Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Tata Group

Tata Group Vendor Cyber Rating & Cyber Score

tata.com

Founded by Jamsetji Tata in 1868, the Tata group is a global enterprise headquartered in India. The group operates in more than 100 countries across six continents with a mission 'To improve the quality of life of the communities we serve globally, through long-term stakeholder value creation based on Leadership with Trust'​. Sixty-six per cent of the equity of Tata Sons, the promoter holding company, is held by philanthropic trusts, thereby returning wealth to society. The Tata name has been respected in India for 150 years for its adherence to strong values and business ethics. The companies of the Tata group employ the best and finest, strengthened by a culture of ethics and integrity. Today we stand strong at 702,454 employees.


Tata Group A.I CyberSecurity Scoring

Tata Group
Company Information
Website:http://www.tata.com
Employees number:1,017,747
Number of followers:5,858,772
NAICS:92111
Industry Type:Executive Offices
Homepage:tata.com
Tata Group Risk Score (AI oriented)
Between 750 and 799
logo
Tata GroupExecutive Offices
Updated:
13/09/2026
782/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Tata Group Global Score (TPRM)
xxxx
logo
Tata GroupExecutive Offices
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Tata GroupFair
Current Score
782Baa (FAIR)
01000
3 incidents
-13.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
782Before Incident
AUGUST 2026
781Before Incident
JULY 2026
781Before Incident
JUNE 2026
805Before Incident
Breach
28 Jun 2026Tata Group
Tata Group and Apple: Apple Strengthens Cooperation with Tata Following Cyber-Attack on Supplier

Cyberattack on Tata Group Subsidiary in Apple's Supply Chain

780After Incident
HIGH-25
TATRED1782606562
Apple and Tata Group Respond to Cyberattack on Supply Chain Partner California-based Apple is deepening its collaboration with India’s Tata Group after a cyberattack on a Tata subsidiary exposed sensitive internal files. The breach, which targeted a company within Apple’s supply chain, prompted immediate investigations by cybersecurity teams to assess the scope of compromised data. Apple is working closely with Tata Group and authorities to contain the incident, though no disruptions to manufacturing or shipping operations have been reported. The attack underscores growing cybersecurity risks in global supply chains, particularly as Apple expands its production footprint in India. The partnership between Apple and Tata covering device assembly, manufacturing, and after-sales services is a cornerstone of Apple’s strategy to diversify its supply chain beyond traditional hubs. The incident highlights the need for heightened security measures as the company scales operations in new markets.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive internal filesOperational Impact: No disruptions to manufacturing or shipping operations reported
DATA BREACH
Type Of Data Compromised: Sensitive internal filesSensitivity Of Data: High
MAY 2026
803Before Incident
APRIL 2026
803Before Incident
MARCH 2026
831Before Incident
FEBRUARY 2026
831Before Incident
JANUARY 2026
801Before Incident
Vulnerability
13 Jan 2026Tata Group
Microsoft: CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963)

Critical SharePoint RCE Vulnerability (CVE-2026-20963) Under Active Exploitation

799After Incident
CRITICAL-2
MIC1773923106
Critical SharePoint RCE Vulnerability (CVE-2026-20963) Under Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that CVE-2026-20963, a remote code execution (RCE) vulnerability in Microsoft SharePoint, is being actively exploited in the wild. The flaw was patched by Microsoft in January 2026 but has since been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog as of Wednesday. ### Vulnerability Details - Affected Products: Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. - Root Cause: Improper deserialization of untrusted data, allowing unauthenticated attackers to execute arbitrary code remotely. - Attack Complexity: Low no user interaction is required for exploitation. - Impact: Successful exploitation could enable attackers to inject and run malicious code on vulnerable SharePoint servers, potentially granting access to sensitive corporate data or serving as an entry point into broader network environments. Microsoft initially assessed the vulnerability as "less likely" to be exploited but still urged organizations to apply the patch immediately. Despite the warning, active exploitation has now been observed. ### CISA’s Response & Deadline CISA’s inclusion of CVE-2026-20963 in the KEV catalog mandates that U.S. federal civilian agencies remediate the flaw by March 21, 2026. While Microsoft has not yet updated its advisory to confirm active attacks, CISA’s action underscores the urgency for all SharePoint users including private and public sector organizations to apply the fix if they haven’t already. SharePoint vulnerabilities remain a high-value target for threat actors due to the platform’s role in storing critical business data and facilitating internal network access.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Sensitive corporate dataSystems Affected: Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Enterprise Server 2016Operational Impact: Potential unauthorized access to internal networks
DATA BREACH
Type Of Data Compromised: Sensitive corporate dataSensitivity Of Data: High
DECEMBER 2025
800Before Incident
NOVEMBER 2025
799Before Incident
OCTOBER 2025
798Before Incident
SEPTEMBER 2025
831Before Incident
Ransomware
02 Sep 2025Tata Group
Marks & Spencer

DragonForce Ransomware Cartel Emerges from Conti’s Leaked Source Code

796After Incident
CRITICAL-35
MAR1193411110425
Marks & Spencer (M&S), a prominent UK retailer, fell victim to a coordinated ransomware attack linked to the DragonForce cartel and its affiliate Scattered Spider. The incident involved the deployment of DragonForce-built ransomware, leveraging Conti’s leaked source code with advanced encryption (ChaCha20 + RSA) and network-spreading capabilities via SMB. The attack targeted both local and shared network storage, with operators threatening to delete decryptors and leak stolen data if ransom demands were unmet by deadlines (September 2 and 22).The breach disrupted M&S’s operations, risking customer data exposure, financial fraud, and reputational damage due to media coverage. DragonForce’s cartel model—recruiting affiliates like Devman and Scattered Spider—amplified the attack’s sophistication, combining initial access tactics with aggressive data exfiltration. While the full scope of compromised data (e.g., payment details, personal records) remains undisclosed, the incident aligns with DragonForce’s pattern of high-impact extortion, including threats to publish sensitive information. The attack underscores the escalating risks posed by ransomware-as-a-service (RaaS) ecosystems, where collaborative cybercriminal groups exploit enterprise vulnerabilities for maximal disruption and profit.
INCIDENT DETAILS -
TYPE
ransomwarecartel-style cybercrime operationaffiliate-based attack
MOTIVATION
financial gaindominance in ransomware ecosystemrecruitment of affiliatesdisruption of rival groups
IMPACT
local storagenetwork shares via SMBencryption of filespotential data leaks (threatened for September 2 and 22)disruption of rival ransomware operations (e.g., BlackLock, Ransomhub)potential reputational damage to affected entities (e.g., Marks & Spencer)undermining trust in rival ransomware groups
DATA BREACH
threatened (e.g., leaks scheduled for September 2 and 22)ChaCha20 + RSA per-file encryption10-byte metadata block (encodes mode, percentage, size)supports full (0x24), partial (0x25), and header-only (0x26) modes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Tata Group ?
?
What was Tata Group's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Tata Group's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Tata Group's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Tata Group ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Tata Group's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?