IP Library Granted Patent US 9,501,647
Granted Patent B2
US 9,501,647 · App. 14/702,661 · Granted Nov 22, 2016

Calculating and benchmarking an entity's cybersecurity risk score

Inventors: Aleksandr Yampolskiy (Brooklyn, NY); Rob Blackin (East Brunswick, NY); Alexander Heid (Hollywood, FL); Samuel Kassoumeh (Brooklyn, NY)
Assignee: Security Scorecard, Inc.
G06F21/57G06F21/577G06Q10/0635G06Q10/06393H04L43/065H04L61/2007H04L61/25H04L63/08H04L63/1433H04L63/1458H04L67/10G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,501,647
App. No.
14/702,661
Granted
Nov 22, 2016
Kind
B2
Abstract

Determining an entity's cybersecurity risk and benchmarking that risk includes non-intrusively collecting one or more types of data associated with an entity. Embodiments include calculating a security score for at least one of the one or more types of data based, at least in part, on processing of security information extracted from the at least one type of data, wherein the security information is indicative of a level of cybersecurity. Some embodiments also comprise assigning a weight to the calculated security score based on a correlation between the extracted security information and an overall security risk determined from analysis of one or more previously-breached entities in the same industry as the entity. Embodiments include calculating an overall cybersecurity risk score for the entity based, at least in part, on the calculated security score and the weight assigned to the calculated security score.

Claims (46)

1. A method for determining an entity's cybersecurity risk, the method comprising:

receiving from a user, at one or more processors operating at a node in a network, parameters for assessing cybersecurity risk of an entity, the parameters including information identifying the entity and one or more types of data corresponding to potential cybersecurity risks of the entity;

in response to receiving the parameters, initiating operations to calculate a cybersecurity risk score of the entity, wherein the cybersecurity risk score represents the cybersecurity posture of the entity, the operations comprising:

non-intrusively searching, based on the parameters, for the one or more types of data corresponding to potential cybersecurity risks of the entity;

assigning, by the one or more processors, a weight to each of the one or more types of data based, at least in part, on an analysis of cybersecurity of one or more other entities in the same industry as the entity;

calculating, by the processor, the cybersecurity risk score for the entity based, at least in part, on the weights assigned to the one or more types of data; and

presenting, by the one or more processors, data representative of the cybersecurity risk score and an interactive tool to the user via a user interface, wherein the interactive tool is configured to allow the user to change the parameters and initiate execution of the operations to calculate the cybersecurity risk score based on the changed parameters.

2. The method of claim 1 , further comprising determining an industry cybersecurity percentile ranking for the entity based, at least in part, on a benchmarking of the cybersecurity risk score against one or more cybersecurity risk scores for the one or more other entities.

3. The method of claim 1 , further comprising generating an alert when the cybersecurity risk score exceeds a cybersecurity threshold.

4. The method of claim 3 , further comprising monitoring the one or more types of data in real-time, wherein the alert is generated based, at least in part, on the real-time monitoring.

5. The method of claim 1 , further comprising initiating operations to intrusively search for a portion of the one or more types of data.

6. The method of claim 1 , further comprising normalizing the cybersecurity risk score based, at least in part, on the one or more types of data and the size of the entity.

7. A computer program product, comprising:

a non-transitory computer-readable medium comprising instructions which, when executed by a processor of a computing system, cause the processor to perform the steps of:

receiving from a user, at one or more processors operating at a node in a network, parameters for assessing cybersecurity risk of an entity, the parameters including information identifying the entity and one or more types of data corresponding to potential cybersecurity risks of the entity;

in response to receiving the parameters, initiating operations to calculate a cybersecurity risk score of the entity, wherein the cybersecurity risk score represents the cybersecurity posture of the entity, the operations comprising:

non-intrusively searching, based on the parameters, for the one or more types of data corresponding to potential cybersecurity risks of the entity;

assigning a weight to each of the one or more types of data based, at least in part, on an analysis of cybersecurity of one or more other entities in the same industry as the entity; and

calculating the cybersecurity risk score for the entity based, at least in part, on the weights assigned to the one or more types of data; and

presenting data representative of the cybersecurity risk score and an interactive tool to the user via a user interface, wherein the interactive tool is configured to allow the user to change the parameters and initiate execution of the operations to calculate the cybersecurity risk score based on the changed parameters.

8. The computer program product of claim 7 , wherein the medium further comprises instructions to cause the processor to perform the step of determining an industry cybersecurity percentile ranking for the entity based, at least in part, on a benchmarking of the cybersecurity risk score against one or more cybersecurity risk scores for the one or more other entities.

9. The computer program product of claim 7 , wherein the non-transitory computer-readable medium further comprises instructions to cause the processor to perform the step of generating an alert when the cybersecurity risk score exceeds a cybersecurity threshold.

10. The computer program product of claim 9 , wherein the non-transitory computer-readable medium further comprises instructions to cause the processor to perform the step of monitoring the one or more types of data in real-time, wherein the alert is generated based, at least in part, on the real-time monitoring.

11. The computer program product of claim 7 , wherein the non-transitory computer-readable medium further comprises instructions to cause the processor to perform the step of initiating operations to intrusively search for a portion of the one or more types of data.

12. The computer program product of claim 7 , wherein the non-transitory computer-readable medium further comprises instructions to cause the processor to perform the step of normalizing the cybersecurity risk score based, at least in part, on the one or more types of data and the size of the entity.

13. An apparatus, comprising:

a memory; and

a processor coupled to the memory, the processor configured to execute the steps of:

receiving from a user, at one or more processors operating at a node in a network, parameters for assessing cybersecurity risk of an entity, the parameters including information identifying the entity and one or more types of data corresponding to potential cybersecurity risks of the entity;

in response to receiving the parameters, initiating operations to calculate a cybersecurity risk score of the entity, wherein the cybersecurity risk score represents the cybersecurity posture of the entity, the operations comprising:

non-intrusively searching, based on the parameters, for the one or more types of data corresponding to potential cybersecurity risks of the entity;

assigning a weight to each of the one or more types of data based, at least in part, on an analysis of cybersecurity of one or more other entities in the same industry as the entity; and

calculating the cybersecurity risk score for the entity based, at least in part, on the weights assigned to the one or more types of data; and

presenting data representative of the cybersecurity risk score and an interactive tool to the user via a user interface, wherein the interactive tool is configured to allow the user to change the parameters and initiate execution of the operations to calculate the cybersecurity risk score based on the changed parameters.

14. The apparatus of claim 13 , wherein the processor is further configured to perform the step of determining an industry cybersecurity percentile ranking for the entity based, at least in part, on a benchmarking of the cybersecurity risk score against one or more cybersecurity risk scores for the one or more other entities.

15. The apparatus of claim 13 , wherein the processor is further configured to perform the steps of monitoring the one or more types of data in real-time, and generating an alert based, at least in part, on the real-time monitoring when the cybersecurity risk score exceeds a cybersecurity threshold.

16. The apparatus of claim 13 , wherein the processor is further configured to perform the step of initiating operations to intrusively search for a portion of the one or more types of data.

17. The apparatus of claim 13 , wherein the processor is further configured to perform the step of normalizing the cybersecurity risk score based, at least in part, on the one or more types of data and the size of the entity.

18. The method of claim 1 , further comprising:

generating an interactive scorecard comprising information representative of the cybersecurity risk score for the entity, the information comprising:

a list of primary factors affecting the cybersecurity risk of the entity; and

a list of secondary factors affecting the cybersecurity risk of the entity; and

presenting the interactive scorecard to the user via the user interface.

19. The method of claim 18 , further comprising presenting recommendations for improving the cybersecurity posture and the cybersecurity risk score of the entity.

20. The method of claim 18 , wherein each factor comprising the list of primary factors and the list of secondary factors is presented within the interactive scorecard as a selectable element, the method further comprising:

in response to a selection of an element corresponding to a factor included in the list of primary factors or the list of secondary factors during presentation of the interactive scorecard, updating presentation of the interactive scorecard to present issues that impacted the cybersecurity risk of the entity, wherein the issues were identified during the non-intrusive searching for the one or more types of data.

Assignments (9)
SECURITY INTEREST Recorded Jul 29, 2025
From: SECURITYSCORECARD, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 072261/0012 →
RELEASE OF SECURITY INTEREST Recorded Sep 19, 2024
From: JPMORGAN CHASE BANK, N.A.
To: SECURITYSCORECARD, INC.
Reel/Frame 068631/0463 →
SECURITY INTEREST Recorded Jun 12, 2024
From: SECURITYSCORECARD, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 067711/0635 →
SECURITY INTEREST Recorded Sep 17, 2021
From: SECURITYSCORECARD, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057514/0519 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME PREVIOUSLY RECORDED ON REEL 035684 FRAME 0438. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 25, 2017
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROBERT; HEID, ALEXANDER
To: SECURITYSCORECARD, INC.
Reel/Frame 043991/0054 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME PREVIOUSLY RECORDED AT REEL: 035684 FRAME: 0484. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 25, 2017
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROBERT; KASSOUMEH, SAMUEL
To: SECURITYSCORECARD, INC.
Reel/Frame 043992/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2015
From: YAMPOLSKIY, ALEKSANDR; KASSOUMEH, SAMUEL; CHOE, DANIEL
To: SECURITY SCORECARD, INC.
Reel/Frame 035684/0526 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2015
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROBERT; KASSOUMEH, SAMUEL
To: SECURITY SCORECARD, INC.
Reel/Frame 035684/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2015
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROBERT; HEID, ALEXANDER
To: SECURITY SCORECARD, INC.
Reel/Frame 035684/0438 →
Continuity (3)
Provisional Application 62091477 · Dec 13, 2014
Provisional Application 62091478 · Dec 13, 2014
Related Publication 20160173521A1 · Jun 16, 2016