Comparison Overview

Brown Box Theatre Project

VS

Lyric Theatre

Brown Box Theatre Project

10647 Griffin Rd, Berlin, MD, 21811, US
Last Update: 2025-12-11

We, at Brown Box, believe that all people deserve easy access to the arts and the community benefits that they foster. Brown Box Theatre Project’s mission is to break down barriers that separate the masses from live theatre by bringing the very best in performance, design, and collaboration to unconventional venues and underserved destinations to reach the widest audience possible. Brown Box Theatre Project creates high-quality theatre and delivers our work directly to communities to expand the reach of impactful, professional performing arts. We implement a bold approach to our productions that connects audiences and artists through vibrant and enlightening experiences to transform the way theatre is created and consumed.

NAICS: 711
NAICS Definition:
Employees: 3
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Lyric Theatre

214 W 43rd St, New York, New York, US, 10036
Last Update: 2025-12-09

Built over the foundations of the original Lyric (1903; 1,261 seats) and Apollo (1920; 1,194 seats) Theatres, today’s Lyric Theatre combines architectural preservation with state-of-the-art construction and technology. The spirit and character of New York’s grandest historic theatres have been maintained and united with the technical amenities of a modern facility. The Lyric Theatre underwent a complete redesign and transformation for the North American premiere of Harry Potter and the Cursed Child, which opened on April 22, 2018 and has since called the Lyric its Broadway home.

NAICS: 7111
NAICS Definition: Performing Arts Companies
Employees: None
Subsidiaries: 37
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/brown-box-theatre-project.jpeg
Brown Box Theatre Project
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/lyricbroadway.jpeg
Lyric Theatre
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Brown Box Theatre Project
100%
Compliance Rate
0/4 Standards Verified
Lyric Theatre
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Performing Arts Industry Average (This Year)

No incidents recorded for Brown Box Theatre Project in 2025.

Incidents vs Performing Arts Industry Average (This Year)

No incidents recorded for Lyric Theatre in 2025.

Incident History — Brown Box Theatre Project (X = Date, Y = Severity)

Brown Box Theatre Project cyber incidents detection timeline including parent company and subsidiaries

Incident History — Lyric Theatre (X = Date, Y = Severity)

Lyric Theatre cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/brown-box-theatre-project.jpeg
Brown Box Theatre Project
Incidents

No Incident

https://images.rankiteo.com/companyimages/lyricbroadway.jpeg
Lyric Theatre
Incidents

No Incident

FAQ

Brown Box Theatre Project company demonstrates a stronger AI Cybersecurity Score compared to Lyric Theatre company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, Lyric Theatre company has disclosed a higher number of cyber incidents compared to Brown Box Theatre Project company.

In the current year, Lyric Theatre company and Brown Box Theatre Project company have not reported any cyber incidents.

Neither Lyric Theatre company nor Brown Box Theatre Project company has reported experiencing a ransomware attack publicly.

Neither Lyric Theatre company nor Brown Box Theatre Project company has reported experiencing a data breach publicly.

Neither Lyric Theatre company nor Brown Box Theatre Project company has reported experiencing targeted cyberattacks publicly.

Neither Brown Box Theatre Project company nor Lyric Theatre company has reported experiencing or disclosing vulnerabilities publicly.

Neither Brown Box Theatre Project nor Lyric Theatre holds any compliance certifications.

Neither company holds any compliance certifications.

Lyric Theatre company has more subsidiaries worldwide compared to Brown Box Theatre Project company.

Neither Brown Box Theatre Project nor Lyric Theatre holds SOC 2 Type 1 certification.

Neither Brown Box Theatre Project nor Lyric Theatre holds SOC 2 Type 2 certification.

Neither Brown Box Theatre Project nor Lyric Theatre holds ISO 27001 certification.

Neither Brown Box Theatre Project nor Lyric Theatre holds PCI DSS certification.

Neither Brown Box Theatre Project nor Lyric Theatre holds HIPAA certification.

Neither Brown Box Theatre Project nor Lyric Theatre holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Risk Information
cvss3
Base: 8.1
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Risk Information
cvss3
Base: 2.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this issue. You should upgrade the affected component. The vendor confirms that this is "[f]ixed in version 4.10.2". Furthermore, that "[b]ackports for older versions in process and will be out as soon as their respective CI pipelines complete."

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Risk Information
cvss3
Base: 4.5
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Risk Information
cvss3
Base: 5.8
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N