ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Founders Peter Siracuse and David Penrose built Benefit Representatives of America, Inc. on a foundation of Social Security Administration (SSA) experience and desire to provide comprehensive, personalized service. Together they bring over 55 years of experience focused exclusively on understanding and working with Social Security Disability (SSD) and Social Security Supplemental Income (SSI). But there are other professional Social Security representatives out there. So what sets Peter and David apart from the rest? Insider knowledge. Peter and David are former Social Security Administration employees with 25 years of combined insider experience. As prior SSA claims representatives they acquired an abundance of expertise in SSD laws and applications. This one-two punch of comprehensive knowledge on both sides of the desk gives their clients clear advantages over the rest. In other words, Peter and David know who to call to get the answers their clients need. They know what SSA employees are looking for in the disability claims. They know the exact administrative path claims follow inside the SSA. They know the precise information the appeals judge will want to see in the medical records. They possess the knowledge attainable to only those who have actually worked inside the SSA. In addition to their extensive experience, David and Peter are certified non-attorney representatives. This means they have passed a rigorous application and evaluation of their credentials and professional abilities. Only non-attorney representatives are subjected to background investigations of their professional fitness and must pass a thorough examination with a minimum score of 80 percent to be awarded certification. Insider experience has given Peter and David more than knowledge–it has given them compassion. While working in the SSA they watched applications hit dead-ends, costing the frustrated applicant incredible amounts of time. Benefit Representatives of America, Inc. was born out of Peter and David’s desire to offer personalized, compassionate representative service that maximized the benefits due to the applicant. Today, Benefit Representatives of America, Inc. is a full-service SSD and SSI representation agency. Benefit Representatives of America, Inc. will handle your paperwork as well as phone and in-office contacts with SSA and medical staff on your behalf. Peter and David’s experience and personalized, compassionate service will ensure you receive accurate information and the maximum benefits you are due.

Benefit Representatives of America A.I CyberSecurity Scoring

BRA

Company Details

Linkedin ID:

ssareps

Employees number:

8

Number of followers:

34

NAICS:

5411

Industry Type:

Legal Services

Homepage:

ssareps.com

IP Addresses:

0

Company ID:

BEN_4777679

Scan Status:

In-progress

AI scoreBRA Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/ssareps.jpeg
BRA Legal Services
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreBRA Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/ssareps.jpeg
BRA Legal Services
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

BRA Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Supplemental Income Trust FundBreach6033/2021
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: The Maine Office of the Attorney General reported on June 1, 2021, that the Supplemental Income 401(k) Plan experienced a data breach resulting from a phishing attack. The breach occurred between March 22, 2021, and April 21, 2021, potentially affecting the personal information of 3 Maine residents, specifically their Social Security numbers. The Plan is offering 24 months of complimentary identity theft protection services through Experian IdentityWorks.

Supplemental Income Trust Fund
Breach
Severity: 60
Impact: 3
Seen: 3/2021
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: The Maine Office of the Attorney General reported on June 1, 2021, that the Supplemental Income 401(k) Plan experienced a data breach resulting from a phishing attack. The breach occurred between March 22, 2021, and April 21, 2021, potentially affecting the personal information of 3 Maine residents, specifically their Social Security numbers. The Plan is offering 24 months of complimentary identity theft protection services through Experian IdentityWorks.

Ailogo

BRA Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for BRA

Incidents vs Legal Services Industry Average (This Year)

No incidents recorded for Benefit Representatives of America in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Benefit Representatives of America in 2025.

Incident Types BRA vs Legal Services Industry Avg (This Year)

No incidents recorded for Benefit Representatives of America in 2025.

Incident History — BRA (X = Date, Y = Severity)

BRA cyber incidents detection timeline including parent company and subsidiaries

BRA Company Subsidiaries

SubsidiaryImage

Founders Peter Siracuse and David Penrose built Benefit Representatives of America, Inc. on a foundation of Social Security Administration (SSA) experience and desire to provide comprehensive, personalized service. Together they bring over 55 years of experience focused exclusively on understanding and working with Social Security Disability (SSD) and Social Security Supplemental Income (SSI). But there are other professional Social Security representatives out there. So what sets Peter and David apart from the rest? Insider knowledge. Peter and David are former Social Security Administration employees with 25 years of combined insider experience. As prior SSA claims representatives they acquired an abundance of expertise in SSD laws and applications. This one-two punch of comprehensive knowledge on both sides of the desk gives their clients clear advantages over the rest. In other words, Peter and David know who to call to get the answers their clients need. They know what SSA employees are looking for in the disability claims. They know the exact administrative path claims follow inside the SSA. They know the precise information the appeals judge will want to see in the medical records. They possess the knowledge attainable to only those who have actually worked inside the SSA. In addition to their extensive experience, David and Peter are certified non-attorney representatives. This means they have passed a rigorous application and evaluation of their credentials and professional abilities. Only non-attorney representatives are subjected to background investigations of their professional fitness and must pass a thorough examination with a minimum score of 80 percent to be awarded certification. Insider experience has given Peter and David more than knowledge–it has given them compassion. While working in the SSA they watched applications hit dead-ends, costing the frustrated applicant incredible amounts of time. Benefit Representatives of America, Inc. was born out of Peter and David’s desire to offer personalized, compassionate representative service that maximized the benefits due to the applicant. Today, Benefit Representatives of America, Inc. is a full-service SSD and SSI representation agency. Benefit Representatives of America, Inc. will handle your paperwork as well as phone and in-office contacts with SSA and medical staff on your behalf. Peter and David’s experience and personalized, compassionate service will ensure you receive accurate information and the maximum benefits you are due.

Loading...
similarCompanies

BRA Similar Companies

UnionLine

UnionLine is the trading name of Trade Union Legal LLP, launched in 2014 by trade unions GMB and the Communication Workers Union. The aim of the practice is to provide legal services to the 835,000 combined membership of the unions, and to be the first line of support to members for any legal need.

lindenpartners

lindenpartners berät aus Berlin-Mitte heraus Mandanten in ganz Deutschland. 2006 von Anwälten aus Großkanzleien gegründet, ist die Sozietät stetig gewachsen und umfasst heute 35 Anwälte, davon 15 Partner. Wir beraten Mandanten in den klassischen Gebieten des Wirtschaftsrechts. Besonders stark sind w

The Clark Law Firm, PC

Attorney Douglas Clark of The Clark Law Firm, PC provides representaion to landowners in negotiating all contracts comprised within the development of the Marcellus Shale. Doug also hosts a weekly radio show, "All Things Marcellus" with Attorney Douglas Clark; airing on GEM 104 and KZFM 96.9 and in

A full-service business law firm, Veritas Law has expertise in corporate and transactional law, litigation, and licensing. From family-owned businesses and neighborhood restaurants, to multinational companies, our clients’ needs come first. Schedule a free consultation and start solving your busi

RAINWATER, HOLT & SEXTON, P.A.

We’re here to help you investigate your wreck or injury, fill out necessary forms on time, handle conversations with the insurance company, and more. We’re here to answer questions, whether you want to know about the compensation you’re entitled to or paperwork you’ve been asked to sign, and give yo

Dauntless Discovery

Dauntless Discovery provides law firm quality eDiscovery services at competitive pricing. We staff and perform document reviews out of locations in North Carolina and Ohio with the assistance of an experienced workforce who have handled thousands of matters for various Fortune 500 companies. Collect

newsone

BRA CyberSecurity News

October 30, 2025 07:00 AM
Nearly half of VA benefits employees working without pay during government shutdown

Veterans service organizations told the Senate VA Committee that their ability to help veterans and their families is also impacted by the...

October 24, 2025 07:00 AM
US House Democrats push USDA to fund food benefits as shutdown continues

More than 200 Democrats in the U.S. House of Representatives told the Agriculture Department on Friday it should draw on its emergency...

August 27, 2025 07:00 AM
Introducing the Anthropic National Security and Public Sector Advisory Council

Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems.

July 31, 2025 07:00 AM
I'm a cybersecurity CEO who advises over 9,000 agencies and Sam Altman is wrong that the AI fraud crisis is coming—it’s already here

We may soon recognize a "Moore's Law"-style principle for AI that I call “Altman's Law”: every 180 days, AI capabilities double.

May 20, 2025 07:00 AM
MEDIA ADVISORY: Committee Announces “Innovation Nation” Field Hearing on US Cybersecurity Posture at Stanford University’s Hoover Institution – Committee on Homeland Security

The House Committee on Homeland Security announced a field hearing for Wednesday, May 28, at the Hoover Institution at Stanford University.

May 01, 2025 07:00 AM
GOP lawmakers advance proposals to reduce federal benefits, gut civil service protections

House Republicans have advanced a series of proposals attempting to cut costs by reducing the value of federal retirement annuities.

March 19, 2025 07:00 AM
Cybersecurity Experts Are Sounding the Alarm on DOGE

Cybersecurity experts warn that Elon Musk's DOGE is posing risks to both individual citizens and national security.

March 18, 2025 07:00 AM
Social Security Employees Warn of Damage From DOGE

When Eleanor H., 66, called the Social Security Administration last month seeking details about her retirement benefits, she didn't expect...

February 01, 2025 08:00 AM
Senator warns of national security risks after Elon Musk's DOGE granted 'full access' to sensitive Treasury systems

A senior US lawmaker says representatives of Elon Musk were granted “full access” to a US Treasury payments system used to disperse trillions of dollars to...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

BRA CyberSecurity History Information

Official Website of Benefit Representatives of America

The official website of Benefit Representatives of America is http://www.ssareps.com/.

Benefit Representatives of America’s AI-Generated Cybersecurity Score

According to Rankiteo, Benefit Representatives of America’s AI-generated cybersecurity score is 736, reflecting their Moderate security posture.

How many security badges does Benefit Representatives of America’ have ?

According to Rankiteo, Benefit Representatives of America currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Benefit Representatives of America have SOC 2 Type 1 certification ?

According to Rankiteo, Benefit Representatives of America is not certified under SOC 2 Type 1.

Does Benefit Representatives of America have SOC 2 Type 2 certification ?

According to Rankiteo, Benefit Representatives of America does not hold a SOC 2 Type 2 certification.

Does Benefit Representatives of America comply with GDPR ?

According to Rankiteo, Benefit Representatives of America is not listed as GDPR compliant.

Does Benefit Representatives of America have PCI DSS certification ?

According to Rankiteo, Benefit Representatives of America does not currently maintain PCI DSS compliance.

Does Benefit Representatives of America comply with HIPAA ?

According to Rankiteo, Benefit Representatives of America is not compliant with HIPAA regulations.

Does Benefit Representatives of America have ISO 27001 certification ?

According to Rankiteo,Benefit Representatives of America is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Benefit Representatives of America

Benefit Representatives of America operates primarily in the Legal Services industry.

Number of Employees at Benefit Representatives of America

Benefit Representatives of America employs approximately 8 people worldwide.

Subsidiaries Owned by Benefit Representatives of America

Benefit Representatives of America presently has no subsidiaries across any sectors.

Benefit Representatives of America’s LinkedIn Followers

Benefit Representatives of America’s official LinkedIn profile has approximately 34 followers.

NAICS Classification of Benefit Representatives of America

Benefit Representatives of America is classified under the NAICS code 5411, which corresponds to Legal Services.

Benefit Representatives of America’s Presence on Crunchbase

No, Benefit Representatives of America does not have a profile on Crunchbase.

Benefit Representatives of America’s Presence on LinkedIn

Yes, Benefit Representatives of America maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/ssareps.

Cybersecurity Incidents Involving Benefit Representatives of America

As of November 30, 2025, Rankiteo reports that Benefit Representatives of America has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Benefit Representatives of America has an estimated 7,392 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Benefit Representatives of America ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

How does Benefit Representatives of America detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with experian identityworks..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Supplemental Income 401(k) Plan Data Breach

Description: The Maine Office of the Attorney General reported on June 1, 2021, that the Supplemental Income 401(k) Plan experienced a data breach resulting from a phishing attack. The breach occurred between March 22, 2021, and April 21, 2021, potentially affecting the personal information of 3 Maine residents, specifically their Social Security numbers. The Plan is offering 24 months of complimentary identity theft protection services through Experian IdentityWorks.

Date Detected: 2021-04-21

Date Publicly Disclosed: 2021-06-01

Type: Data Breach

Attack Vector: Phishing

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach SSA340072725

Data Compromised: Social security numbers

Identity Theft Risk: High

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information.

Which entities were affected by each incident ?

Incident : Data Breach SSA340072725

Entity Name: Supplemental Income 401(k) Plan

Entity Type: Organization

Industry: Financial Services

Location: Maine

Customers Affected: 3

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach SSA340072725

Third Party Assistance: Experian Identityworks.

How does the company involve third-party assistance in incident response ?

Third-Party Assistance: The company involves third-party assistance in incident response through Experian IdentityWorks, .

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach SSA340072725

Type of Data Compromised: Personal Information

Number of Records Exposed: 3

Sensitivity of Data: High

Personally Identifiable Information: Social Security numbers

References

Where can I find more information about each incident ?

Incident : Data Breach SSA340072725

Source: Maine Office of the Attorney General

Date Accessed: 2021-06-01

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2021-06-01.

Post-Incident Analysis

What is the company's process for conducting post-incident analysis ?

Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Experian Identityworks, .

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2021-04-21.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2021-06-01.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Social Security numbers and .

Response to the Incidents

What third-party assistance was involved in the most recent incident ?

Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was experian identityworks, .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach was Social Security numbers.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 3.0.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Maine Office of the Attorney General.

cve

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing manipulation can lead to use of hard-coded cryptographic key . The physical device can be targeted for the attack. A high complexity level is associated with this attack. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 1.2
Severity: HIGH
AV:L/AC:H/Au:N/C:P/I:N/A:N
cvss3
Base: 2.0
Severity: HIGH
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
cvss4
Base: 1.0
Severity: HIGH
CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files based solely on an authenticated session and user-supplied identifiers, without verifying whether the requester has permission to access the associated interview record. Because the server does not perform any recruitment-level authorization checks, an ESS-level user with no access to recruitment workflows can directly request interview attachment URLs and receive the corresponding files. This exposes confidential interview documents—including candidate CVs, evaluations, and supporting files—to unauthorized users. The issue arises from relying on predictable object identifiers and session presence rather than validating the user’s association with the relevant recruitment process. This issue has been patched in version 5.8.

Risk Information
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required authorization checks before serving candidate files. Even users restricted to ESS-level access, who have no permission to view the Recruitment module, can directly access candidate attachment URLs. When an authenticated request is made to the attachment endpoint, the system validates the session but does not confirm that the requesting user has the necessary recruitment permissions. As a result, any authenticated user can download CVs and other uploaded documents for arbitrary candidates by issuing direct requests to the attachment endpoint, leading to unauthorized exposure of sensitive applicant data. This issue has been patched in version 5.8.

Risk Information
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain valid indefinitely. As a result, a disabled user, or an attacker using a compromised account, can continue to access protected pages and perform operations as long as a prior session remains active. Because the server performs no session revocation or session-store cleanup during these critical state changes, disabling an account or updating credentials has no effect on already-established sessions. This makes administrative disable actions ineffective and allows unauthorized users to retain full access even after an account is closed or a password is reset, exposing the system to prolonged unauthorized use and significantly increasing the impact of account takeover scenarios. This issue has been patched in version 5.8.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset process was originally initiated. After obtaining a valid reset link for any account they can receive email for, an attacker can alter the username parameter in the final reset request to target a different user. Because the system accepts the supplied username without verification, the attacker can set a new password for any chosen account, including privileged accounts, resulting in full account takeover. This issue has been patched in version 5.8.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=ssareps' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge