IP Library Granted Patent US 11,677,767
Granted Patent B2
US 11,677,767 · App. 17/688,636 · Granted Jun 13, 2023

Systems and methods for determining individual and group risk scores

Inventors: Eric Sites (Clearwater, FL); Greg Kras (Dunedin, FL); Alin Irimie (Clearwater, FL); Stu Sjouwerman (Belleair, FL); Marcio Castilho (Palm Harbor, FL); Siegfried Martens (Tampa, FL); Eric Bonabeau (Tampa, FL); Kristian Kime (Tampa, FL)
Assignee: KnowBe4, Inc.
H04L63/1416H04L63/14H04L63/1408H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,677,767
App. No.
17/688,636
Granted
Jun 13, 2023
Kind
B2
Abstract

Embodiments disclosed herein describe a server, for example a security awareness server or an artificial intelligence machine learning system that establishes a risk score or vulnerable for a user of a security awareness system, or for a group of users of a security awareness system. The server may create a frequency score for a user, which predicts the frequency at which the user is to be hit with a malicious attack. The frequency score may be based on at least a job score, which may be represented by a value that is based on the type of job the user has, and a breach score that may be represented by a value that is based on the user's level of exposure to email.

Claims (33)

1. A method comprising:

receiving, by one or more servers, information related to data breaches associated with a user;

identifying, by the one or more servers, whether the user clicks on one or more links of one or more simulated phishing tests;

identifying, by the one or more servers, whether the user has completed one or more training courses;

determining, by the one or more servers, a risk score of the user as a function of the information related to data breaches associated with the user, whether the user clicks on one or more links of one or more simulated phishing tests and whether the user has completed one or more training courses; and

providing, by the one or more servers, the risk score for display via a user interface on a display device.

2. The method of claim 1 , further comprising identifying, by the one or more servers, a training history of the user.

3. The method of claim 2 , further comprising determining, by the one or more servers, the risk score of the user based on the training history of the user.

4. The method of claim 2 , wherein the training history identifies one or more of the following: courses that the user is enrolled in by the one or more servers, courses that the user has chosen to enroll in, courses that the user has started, or courses that the user has completed.

5. The method of claim 2 , wherein the training history identifies one or more time intervals between completions of one or more training courses.

6. The method of claim 2 , wherein the training history is based on a type of training.

7. The method of claim 1 , wherein the function is one of a weighted function or a logarithmic function of information related to data breaches associated with the user, whether the user clicks on one or more links of one or more simulated phishing tests and whether the user has completed one or more training courses.

8. The method of claim 1 , further comprising identifying, by the one or more servers, results of at least one or more user assessment surveys for the user.

9. The method of claim 8 , further comprising determining, by the one or more servers, the risk score of the user as the function of the information related to data breaches associated with the user, whether the user clicks on one or more links of one or more simulated phishing tests, whether the user has completed one or more training courses and the results of the at least one or more user assessment surveys for the user.

10. The method of claim 1 , further comprising aggregating, by the one or more servers, a group risk from risk scores of a plurality of users.

11. The method of claim 1 , further comprising causing, by the one or more servers, a display of a probability that the user will respond to a hit of one or more types of malicious attacks.

12. A system comprising:

one or more servers, comprising one or more processors, coupled to memory and configured to:

receive information related to data breaches associated with a user;

identify whether the user clicks on one or more links of one or more simulated phishing tests;

identify whether the user has completed one or more training courses;

determine a risk score of the user as a function of the information related to data breaches associated with the user, whether the user clicks on one or more links of one or more simulated phishing tests and whether the user has completed one or more training courses; and

provide the risk score for display via a user interface on a display device.

13. The system of claim 12 , wherein the one or more servers are further configured to identify a training history of the user.

14. The system of claim 13 , wherein the one or more servers are further configured to determine the risk score of the user based on the training history of the user.

15. The system of claim 13 , wherein the training history identifies one or more of the following: courses that the user is enrolled in by the one or more servers, courses that the user has chosen to enroll in, courses that the user has started, or courses that the user has completed.

16. The system of claim 13 , wherein the training history identifies one or more time intervals between completions of one or more training courses.

17. The system of claim 13 , wherein the training history is based on a Previously Presented of training.

18. The system of claim 12 , wherein the function is one of a weighted function or a logarithmic function of the information related to data breaches associated with the user, whether the user clicks on one or more links of one or more simulated phishing tests and whether the user has completed one or more training courses.

19. The system of claim 12 , wherein the one or more servers are further configured to identify results of at least one or more user assessment surveys for the user.

20. The system of claim 19 , wherein the one or more servers are further configured to determine the risk score of the user as the function of the information related to data breaches associated with the user, whether the user clicks on one or more links of one or more simulated phishing tests, whether the user has completed one or more training courses and the results of the at least one or more user assessment surveys for the user.

21. The system of claim 12 , wherein the one or more servers are further configured to aggregate a group risk from risk scores of a plurality of users.

22. The system of claim 12 , wherein the one or more servers are further configured to cause a display of a probability that the user will responds to a hit of one or more types of malicious attacks.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2022
From: SITES, ERIC; KRAS, GREG; IRIMIE, ALIN; SJOUWERMAN, STU; CASTILHO, MARCIO; MARTENS, SIEGFRIED; BONABEAU, ERIC; KIME, KRISTIAN
To: KNOWBE4, INC.
Reel/Frame 059700/0619 →
Continuity (7)
Continuation 17411565 · Aug 25, 2021
Continuation 17121442 · Dec 14, 2020
Continuation 16855502 · Apr 22, 2020
Continuation 16413021 · May 15, 2019
Provisional Application 62672390 · May 16, 2018
Provisional Application 62672386 · May 16, 2018
Related Publication 20220201018A1 · Jun 23, 2022