IP Library Granted Patent US 12689649
Granted Patent B2
US 12689649 · App. 18/781,751 · Granted Jul 21, 2026

Determining additional signals for determining cybersecurity risk

Inventors: Ann Irvine (Baltimore, MD); Robert Mealey (Baltimore, MD); Russell Snyder (Baltimore, MD)
Assignee: Arceo Labs Inc.
H04L63/1433G06F18/29H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12689649
App. No.
18/781,751
Granted
Jul 21, 2026
Kind
B2
Abstract

Determining additional signals for determining cybersecurity risk is disclosed, including: obtaining signals associated with a cybersecurity risk, wherein the obtained signals include technographic signals and query derived signals obtained from queries; combining the technographic signals and the query derived signals into a Bayesian model indicating the cybersecurity risk; and determining additional technographic signals or additional query derived signals associated with the cybersecurity risk to obtain such that the additional technographic signals or the additional query derived signals are to be computed to impact the cybersecurity risk.

Claims (47)

1 . A system, comprising:

one or more processors configured to:

obtain signals associated with a cybersecurity risk with respect to an organization, wherein the obtained signals include technographic signals and query derived signals obtained from queries;

use the technographic signals and the query derived signals as leaf nodes in a Bayesian model associated with the cybersecurity risk with respect to the organization;

identify a set of related signals from the technographic signals and the query derived signals to combine into an assessment node of the Bayesian model according to a set of configuration information associated with the cybersecurity risk;

determine additional technographic signals or additional query derived signals associated with the cybersecurity risk to obtain based at least in part on one or more of the following: an already obtained technographic signal or an already obtained query derived signal, the assessment node that has been determined by combining the set of related signals from the technographic signals and the query derived signals, and a signal that was attempted but not successfully obtained as a technographic signal, wherein the signal that was attempted but not successfully obtained as the technographic signal comprises a determination that a distribution of probabilities across a set of possible input values associated with the obtained technographic signal is associated with low confidence, and in response, an additional query derived signal is determined to be obtained;

prioritize the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain such that the additional technographic signals or the additional query derived signals are to be computed to impact the cybersecurity risk in the Bayesian model; and

output, at a user interface, the Bayesian model associated with the cybersecurity risk with respect to the organization; and

one or more memories coupled to the one or more processors and configured to provide the one or more processors with instructions.

2 . The system of claim 1 , wherein the one or more processors are configured to obtain the technographic signals associated with the organization by querying one or more data source servers via one or more application programming interfaces (APIs).

3 . The system of claim 1 , wherein the one or more processors are configured to obtain the query derived signals associated with the organization including by performing character recognition on query responses provided by the organization.

4 . The system of claim 1 , wherein to combine the set of related signals into the assessment node of the Bayesian model comprises to:

obtain a conditional probability table corresponding to the assessment node; and

combine the set of related signals' respective sets of probabilities corresponding to possible input values using the conditional probability table corresponding to the assessment node to determine an assessment node probability.

5 . The system of claim 4 , wherein the one or more processors are further configured to combine two or more assessment nodes into a scenario node of the Bayesian model, wherein the scenario node comprises the cybersecurity risk.

6 . The system of claim 1 , wherein the one or more processors are further configured to:

determine rankings corresponding to the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain; and

prioritize obtaining at least a portion of the additional technographic signals or the additional query derived signals associated with the cybersecurity risk in a sequence that is determined based at least in part on the determined rankings.

7 . The system of claim 6 , wherein the rankings corresponding to the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain are determined based on impact weights corresponding to the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain, wherein the impact weights are determined based at least in part on one or more of the following: an organization type associated with the organization associated with the Bayesian model, predetermined impact weights, and a cybersecurity risk type associated with the cybersecurity risk.

8 . The system of claim 6 , wherein a first additional signal to obtain that is ranked higher is obtained before a second additional signal to obtain that is ranked lower.

9 . The system of claim 1 , wherein the one or more processors are further configured to:

obtain at least one of the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain; and

update the Bayesian model associated with the cybersecurity risk using the obtained at least one of the additional technographic signals or the additional query derived signals.

10 . The system of claim 1 , wherein the one or more processors are further configured to:

obtain benchmark data corresponding to a node in the Bayesian model; and

compare the node to the benchmark data to determine a metric associated with the node.

11 . The system of claim 1 , wherein to output the Bayesian model associated with the cybersecurity risk with respect to the organization comprises to determine first appearances of the obtained signals of the Bayesian model based at least in part on types associated with the obtained signals and to determine a second appearance of the assessment node based at least in part on an impact associated with the assessment node.

12 . A method, comprising:

obtaining signals associated with a cybersecurity risk with respect to an organization, wherein the obtained signals include technographic signals and query derived signals obtained from queries;

using the technographic signals and the query derived signals as leaf nodes in a Bayesian model associated with the cybersecurity risk with respect to the organization;

identifying a set of related signals from the technographic signals and the query derived signals to combine into an assessment node of the Bayesian model according to a set of configuration information associated with the cybersecurity risk;

determining additional technographic signals or additional query derived signals associated with the cybersecurity risk to obtain based at least in part on one or more of the following: an already obtained technographic signal or an already obtained query derived signal, the assessment node that has been determined by combining the set of related signals from the technographic signals and the query derived signals, and a signal that was attempted but not successfully obtained as a technographic signal, wherein the signal that was attempted but not successfully obtained as the technographic signal comprises a determination that a distribution of probabilities across a set of possible input values associated with the obtained technographic signal is associated with low confidence, and in response, an additional query derived signal is determined to be obtained;

prioritizing the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain such that the additional technographic signals or the additional query derived signals are to be computed to impact the cybersecurity risk in the Bayesian model; and

outputting, at a user interface, the Bayesian model associated with the cybersecurity risk with respect to the organization.

13 . The method of claim 12 , further comprising obtaining the technographic signals associated with the organization by querying one or more data source servers via one or more application programming interfaces (APIs).

14 . The method of claim 12 , further comprising obtaining the query derived signals associated with the organization including by performing character recognition on query responses provided by the organization.

15 . The method of claim 12 , wherein to combine the set of related signals into the assessment node of the Bayesian model comprises to:

obtain a conditional probability table corresponding to the assessment node; and

combine the set of related signals' respective sets of probabilities corresponding to possible input values using the conditional probability table corresponding to the assessment node to determine an assessment node probability.

16 . The method of claim 15 , further comprising combining two or more assessment nodes into a scenario node of the Bayesian model, wherein the scenario node comprises the cybersecurity risk.

17 . A computer program product, the computer program product being embodied in a non-transitory computer-readable storage medium and comprising computer instructions for:

obtaining signals associated with a cybersecurity risk with respect to an organization, wherein the obtained signals include technographic signals and query derived signals obtained from queries;

using the technographic signals and the query derived signals as leaf nodes in a Bayesian model associated with the cybersecurity risk with respect to the organization;

identifying a set of related signals from the technographic signals and the query derived signals to combine into an assessment node of the Bayesian model according to a set of configuration information associated with the cybersecurity risk;

determining additional technographic signals or additional query derived signals associated with the cybersecurity risk to obtain based at least in part on one or more of the following: an already obtained technographic signal or an already obtained query derived signal, the assessment node that has been determined by combining the set of related signals from the technographic signals and the query derived signals, and a signal that was attempted but not successfully obtained as a technographic signal, wherein the signal that was attempted but not successfully obtained as the technographic signal comprises a determination that a distribution of probabilities across a set of possible input values associated with the obtained technographic signal is associated with low confidence, and in response, an additional query derived signal is determined to be obtained;

prioritizing the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain such that the additional technographic signals or the additional query derived signals are to be computed to impact the cybersecurity risk in the Bayesian model; and

outputting, at a user interface, the Bayesian model associated with the cybersecurity risk with respect to the organization.