IP Library Granted Patent US 11,625,689
Granted Patent B2
US 11,625,689 · App. 17/215,935 · Granted Apr 11, 2023

Systems and methods for human resources applications of security awareness testing

Inventors: Alin Irimie (Clearwater, FL); Drew Graef (Clearwater, FL); Nicole McBride (Oldsmar, FL); Isida Drake (Dunedin, FL); Daniel Lorch (Clearwater, FL)
Assignee: KnowBe4, Inc.
G06Q10/1053G06Q10/0635H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,625,689
App. No.
17/215,935
Granted
Apr 11, 2023
Kind
B2
Abstract

Systems and methods are described for facilitating assessment of security awareness of a candidate prior to a decision on whether or not to hire the candidate. Security awareness of the candidate in association with an application for a job may be assessed using responses to one or more simulated phishing communications provided by the candidate. Responses to the one or more simulated phishing communications may be used to determine a risk score for the candidate. Further, the risk score for the candidate may be used to make a decision on whether or not to hire the candidate.

Claims (29)

1. A method of using one or more simulated phishing communications to provide a risk score for a candidate in association with an application for a job, the method comprising:

receiving, by a server configured to communicate one or more simulated phishing communications and configured to communicate with a job application system executed on one or more servers, via one or more application programming interfaces (APIs) between the server and the job application system, information about a candidate from a job application process of the job application system responsive to the job application process and authentication information used by the candidate during creation of a profile via the job application system;

generating, by the server responsive to receiving the information, one or more simulated phishing communications to include content personalized by the server based at least on the information about the candidate received from the job application process;

communicating, by the server responsive to receiving the information, the one or more simulated phishing communications to one or more devices of the candidate;

receiving, by the server, one or more responses to the one or more simulated phishing communications from the one or more devices of the candidate;

determining, by the server responsive to the one more responses, a risk score for the candidate based at least on the authentication information received from the job application system and the one or more responses to the one or more simulated phishing communications received from the one or more devices of the candidate; and

providing, by the server via the one or more APIs, the risk score to the job application system for use by the job application system to provide information on whether or not the candidate is to be hired.

2. The method of claim 1 , further comprising receiving the information about the candidate during one of a profile creation process or a job application process of the job application system.

3. The method of claim 1 , further comprising generating, by the server, the one or more simulated phishing communications by personalizing content of the one or more simulated phishing communications based at least on the information about the candidate that identifies one or more social media platforms of the candidate.

4. The method of claim 1 , wherein the authentication information includes at least one of strength of password or selection of one-factor or two-factor authentication.

5. The method of claim 1 , further comprising identifying, by the server for use in determining the risk score, whether or not any of the authentication information has been associated with a data breach.

6. The method of claim 1 , further comprising receiving, by the server, one or more responses of the candidate to one or more security related questions presented by the job application system to the candidate.

7. The method of claim 6 , further comprising determining, by the server, the risk score of the candidate based on the one or more responses.

8. The method of claim 1 , further comprising determining, by the server, the risk score as a weighted function of two or more of the following information received via the job application system: password strength, password reuse, security question selection, phish prone percentage, email exposure and whether or not two-factor authentication is used.

9. A system of using one or more simulated phishing communications to provide a risk score for a candidate in association with an application for a job, the system comprising:

a server comprising one or more processors, coupled to memory and configured to communicate one or more simulated phishing communications and configured to communicate with a job application system executed on one or more servers and to:

receive, via one or more application programming interfaces (APIs) between the server and the job application system, information about a candidate from a job application process of a job application system responsive to the job application process and authentication information used by the candidate during creation of a profile via the job application system;

generate, responsive to receiving the information, one or more simulated phishing communications to include content personalized by the server based at least on the information about the candidate received from the job application process;

communicate, responsive to receiving the information, the one or more simulated phishing communications to one or more devices of the candidate;

receive one or more responses to the one or more simulated phishing communications from the one or more devices of the candidate;

determine, responsive to the one more responses, a risk score for the candidate based at least on the authentication information received from the job application system and the one or more responses to the one or more simulated phishing communications received from the one or more devices of the candidate; and

provide, via the one or more APIs, the risk score to the job application system for use by the job application system to provide information on whether or not the candidate is to be hired.

10. The system of claim 9 , wherein the server is further configured to receive the information about the candidate during one of a profile creation process or a job application process of the job application system.

11. The system of claim 9 , wherein the server is further configured to generate the one or more simulated phishing communications by personalizing content of the one or more simulated phishing communications based at least on the information about the candidate that identifies one or more social media platforms of the candidate.

12. The system of claim 9 , wherein the authentication information includes at least one of strength of password or selection of one-factor or two-factor authentication.

13. The system of claim 9 , wherein the server is further configured to identify for use in determining the risk score, whether or not any of the authentication information has been associated with a data breach.

14. The system of claim 9 , wherein the server is further configured to receive one or more responses of the candidate to one or more security related questions presented by the job application system to the candidate.

15. The system of claim 14 , wherein the server is further configured to determine the risk score of the candidate based on the one or more responses.

16. The system of claim 9 , wherein the server is further configured to determine the risk score as a weighted function of two or more of the following information received via the job application system: password strength, password reuse, security question selection, phish prone percentage, email exposure and whether or not two-factor authentication is used.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2023
From: IRIMIE, ALIN; GRAEF, DREW; MCBRIDE, NICOLE; DRAKE, ISIDA; LORCH, DANIEL
To: KNOWBE4, INC.
Reel/Frame 062794/0012 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2021
From: IRIMIE, ALIN; GRAEF, DREW; MCBRIDE, NICOLE; DRAKE, ISIDA; LORCH, DANIEL
To: KNOWBE4, INC.
Reel/Frame 055757/0037 →