Company Details
the-curtis-group
39
951
561
thecurtisgroup.com
0
THE_1771237
In-progress

The Curtis Group Company CyberSecurity Posture
thecurtisgroup.comThe Curtis Group is committed to promoting philanthropy and helping nonprofits plan their future, build awareness, and raise substantial amounts of money. Since our founding in 1989, The Curtis Group has raised hundreds of millions of dollars and worked with nearly 200 nonprofits across all sectors: arts and cultural, educational, environment and animals, civic and public affairs, human services, and health care. We have met the rigorous standards of the prestigious Giving Institute, an organization composed of nearly 50 of North America’s leading fundraising consulting firms. As a Giving Institute member, we are involved in Giving USA, the annual report on philanthropy; contribute to ongoing thought leadership on philanthropy; and have access to important statistics, reports, and projections on giving and fundraising. Curtis Group’s principals are frequent presenters for many national and regional industry and sector conferences, and have each contributed articles to national philanthropy trade publications.
Company Details
the-curtis-group
39
951
561
thecurtisgroup.com
0
THE_1771237
In-progress
Between 750 and 799

CG Global Score (TPRM)XXXX



No incidents recorded for The Curtis Group in 2025.
No incidents recorded for The Curtis Group in 2025.
No incidents recorded for The Curtis Group in 2025.
CG cyber incidents detection timeline including parent company and subsidiaries

The Curtis Group is committed to promoting philanthropy and helping nonprofits plan their future, build awareness, and raise substantial amounts of money. Since our founding in 1989, The Curtis Group has raised hundreds of millions of dollars and worked with nearly 200 nonprofits across all sectors: arts and cultural, educational, environment and animals, civic and public affairs, human services, and health care. We have met the rigorous standards of the prestigious Giving Institute, an organization composed of nearly 50 of North America’s leading fundraising consulting firms. As a Giving Institute member, we are involved in Giving USA, the annual report on philanthropy; contribute to ongoing thought leadership on philanthropy; and have access to important statistics, reports, and projections on giving and fundraising. Curtis Group’s principals are frequent presenters for many national and regional industry and sector conferences, and have each contributed articles to national philanthropy trade publications.

Classy from GoFundMe is a Public Benefit Corporation that creates meaningful connections through giving by empowering nonprofits to take advantage of every opportunity to connect with donors and build lasting relationships. By connecting motivated donors to the causes they care about most through po
BC Children’s Hospital is the only hospital in the province devoted exclusively to the care of children. As one of the few pediatric medical centres in North America with a world-class acute care centre, research institute, mental health facility and soon, rehabilitation centre, all on a single camp

Peoria Humane Society is dedicated to creating a humane environment for animals and humans. We are focused on ending pet overpopulation, cruelty and neglect to animals, and promoting respect and kindness to all through education and public awareness. The Peoria Humane Society incorporated more than
Notre mission est d'inspirer la communauté philanthropique à investir dans des initiatives transformatrices, conçues et guidées par nos leaders médicaux, qui ont un impact significatif sur la vie des patients. Ce faisant, nous perpétuons l'esprit pionnier de l'Hôpital général de Montréal, qui a uni

Wastyn & Associates helps you succeed with integrated services that help you better serve your clients with careful planning, research, development, implementation and stewardship consulting and services that let you and your organization do what you do best - make ideas happen. What leads the lis

NOVA List Company is a comprehensive direct marketing and fundraising company that offers full service list brokerage and list marketing solutions for over 45 nationally branded clients. We manage 100 million names annually and a master file of more than 2.5 million active donors who have supported
.png)
MINNEAPOLIS — DCM Services, Inc. (“DCMS”), the industry leader in estate and specialty account recovery solutions, is pleased to announce...
The FBI continues monitoring an especially audacious group of young english-speaking hackers from the US, UK, and Canada known as Scattered Spider.
Like many companies these days, cybersecurity firm Armis is keeping a close eye on agentic AI, one of the hottest areas in tech over the...
Collaboration between red teams (offensive security) and blue teams (defensive security) can help organizations identify vulnerabilities,...
The list features people from all over the globe and from different specialisms, including fraud detection, corporate governance, cyber defense, ethical...
Massachusetts Chief Information Officer Curtis Wood will step down Jan. 5 from his role as the commonwealth's top technology official.
The effects of a breach of a car, or fleet, could be devastating. Auto manufacturers and suppliers have aggressive plans, and a lot of firewalls.
Speakers at a county leaders conference also urged IT officials to find people in their own organizations who are equally serious about...
In a move to take advantage of the Texas capital's tech talent and its quality of life, Infocyte Inc. is moving its headquarters to Austin.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of The Curtis Group is http://www.thecurtisgroup.com.
According to Rankiteo, The Curtis Group’s AI-generated cybersecurity score is 757, reflecting their Fair security posture.
According to Rankiteo, The Curtis Group currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, The Curtis Group is not certified under SOC 2 Type 1.
According to Rankiteo, The Curtis Group does not hold a SOC 2 Type 2 certification.
According to Rankiteo, The Curtis Group is not listed as GDPR compliant.
According to Rankiteo, The Curtis Group does not currently maintain PCI DSS compliance.
According to Rankiteo, The Curtis Group is not compliant with HIPAA regulations.
According to Rankiteo,The Curtis Group is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
The Curtis Group operates primarily in the Fundraising industry.
The Curtis Group employs approximately 39 people worldwide.
The Curtis Group presently has no subsidiaries across any sectors.
The Curtis Group’s official LinkedIn profile has approximately 951 followers.
No, The Curtis Group does not have a profile on Crunchbase.
Yes, The Curtis Group maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/the-curtis-group.
As of December 21, 2025, Rankiteo reports that The Curtis Group has not experienced any cybersecurity incidents.
The Curtis Group has an estimated 1,146 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, The Curtis Group has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user. Due to improper privilege handling and a time-of-check time-of-use race condition combined with symbolic link and mount point manipulation, a local authenticated attacker can coerce the service into deleting arbitrary directories with SYSTEM privileges. This can be exploited to delete protected system folders such as C:\\Config.msi and subsequently achieve execution as NT AUTHORITY\\SYSTEM via MSI rollback techniques.
The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackers, with Candidate-level access and above, to inject cross-site scripting into the 'status' parameter of applied jobs for any user.
The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.7 via the 'cs_update_application_status_callback' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Candidate-level access and above, to send a site-generated email with injected HTML to any user.
The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires TheGem theme (premium) to be installed with Header Builder mode enabled, and the FiboSearch "Replace search bars" option enabled for TheGem integration.
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictable low-entropy token (5 hex characters derived from md5 of post ID) to identify member directories and insufficient authorization checks on the unauthenticated AJAX endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, display names, user roles (including administrator accounts), profile URLs, and user IDs by enumerating predictable directory_id values or brute-forcing the small 16^5 token space.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.