IP Library Granted Patent US 11,552,984
Granted Patent B2
US 11,552,984 · App. 17/546,676 · Granted Jan 10, 2023

Systems and methods for improving assessment of security risk based on personal internet account data

Inventor: Greg Kras (Dunedin, FL)
Assignee: KnowBe4, Inc.
H04L63/1433G06F21/6245H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,552,984
App. No.
17/546,676
Granted
Jan 10, 2023
Kind
B2
Abstract

Systems and methods are described for improving assessment of security risk based on a user's personal information. Registration of personal information of a user of an organization is received at a security awareness system. Post receiving the registration of the personal information, at least one of an exposure check or a security audit of the personal information of the user is performed by the security awareness system. A personal risk score of the user is then generated or adjusted based at least on a result of one of the exposure check or the security audit.

Claims (29)

1. A method comprising:

receiving, by a security awareness system configured on one or more servers, from a user of an organization registration of personal information;

performing, by the security awareness system, at least one of an exposure check against one or more breach databases or a security audit of the personal information of the user; and

adjusting, by the security awareness system, a personal risk score of the user based at least on a result of one of the exposure check or the security audit, the personal risk score comprising at least a component representing a willingness of the user to provide the personal information to the organization to which the user is not obliged to provide the personal information; and

performing, by the security awareness system based on at least the personal risk score of the user, one of a computer-based remedial training or a simulated phishing campaign directed to the user.

2. The method of claim 1 , further comprising verifying, by the security awareness system, an email address as used in a personal domain of the user.

3. The method of claim 2 , further comprising storing, by the security awareness system, the email address used in the personal domain of the user in association with a profile of the user for the security awareness system.

4. The method of claim 2 , further comprising registering the personal information with the security awareness system responsive to the email address used in the personal domain of the user being verified.

5. The method of claim 1 , further comprising storing, by the security awareness system, the personal information in an obfuscated form.

6. The method of claim 1 , further comprising performing the exposure check by searching using at least one of an email address or a username in the personal information for breached user information in the one or more breach databases.

7. The method of claim 1 , further comprising performing the security audit by assessing a strength of one or more registered personal passwords from the personal information and compliances to password requirements of the organization.

8. The method of claim 1 , further comprising adjusting the personal risk score of the user based at least on the user's registration of the personal information with the security awareness system.

9. The method of claim 1 , further comprising determining, by the security awareness system, a risk score based at least on the personal risk score of the user.

10. The method of claim 1 , further comprising monitoring, by the security awareness system, the one or more breach databases for the personal information.

11. A system comprising:

a security awareness system configured on one or more processors, coupled to memory, the security awareness system configured to:

receive from a user of an organization registration of personal information;

perform at least one of an exposure check against one or more breach databases or a security audit of the personal information of the user;

adjust a personal risk score of the user based at least on a result of one of the exposure check or the security audit, the personal risk score comprising at least a component representing a willingness of the user to provide the personal information to the organization to which the user is not obliged to provide the personal information; and

perform, based on at least the personal risk score of the user, one of a computer-based remedial training or a simulated phishing campaign directed to the user.

12. The system of claim 11 , wherein the security awareness system is further configured to verify an email address as used in a personal domain of the user.

13. The system of claim 12 , wherein the security awareness system is further configured to store the email address used in the personal domain of the user in association with a profile of the user for the security awareness system.

14. The system of claim 12 , wherein the security awareness system is further configured to register the personal information responsive to the email address used in the personal domain of the user being verified.

15. The system of claim 11 , wherein the security awareness system is further configured to store the personal information in an obfuscated form.

16. The system of claim 11 , wherein the security awareness system is further configured to perform the exposure check by searching using at least one of an email address or a username in the personal information for breached user information in the one or more breach databases.

17. The system of claim 11 , wherein the security awareness system is further configured to perform the security audit by assessing a strength of one or more registered personal passwords from the personal information and compliances to password requirements of the organization.

18. The system of claim 11 , wherein the security awareness system is further configured to adjust the personal risk score of the user based at least on the user's registration of the personal information with the security awareness system.

19. The system of claim 11 , wherein the security awareness system is further configured to determine a risk score based at least on the personal risk score of the user.

20. The system of claim 11 , wherein the security awareness system is further configured to monitor the one or more breach databases for the personal information.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2022
From: KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 062175/0523 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2022
From: KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 061991/0545 →
Continuity (3)
Provisional Application 63142071 · Jan 27, 2021
Provisional Application 63123812 · Dec 10, 2020
Related Publication 20220191233A1 · Jun 16, 2022