Company Details
petrofac_3
15,814
1,654,395
54139
petrofac.com
0
PET_4502697
In-progress

Petrofac Company CyberSecurity Posture
petrofac.comWe are a leading international service provider to the energy industry, with a diverse client portfolio including many of the world’s leading energy companies. Petrofac designs, builds, manages and maintains oil, gas, refining, petrochemicals and renewable energy infrastructure. Our purpose is to enable our clients to meet the world’s evolving energy needs. Our core markets are in the Middle East and North Africa (MENA) region and the UK North Sea, where we have built a long and successful track record of safe, reliable and innovative execution, underpinned by a cost effective and local delivery model with a strong focus on in-country value. We operate in several other significant markets, including India, South East Asia and the United States. We have 8,200 employees based across more than 30 offices globally. Petrofac is quoted on the London Stock Exchange (symbol: PFC). To find out more, visit www.petrofac.com
Company Details
petrofac_3
15,814
1,654,395
54139
petrofac.com
0
PET_4502697
In-progress
Between 800 and 849

Petrofac Global Score (TPRM)XXXX



No incidents recorded for Petrofac in 2025.
No incidents recorded for Petrofac in 2025.
No incidents recorded for Petrofac in 2025.
Petrofac cyber incidents detection timeline including parent company and subsidiaries

We are a leading international service provider to the energy industry, with a diverse client portfolio including many of the world’s leading energy companies. Petrofac designs, builds, manages and maintains oil, gas, refining, petrochemicals and renewable energy infrastructure. Our purpose is to enable our clients to meet the world’s evolving energy needs. Our core markets are in the Middle East and North Africa (MENA) region and the UK North Sea, where we have built a long and successful track record of safe, reliable and innovative execution, underpinned by a cost effective and local delivery model with a strong focus on in-country value. We operate in several other significant markets, including India, South East Asia and the United States. We have 8,200 employees based across more than 30 offices globally. Petrofac is quoted on the London Stock Exchange (symbol: PFC). To find out more, visit www.petrofac.com


𝐀 𝐰𝐨𝐫𝐥𝐝 𝐥𝐞𝐚𝐝𝐞𝐫 𝐢𝐧 𝐄𝐧𝐠𝐢𝐧𝐞𝐞𝐫𝐢𝐧𝐠 𝐚𝐧𝐝 𝐈𝐓 𝐒𝐞𝐫𝐯𝐢𝐜𝐞𝐬 ALTEN is committed to meeting the expectations of its stakeholders and anticipating their requirements in the fields of innovation, R&D, and technological information systems. Founded in 1988 and present in 30+ countries, the Group has established its

UGL is CIMIC Group's specialist end-to-end engineering, services and operations provider. We have a rich history dating back to 1899 and since then we have grown to be a market leader in many of the sectors in which we operate. Working with some of the most important companies and governments in Au

Atkins is now AtkinsRéalis. Please follow AtkinsRéalis on LinkedIn. We are a world-class engineering services and nuclear organization. We connect people, data and technology to transform the world’s infrastructure and energy systems. Together, with our industry partners and clients, and our glob
We're a global product engineering and digital services company focused on fulfilling our mission of helping the world drive, fly, build, and farm by enabling our customers to realize better products and deliver better experiences. We’re the strategic engineering partner businesses turn to when they

At ST Engineering, we apply our technology and innovation to solve real-world problems and improve lives. Our commitment to excellence and our track record as a global technology, defence, and engineering company earns us a reputation for quality and trust. Subscribe to get the latest news de
Saipem is a global leader in the engineering and construction of major projects for the energy and infrastructure sectors, both offshore and onshore. Saipem is “One Company” organized into business lines: Asset Based Services, Drilling, Energy Carriers, Offshore Wind, Sustainable Infrastructures, Ro
We are a world-class engineering services and nuclear organization. We connect people, data and technology to transform the world’s infrastructure and energy systems. Together, with our industry partners and clients, and our global team of consultants, designers, engineers and project manager
We are Quest Global. We’re in the business of engineering, but what we’re really building is a brighter future. It’s not just what we do, but why we do it that makes us different. We believe engineering has the unique opportunity to solve the problems of today that stand in the way of tomorrow. For

L&T Technology Services (LTTS) is one of the world’s leading engineering and technology service providers. With operations in over 25 countries and a growing annual revenue that now surpasses USD 1.2 billion, we work with organizations who design, develop or deliver products and services. We help
.png)
Event tackles how AI is reshaping cyber threats, defence, governance & real-time security.
Dubai: Petrofac's collapse has become more than a company crisis — it's a stress test for how the global energy industry manages risk.
Cybersecurity council chief Mohamed Al Kuwaiti says 100 per cent security is within reach.
Our knowledge and insight coupled with the right set of tools help us understand the factors that lead to risk and allow us to manage them effectively.
'Hacktivists' using AI for more effective 'distributed denial-of-service' strikes.
With a global IT crisis in her first week, Samantha, our Chief Information Officer (CIO) had an interesting start to her career at Petrofac.
Here are the worldwide cybersecurity job openings available as of June 10, 2025, including on-site, hybrid, and remote roles.
Hamad Obaid Al Mansoori, director general of Digital Dubai, will be speaking at the conference to discuss how technology and AI has been...
Cyber security council chief Mohamed Al Kuwaiti says partnerships are key to country's success in the sector.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Petrofac is http://www.petrofac.com.
According to Rankiteo, Petrofac’s AI-generated cybersecurity score is 801, reflecting their Good security posture.
According to Rankiteo, Petrofac currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Petrofac is not certified under SOC 2 Type 1.
According to Rankiteo, Petrofac does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Petrofac is not listed as GDPR compliant.
According to Rankiteo, Petrofac does not currently maintain PCI DSS compliance.
According to Rankiteo, Petrofac is not compliant with HIPAA regulations.
According to Rankiteo,Petrofac is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Petrofac operates primarily in the Engineering Services industry.
Petrofac employs approximately 15,814 people worldwide.
Petrofac presently has no subsidiaries across any sectors.
Petrofac’s official LinkedIn profile has approximately 1,654,395 followers.
Petrofac is classified under the NAICS code 54139, which corresponds to Engineering Services.
Yes, Petrofac has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/petrofac.
Yes, Petrofac maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/petrofac_3.
As of December 11, 2025, Rankiteo reports that Petrofac has not experienced any cybersecurity incidents.
Petrofac has an estimated 1,305 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, Petrofac has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.