ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

As an innovative leader, New York Air Brake has been serving the rail industry since 1890. Through the years, our basic philosophy has reflected a deep respect for the customer, and a commitment to providing quality products at a cost-effective price. New York Air Brake's participation in ISO 9001, and our corresponding certification, echoes a company-wide spirit. From management, to administration, to engineering, to the production floor, quality is an ever-present compass. Recent years have seen a major expansion in engineering resources dedicated to bringing new technology to the marketplace. We have made significant capital investments in new facilities, machining centers, and test equipment, while increasing efficiency by utilizing highly focused teams in our manufacturing processes. .

New York Air Brake A.I CyberSecurity Scoring

NYAB

Company Details

Linkedin ID:

new-york-air-brake

Employees number:

439

Number of followers:

6,062

NAICS:

3365

Industry Type:

Railroad Equipment Manufacturing

Homepage:

nyab.com

IP Addresses:

0

Company ID:

NEW_1953257

Scan Status:

In-progress

AI scoreNYAB Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/new-york-air-brake.jpeg
NYAB Railroad Equipment Manufacturing
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreNYAB Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/new-york-air-brake.jpeg
NYAB Railroad Equipment Manufacturing
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

NYAB Company CyberSecurity News & History

Past Incidents
0
Attack Types
0
No data available
Ailogo

NYAB Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for NYAB

Incidents vs Railroad Equipment Manufacturing Industry Average (This Year)

No incidents recorded for New York Air Brake in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for New York Air Brake in 2025.

Incident Types NYAB vs Railroad Equipment Manufacturing Industry Avg (This Year)

No incidents recorded for New York Air Brake in 2025.

Incident History — NYAB (X = Date, Y = Severity)

NYAB cyber incidents detection timeline including parent company and subsidiaries

NYAB Company Subsidiaries

SubsidiaryImage

As an innovative leader, New York Air Brake has been serving the rail industry since 1890. Through the years, our basic philosophy has reflected a deep respect for the customer, and a commitment to providing quality products at a cost-effective price. New York Air Brake's participation in ISO 9001, and our corresponding certification, echoes a company-wide spirit. From management, to administration, to engineering, to the production floor, quality is an ever-present compass. Recent years have seen a major expansion in engineering resources dedicated to bringing new technology to the marketplace. We have made significant capital investments in new facilities, machining centers, and test equipment, while increasing efficiency by utilizing highly focused teams in our manufacturing processes. .

Loading...
similarCompanies

NYAB Similar Companies

CLW GROUP TRUCK

CLW GROUP TRUCK produce trucks specially for you,we are the biggest special trucks manufacturer in China,you can find all kinds of the special trucks produced in our factory ,and you can also send us the drawings and the requirement details to produced specially for you . In our factory you can f

Exolgan Container Terminal

EXOLGAN, es la mayor Terminal de Contenedores de la República Argentina. Ubicada en Dock Sud, Avellaneda, sobre un predio de 50 hectáreas y con 1.200 mts lineales de muelle, es el principal operador en el Comercio Exterior de la carga Containerizada que ingresa y egresa de nuestro País. El servic

We’re an innovative NSW government organisation comprised of a network of agencies and divisions that keep the state moving. Our focus is on delivering safe, reliable and integrated transport networks for everyone. With over 28,000 team members, we’re committed to inclusion, diversity, and opportun

Grimaldi Group

Established in 1947, Grimaldi is a fully integrated multinational logistics Group specialising in maritime transport of cars, rolling cargo, containers and passengers. Wholly owned by the Grimaldi family, the Group is led by Gianluca and Emanuele Grimaldi, sons of the founder Guido, and their broth

Yellow, a Fortune 500 company headquartered in Nashville, TN is one of the largest super-regional less-than-truckload (LTL) companies in North America. Nearly 100 years ago, Yellow created the LTL industry, and now it comprises four successful regional LTL companies and an in-house logistics brokera

Transnet Freight Rail

Transnet Freight Rail is the largest division of Transnet SOC Ltd. It is a world class heavy haul freight rail company that specialises in the transportation of freight. The company maintains an extensive rail network across South Africa that connects with other rail networks in the sub-Saharan reg

newsone

NYAB CyberSecurity News

December 02, 2024 04:28 PM
$625K Westinghouse Air Brake Technologies data breach class action settlement

A $625000 class action settlement resolves allegations related to a Westinghouse Air Brake Technologies Corporation cybersecurity incident.

July 19, 2024 07:00 AM
Chaos and Confusion: Tech Outage Causes Disruptions Worldwide (Published 2024)

Airlines, hospitals and people's computers were affected after CrowdStrike, a cybersecurity company, sent out a flawed software update.

March 02, 2023 08:00 AM
New Biden Cybersecurity Strategy Assigns Responsibility to Tech Firms (Published 2023)

The Biden administration issued a new cybersecurity strategy on Thursday that calls on software makers and American industry to take far greater responsibility.

May 31, 2022 07:00 AM
Nexxiot, Knorr-Bremse integrating technology to build better rail brakes

Knorr-Bremse's North American subsidiaries New York Air Brake and Knorr Brake Co. to deploy Nexxiot's technology.

April 09, 2020 06:41 PM
Railroads, suppliers commit to transparency on cyber attacks

article about: Cybersecurity, Association of American Railroads, AAR, Rail Information Security Committee, RISC, Mark Grant, CSX, Paul Veeneman,...

June 07, 2017 07:00 AM
Why Car Companies Are Hiring Computer Security Experts (Published 2017)

Researchers have proved a car can be remotely hacked. Now imagine if that car was being driven entirely by a computer.

June 19, 2016 07:00 AM
Envisioning the Hack That Could Take Down New York City

The day cars drove themselves into walls and the hospitals froze. A scenario that could happen based on what already has.

May 01, 2015 07:00 AM
New Rules Are Big Brake for Two Rail Suppliers

Wabtec and New York Air Brake are only makers of electronic pneumatic brakes.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

NYAB CyberSecurity History Information

Official Website of New York Air Brake

The official website of New York Air Brake is https://www.nyab.com.

New York Air Brake’s AI-Generated Cybersecurity Score

According to Rankiteo, New York Air Brake’s AI-generated cybersecurity score is 749, reflecting their Moderate security posture.

How many security badges does New York Air Brake’ have ?

According to Rankiteo, New York Air Brake currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does New York Air Brake have SOC 2 Type 1 certification ?

According to Rankiteo, New York Air Brake is not certified under SOC 2 Type 1.

Does New York Air Brake have SOC 2 Type 2 certification ?

According to Rankiteo, New York Air Brake does not hold a SOC 2 Type 2 certification.

Does New York Air Brake comply with GDPR ?

According to Rankiteo, New York Air Brake is not listed as GDPR compliant.

Does New York Air Brake have PCI DSS certification ?

According to Rankiteo, New York Air Brake does not currently maintain PCI DSS compliance.

Does New York Air Brake comply with HIPAA ?

According to Rankiteo, New York Air Brake is not compliant with HIPAA regulations.

Does New York Air Brake have ISO 27001 certification ?

According to Rankiteo,New York Air Brake is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of New York Air Brake

New York Air Brake operates primarily in the Railroad Equipment Manufacturing industry.

Number of Employees at New York Air Brake

New York Air Brake employs approximately 439 people worldwide.

Subsidiaries Owned by New York Air Brake

New York Air Brake presently has no subsidiaries across any sectors.

New York Air Brake’s LinkedIn Followers

New York Air Brake’s official LinkedIn profile has approximately 6,062 followers.

NAICS Classification of New York Air Brake

New York Air Brake is classified under the NAICS code 3365, which corresponds to Railroad Rolling Stock Manufacturing.

New York Air Brake’s Presence on Crunchbase

No, New York Air Brake does not have a profile on Crunchbase.

New York Air Brake’s Presence on LinkedIn

Yes, New York Air Brake maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/new-york-air-brake.

Cybersecurity Incidents Involving New York Air Brake

As of November 27, 2025, Rankiteo reports that New York Air Brake has not experienced any cybersecurity incidents.

Number of Peer and Competitor Companies

New York Air Brake has an estimated 274 peer or competitor companies worldwide.

New York Air Brake CyberSecurity History Information

How many cyber incidents has New York Air Brake faced ?

Total Incidents: According to Rankiteo, New York Air Brake has faced 0 incidents in the past.

What types of cybersecurity incidents have occurred at New York Air Brake ?

Incident Types: The types of cybersecurity incidents that have occurred include .

Incident Details

What are the most common types of attacks the company has faced ?

Additional Questions

cve

Latest Global CVEs (Not Company-Specific)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.

Risk Information
cvss4
Base: 7.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.

Risk Information
cvss4
Base: 6.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=new-york-air-brake' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge