IP Library Granted Patent US 11,336,677
Granted Patent B2
US 11,336,677 · App. 16/690,223 · Granted May 17, 2022

Online portal for improving cybersecurity risk scores

Inventors: Aleksandr Yampolskiy (New York, NY); Rob Blackin (East Brunswick, NJ); Alexander Heid (Hollywood, FL); Samuel Kassoumeh (New York, NY)
Assignee: SecurityScorecard, Inc.
H04L63/1433G06F21/56G06F21/57G06F21/577G06N20/00G06Q10/0635G06Q10/06393H04L29/12066H04L43/065H04L61/1511H04L61/2007H04L61/2076H04L61/25H04L61/2503H04L63/08H04L63/1425H04L63/1458H04L67/10H04W84/12G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,336,677
App. No.
16/690,223
Granted
May 17, 2022
Kind
B2
Abstract

Determining an entity's cybersecurity risk and benchmarking that risk includes non-intrusively collecting one or more types of data associated with an entity. Embodiments further include calculating a security score for at least one of the one or more types of data based, at least in part, on processing of security information extracted from the at least one type of data, wherein the security information is indicative of a level of cybersecurity. Some embodiments also comprise assigning a weight to the calculated security score based on a correlation between the extracted security information and an overall security risk determined from analysis of one or more previously-breached entities in the same industry as the entity. Additional embodiments include calculating an overall cybersecurity risk score for the entity based, at least in part, on the calculated security score and the weight assigned to the calculated security score.

Claims (31)

1. A method for comparing an entity's cybersecurity risk using a cybersecurity risk assessment portal, the method comprising:

receiving, via the cybersecurity risk assessment portal operating on one or more machines, a request to compare the entity's cybersecurity risk based, at least in part, on a first set of attributes of the entity, the first set of attributes comprising an industry in which the entity operates and an identification of one or more of the entity's competitors;

identifying one or more data sources from which to collect one or more types of data relating to the entity's cybersecurity risk and the one or more of the entity's competitors' cybersecurity risk;

ranking, based on the one or more types of data collected from the identified one or more data sources, the entity's cybersecurity risk and the one or more of the entity's competitors' cybersecurity risk;

transmitting, via the cybersecurity risk assessment portal operating on the one or more machines, data relating to the ranking.

2. The method of claim 1 , further comprising establishing a benchmark percentile reference of the industry based, at least in part, on the entity's cybersecurity risk and the one or more of the entity's competitors' cybersecurity risk.

3. The method of claim 2 , further comprising comparing the benchmark percentile reference of the industry with a benchmark percentile reference of another industry to provide an indication of how the industry compares to the another industry with respect to cybersecurity.

4. The method of claim 1 , wherein the ranking includes percentile-based ranking.

5. The method of claim 1 , further comprising transmitting, via the cybersecurity risk assessment portal, an identification of one or more objectives to complete to improve the entity's cybersecurity risk.

6. The method of claim 5 , further comprising:

receiving, via the cybersecurity risk assessment portal, an indication that the one or more objectives has been achieved; and

calculating an updated cybersecurity risk score for the entity based on data collected from the one or more data sources and the achieved one or more objectives.

7. The method of claim 1 wherein the cybersecurity risk assessment portal is an online portal.

8. An apparatus comprising:

a memory; and

a processor coupled to the memory, the processor configured to execute the steps of:

receiving, via a cybersecurity risk assessment portal operating on one or more machines, a request to compare an entity's cybersecurity risk based, at least in part, on a first set of attributes of the entity, the first set of attributes comprising an industry in which the entity operates and an identification of one or more of the entity's competitors;

identifying one or more data sources from which to collect one or more types of data relating to the entity's cybersecurity risk and the one or more of the entity's competitors' cybersecurity risk;

ranking, based on the one or more types of data collected from the identified one or more data sources, the entity's cybersecurity risk and the one or more of the entity's competitors' cybersecurity risk;

transmitting, via the cybersecurity risk assessment portal operating on the one or more machines, data relating to the ranking.

9. The apparatus of claim 8 where the processor is further configured to execute the steps of:

transmitting, in response to the request, via the cybersecurity risk assessment portal operating on the one or more machines, an identification of one or more objectives to achieve to improve the entity's cybersecurity risk.

10. The apparatus of claim 8 where the processor is further configured to execute the steps of:

receiving, via the cybersecurity risk assessment portal, an indication that the one or more objectives has been achieved; and

calculating an updated cybersecurity risk score for the entity based on data collected from the one or more data sources and the achieved one or more objectives.

11. The apparatus of claim 8 where the processor is further configured to execute the steps of:

establishing a benchmark percentile reference of the industry based, at least in part, on the entity's cybersecurity risk and the one or more of the entity's competitors' cybersecurity risk.

12. The apparatus of claim 11 where the processor is further configured to execute the steps of:

comparing the benchmark percentile reference of the industry with a benchmark percentile reference of another industry to provide an indication of how the industry compares to the another industry with respect to cybersecurity.

13. The apparatus of claim 8 wherein the ranking includes percentile-based ranking.

14. The apparatus of claim 8 wherein the cybersecurity risk assessment portal is an online portal.

Assignments (6)
SECURITY INTEREST Recorded Jul 29, 2025
From: SECURITYSCORECARD, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 072261/0012 →
RELEASE OF SECURITY INTEREST Recorded Sep 19, 2024
From: JPMORGAN CHASE BANK, N.A.
To: SECURITYSCORECARD, INC.
Reel/Frame 068631/0463 →
SECURITY INTEREST Recorded Jun 12, 2024
From: SECURITYSCORECARD, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 067711/0635 →
SECURITY INTEREST Recorded Sep 17, 2021
From: SECURITYSCORECARD, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057514/0519 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2021
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROB; KASSOUMEH, SAMUEL
To: SECURITYSCORECARD, INC.
Reel/Frame 054981/0952 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2021
From: YAMPOLSKIY, ALEKSANDR; BLACKIN, ROB; HEID, ALEXANDER
To: SECURITYSCORECARD, INC.
Reel/Frame 054982/0260 →
Continuity (5)
Continuation 15072168 · Mar 16, 2016
Continuation 14702664 · May 1, 2015
Provisional Application 62091478 · Dec 13, 2014
Provisional Application 62091477 · Dec 13, 2014
Related Publication 20200092320A1 · Mar 19, 2020
Cited By (1)
US 12,670,458