Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

EcopetrolEcopetrol
VS
ChevronChevron
Ecopetrol

Ecopetrol

Cra. 13 No. 36-24, Bogotá, CO, ----

Last Update: 13/09/2026

View Profile
Between 650 and 699
http://www.ecopetrol.com.co
655/1000Weak

Ecopetrol (NYSE: EC) es la compañía más grande en Colombia y uno de los principales grupos de energía de Latinoamérica. Cuenta con más de 18.000 empleados y es responsable del 60% de la producción de hidrocarburos en Colombia. Es propietaria de las dos refinerías del Co...

NAICS:211
NAICS Definition:Oil and Gas Extraction
Employees:13,056
Subsidiaries:2
12-month incidents
2
Known data breaches
1
Attack type number
2
Chevron

Chevron

1400 Smith St, Houston, Texas, US, 77002

Last Update: 05/09/2026

View Profile
Between 800 and 849
http://www.chevron.com
839/1000Good

Our greatest resource is our people. Their ingenuity, creativity and collaboration have met the complex challenges of energy’s past. Together, we’ll take on the future. We support the LinkedIn Terms of Use (User Agreement), and we expect visitors to our page to do the ...

NAICS:211
NAICS Definition:Oil and Gas Extraction
Employees:53,738
Subsidiaries:12
12-month incidents
1
Known data breaches
0
Attack type number
1

Compliance Ranges Comparison

Based On Specific Ai Models Category
Ecopetrol

Ecopetrol

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
Chevron

Chevron

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Oil and Gas Industry Avg (This Year)

Ecopetrol has 14.16% fewer incidents than the average of same-industry companies with at least one recorded incident.

Incidents

Incidents vs Oil and Gas Industry Avg (This Year)

Chevron has 2.91% fewer incidents than the average of all companies with at least one recorded incident.

Incidents

Incident History - Ecopetrol (X = Date, Y = Severity)

Ecopetrol cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - Chevron (X = Date, Y = Severity)

Chevron cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
Ecopetrol

Ecopetrol

Incidents
🔒 Incident : Ransomware
ECO1784557630
🔒 Incident : Breach
ECO1784348677
Chevron

Chevron

Incidents
🔒 Incident : Vulnerability
MERCHESAMCOMFOXATTFORTOY1781713752

FAQ

Between Ecopetrol company and Chevron company, which one has the best AI Cybersecurity Score ?
Between Ecopetrol company and Chevron company, which one has experienced more cyber incidents in the past ?
Between Ecopetrol company and Chevron company, which one has experienced more cyber incidents this year ?
Between Ecopetrol company and Chevron company, which one has experienced at least one ransomware attack ?
Between Ecopetrol company and Chevron company, which one has experienced at least one data breach ?
Between Ecopetrol company and Chevron company, which one has experienced at least one targeted cyberattack ?
Between Ecopetrol company and Chevron company, which one has experienced at least one vulnerability ?
Between Ecopetrol company and Chevron company, which one holds the most compliance certifications ?
Between Ecopetrol company and Chevron company, which one holds the fewest compliance certifications ?
Between Ecopetrol company and Chevron company, which one has the most subsidiaries ?
Between Ecopetrol company and Chevron company, which one has the largest number of employees ?
Between Ecopetrol and Chevron, which company holds both SOC 2 Type 1 certifications ?
Between Ecopetrol and Chevron, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - Ecopetrol or Chevron ?
Which company is PCI DSS compliant - Ecopetrol or Chevron ?
Between Ecopetrol and Chevron, which company complies with HIPAA regulations for healthcare data ?
Between Ecopetrol and Chevron, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-94057
SUMMARY

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

PUBLISHED
Date2026-09-19
UPDATED
Date2026-09-19
RISK INFORMATION (Score: 4)
CVSS3
Base Score: 4.0
Complexity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
IMPACT SCORE
1.4
EXPLOITABILITY
2.2
CVE-2026-94056
SUMMARY

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

PUBLISHED
Date2026-09-19
UPDATED
Date2026-09-19
RISK INFORMATION (Score: 7.5)
CVSS3
Base Score: 7.5
Complexity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L
IMPACT SCORE
4.7
EXPLOITABILITY
2.2
CVE-2026-94055
SUMMARY

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

PUBLISHED
Date2026-09-19
UPDATED
Date2026-09-19
RISK INFORMATION (Score: 3.7)
CVSS3
Base Score: 3.7
Complexity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
IMPACT SCORE
1.4
EXPLOITABILITY
2.2
CVE-2026-94054
SUMMARY

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

PUBLISHED
Date2026-09-19
UPDATED
Date2026-09-19
RISK INFORMATION (Score: 7)
CVSS3
Base Score: 7.0
Complexity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
IMPACT SCORE
4.7
EXPLOITABILITY
2.2
CVE-2026-93993
SUMMARY

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.

PUBLISHED
Date2026-09-19
UPDATED
Date2026-09-19
RISK INFORMATION (Score: 8.8)
CVSS3
Base Score: 8.8
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS4
Base Score: 8.6
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
5.9
EXPLOITABILITY
2.8