Comparison Overview

Orchestra of St. Luke's (OSL)

VS

Culture Project

Orchestra of St. Luke's (OSL)

450 West 37th Street, New York, undefined, 10036, US
Last Update: 2025-12-13
Between 750 and 799

Called “[New York’s} hometown band” by The New York Times, OSL performs at venues throughout the city including Carnegie Hall, Lincoln Center, New York City Center, Merkin Hall, The Morgan Library and Museum, Brooklyn Museum, and many more. OSL is dedicated to cultivating a lifetime of engagement with classical music and offers free instrumental training and mentorship for students from elementary school through conservatory and beyond; produces guided community and educational performances for thousands of students and families; and owns and operates The DiMenna Center for Classical Music, New York City’s only rehearsal, recording, education, and performance facility expressly dedicated to classical music, serving more than 500 ensembles and more than 30,000 musicians each year. OSL has participated in 118 recordings, four of; which have won Grammy Awards; has commissioned more than 50 new works; and has given more than 179 world, US, and New York City premieres. Recent guests and collaborators include cellist Alisa Weilerstein, tenor Jonas Kauffman, composer Gabriela Lena-Frank, violinist Christian Tetzlaff, and pianist Jeremy Denk. As New York Magazine notes, the Orchestra has a “...reputation for being able to play virtually any score as if the musicians had all grown up with it under their pillows.” Learn more at OSLmusic.org or @OSLmusic on Instagram, Facebook, Spotify and more. See behind the scenes of New York City's music-making community at The DiMenna Center for Classical Music @TheDiMennaCenter on Facebook and Instagram

NAICS: 711
NAICS Definition:
Employees: 62
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Culture Project

49 Bleecker Street, Suite 602, New York, New York, US, 10012
Last Update: 2025-12-14

Culture Project is dedicated to addressing critical human rights issues by shining an artistic spotlight on injustice. By fostering innovative collaboration between human rights organizations and artists, they aim to inspire and impact public dialogue, encouraging democratic participation in the most urgent matters of our time. Founded by Allan Buchman in 1996, Culture Project has premiered celebrated shows including The Exonerated, Sarah Jones’ Bridge & Tunnel, Guantanamo: Honor Bound to Defend Freedom, Lawrence Wright’s My Trip To Al-Qaeda, Tings Dey Happen, the Lucille Lortel Award-winning world premiere of George Packer’s Betrayed, and Temple University’s acclaimed production of In Conflict. Culture Project also produced "Breaking the Silence, Beating the Drum", a groundbreaking concert at the United Nations to commemorate the abolition of the Trans-Atlantic Slave Trade. In 2012, Culture Project celebrated its return to the theaters at 45 Bleecker Street. Since then, productions have included James X, directed by Gabriel Byrne, the revival of Rinde Eckert's acclaimed And God Created Great Whales, Shaheed: The Dream and Death of Benazir Bhutto, along with the 10th anniversary remount of The Exonerated.

NAICS: 7111
NAICS Definition: Performing Arts Companies
Employees: 10
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/orchestra-of-st--luke's.jpeg
Orchestra of St. Luke's (OSL)
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/culture-project.jpeg
Culture Project
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Orchestra of St. Luke's (OSL)
100%
Compliance Rate
0/4 Standards Verified
Culture Project
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Performing Arts Industry Average (This Year)

No incidents recorded for Orchestra of St. Luke's (OSL) in 2025.

Incidents vs Performing Arts Industry Average (This Year)

No incidents recorded for Culture Project in 2025.

Incident History — Orchestra of St. Luke's (OSL) (X = Date, Y = Severity)

Orchestra of St. Luke's (OSL) cyber incidents detection timeline including parent company and subsidiaries

Incident History — Culture Project (X = Date, Y = Severity)

Culture Project cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/orchestra-of-st--luke's.jpeg
Orchestra of St. Luke's (OSL)
Incidents

No Incident

https://images.rankiteo.com/companyimages/culture-project.jpeg
Culture Project
Incidents

No Incident

FAQ

Both Orchestra of St. Luke's (OSL) company and Culture Project company demonstrate a comparable AI Cybersecurity Score, with strong governance and monitoring frameworks in place.

Historically, Culture Project company has disclosed a higher number of cyber incidents compared to Orchestra of St. Luke's (OSL) company.

In the current year, Culture Project company and Orchestra of St. Luke's (OSL) company have not reported any cyber incidents.

Neither Culture Project company nor Orchestra of St. Luke's (OSL) company has reported experiencing a ransomware attack publicly.

Neither Culture Project company nor Orchestra of St. Luke's (OSL) company has reported experiencing a data breach publicly.

Neither Culture Project company nor Orchestra of St. Luke's (OSL) company has reported experiencing targeted cyberattacks publicly.

Neither Orchestra of St. Luke's (OSL) company nor Culture Project company has reported experiencing or disclosing vulnerabilities publicly.

Neither Orchestra of St. Luke's (OSL) nor Culture Project holds any compliance certifications.

Neither company holds any compliance certifications.

Neither Orchestra of St. Luke's (OSL) company nor Culture Project company has publicly disclosed detailed information about the number of their subsidiaries.

Orchestra of St. Luke's (OSL) company employs more people globally than Culture Project company, reflecting its scale as a Performing Arts.

Neither Orchestra of St. Luke's (OSL) nor Culture Project holds SOC 2 Type 1 certification.

Neither Orchestra of St. Luke's (OSL) nor Culture Project holds SOC 2 Type 2 certification.

Neither Orchestra of St. Luke's (OSL) nor Culture Project holds ISO 27001 certification.

Neither Orchestra of St. Luke's (OSL) nor Culture Project holds PCI DSS certification.

Neither Orchestra of St. Luke's (OSL) nor Culture Project holds HIPAA certification.

Neither Orchestra of St. Luke's (OSL) nor Culture Project holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

Risk Information
cvss3
Base: 8.1
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Risk Information
cvss3
Base: 2.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description

A vulnerability was detected in Mayan EDMS up to 4.10.1. The affected element is an unknown function of the file /authentication/. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.10.2 is sufficient to fix this issue. You should upgrade the affected component. The vendor confirms that this is "[f]ixed in version 4.10.2". Furthermore, that "[b]ackports for older versions in process and will be out as soon as their respective CI pipelines complete."

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Risk Information
cvss3
Base: 4.5
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Risk Information
cvss3
Base: 5.8
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N