ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

SH:24 is a fully integrated digital sexual and reproductive health service, delivered in partnership with the UK’s National Health Service. SH:24 makes it easier for people to access STI testing, chlamydia treatment, partner notification, contraception and clinical support - 24 hours a day. Working in partnership with specialist sexual & reproductive health providers and primary care, SH:24 helps to transform and modernise healthcare services. We put people at the heart of what we do. We design services that are easier to use, access and understand. We are not-for-profit and passionate about delivering discreet, convenient and clinically safe experiences. Our brands include Fettle.health (https://fettle.health/), which offers users the choice of paying for sexual and reproductive health services online.

SH:24 A.I CyberSecurity Scoring

SH:24

Company Details

Linkedin ID:

sh-24

Employees number:

162

Number of followers:

2,828

NAICS:

923

Industry Type:

Public Health

Homepage:

sh24.org.uk

IP Addresses:

0

Company ID:

SH:_7148148

Scan Status:

In-progress

AI scoreSH:24 Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/sh-24.jpeg
SH:24 Public Health
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreSH:24 Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/sh-24.jpeg
SH:24 Public Health
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

SH:24 Company CyberSecurity News & History

Past Incidents
0
Attack Types
0
No data available
Ailogo

SH:24 Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for SH:24

Incidents vs Public Health Industry Average (This Year)

No incidents recorded for SH:24 in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for SH:24 in 2025.

Incident Types SH:24 vs Public Health Industry Avg (This Year)

No incidents recorded for SH:24 in 2025.

Incident History — SH:24 (X = Date, Y = Severity)

SH:24 cyber incidents detection timeline including parent company and subsidiaries

SH:24 Company Subsidiaries

SubsidiaryImage

SH:24 is a fully integrated digital sexual and reproductive health service, delivered in partnership with the UK’s National Health Service. SH:24 makes it easier for people to access STI testing, chlamydia treatment, partner notification, contraception and clinical support - 24 hours a day. Working in partnership with specialist sexual & reproductive health providers and primary care, SH:24 helps to transform and modernise healthcare services. We put people at the heart of what we do. We design services that are easier to use, access and understand. We are not-for-profit and passionate about delivering discreet, convenient and clinically safe experiences. Our brands include Fettle.health (https://fettle.health/), which offers users the choice of paying for sexual and reproductive health services online.

Loading...
similarCompanies

SH:24 Similar Companies

Delaware Public Health District

The Delaware Public Health District came into existence in the early part of the 1900's after the flu pandemic which killed over 25 million people world wide, with over 500,000 dead in the United States. State government officials, following the flu pandemic and other serious health threats, realize

Dr Consulta

¿Eres médico? ¡AFILIATE! Somos una Red de Servicios de Salud a Nivel Nacional. A través de nuestro portal web y medios sociales, tus potenciales nuevos pacientes te podrán localizar, te brindamos un respaldo integral para que tu negocio de salud crezca en tu sector. Ahora cuentas con un servicio que

Health Promotion & Wellness | San Francisco State University

Health Promotion & Wellness (HPW) provides health education for the SF State community through campus health initiatives and programming. Our focus areas include alcohol, tobacco and other drugs, mental health, nutrition, sleep, men's health, sexual health, and peer health leadership. We work to ach

Brandenburg

Our vision is to develop sustainable and innovative solutions, providing peace of mind, protecting public health and working in harmony with nature. Our leading commercial and retail brands deliver innovative pest management solutions and garden care products to a global customer base of more than

Bedsider Providers

Bedsider Providers is a project of Power to Decide and Bedsider, focused on supporting health care providers in delivering effective, patient-centered sexual and reproductive health care. Our goal is to make sexual and reproductive health care more accessible, approachable, and effective for everyon

Vaccine Ambassadors

Through a joint initiative, Facilitating Equitable Access to Vaccines in the Americas, with our partners at the Pan American Health Organization, Vaccine Ambassadors funds the purchase and shipping of high-quality vaccines for children and families residing in Latin America and the Caribbean. In or

newsone

SH:24 CyberSecurity News

October 24, 2025 07:00 AM
DoT Hosts Cyber Security Awareness Webinar to Strengthen Telecom Sector Resilience

DoT Hosts Cyber Security Awareness Webinar to Strengthen Telecom Sector Resilience. Experts Highlight Phishing, AI Threats in Cyber Security

February 26, 2025 08:00 AM
Leaked Black Basta Ransomware Chat Logs Reveal Inner Workings and Internal Conflicts

Leaked Black Basta chat logs expose internal conflicts, $107M in ransom earnings, and new attack tactics.

July 04, 2024 07:00 AM
General public is alerted on fake and fraudulent e-mails bearing names, signatures, stamps and logos of Delhi Police Cyber Crime and Economic Offence, Central Economic Intelligence Bureau (CEIB), Intelligence Bureau and Cyber Cell, Delhi

The fake letter levels allegations of child pornography, pedophilia, cyber pornography, sexual explicit exhibit, grooming etc. against probable victims.

August 23, 2022 07:00 AM
Equity half year net profit up 36pc to Sh24.4 billion - VIDEO

Equity Group has posted a 36 percent jump in net profits to Sh24.4 billion in the first half of this year on increased lending and strong...

July 19, 2019 07:00 AM
Cyber threats in Kenya are increasing in frequency and magnitude

New research from Kenya's Communications Authority (CA) has indicated that the increasingly digitalising business environment in Kenya is...

June 01, 2019 05:49 PM
SH-24/US-30 closure planned under I-84 (Exit 211) – watch for detours this weekend

The Idaho Transportation Department is closing State Highway 24/U.S. Highway 30 under Interstate 84 at Exit 211 from Friday, April 4, at 6 p.m. through...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

SH:24 CyberSecurity History Information

Official Website of SH:24

The official website of SH:24 is https://sh24.org.uk.

SH:24’s AI-Generated Cybersecurity Score

According to Rankiteo, SH:24’s AI-generated cybersecurity score is 763, reflecting their Fair security posture.

How many security badges does SH:24’ have ?

According to Rankiteo, SH:24 currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does SH:24 have SOC 2 Type 1 certification ?

According to Rankiteo, SH:24 is not certified under SOC 2 Type 1.

Does SH:24 have SOC 2 Type 2 certification ?

According to Rankiteo, SH:24 does not hold a SOC 2 Type 2 certification.

Does SH:24 comply with GDPR ?

According to Rankiteo, SH:24 is not listed as GDPR compliant.

Does SH:24 have PCI DSS certification ?

According to Rankiteo, SH:24 does not currently maintain PCI DSS compliance.

Does SH:24 comply with HIPAA ?

According to Rankiteo, SH:24 is not compliant with HIPAA regulations.

Does SH:24 have ISO 27001 certification ?

According to Rankiteo,SH:24 is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of SH:24

SH:24 operates primarily in the Public Health industry.

Number of Employees at SH:24

SH:24 employs approximately 162 people worldwide.

Subsidiaries Owned by SH:24

SH:24 presently has no subsidiaries across any sectors.

SH:24’s LinkedIn Followers

SH:24’s official LinkedIn profile has approximately 2,828 followers.

SH:24’s Presence on Crunchbase

No, SH:24 does not have a profile on Crunchbase.

SH:24’s Presence on LinkedIn

Yes, SH:24 maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/sh-24.

Cybersecurity Incidents Involving SH:24

As of November 28, 2025, Rankiteo reports that SH:24 has not experienced any cybersecurity incidents.

Number of Peer and Competitor Companies

SH:24 has an estimated 280 peer or competitor companies worldwide.

SH:24 CyberSecurity History Information

How many cyber incidents has SH:24 faced ?

Total Incidents: According to Rankiteo, SH:24 has faced 0 incidents in the past.

What types of cybersecurity incidents have occurred at SH:24 ?

Incident Types: The types of cybersecurity incidents that have occurred include .

Incident Details

What are the most common types of attacks the company has faced ?

Additional Questions

cve

Latest Global CVEs (Not Company-Specific)

Description

ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.

Risk Information
cvss4
Base: 6.2
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).

Risk Information
cvss3
Base: 9.9
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Description

Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.

Description

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=sh-24' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge