Comparison Overview
Ecopetrol

Ecopetrol
Cra. 13 No. 36-24, Bogotá, ----, CO
Last Update: 18/07/2026
Ecopetrol (NYSE: EC) es la compañía más grande en Colombia y uno de los principales grupos de energía de Latinoamérica. Cuenta con más de 18.000 empleados y es responsable del 60% de la producción de hidrocarburos en Colombia. Es propietaria de las dos refinerías del Co...

Oxy
Houston, 77046, US
Last Update: 01/04/2026
Oxy is an international energy company with assets primarily in the United States, the Middle East and North Africa. We are one of the largest oil producers in the U.S., including a leading producer in the Permian and DJ basins, and offshore Gulf of Mexico. Our midstrea...
Compliance Ranges Comparison

Ecopetrol







Oxy






Benchmark & Cyber Underwriting Signals
Incidents vs Oil and Gas Industry Avg (This Year)
No incidents recorded for Ecopetrol in 2026.
Incidents vs Oil and Gas Industry Avg (This Year)
No incidents recorded for Oxy in 2026.
Incident History - Ecopetrol (X = Date, Y = Severity)
Ecopetrol cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Oxy (X = Date, Y = Severity)
Oxy cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Ecopetrol

Oxy
FAQ
Latest Global CVEs
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.