IP Library Patent Application 14702666
Patent Application
App. No. 14/702,666

CYBERSECURITY RISK ASSESSMENT ON AN INDUSTRY BASIS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/702,666
Abstract

Determining an entity's cybersecurity risk and benchmarking that risk includes non-intrusively collecting one or more types of data associated with an entity. Embodiments further include calculating a security score for at least one of the one or more types of data based, at least in part, on processing of security information extracted from the at least one type of data, wherein the security information is indicative of a level of cybersecurity. Some embodiments also comprise assigning a weight to the calculated security score based on a correlation between the extracted security information and an overall security risk determined from analysis of one or more previously-breached entities in the same industry as the entity. Additional embodiments include calculating an overall cybersecurity risk score for the entity based, at least in part, on the calculated security score and the weight assigned to the calculated security score.

Claims (47)

1 . A method for benchmarking an entity's cybersecurity risk on an industry basis:

storing, in non-transitory memory, a set of attributes for each of a plurality of entities, the set of attributes comprising:

an identity of the plurality of entities, and

non-intrusive and intrusive data associated with the plurality of entities;

identifying requisite attributes of the set of attributes where entities having the requisite attributes are identified as belonging to a group, wherein the group comprises an entity and at least one competitor of each entity of the plurality of entities;

calculating an individual cybersecurity risk score for each of the plurality of entities in the group entity based, at least in part, on the set of attributes stored for each of the plurality of entities in the group;

generating, based on the calculated individual cybersecurity risk scores, a composite cybersecurity risk score for the group; and

generating an indication of relative cybersecurity risk score of one or more entities, the relative cybersecurity risk score based on a comparison of the individual cybersecurity risk score of the one or more entities to the composite cybersecurity risk score of the group.

2 . The method of claim 1 further comprising:

transmitting, to one or more entities in the group, an identification of one or more objectives to complete to improve the relative cybersecurity risk score of the one or more entities.

3 . The method of claim 2 further comprising:

receiving an indication the one or more objectives have been achieved;

calculating an updated relative cybersecurity risk score for the one or more entities based on the stored attributes and the achieved one or more objectives; and

transmitting an indication of the updated relative cybersecurity risk score of the one or more entities.

4 . The method of claim 1 wherein the set of attributes further comprises:

a number of employees of an entity, an industry in which the entity operates, and an identification of one or more of the entity's competitors.

5 . The method of claim 1 further comprising:

monitoring the relative cybersecurity risk score for each entity in the group; and

when the relative cybersecurity risk score for one or more entities in the group decreases,

transmitting an alert to the one or more entities whose relative cybersecurity risk score decreased.

6 . The method of claim 5 further comprising:

when the relative cybersecurity risk score for the one or more entities in the group decreases,

transmitting an identification of one or more updated objectives to complete to improve the relative cybersecurity risk score of the one or more entities to the one or more entities whose relative cybersecurity risk score decreased.

7 . An apparatus for benchmarking an entity's cybersecurity risk on an industry basis, the apparatus comprising:

a non-transitory memory storing a set of attributes for each of a plurality of entities, the set of attributes comprising:

an identity for each of the plurality of entities, and

non-intrusive and intrusive data associated with the plurality of entities; and

a processor coupled to the memory, the processor configured to execute steps of:

identifying requisite attributes of the set of attributes where entities having the requisite attributes are identified as belonging to a group, wherein the group comprises an entity and a competitor of the entity;

calculating an individual cybersecurity risk score for each of the plurality of entities in the group entity based, at least in part, on the set of attributes stored for each of the plurality of entities in the group;

generating, based on the calculated individual cybersecurity risk scores, a composite cybersecurity risk score for the group; and

generating an indication of relative cybersecurity risk score of one or more entities, the relative cybersecurity risk score based on a comparison of the individual cybersecurity risk score of the one or more entities to the composite cybersecurity risk score of the group.

8 . The apparatus of claim 7 where the processor is further configured to execute steps of:

transmitting, to one or more entities in the group, an identification of one or more objectives to complete to improve the relative cybersecurity risk score of the one or more entities.

9 . The apparatus of claim 8 where the processor is further configured to execute steps of:

receiving an indication the one or more objectives have been achieved;

calculating an updated relative cybersecurity risk score for the one or more entities based on the stored attributes and the achieved one or more objectives; and

transmitting an indication of the updated relative cybersecurity risk score of one or more entities.

10 . The apparatus of claim 7 wherein the set of attributes further comprises:

a number of employees of an entity, an industry in which the entity operates, and an identification of one or more of the entity's competitors.

11 . The apparatus of claim 7 where the processor is further configured to execute steps of:

monitoring the relative cybersecurity risk score for each entity in the group; and

when the relative cybersecurity risk score for one or more entities in the group decreases,

transmitting an alert to the one or more entities whose relative cybersecurity risk score decreased.

12 . The apparatus of claim 11 where the processor is further configured to execute steps of:

when the relative cybersecurity risk score for the one or more entities in the group decreases,

transmitting an identification of one or more updated objectives to complete to improve the relative cybersecurity risk score of the one or more entities to the one or more entities whose relative cybersecurity risk score decreased.

Assignments (6)
SECURITY INTEREST Recorded Sep 17, 2021
From: SECURITYSCORECARD, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057514/0519 →
CORRECTIVE ASSIGNMENT TO CORRECT ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 035687 FRAME 0244. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 25, 2017
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROB; HEID, ALEXANDER
To: SECURITYSCORECARD, INC.
Reel/Frame 043991/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 035687 FRAME 0291. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 25, 2017
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROB; KASSOUMEH, SAMUEL
To: SECURITYSCORECARD, INC.
Reel/Frame 043991/0079 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2015
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROB; HEID, ALEXANDER
To: SECURITY SCORECARD, INC.
Reel/Frame 035687/0244 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2015
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROB; KASSOUMEH, SAMUEL
To: SECURITY SCORECARD, INC.
Reel/Frame 035687/0291 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2015
From: YAMPOLSKIY, ALEKSANDR; KASSOUMEH, SAMUEL; CHOE, DANIEL
To: SECURITY SCORECARD, INC.
Reel/Frame 035687/0336 →