IP Library Granted Patent US 11,625,486
Granted Patent B2
US 11,625,486 · App. 16/703,843 · Granted Apr 11, 2023

Methods and systems of a cybersecurity scoring model

Inventors: Saket Modi (New Delhi, IN); Nitin Aggarwal (New Delhi, IN); Preetish Bajpai (New Delhi, IN); Jyoti Yadav (New Delhi, IN); Rohit Saini (New Delhi, IN)
Assignee: SAFE Securities Inc.
G06F21/57G06N20/00G06Q10/0635G06F2221/07
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,625,486
App. No.
16/703,843
Granted
Apr 11, 2023
Kind
B2
Abstract

In one aspect, a computerized-process for implementing Security Assessment For Enterprise (SAFE) Scoring Model include the step of generating a cybersecurity model by the following steps. The process determines a Governance Policy Score. The process determines a People Awareness Score. The process determines a Cybersecurity Architecture Score. The process determines an External Score. The process determines a Technology Score.

Claims (30)

1. A computerized method for implementing Security Assessment For Enterprise (SAFE) Scoring Model comprising:

generating a cybersecurity model, wherein the generating comprises:

determining a Governance Policy Score with weight wGPS,

determining a People Awareness Score with weight wPAS,

determining a Cybersecurity Architecture Score with weight wCAS,

determining an External Score with weight wES, wherein the External Score measures: (i) a strength of an enterprise in cyber defense against a disclosure of security information from an external source, and (ii) a strength of entry points into the enterprise for cyber attacks, and

determining a Technology Score with weight wTS, and

training the cybersecurity model using machine learning to provide a trained cybersecurity model.

2. The computerized method of claim 1 , wherein the cybersecurity model is trained using a set of continuous feedback.

3. The computerized method of claim 2 , wherein the set of continuous feedback comprises a dataset provided by a set of experts based on field experience.

4. The computerized method of claim 2 , wherein the set of continuous feedback comprises a dataset provided by a set of lab experiments.

5. The computerized method of claim 1 , further comprising:

providing a cyber security recommendation using the trained cybersecurity model.

6. The computerized method of claim 1 , wherein the Governance Policy Score comprises a scoring of a set of Governance Policies derived from a set of auditor reports.

7. The computerized method of claim 1 , wherein the Cybersecurity Architecture Score is derived from an analysis of a usage of specified enterprise level cybersecurity products used to provide a set of security controls.

8. The computerized method of claim 1 , wherein the People Awareness Score comprises an assessment of Information Security Awareness Campaigns launched in the enterprise with an intent to train employees to govern their actions in various situations that makes the enterprise vulnerable to a cyber-attack.

9. The computerized method of claim 1 , wherein the Technology Score is based on a risk associated with informational technology assets of the enterprise.

10. The computerized method of claim 1 , wherein the generating further comprises determining one or more of:

a Weakness Score,

an Asset Score,

a Product Score,

a Vertical Score, and

a Location Score.

11. The computerized method of claim 1 , wherein the Governance Policy Score is generated based on an Individual Policy Score for each of a set of Governance Policies, and wherein the Individual Policy Score for each Governance Policy is determined based on a penalization principle where failed controls are treated as weakness in the Governance Policy and penalized according to a Risk Score Transform to give multipliers to apply to corresponding penalties, and the Individual Policy Score for each of the set of Governance Policies is determined by aggregating and scaling the multipliers.

12. The computerized method of claim 11 , wherein the penalization principle puts a heavy penalty for a lower Individual Policy Score and a negligible penalty for a higher Individual Policy Score.

13. The computerized method of claim 7 , wherein the Cybersecurity Architecture Score is generated based on an Individual Cybersecurity Architecture Score of each of the specified enterprise level cybersecurity products, and wherein the Individual Cybersecurity Architecture Score for each of the specified enterprise level cybersecurity products is determined based on a penalization principle where failed controls are treated as weakness in the enterprise level cybersecurity product and penalized according to a Risk Score Transform to give multipliers to apply to corresponding penalties, and the Individual Cybersecurity Architecture Score for each of the specified enterprise level cybersecurity products is determined by aggregating and scaling the multipliers.

14. The computerized method of claim 8 , wherein the People Awareness Score is generated based on an Individual Campaign Score for each of the Information Security Awareness Campaigns, and wherein the Individual Campaign Score for each of the Information Security Awareness Campaigns is determined based on a penalization principle where failed controls are treated as weakness in the Information Security Awareness Campaign and penalized according to a Risk Score Transform to give multipliers to apply to corresponding penalties, and the Individual Campaign Score for each of the Information Security Awareness Campaigns is determined by aggregating and scaling the multipliers.

15. The computerized method of claim 8 , wherein an Information Security Awareness Campaign is customized according to security requirements of the enterprise.

16. The computerized method of claim 1 , wherein the security information from the external source comprises sensitive information that is made available online without a knowledge of the enterprise.

17. The computerized method of claim 1 , wherein the security information is customized according to an industry that the enterprise belongs to and a business function and goal of the enterprise.

Assignments (4)
SECURITY INTEREST Recorded Dec 1, 2025
From: SAFE SECURITIES INC.
To: WTI FUND X, INC.; WTI FUND XI, INC.
Reel/Frame 073075/0685 →
SECURITY INTEREST Recorded Jul 6, 2023
From: SAFE SECURITIES INC.
To: WTI FUND X, INC.
Reel/Frame 064171/0547 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2022
From: MODI, SAKET; AGGARWAL, NITIN; BAJPAI, PREETISH; YADAV, JYOTI; SAINI, ROHIT
To: SAFE SECURITIES INC.
Reel/Frame 059980/0307 →
SECURITY INTEREST Recorded Aug 19, 2021
From: SAFE SECURITIES INC.
To: VENTURE LENDING & LEASING IX, INC.
Reel/Frame 057235/0294 →
Continuity (4)
Provisional Application 62774866 · Dec 4, 2018
Provisional Application 62774867 · Dec 4, 2018
Provisional Application 62774865 · Dec 4, 2018
Related Publication 20220058266A1 · Feb 24, 2022