Comparison Overview

Chubb

VS

American Family Insurance

Chubb

Bärengasse 32, CH, CH-8001
Last Update: 2026-01-17
Between 800 and 849

Chubb is a world leader in insurance. With operations in 54 countries and territories, Chubb provides commercial and personal property and casualty insurance, personal accident and supplemental health insurance, reinsurance and life insurance to a diverse group of clients. As an underwriting company, we assess, assume and manage risk with insight and discipline. We service and pay our claims fairly and promptly. The company is also defined by its extensive product and service offerings, broad distribution capabilities, exceptional financial strength and local operations globally. Parent company Chubb Limited is listed on the New York Stock Exchange (NYSE: CB) and is a component of the S&P 500 index. Chubb maintains executive offices in Zurich, New York, London, Paris and other locations, and employs approximately 40,000 people worldwide. Read our Social Media Guidelines here: https://www.chubb.com/us-en/about-chubb/chubbs-social-media-guidelines.aspx Notre section « À propos » est également disponible en français, ici: https://www.chubb.com/ca-fr/about-chubb-in-canada/a-propos-de-chubb-au-canada.aspx

NAICS: 524
NAICS Definition: Insurance Carriers and Related Activities
Employees: 39,339
Subsidiaries: 6
12-month incidents
0
Known data breaches
0
Attack type number
0

American Family Insurance

6000 American Pkwy, Madison, 53783, US
Last Update: 2026-01-19
Between 750 and 799

For more than 90 years, American Family Insurance has built its reputation on sound principles. We strive to provide you industry-leading service, exceptional claims experience and products that build long-term relationships. This is accomplished by treating policyholders fairly in a helpful and caring way and making it easy and convenient to work with us. We know our customers like family. American Family Insurance thrives by conducting its business in accordance with the highest ethical standards and the law at all times. Integrity is part of our culture and always has been. The reputation we enjoy and trust-based relationships we have built with our customers are determined by the example set by management and the character and good judgment exercised at all levels of our organization. It’s a way of doing business that our customers have come to expect from us and a standard that we continue to live up to. 1-800MYAMFAM (1-800-692-6326)

NAICS: 524
NAICS Definition: Insurance Carriers and Related Activities
Employees: 18,297
Subsidiaries: 2
12-month incidents
0
Known data breaches
1
Attack type number
3

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/chubb.jpeg
Chubb
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/american-family-insurance.jpeg
American Family Insurance
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Chubb
100%
Compliance Rate
0/4 Standards Verified
American Family Insurance
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Insurance Industry Average (This Year)

No incidents recorded for Chubb in 2026.

Incidents vs Insurance Industry Average (This Year)

No incidents recorded for American Family Insurance in 2026.

Incident History — Chubb (X = Date, Y = Severity)

Chubb cyber incidents detection timeline including parent company and subsidiaries

Incident History — American Family Insurance (X = Date, Y = Severity)

American Family Insurance cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/chubb.jpeg
Chubb
Incidents

No Incident

https://images.rankiteo.com/companyimages/american-family-insurance.jpeg
American Family Insurance
Incidents

Date Detected: 10/2023
Type:Vulnerability
Blog: Blog

Date Detected: 05/2021
Type:Breach
Blog: Blog

Date Detected: 2/2021
Type:Cyber Attack
Attack Vector: Cyberattack
Blog: Blog

FAQ

Chubb company demonstrates a stronger AI Cybersecurity Score compared to American Family Insurance company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

American Family Insurance company has historically faced a number of disclosed cyber incidents, whereas Chubb company has not reported any.

In the current year, American Family Insurance company and Chubb company have not reported any cyber incidents.

Neither American Family Insurance company nor Chubb company has reported experiencing a ransomware attack publicly.

American Family Insurance company has disclosed at least one data breach, while Chubb company has not reported such incidents publicly.

American Family Insurance company has reported targeted cyberattacks, while Chubb company has not reported such incidents publicly.

American Family Insurance company has disclosed at least one vulnerability, while Chubb company has not reported such incidents publicly.

Neither Chubb nor American Family Insurance holds any compliance certifications.

Neither company holds any compliance certifications.

Chubb company has more subsidiaries worldwide compared to American Family Insurance company.

Chubb company employs more people globally than American Family Insurance company, reflecting its scale as a Insurance.

Neither Chubb nor American Family Insurance holds SOC 2 Type 1 certification.

Neither Chubb nor American Family Insurance holds SOC 2 Type 2 certification.

Neither Chubb nor American Family Insurance holds ISO 27001 certification.

Neither Chubb nor American Family Insurance holds PCI DSS certification.

Neither Chubb nor American Family Insurance holds HIPAA certification.

Neither Chubb nor American Family Insurance holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Risk Information
cvss3
Base: 9.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Description

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

Risk Information
cvss3
Base: 9.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description

Azure Entra ID Elevation of Privilege Vulnerability

Risk Information
cvss3
Base: 9.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Description

Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, instances configured with the "ldap" component enabled are vulnerable to LDAP search filter injection techniques via the login endpoint. The 401 error response message can be used to determine whether or not a search was successful, allowing for brute force methods to discover LDAP entries on the server such as user IDs and user attributes. This issue has been fixed in version 0.10.0.

Risk Information
cvss4
Base: 2.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an authenticated user to execute arbitrary system commands on the host server by injecting shell metacharacters into backup filenames. The BackupManager fails to sanitize the filenames of uploaded backups. The system persists user-uploaded files directly to the host filesystem using the raw originalname provided in the request. This allows an attacker to stage a file containing shell metacharacters (e.g., $(id).tar.gz) at a predictable path, which is later referenced during the restore process. The successful storage of the file is what allows the subsequent restore command to reference and execute it. This issue has been fixed in version 4.7.0.

Risk Information
cvss3
Base: 8.0
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H