Controls offers the world`s largest portfolio of building technology and software as well as service solutions from some of the most trusted names in the industry. Visit www.johnsoncontrols.com for more information.

NAICS: 3332
NAICS Definition: Industrial Machinery Manufacturing
Employees: 60,211
Subsidiaries: 17
12-month incidents
0
Known data breaches
0
Attack type number
2

Wärtsilä

Hiililaiturinkuja 2, Helsinki, 00180, FI
Last Update: 2026-04-01
Between 750 and 799

We enable sustainable societies through innovation in technology and services together with all our stakeholders – today and tomorrow. We emphasise innovation in sustainable technology and services to help our customers continuously improve environmental and economic performance. We work together with our strong ecosystem of partners every day, providing a wide portfolio of leading technologies and innovative solutions that offer our customers superior uptime, reliability and foreseeable lifecycle costs across their operations. Our global passionate team of 17,500 energy and maritime experts in 200 locations in more than 70 countries is committed to shaping decarbonisation transformation of our industries across the globe.

NAICS: 3332
NAICS Definition: Industrial Machinery Manufacturing
Employees: 16,129
Subsidiaries: 4
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/johnson-controls.jpeg
Johnson Controls
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/wartsila.jpeg
Wärtsilä
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Johnson Controls
100%
Compliance Rate
0/4 Standards Verified
Wärtsilä
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Industrial Machinery Manufacturing Industry Average (This Year)

No incidents recorded for Johnson Controls in 2026.

Incidents vs Industrial Machinery Manufacturing Industry Average (This Year)

No incidents recorded for Wärtsilä in 2026.

Incident History — Johnson Controls (X = Date, Y = Severity)

Johnson Controls cyber incidents detection timeline including parent company and subsidiaries

Incident History — Wärtsilä (X = Date, Y = Severity)

Wärtsilä cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/johnson-controls.jpeg
Johnson Controls
Incidents

Date Detected: 6/2025
Type:Vulnerability
Attack Vector: Publicly Accessible Devices, Default Credentials, Unpatched Software Vulnerabilities, Lack of Firewalls/Encryption
Blog: Blog

Date Detected: 09/2023
Type:Ransomware
Motivation: Financial Gain
Blog: Blog
https://images.rankiteo.com/companyimages/wartsila.jpeg
Wärtsilä
Incidents

No Incident

FAQ

Wärtsilä company demonstrates a stronger AI Cybersecurity Score compared to Johnson Controls company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Johnson Controls company has historically faced a number of disclosed cyber incidents, whereas Wärtsilä company has not reported any.

In the current year, Wärtsilä company and Johnson Controls company have not reported any cyber incidents.

Johnson Controls company has confirmed experiencing a ransomware attack, while Wärtsilä company has not reported such incidents publicly.

Neither Wärtsilä company nor Johnson Controls company has reported experiencing a data breach publicly.

Neither Wärtsilä company nor Johnson Controls company has reported experiencing targeted cyberattacks publicly.

Johnson Controls company has disclosed at least one vulnerability, while Wärtsilä company has not reported such incidents publicly.

Neither Johnson Controls nor Wärtsilä holds any compliance certifications.

Neither company holds any compliance certifications.

Johnson Controls company has more subsidiaries worldwide compared to Wärtsilä company.

Johnson Controls company employs more people globally than Wärtsilä company, reflecting its scale as a Industrial Machinery Manufacturing.

Neither Johnson Controls nor Wärtsilä holds SOC 2 Type 1 certification.

Neither Johnson Controls nor Wärtsilä holds SOC 2 Type 2 certification.

Neither Johnson Controls nor Wärtsilä holds ISO 27001 certification.

Neither Johnson Controls nor Wärtsilä holds PCI DSS certification.

Neither Johnson Controls nor Wärtsilä holds HIPAA certification.

Neither Johnson Controls nor Wärtsilä holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

Description

XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services

Description

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.

Description

A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.