IP Library Granted Patent US 12,670,807
Granted Patent B2
US 12,670,807 · App. 18/648,692 · Granted Jun 30, 2026

Method and system for evaluating individual and group cyber threat awareness

Inventors: Phillip Atencio (Erie, CO); Cassandra Brubaker (Boulder, CO); George A. Wright (Atlanta, GA); Brandon Dorris (Erie, CO); Peter Grundy (Niwot, CO); Charles A. Hardin (Decatur, GA)
Assignee: Circadence Corporation
G09B19/0053A63F13/46A63F13/822G09B5/12H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,670,807
App. No.
18/648,692
Granted
Jun 30, 2026
Kind
B2
Abstract

A system has an evaluation server that includes at least one database storing a plurality of cybersecurity awareness evaluations, the database connected to the server, a plurality of clients connected to the server and configured to run at least one of the cybersecurity awareness evaluations for play by users on user devices, the users performing actions in the evaluation including offensive actions and defensive actions, and an evaluation dashboard including an interface configured to display scoring results of the cybersecurity awareness evaluations as determined by the server, the scoring results including a plurality of offensive component scores for at least one of the users, a plurality of defensive component scores for at least one of the users, at least one composite offensive score for at least one of the users and at least one composite defensive score for at least one of the users, the composite offensive score being determined based on a plurality of the component offensive scores and the composite defensive score being determined based on a plurality of the component defensive scores.

Claims (31)

1 . A system for evaluating cybersecurity awareness of an organization, comprising:

an evaluation server comprising a processor and a memory, the memory storing non-transitory machine-readable code to be executed by the processor;

at least one database storing a plurality of cybersecurity awareness evaluations, the database connected to the evaluation server;

a plurality of client devices connected to the evaluation server, each of said client devices comprising a processor, a memory and a display;

said machine-readable code of said evaluation server configured to implement one of said cybersecurity awareness evaluations from said at least one database comprising causing at least one of said plurality of client devices to display a sequence of cyber-security information to said user of said client device which prompt a user action comprising a response comprising a user selection of at least one of a cybersecurity offensive action and a cybersecurity defensive action;

said machine-readable code configured to cause, when executed, said processor of said evaluation server to generate a plurality of scoring results for said user of the cybersecurity awareness evaluations based upon the user selections, said plurality of scoring results comprising at least one offensive score and at least one defensive score, and generating a total evaluation score comprising a combination of said plurality of scoring results weighted by behavior importance for cybersecurity awareness;

said machine-readable code configured to cause, when executed, said processor of said evaluation server to generate risk reduction score comprising a normalized representation of at least two generated total evaluation scores over a period of time for each of a plurality of users to generate a risk reduction score for each of said plurality of users;

said machine-readable code configured to cause, when executed, said processor of said evaluation server to store said risk reduction scores for a plurality of users of said organization and generate, relative to a first group of said organization comprising a first two or more of said plurality of users and relative to a second group of said organization comprising a second two or more of said plurality of users, a first ranking based upon a comparison of said risk reduction scores of said first two or more of said plurality of users to said risk reduction scores of said second two or more of said plurality of users and a second ranking based upon a comparison of said risk reduction scores of said second two or more of said plurality of users to said risk reduction scores of said first two or more of said plurality of users; and

said machine-readable code configured to cause, when executed, said processor of said evaluation server to generate an evaluation dashboard comprising at least one graphical user interface displaying at least one of said first and second rankings.

2 . The system in accordance with claim 1 , wherein said graphical user interface displays said at least of said first and second rankings as numerical values.

3 . The system in accordance with claim 1 , wherein said graphical user interface displays said at one of said first and second rankings as a graph versus time.

4 . The system in accordance with claim 1 , wherein said first group and said second group comprise at least one of a department and a division of said organization.

5 . The system in accordance with claim 1 , wherein said plurality of scoring results comprise at least: an offensive behavior score, an offensive effectiveness score, a defensive behavior score, a defensive effectiveness score, a risk mitigation score, a composite tactical score, a total behavioral score, a kill chain alignment score, a risk reduction score and an overall awareness score.

6 . The system in accordance with claim 1 , wherein said sequence of cyber-security information comprises a sequence of simulated cyber-security scenarios.

7 . The system in accordance with claim 1 , wherein said cybersecurity awareness evaluation is presented to two users of at least two of said client devices as a competition between said at least two users.

8 . The system in accordance with claim 1 , wherein said evaluation dashboard is presented via a web-based application running on said evaluation server.

9 . The system in accordance with claim 1 , wherein said cybersecurity awareness evaluation is presented as a game.

10 . A method for evaluating cybersecurity awareness of an organization, comprising:

presenting, to a user of a client device comprising a processor, a memory and a display, said client device in communication with an evaluation server comprising a processor and a memory, the memory storing non-transitory machine-readable code to be executed by the processor, and at least one database storing a plurality of cybersecurity awareness evaluations, the database connected to the evaluation server, one of said cybersecurity awareness evaluations from said at least one database, comprising causing said client device to display a sequence of cyber-security information to said user of said client device which prompt a user action comprising a response comprising a user selection of at least one of a cybersecurity offensive action and a cybersecurity defensive action;

receiving, from said client device at said evaluation server, information regarding said user selections;

generating, by said evaluation server, a plurality of scoring results for said user of the cybersecurity awareness evaluations based upon the user selections, said plurality of scoring results comprising at least one offensive score and at least one defensive score, and generating a total evaluation score comprising a combination of said plurality of scoring results weighted by behavior importance for cybersecurity awareness;

generating, via said evaluation server, a risk reduction score comprising a normalized representation of at least two generated total evaluation scores over a period of time for each of a plurality of users to generate a risk reduction score for each of said plurality of users;

storing risk reduction scores for a plurality of users of said organization and generating, relative to a first group of said organization comprising a first two or more of said plurality of users and relative to a second group of said organization comprising a second two or more of said plurality of users, a first ranking based upon a comparison of said risk reduction scores of said first two or more of said plurality of users to said risk reduction scores of said second two or more of said plurality of users and a second ranking based upon a comparison of said risk reduction scores of said second two or more of said plurality of users to said risk reduction scores of said first two or more of said plurality of users; and

generating, via said evaluation server, an evaluation dashboard comprising at least one graphical user interface displaying at least one of said first and second rankings.

11 . The method in accordance with claim 10 , wherein said graphical user interface displays said at least of said first and second rankings as numerical values.

12 . The method in accordance with claim 10 , wherein said graphical user interface displays said at one of said first and second rankings as a graph versus time.

13 . The method in accordance with claim 10 , wherein said first group and said second group comprise at least one of a department and a division of said organization.

14 . The method in accordance with claim 10 , wherein said sequence of cyber-security information comprises a sequence of simulated cyber-security scenarios.

15 . The method in accordance with claim 10 , wherein said cybersecurity awareness evaluation is presented as a game.

16 . The method in accordance with claim 15 , wherein said cybersecurity awareness evaluation is played as said game by at least two users against one another.

17 . The method in accordance with claim 10 , further comprising the step of causing, via said evaluation server, said client device to provide feedback to said user regarding a result of said evaluation, said feedback comprising at least one education component.