Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

DiscoverDiscover
VS
TIAATIAA
Discover

Discover

2500 Lake Cook Road, Riverwoods, IL, US, 60015

Last Update: 16/09/2026

View Profile
Between 600 and 649
http://www.discover.com
622/1000Poor

Discover® is now part of Capital One. Together, we’ll continue to deliver exceptional financial products and experiences, drive innovation, and serve customers. Find the latest updates at https://capitalonediscover.com. Discover is one of the most recognized brands in ...

NAICS:52
NAICS Definition:Finance and Insurance
Employees:19,187
Subsidiaries:0
12-month incidents
0
Known data breaches
33
Attack type number
2
TIAA

TIAA

730 Third Ave., New York, 10017, US

Last Update: 06/09/2026

View Profile
Between 550 and 599
https://www.tiaa.org
563/1000Very Poor

At TIAA, we believe everyone has the right to retire with dignity. For more than 100 years, we’ve provided retirement plans, insurance, and investment services, empowering millions of people— in education, healthcare, and nonprofit —with the knowledge, guidance, and lif...

NAICS:52
NAICS Definition:Finance and Insurance
Employees:13,272
Subsidiaries:3
12-month incidents
0
Known data breaches
4
Attack type number
2

Compliance Ranges Comparison

Based On Specific Ai Models Category
Discover

Discover

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
TIAA

TIAA

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Financial Services Industry Avg (This Year)

No incidents recorded for Discover in 2026.

Incidents

Incidents vs Financial Services Industry Avg (This Year)

No incidents recorded for TIAA in 2026.

Incidents

Incident History - Discover (X = Date, Y = Severity)

Discover cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - TIAA (X = Date, Y = Severity)

TIAA cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
Discover

Discover

Incidents
🔒 Incident : Breach
DIS631072825
🔒 Incident : Breach
DIS406072525
🔒 Incident : Breach
DIS027091825
TIAA

TIAA

Incidents
🔒 Incident : Ransomware
TIA1773398169
🔒 Incident : Breach
TIA904072625
🔒 Incident : Breach
TIA437072825

FAQ

Between Discover company and TIAA company, which one has the best AI Cybersecurity Score ?
Between Discover company and TIAA company, which one has experienced more cyber incidents in the past ?
Between Discover company and TIAA company, which one has experienced more cyber incidents this year ?
Between Discover company and TIAA company, which one has experienced at least one ransomware attack ?
Between Discover company and TIAA company, which one has experienced at least one data breach ?
Between Discover company and TIAA company, which one has experienced at least one targeted cyberattack ?
Between Discover company and TIAA company, which one has experienced at least one vulnerability ?
Between Discover company and TIAA company, which one holds the most compliance certifications ?
Between Discover company and TIAA company, which one holds the fewest compliance certifications ?
Between Discover company and TIAA company, which one has the most subsidiaries ?
Between Discover company and TIAA company, which one has the largest number of employees ?
Between Discover and TIAA, which company holds both SOC 2 Type 1 certifications ?
Between Discover and TIAA, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - Discover or TIAA ?
Which company is PCI DSS compliant - Discover or TIAA ?
Between Discover and TIAA, which company complies with HIPAA regulations for healthcare data ?
Between Discover and TIAA, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-84411
SUMMARY

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

PUBLISHED
Date2026-10-02
UPDATED
Date2026-10-02
RISK INFORMATION (Score: 9.8)
CVSS3
Base Score: 9.8
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS4
Base Score: 9.3
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
5.9
EXPLOITABILITY
3.9
CVE-2026-105051
SUMMARY

Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).

PUBLISHED
Date2026-10-02
UPDATED
Date2026-10-02
RISK INFORMATION (Score: 1.9)
CVSS3
Base Score: 1.9
Complexity: HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
IMPACT SCORE
1.4
EXPLOITABILITY
0.5
CVE-2026-105050
SUMMARY

PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.

PUBLISHED
Date2026-10-02
UPDATED
Date2026-10-02
RISK INFORMATION (Score: )
CVSS4
Base Score: 7.1
Complexity: LOW
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
NA
EXPLOITABILITY
NA
CVE-2026-105049
SUMMARY

Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.

PUBLISHED
Date2026-10-02
UPDATED
Date2026-10-02
RISK INFORMATION (Score: 5.8)
CVSS3
Base Score: 5.8
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
IMPACT SCORE
1.4
EXPLOITABILITY
3.9
CVE-2026-105048
SUMMARY

The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).

PUBLISHED
Date2026-10-02
UPDATED
Date2026-10-02
RISK INFORMATION (Score: 4)
CVSS3
Base Score: 4.0
Complexity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
IMPACT SCORE
1.4
EXPLOITABILITY
2.2