ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Dorfman Museum Figures, Inc. has been in business for 60 years, providing ultra Realistic Figures and Forms to the museum community, helping to keep history alive, dynamic, and relevant! Originally specializing in creating life-size, life-like realistic figures for museums, DMF has sculpted over 840 heads with which it has created thousands of figures for museums, visitor centers, design /exhibit companies, corporate entities, and private clients. DMF also fabricates a comprehensive line of conservationally sound forms out of Ethafoam® for display and storage of high value artifact costumes, uniforms, and clothing. Our Museum Figures and Conservation Forms are used in exhibit collections worldwide in over 30 countries. Driven by our client’s needs, we are continually adding to our line of products. So if you don’t see what you need, give us a call and let us know what we can do for you!

Dorfman Museum Figures, Inc. A.I CyberSecurity Scoring

DMFI

Company Details

Linkedin ID:

dorfman-museum-figures-inc

Employees number:

3

Number of followers:

21

NAICS:

712

Industry Type:

Museums, Historical Sites, and Zoos

Homepage:

museumfigures.com

IP Addresses:

0

Company ID:

DOR_1635311

Scan Status:

In-progress

AI scoreDMFI Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/dorfman-museum-figures-inc.jpeg
DMFI Museums, Historical Sites, and Zoos
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreDMFI Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/dorfman-museum-figures-inc.jpeg
DMFI Museums, Historical Sites, and Zoos
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

DMFI Company CyberSecurity News & History

Past Incidents
0
Attack Types
0
No data available
Ailogo

DMFI Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for DMFI

Incidents vs Museums, Historical Sites, and Zoos Industry Average (This Year)

No incidents recorded for Dorfman Museum Figures, Inc. in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Dorfman Museum Figures, Inc. in 2025.

Incident Types DMFI vs Museums, Historical Sites, and Zoos Industry Avg (This Year)

No incidents recorded for Dorfman Museum Figures, Inc. in 2025.

Incident History — DMFI (X = Date, Y = Severity)

DMFI cyber incidents detection timeline including parent company and subsidiaries

DMFI Company Subsidiaries

SubsidiaryImage

Dorfman Museum Figures, Inc. has been in business for 60 years, providing ultra Realistic Figures and Forms to the museum community, helping to keep history alive, dynamic, and relevant! Originally specializing in creating life-size, life-like realistic figures for museums, DMF has sculpted over 840 heads with which it has created thousands of figures for museums, visitor centers, design /exhibit companies, corporate entities, and private clients. DMF also fabricates a comprehensive line of conservationally sound forms out of Ethafoam® for display and storage of high value artifact costumes, uniforms, and clothing. Our Museum Figures and Conservation Forms are used in exhibit collections worldwide in over 30 countries. Driven by our client’s needs, we are continually adding to our line of products. So if you don’t see what you need, give us a call and let us know what we can do for you!

Loading...
similarCompanies

DMFI Similar Companies

National Women's Hall of Fame

Founded in 1969, the National Women's Hall of Fame was created to build a permanent home to honor women whose enduring contributions have transformed the landscape of America. Today we honor over 300 remarkable women in our gallery from the arts, athletics, business, education, government, humanit

Providence Children's Museum

Providence Children's Museum is Rhode Island's only hands-on museum for children and their grown-ups. The Museum's mission is to inspire lifelong learning for all through play, creativity, and exploration. The Museum serves the children of southern New England and the adults who care for them by

Oakland Museum of California

The Oakland Museum of California (OMCA) tells the many stories that comprise California, creating the space and context for greater connection, trust, and understanding between people. Through its inclusive exhibitions, public programs, educational initiatives, and cultural events, OMCA brings Cali

Toledo Museum of Art

Since our founding in 1901, the Toledo Museum of Art has earned a global reputation for the quality of our collection, our innovative and extensive education programs, and our architecturally significant campus. More than 30,000 works of art represent American and European painting, the history o

Dixon Gallery & Gardens

Founded in 1976 by Hugo and Margaret Dixon, the Dixon Gallery and Gardens is a fine art museum and public garden distinguished by its diverse and innovative programs in the arts and horticulture. The Dixon features a permanent collection of over 2,000 objects, including French and American Impressio

Japanese Culture Center

The Japanese Culture Center was established in 1977 in Chicago by Aikido Shihan (Teacher of Teachers) and Zen Master Fumio Toyoda to make some of the martial arts, crafts, and philosophical riches of Japan available to the public. Today the JCC continues this tradition, offering classes in over a do

newsone

DMFI CyberSecurity News

December 02, 2025 11:38 PM
Your 2026 AI Cybersecurity Strategy: Breaking Down the Hard Choices for Tech Leaders

Longtime CIO and author Mark Settle shares how leaders can balance AI-driven risks, automation, and shrinking budgets to strengthen...

December 02, 2025 10:29 PM
Senator Schmitt Emphasizes Need to Strengthen, Update Cybersecurity Technology

WASHINGTON — Today, during a Senate Commerce Committee hearing, U.S. Senator Eric Schmitt (R-MO) questioned witnesses about the need to...

December 02, 2025 10:27 PM
Alexandria cybersecurity startup SpecterOps raises $30M

Fast-growing Alexandria cybersecurity startup SpecterOps has raised $30 million in new funding, bringing its total raised since March to...

December 02, 2025 10:26 PM
Press Release: Senator Eric Schmitt Urges Modernization of Cybersecurity Technology in Senate Hearing

Senator Eric Schmitt advocates for enhanced cybersecurity measures during a Senate hearing, addressing procurement and satellite security...

December 02, 2025 10:26 PM
Press Release: Deb Fischer Holds Hearing on Protecting U.S. Telecommunications Networks amid Cybersecurity Concerns

Senator Deb Fischer held a hearing addressing cybersecurity threats and advocating for the FACT Act to protect telecommunications.

December 02, 2025 10:20 PM
CISA tells staff to not speak with reporters, internal email shows

The Cybersecurity and Infrastructure Security Agency issued a Friday email to staff telling them to not speak to news reporters in an...

December 02, 2025 10:13 PM
James Uthmeier files subpoena against Wi-Fi router tech firm, alleges links to China

It's the second time this year Uthmeier has initiated legal action alleging cybersecurity issues about a company with Chinese connections.

December 02, 2025 10:10 PM
Top Cybersecurity Stocks To Consider - December 2nd

CrowdStrike, Palo Alto Networks, Fortinet, SentinelOne, Globant, BlackBerry, and Arqit Quantum are the seven Cybersecurity stocks to watch...

December 02, 2025 10:09 PM
Cybersecurity Firm CrowdStrike's Earnings, Revenue Edge By Estimates

CrowdStrike Holdings (CRWD) said third-quarter earnings and revenue came in slightly above consensus estimates. The cybersecurity firm's...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

DMFI CyberSecurity History Information

Official Website of Dorfman Museum Figures, Inc.

The official website of Dorfman Museum Figures, Inc. is http://www.museumfigures.com.

Dorfman Museum Figures, Inc.’s AI-Generated Cybersecurity Score

According to Rankiteo, Dorfman Museum Figures, Inc.’s AI-generated cybersecurity score is 766, reflecting their Fair security posture.

How many security badges does Dorfman Museum Figures, Inc.’ have ?

According to Rankiteo, Dorfman Museum Figures, Inc. currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Dorfman Museum Figures, Inc. have SOC 2 Type 1 certification ?

According to Rankiteo, Dorfman Museum Figures, Inc. is not certified under SOC 2 Type 1.

Does Dorfman Museum Figures, Inc. have SOC 2 Type 2 certification ?

According to Rankiteo, Dorfman Museum Figures, Inc. does not hold a SOC 2 Type 2 certification.

Does Dorfman Museum Figures, Inc. comply with GDPR ?

According to Rankiteo, Dorfman Museum Figures, Inc. is not listed as GDPR compliant.

Does Dorfman Museum Figures, Inc. have PCI DSS certification ?

According to Rankiteo, Dorfman Museum Figures, Inc. does not currently maintain PCI DSS compliance.

Does Dorfman Museum Figures, Inc. comply with HIPAA ?

According to Rankiteo, Dorfman Museum Figures, Inc. is not compliant with HIPAA regulations.

Does Dorfman Museum Figures, Inc. have ISO 27001 certification ?

According to Rankiteo,Dorfman Museum Figures, Inc. is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Dorfman Museum Figures, Inc.

Dorfman Museum Figures, Inc. operates primarily in the Museums, Historical Sites, and Zoos industry.

Number of Employees at Dorfman Museum Figures, Inc.

Dorfman Museum Figures, Inc. employs approximately 3 people worldwide.

Subsidiaries Owned by Dorfman Museum Figures, Inc.

Dorfman Museum Figures, Inc. presently has no subsidiaries across any sectors.

Dorfman Museum Figures, Inc.’s LinkedIn Followers

Dorfman Museum Figures, Inc.’s official LinkedIn profile has approximately 21 followers.

Dorfman Museum Figures, Inc.’s Presence on Crunchbase

No, Dorfman Museum Figures, Inc. does not have a profile on Crunchbase.

Dorfman Museum Figures, Inc.’s Presence on LinkedIn

Yes, Dorfman Museum Figures, Inc. maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/dorfman-museum-figures-inc.

Cybersecurity Incidents Involving Dorfman Museum Figures, Inc.

As of December 02, 2025, Rankiteo reports that Dorfman Museum Figures, Inc. has not experienced any cybersecurity incidents.

Number of Peer and Competitor Companies

Dorfman Museum Figures, Inc. has an estimated 2,131 peer or competitor companies worldwide.

Dorfman Museum Figures, Inc. CyberSecurity History Information

How many cyber incidents has Dorfman Museum Figures, Inc. faced ?

Total Incidents: According to Rankiteo, Dorfman Museum Figures, Inc. has faced 0 incidents in the past.

What types of cybersecurity incidents have occurred at Dorfman Museum Figures, Inc. ?

Incident Types: The types of cybersecurity incidents that have occurred include .

Incident Details

What are the most common types of attacks the company has faced ?

Additional Questions

cve

Latest Global CVEs (Not Company-Specific)

Description

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm loads a model config that contains an auto_map entry, the config class resolves that mapping with get_class_from_dynamic_module(...) and immediately instantiates the returned class. This fetches and executes Python from the remote repository referenced in the auto_map string. Crucially, this happens even when the caller explicitly sets trust_remote_code=False in vllm.transformers_utils.config.get_config. In practice, an attacker can publish a benign-looking frontend repo whose config.json points via auto_map to a separate malicious backend repo; loading the frontend will silently run the backend’s code on the victim host. This vulnerability is fixed in 0.11.1.

Risk Information
cvss3
Base: 7.1
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Description

fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.

Risk Information
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.

Risk Information
cvss4
Base: 8.5
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.

Risk Information
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=dorfman-museum-figures-inc' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge