Comparison Overview

Tietoevry

VS

Diebold Nixdorf

Tietoevry

Helsinki, FI-02101, FI
Last Update: 2026-03-21
Between 700 and 749

In a rapidly changing world, technology is everything. It's in the fabric of society. In every part of every business. At the very heart of human evolution. It’s a great power that comes with great responsibility. At Tietoevry, we believe it’s time to shift perspective. It’s not about what technology can do anymore — but what it should. So that the futures of businesses, societies, and humanity can live and thrive. Side by side. This is why we're making it our business to create purposeful technology that reinvents the world for good. https://www.tietoevry.com/en/ #purposefultechnology #Tietoevry

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 11,643
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
1

Diebold Nixdorf

350 Orchard Ave NE, North Canton, 44720, US
Last Update: 2026-03-21
Between 650 and 699

Diebold Nixdorf automates, digitizes and transforms the way people bank and shop. Its integrated solutions connect digital and physical channels conveniently, securely and efficiently for millions of consumers every day. As an innovation partner for nearly all of the world's top 100 financial institutions and a majority of the top 25 global retailers, Diebold Nixdorf delivers unparalleled services and technology that power the daily operations and consumer experience of financial institutions and retailers around the world.

NAICS: 5415
NAICS Definition: Computer Systems Design and Related Services
Employees: 20,251
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
3

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/tietoevry.jpeg
Tietoevry
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/diebold.jpeg
Diebold Nixdorf
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Tietoevry
100%
Compliance Rate
0/4 Standards Verified
Diebold Nixdorf
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for Tietoevry in 2026.

Incidents vs IT Services and IT Consulting Industry Average (This Year)

No incidents recorded for Diebold Nixdorf in 2026.

Incident History — Tietoevry (X = Date, Y = Severity)

Tietoevry cyber incidents detection timeline including parent company and subsidiaries

Incident History — Diebold Nixdorf (X = Date, Y = Severity)

Diebold Nixdorf cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/tietoevry.jpeg
Tietoevry
Incidents

Date Detected: 02/2021
Type:Ransomware
Blog: Blog
https://images.rankiteo.com/companyimages/diebold.jpeg
Diebold Nixdorf
Incidents

Date Detected: 4/2025
Type:Ransomware
Motivation: Financial gain
Blog: Blog

Date Detected: 8/2024
Type:Vulnerability
Attack Vector: Hard Drive Encryption Bypass
Motivation: Financial Data Breach, Unauthorized Cash Withdrawals
Blog: Blog

Date Detected: 05/2020
Type:Cyber Attack
Blog: Blog

FAQ

Tietoevry company demonstrates a stronger AI Cybersecurity Score compared to Diebold Nixdorf company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Diebold Nixdorf company has faced a higher number of disclosed cyber incidents historically compared to Tietoevry company.

In the current year, Diebold Nixdorf company and Tietoevry company have not reported any cyber incidents.

Both Diebold Nixdorf company and Tietoevry company have confirmed experiencing at least one ransomware attack.

Neither Diebold Nixdorf company nor Tietoevry company has reported experiencing a data breach publicly.

Diebold Nixdorf company has reported targeted cyberattacks, while Tietoevry company has not reported such incidents publicly.

Diebold Nixdorf company has disclosed at least one vulnerability, while Tietoevry company has not reported such incidents publicly.

Neither Tietoevry nor Diebold Nixdorf holds any compliance certifications.

Neither company holds any compliance certifications.

Neither Tietoevry company nor Diebold Nixdorf company has publicly disclosed detailed information about the number of their subsidiaries.

Diebold Nixdorf company employs more people globally than Tietoevry company, reflecting its scale as a IT Services and IT Consulting.

Neither Tietoevry nor Diebold Nixdorf holds SOC 2 Type 1 certification.

Neither Tietoevry nor Diebold Nixdorf holds SOC 2 Type 2 certification.

Neither Tietoevry nor Diebold Nixdorf holds ISO 27001 certification.

Neither Tietoevry nor Diebold Nixdorf holds PCI DSS certification.

Neither Tietoevry nor Diebold Nixdorf holds HIPAA certification.

Neither Tietoevry nor Diebold Nixdorf holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulation of the argument ID can lead to HTML injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible to be carried out remotely.

Risk Information
cvss2
Base: 4.0
Severity: LOW
AV:N/AC:L/Au:S/C:N/I:P/A:N
cvss3
Base: 3.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which generates a valid password reset token for the currently logged-in user viewing the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to craft a malicious pending post that, when previewed by an Administrator, generates a password reset token for the Administrator and exfiltrates it to an attacker-controlled server, leading to full account takeover.

Risk Information
cvss3
Base: 8.0
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Description

LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavior by using integers in places where the code expected a string. This was fixed in v3.3.0. A workaround is available. Users importing keys through a JWK file should not do so from untrusted sources. Use the `jwk2key` tool to check for validity of a JWK file. Likewise, if possible, do not use JWK files with RSA-PSS keys.

Risk Information
cvss4
Base: 5.8
Severity: HIGH
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:A/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25, a prototype pollution vulnerability exists in the `parse_str` function of the npm package locutus. An attacker can pollute `Object.prototype` by overriding `RegExp.prototype.test` and then passing a crafted query string to `parse_str`, bypassing the prototype pollution guard. This vulnerability stems from an incomplete fix for CVE-2026-25521. The CVE-2026-25521 patch replaced the `String.prototype.includes()`-based guard with a `RegExp.prototype.test()`-based guard. However, `RegExp.prototype.test` is itself a writable prototype method that can be overridden, making the new guard bypassable in the same way as the original — trading one hijackable built-in for another. Version 3.0.25 contains an updated fix.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X