Comparison Overview
Talbot Underwriting

Talbot Underwriting
58 Fenchurch Street, London, undefined, EC3M 4AB, GB
Last Update: 28/03/2026
Talbot Underwriting Ltd (“Talbot”) is an international insurer and reinsurer operating within the Lloyd’s market through Syndicates 1183 and 2019. We have been part of AIG since 2018 and our ambition is to be AIG’s centre of excellence at Lloyd’s. We have a diversifi...

Lockton
Global, US
Last Update: 30/03/2026
What makes Lockton stand apart is also what makes us better: independence. Our private ownership empowers our 13,100+ Associates doing business in over 140+ countries to focus solely on clients' risk and insurance needs. With expertise that reaches around the globe, we ...
Compliance Ranges Comparison

Talbot Underwriting







Lockton






Benchmark & Cyber Underwriting Signals
Incidents vs Insurance Industry Avg (This Year)
No incidents recorded for Talbot Underwriting in 2026.
Incidents vs Insurance Industry Avg (This Year)
No incidents recorded for Lockton in 2026.
Incident History - Talbot Underwriting (X = Date, Y = Severity)
Talbot Underwriting cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Lockton (X = Date, Y = Severity)
Lockton cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Talbot Underwriting

Lockton
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.