Comparison Overview

Caltrans

VS

State of Michigan

Caltrans

1120 N Street, None, Sacramento, CA, US, 95814
Last Update: 2025-12-09
Between 750 and 799

From roads less traveled to highways supporting California’s demanding commute. The California Department of Transportation (Caltrans) manages more than 50,000 miles of California's highway and freeway lanes, provides inter-city rail services, permits more than 400 public-use airports and special-use hospital heliports, and works with local agencies to keep California moving. More than the road workers, we are California’s transportation infrastructure; established in 1895, Caltrans has been active in moving the people and commerce of California and continues to model the way in innovative transportation systems. Caltrans specializes in many areas related to transportation: Engineering, Environmental Analysis, Information Technology, Maintenance, Equipment, Transportation Planning, Land Surveys, Right of Way, Finance, Traffic Operations, Aeronautics, Legal, and Administration It is our commitment to the residents of California that keeps us honest in our mission of providing a safe and reliable transportation network that serves all people and respects the environment.

NAICS: 92
NAICS Definition: Public Administration
Employees: 12,475
Subsidiaries: 29
12-month incidents
0
Known data breaches
29
Attack type number
3

State of Michigan

State Capitol, Lansing, Michigan, US, 48913
Last Update: 2025-12-09

Every day the contributions and achievements of State of Michigan employees have a direct impact on over 10 million Michiganders across the state. If you're looking for a fulfilling career in state government that can make a real difference in the lives of others, you can find your place working with us. We have opportunities in a number of career pathways, including, but not limited to, business and administrative support, education and human services, IT and computers, medical and healthcare, natural resources, law enforcement and public safety, skilled trades and more. Join our team for an: - Opportunity to make a difference - Challenging and rewarding work - Competitive salaries - Fun working environment - Great benefits (community service, vacation and sick leave, paid holidays, paid parental leave, longevity bonuses) - Job stability and career advancement - Flexible alternative and remote work schedules - Tuition discounts and student loan forgiveness - Professional development/training - Employee discount plan With positions in over 18 state departments, your perfect career fit is waiting for you at the State of Michigan. From urban centers to beach towns to the great outdoors, the opportunities are endless in Pure Michigan. With your state salary and benefits and Michigan’s affordable cost of living, you can explore all that Michigan has to offer. Ready to join our team? Visit www.Michigan.gov/Employment to search hundreds of state job openings by key word, job type, location, department, job category, salary and more. The State of Michigan is an Equal Opportunity Employer. We aim to recruit, hire, develop, and retain a diverse and high performing workforce. Our diversity helps drive our creative and effective problem solving, mutual respect, teamwork, and effective communication with the people we serve. Follow us on social media at www.Michigan.gov/SocialMedia and search hashtag #MiGovJobs for updates from state agencies.

NAICS: 92
NAICS Definition: Public Administration
Employees: 34,307
Subsidiaries: 43
12-month incidents
0
Known data breaches
1
Attack type number
1

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/caltrans.jpeg
Caltrans
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/migovernment.jpeg
State of Michigan
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Caltrans
100%
Compliance Rate
0/4 Standards Verified
State of Michigan
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Government Administration Industry Average (This Year)

No incidents recorded for Caltrans in 2025.

Incidents vs Government Administration Industry Average (This Year)

No incidents recorded for State of Michigan in 2025.

Incident History — Caltrans (X = Date, Y = Severity)

Caltrans cyber incidents detection timeline including parent company and subsidiaries

Incident History — State of Michigan (X = Date, Y = Severity)

State of Michigan cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/caltrans.jpeg
Caltrans
Incidents

Date Detected: 1/2025
Type:Breach
Attack Vector: Inadvertent Email
Blog: Blog

Date Detected: 6/2024
Type:Breach
Attack Vector: Unauthorized Access
Blog: Blog

Date Detected: 2/2024
Type:Breach
Attack Vector: Unauthorized Dissemination
Blog: Blog
https://images.rankiteo.com/companyimages/migovernment.jpeg
State of Michigan
Incidents

Date Detected: 8/2025
Type:Breach
Motivation: Prevent identity theft and protect consumer privacy by strengthening data breach accountability and corporate safeguards.
Blog: Blog

FAQ

State of Michigan company demonstrates a stronger AI Cybersecurity Score compared to Caltrans company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Caltrans company has faced a higher number of disclosed cyber incidents historically compared to State of Michigan company.

In the current year, State of Michigan and Caltrans have reported a similar number of cyber incidents.

Caltrans company has confirmed experiencing a ransomware attack, while State of Michigan company has not reported such incidents publicly.

Both State of Michigan company and Caltrans company have disclosed experiencing at least one data breach.

Neither State of Michigan company nor Caltrans company has reported experiencing targeted cyberattacks publicly.

Neither Caltrans company nor State of Michigan company has reported experiencing or disclosing vulnerabilities publicly.

Neither Caltrans nor State of Michigan holds any compliance certifications.

Neither company holds any compliance certifications.

State of Michigan company has more subsidiaries worldwide compared to Caltrans company.

State of Michigan company employs more people globally than Caltrans company, reflecting its scale as a Government Administration.

Neither Caltrans nor State of Michigan holds SOC 2 Type 1 certification.

Neither Caltrans nor State of Michigan holds SOC 2 Type 2 certification.

Neither Caltrans nor State of Michigan holds ISO 27001 certification.

Neither Caltrans nor State of Michigan holds PCI DSS certification.

Neither Caltrans nor State of Michigan holds HIPAA certification.

Neither Caltrans nor State of Michigan holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting (XSS) vulnerability in the /WeGIA/html/geral/configurar_senhas.php endpoint. The application does not sanitize user-controlled data before rendering it inside the employee selection dropdown. The application retrieves employee names from the database and injects them directly into HTML <option> elements without proper escaping. This issue is fixed in version 3.5.5.

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

ZITADEL is an open-source identity infrastructure tool. Versions 4.0.0-rc.1 through 4.7.0 are vulnerable to DOM-Based XSS through the Zitadel V2 logout endpoint. The /logout endpoint insecurely routes to a value that is supplied in the post_logout_redirect GET parameter. As a result, unauthenticated remote attacker can execute malicious JS code on Zitadel users’ browsers. To carry out an attack, multiple user sessions need to be active in the same browser, however, account takeover is mitigated when using Multi-Factor Authentication (MFA) or Passwordless authentication. This issue is fixed in version 4.7.1.

Risk Information
cvss3
Base: 8.0
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Description

ZITADEL is an open-source identity infrastructure tool. Versions 4.7.0 and below are vulnerable to an unauthenticated, full-read SSRF vulnerability. The ZITADEL Login UI (V2) treats the x-zitadel-forward-host header as a trusted fallback for all deployments, including self-hosted instances. This allows an unauthenticated attacker to force the server to make HTTP requests to arbitrary domains, such as internal addresses, and read the responses, enabling data exfiltration and bypassing network-segmentation controls. This issue is fixed in version 4.7.1.

Risk Information
cvss3
Base: 9.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Description

NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue is fixed in version 3.4.0.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

Risk Information
cvss4
Base: 9.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X