Comparison Overview

Southeastern Railway Museum

VS

First Division Museum at Cantigny

Southeastern Railway Museum

3595 Buford Hwy, Duluth, GA, US, 30096
Last Update: 2025-12-01

The Southeastern Railway Museum occupies a 35-acre site in Duluth, Georgia, in northeast suburban Atlanta. In operation since 1970, the Museum features about 90 items of rolling stock including historic Pullman cars and classic steam locomotives. It is owned and operated by the Atlanta Chapter of the National Railway Historical Society. The Southeastern Railway Museum is recognized by the IRS as a 501(c)(3) non-profit organization for historical and educational purposes. The museum is staffed almost completely with volunteers.

NAICS: 712
NAICS Definition: Museums, Historical Sites, and Similar Institutions
Employees: 18
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

First Division Museum at Cantigny

1 S 151 Winfield Road, Wheaton, IL, 60189, US
Last Update: 2025-12-03

The First Division Museum at Cantigny is dedicated to the1st Infantry Division of the US Army, the famous "Big Red One." Located on Cantigny Park in Wheaton, IL, the historic home and estate of the late Colonel Robert R.McCormick, the museum presents the history of America's first and oldest, continuously serving combat division. Formed for World War I in June,1917, the Big Red One has seen action in all of America's wars since, with the exception of the Korean War (1950-1953), when the division wason occupation duty in Germany. The division's story is told in breath-taking, immersive and interactive galleries, including the trenches of the First World War Western Front, Omaha Beach of D-Day fame in Normandy, France,during WorldWar I, and the triple canopy jungles of Vietnam. The museum houses15,000 artifacts,includes a research center with over 200,000 books and documents, and hasa vigorous public and educational programming and outreach agenda. The museum and park were bequeathed to "the peopleof Illinois" by Colonel McCormick in 1955 and are named for the village and battle of Cantigny, France, where McCormick served with the First Division in World War I. The Colonel went on to be the owner and publisher of the Chicago Tribune until his death. The museum and park are operated by the Robert R. McCormick Foundation of Chicago.

NAICS: 712
NAICS Definition:
Employees: 13
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/southeastern-railway-museum.jpeg
Southeastern Railway Museum
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/first-division-museum-at-cantigny.jpeg
First Division Museum at Cantigny
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Southeastern Railway Museum
100%
Compliance Rate
0/4 Standards Verified
First Division Museum at Cantigny
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Museums, Historical Sites, and Zoos Industry Average (This Year)

No incidents recorded for Southeastern Railway Museum in 2025.

Incidents vs Museums, Historical Sites, and Zoos Industry Average (This Year)

No incidents recorded for First Division Museum at Cantigny in 2025.

Incident History — Southeastern Railway Museum (X = Date, Y = Severity)

Southeastern Railway Museum cyber incidents detection timeline including parent company and subsidiaries

Incident History — First Division Museum at Cantigny (X = Date, Y = Severity)

First Division Museum at Cantigny cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/southeastern-railway-museum.jpeg
Southeastern Railway Museum
Incidents

No Incident

https://images.rankiteo.com/companyimages/first-division-museum-at-cantigny.jpeg
First Division Museum at Cantigny
Incidents

No Incident

FAQ

Southeastern Railway Museum company demonstrates a stronger AI Cybersecurity Score compared to First Division Museum at Cantigny company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, First Division Museum at Cantigny company has disclosed a higher number of cyber incidents compared to Southeastern Railway Museum company.

In the current year, First Division Museum at Cantigny company and Southeastern Railway Museum company have not reported any cyber incidents.

Neither First Division Museum at Cantigny company nor Southeastern Railway Museum company has reported experiencing a ransomware attack publicly.

Neither First Division Museum at Cantigny company nor Southeastern Railway Museum company has reported experiencing a data breach publicly.

Neither First Division Museum at Cantigny company nor Southeastern Railway Museum company has reported experiencing targeted cyberattacks publicly.

Neither Southeastern Railway Museum company nor First Division Museum at Cantigny company has reported experiencing or disclosing vulnerabilities publicly.

Neither Southeastern Railway Museum nor First Division Museum at Cantigny holds any compliance certifications.

Neither company holds any compliance certifications.

Neither Southeastern Railway Museum company nor First Division Museum at Cantigny company has publicly disclosed detailed information about the number of their subsidiaries.

Southeastern Railway Museum company employs more people globally than First Division Museum at Cantigny company, reflecting its scale as a Museums, Historical Sites, and Zoos.

Neither Southeastern Railway Museum nor First Division Museum at Cantigny holds SOC 2 Type 1 certification.

Neither Southeastern Railway Museum nor First Division Museum at Cantigny holds SOC 2 Type 2 certification.

Neither Southeastern Railway Museum nor First Division Museum at Cantigny holds ISO 27001 certification.

Neither Southeastern Railway Museum nor First Division Museum at Cantigny holds PCI DSS certification.

Neither Southeastern Railway Museum nor First Division Museum at Cantigny holds HIPAA certification.

Neither Southeastern Railway Museum nor First Division Museum at Cantigny holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.

Risk Information
cvss3
Base: 4.9
Severity: HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Description

FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in an executable location) without sufficient validation, sanitization, or execution restrictions. An authenticated remote attacker can upload a crafted PHP file and cause the application or web server to execute it, resulting in remote code execution (RCE).

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description

PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query.

Risk Information
cvss3
Base: 6.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.

Risk Information
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which in certain deployment scenarios can enable users on client workstations to modify the program executables and libraries.

Risk Information
cvss3
Base: 8.0
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
cvss4
Base: 7.1
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X