Determining additional signals for determining cybersecurity risk
Determining additional signals for determining cybersecurity risk is disclosed, including: obtaining signals associated with a cybersecurity risk, wherein the obtained signals include technographic signals and query derived signals obtained from queries; combining the technographic signals and the query derived signals into a Bayesian model indicating the cybersecurity risk; and determining additional technographic signals or additional query derived signals associated with the cybersecurity risk to obtain such that the additional technographic signals or the additional query derived signals are to be computed to impact the cybersecurity risk.
1 . A system, comprising:
one or more processors configured to:
obtain signals associated with a cybersecurity risk with respect to an organization, wherein the obtained signals include technographic signals and query derived signals obtained from queries;
use the technographic signals and the query derived signals as leaf nodes in a Bayesian model associated with the cybersecurity risk with respect to the organization;
identify a set of related signals from the technographic signals and the query derived signals to combine into an assessment node of the Bayesian model according to a set of configuration information associated with the cybersecurity risk;
determine additional technographic signals or additional query derived signals associated with the cybersecurity risk to obtain based at least in part on one or more of the following: an already obtained technographic signal or an already obtained query derived signal, the assessment node that has been determined by combining the set of related signals from the technographic signals and the query derived signals, and a signal that was attempted but not successfully obtained as a technographic signal, wherein the signal that was attempted but not successfully obtained as the technographic signal comprises a determination that a distribution of probabilities across a set of possible input values associated with the obtained technographic signal is associated with low confidence, and in response, an additional query derived signal is determined to be obtained;
prioritize the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain such that the additional technographic signals or the additional query derived signals are to be computed to impact the cybersecurity risk in the Bayesian model; and
output, at a user interface, the Bayesian model associated with the cybersecurity risk with respect to the organization; and
one or more memories coupled to the one or more processors and configured to provide the one or more processors with instructions.
2 . The system of claim 1 , wherein the one or more processors are configured to obtain the technographic signals associated with the organization by querying one or more data source servers via one or more application programming interfaces (APIs).
3 . The system of claim 1 , wherein the one or more processors are configured to obtain the query derived signals associated with the organization including by performing character recognition on query responses provided by the organization.
4 . The system of claim 1 , wherein to combine the set of related signals into the assessment node of the Bayesian model comprises to:
obtain a conditional probability table corresponding to the assessment node; and
combine the set of related signals' respective sets of probabilities corresponding to possible input values using the conditional probability table corresponding to the assessment node to determine an assessment node probability.
5 . The system of claim 4 , wherein the one or more processors are further configured to combine two or more assessment nodes into a scenario node of the Bayesian model, wherein the scenario node comprises the cybersecurity risk.
6 . The system of claim 1 , wherein the one or more processors are further configured to:
determine rankings corresponding to the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain; and
prioritize obtaining at least a portion of the additional technographic signals or the additional query derived signals associated with the cybersecurity risk in a sequence that is determined based at least in part on the determined rankings.
7 . The system of claim 6 , wherein the rankings corresponding to the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain are determined based on impact weights corresponding to the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain, wherein the impact weights are determined based at least in part on one or more of the following: an organization type associated with the organization associated with the Bayesian model, predetermined impact weights, and a cybersecurity risk type associated with the cybersecurity risk.
8 . The system of claim 6 , wherein a first additional signal to obtain that is ranked higher is obtained before a second additional signal to obtain that is ranked lower.
9 . The system of claim 1 , wherein the one or more processors are further configured to:
obtain at least one of the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain; and
update the Bayesian model associated with the cybersecurity risk using the obtained at least one of the additional technographic signals or the additional query derived signals.
10 . The system of claim 1 , wherein the one or more processors are further configured to:
obtain benchmark data corresponding to a node in the Bayesian model; and
compare the node to the benchmark data to determine a metric associated with the node.
11 . The system of claim 1 , wherein to output the Bayesian model associated with the cybersecurity risk with respect to the organization comprises to determine first appearances of the obtained signals of the Bayesian model based at least in part on types associated with the obtained signals and to determine a second appearance of the assessment node based at least in part on an impact associated with the assessment node.
12 . A method, comprising:
obtaining signals associated with a cybersecurity risk with respect to an organization, wherein the obtained signals include technographic signals and query derived signals obtained from queries;
using the technographic signals and the query derived signals as leaf nodes in a Bayesian model associated with the cybersecurity risk with respect to the organization;
identifying a set of related signals from the technographic signals and the query derived signals to combine into an assessment node of the Bayesian model according to a set of configuration information associated with the cybersecurity risk;
determining additional technographic signals or additional query derived signals associated with the cybersecurity risk to obtain based at least in part on one or more of the following: an already obtained technographic signal or an already obtained query derived signal, the assessment node that has been determined by combining the set of related signals from the technographic signals and the query derived signals, and a signal that was attempted but not successfully obtained as a technographic signal, wherein the signal that was attempted but not successfully obtained as the technographic signal comprises a determination that a distribution of probabilities across a set of possible input values associated with the obtained technographic signal is associated with low confidence, and in response, an additional query derived signal is determined to be obtained;
prioritizing the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain such that the additional technographic signals or the additional query derived signals are to be computed to impact the cybersecurity risk in the Bayesian model; and
outputting, at a user interface, the Bayesian model associated with the cybersecurity risk with respect to the organization.
13 . The method of claim 12 , further comprising obtaining the technographic signals associated with the organization by querying one or more data source servers via one or more application programming interfaces (APIs).
14 . The method of claim 12 , further comprising obtaining the query derived signals associated with the organization including by performing character recognition on query responses provided by the organization.
15 . The method of claim 12 , wherein to combine the set of related signals into the assessment node of the Bayesian model comprises to:
obtain a conditional probability table corresponding to the assessment node; and
combine the set of related signals' respective sets of probabilities corresponding to possible input values using the conditional probability table corresponding to the assessment node to determine an assessment node probability.
16 . The method of claim 15 , further comprising combining two or more assessment nodes into a scenario node of the Bayesian model, wherein the scenario node comprises the cybersecurity risk.
17 . A computer program product, the computer program product being embodied in a non-transitory computer-readable storage medium and comprising computer instructions for:
obtaining signals associated with a cybersecurity risk with respect to an organization, wherein the obtained signals include technographic signals and query derived signals obtained from queries;
using the technographic signals and the query derived signals as leaf nodes in a Bayesian model associated with the cybersecurity risk with respect to the organization;
identifying a set of related signals from the technographic signals and the query derived signals to combine into an assessment node of the Bayesian model according to a set of configuration information associated with the cybersecurity risk;
determining additional technographic signals or additional query derived signals associated with the cybersecurity risk to obtain based at least in part on one or more of the following: an already obtained technographic signal or an already obtained query derived signal, the assessment node that has been determined by combining the set of related signals from the technographic signals and the query derived signals, and a signal that was attempted but not successfully obtained as a technographic signal, wherein the signal that was attempted but not successfully obtained as the technographic signal comprises a determination that a distribution of probabilities across a set of possible input values associated with the obtained technographic signal is associated with low confidence, and in response, an additional query derived signal is determined to be obtained;
prioritizing the additional technographic signals or the additional query derived signals associated with the cybersecurity risk to obtain such that the additional technographic signals or the additional query derived signals are to be computed to impact the cybersecurity risk in the Bayesian model; and
outputting, at a user interface, the Bayesian model associated with the cybersecurity risk with respect to the organization.