Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

CERAWeekCERAWeek
VS
SuncorSuncor
CERAWeek

CERAWeek

55 Cambridge Parkway, Cambridge, 02142, US

Last Update: 29/01/2026

View Profile
754/1000Fair

CERAWeek by S&P Global is the energy industry’s preeminent gathering of senior executives, government officials, thought leaders, academics, technology innovators, and financial leaders. For forty years, CERAWeek has been providing an integrated framework for understand...

NAICS:211
NAICS Definition:Oil and Gas Extraction
Employees:None
Subsidiaries:24
12-month incidents
0
Known data breaches
0
Attack type number
0
Suncor

Suncor

150 - 6 Avenue SW, Calgary, CA

Last Update: 06/09/2026

View Profile
Between 800 and 849
http://www.suncor.com
818/1000Good

In 1967, we pioneered commercial development of Canada's oil sands – one of the largest petroleum resource basins in the world. Since then, Suncor has grown to become a globally competitive integrated energy company with a balanced portfolio of high-quality assets, a st...

NAICS:211
NAICS Definition:Oil and Gas Extraction
Employees:14,579
Subsidiaries:1
12-month incidents
0
Known data breaches
0
Attack type number
1

Compliance Ranges Comparison

Based On Specific Ai Models Category
CERAWeek

CERAWeek

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
Suncor

Suncor

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Oil and Gas Industry Avg (This Year)

No incidents recorded for CERAWeek in 2026.

Incidents

Incidents vs Oil and Gas Industry Avg (This Year)

No incidents recorded for Suncor in 2026.

Incidents

Incident History - CERAWeek (X = Date, Y = Severity)

CERAWeek cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - Suncor (X = Date, Y = Severity)

Suncor cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
CERAWeek

CERAWeek

Incidents
No explicit notable incidents reported.
Suncor

Suncor

Incidents
🔒 Incident : Cyber Attack
SUN23169723

FAQ

Between CERAWeek company and Suncor company, which one has the best AI Cybersecurity Score ?
Between CERAWeek company and Suncor company, which one has experienced more cyber incidents in the past ?
Between CERAWeek company and Suncor company, which one has experienced more cyber incidents this year ?
Between CERAWeek company and Suncor company, which one has experienced at least one ransomware attack ?
Between CERAWeek company and Suncor company, which one has experienced at least one data breach ?
Between CERAWeek company and Suncor company, which one has experienced at least one targeted cyberattack ?
Between CERAWeek company and Suncor company, which one has experienced at least one vulnerability ?
Between CERAWeek company and Suncor company, which one holds the most compliance certifications ?
Between CERAWeek company and Suncor company, which one holds the fewest compliance certifications ?
Between CERAWeek company and Suncor company, which one has the most subsidiaries ?
Between CERAWeek company and Suncor company, which one has the largest number of employees ?
Between CERAWeek and Suncor, which company holds both SOC 2 Type 1 certifications ?
Between CERAWeek and Suncor, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - CERAWeek or Suncor ?
Which company is PCI DSS compliant - CERAWeek or Suncor ?
Between CERAWeek and Suncor, which company complies with HIPAA regulations for healthcare data ?
Between CERAWeek and Suncor, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-93436
SUMMARY

vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.

PUBLISHED
Date2026-09-17
UPDATED
Date2026-09-17
RISK INFORMATION (Score: 7.5)
CVSS3
Base Score: 7.5
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS4
Base Score: 8.7
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.6
EXPLOITABILITY
3.9
CVE-2026-93435
SUMMARY

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.

PUBLISHED
Date2026-09-17
UPDATED
Date2026-09-17
RISK INFORMATION (Score: 7.5)
CVSS3
Base Score: 7.5
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS4
Base Score: 8.7
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.6
EXPLOITABILITY
3.9
CVE-2026-87701
SUMMARY

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Date2026-09-17
UPDATED
Date2026-09-17
RISK INFORMATION (Score: 9.6)
CVSS3
Base Score: 9.6
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
IMPACT SCORE
5.8
EXPLOITABILITY
3.1
CVE-2026-85917
SUMMARY

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Date2026-09-17
UPDATED
Date2026-09-17
RISK INFORMATION (Score: 7.5)
CVSS3
Base Score: 7.5
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
IMPACT SCORE
3.6
EXPLOITABILITY
3.9
CVE-2026-85889
SUMMARY

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

PUBLISHED
Date2026-09-17
UPDATED
Date2026-09-17
RISK INFORMATION (Score: 10)
CVSS3
Base Score: 10.0
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
IMPACT SCORE
6
EXPLOITABILITY
3.9