IP Library Granted Patent US 12,321,462
Granted Patent B2
US 12,321,462 · App. 17/987,350 · Granted Jun 3, 2025

Cybersecurity risk assessment system and method

Inventors: Kevin T. Coppins (Lutz, FL); Liam Irish (Temple Terrace, FL); Spencer Vore (Broomfield, CO); Cory Retherford (Bloomington, IN)
Assignee: Spirion, LLC
G06F21/577G06F21/6245G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,321,462
App. No.
17/987,350
Granted
Jun 3, 2025
Kind
B2
Abstract

Techniques for evaluating and improving data security are provided. In one embodiment, a method includes receiving results from a sensitive data scan of information technology (IT) infrastructure of an organization, in which the result includes indications of a volume of sensitive data found during the scan, types of the sensitive data found during the scan, and locations at which the sensitive data was found during the scan. The method also includes determining a cybersecurity risk score for the IT infrastructure. This can include calculating the cybersecurity risk score based on the volume of sensitive data found during the scan, value of the sensitive data found during the scan, and vulnerability of the locations at which the sensitive data was found during the scan. Additional systems, devices, and methods are also disclosed.

Claims (28)

1. A computer-implemented method for determining a cybersecurity risk score of information technology (IT) infrastructure, the method comprising:

receiving results from a sensitive data scan of IT infrastructure of an organization, the results including indications of a volume of sensitive data found during the scan, types of the sensitive data found during the scan, and locations at which the sensitive data was found during the scan; and

determining a cybersecurity risk score for the IT infrastructure of the organization, wherein determining the cybersecurity risk score includes calculating the cybersecurity risk score based on the volume of sensitive data found during the scan, value of the sensitive data found during the scan, and vulnerability of the locations at which the sensitive data was found during the scan; and wherein the value of the sensitive data found during the scan represents relative worth to the organization of the sensitive data, determining the cybersecurity risk score includes parsing out data from the results of the sensitive data scan and applying weighting coefficients in calculating the cybersecurity risk score, and the weighting coefficients applied include vulnerability coefficients for the locations at which the sensitive data was found during the scan and value coefficients for the types of the sensitive data found during the scan.

2. The computer-implemented method of claim 1 , comprising performing remediation to reduce cybersecurity risk to the IT infrastructure.

3. The computer-implemented method of claim 2 , wherein performing remediation to reduce cybersecurity risk to the IT infrastructure includes removing one or more items of sensitive data from a location at which the one or more items of sensitive data were found during the scan.

4. The computer-implemented method of claim 2 , wherein performing remediation to reduce cybersecurity risk to the IT infrastructure includes encrypting one or more items of sensitive data found during the scan.

5. The computer-implemented method of claim 2 , comprising determining an updated cybersecurity risk score for the IT infrastructure following the remediation.

6. The computer-implemented method of claim 1 , comprising determining the vulnerability coefficients.

7. The computer-implemented method of claim 1 , comprising determining the value coefficients.

8. The computer-implemented method of claim 1 , comprising performing the sensitive data scan of the IT infrastructure of the organization.

9. An apparatus comprising:

a processor-based computer system including a memory and a processor, the memory having computer-readable instructions that, when executed, cause the computer system to:

receive results from a sensitive data scan of information technology (IT) infrastructure of an organization, the results including indications of a volume of sensitive data found during the scan, types of the sensitive data found during the scan, and locations at which the sensitive data was found during the scan;

determine a cybersecurity risk score for the IT infrastructure of the organization, wherein determining the cybersecurity risk score includes calculating the cybersecurity risk score based on the volume of sensitive data found during the scan, value of the sensitive data found during the scan, and vulnerability of the locations at which the sensitive data was found during the scan; and wherein the value of the sensitive data found during the scan represents relative worth to the organization of the sensitive data, determining the cybersecurity risk score includes parsing out data from the results of the sensitive data scan and applying weighting coefficients in calculating the cybersecurity risk score, and the weighting coefficients applied include vulnerability coefficients for the locations at which the sensitive data was found during the scan and value coefficients for the types of the sensitive data found during the scan;

compare the cybersecurity risk score to a threshold value;

based on the comparison of the cybersecurity risk score to the threshold value, remediate one or more items of sensitive data found at one or more locations during the scan; and

after remediating the one or more items of sensitive data found at the one or more locations during the scan, determine an updated cybersecurity risk score for the IT infrastructure of the organization.

10. The apparatus of claim 9 , wherein the memory has computer-readable instructions that, when executed, cause the computer system to receive a user-defined monetary threshold and to set the threshold score value to the user-defined monetary threshold.

11. The apparatus of claim 9 , wherein the computer-readable instructions that, when executed, cause the computer system to remediate one or more items of sensitive data found at one or more locations during the scan include instructions that, when executed, cause the computer system to remove at least one item of sensitive data of the one or more items of sensitive data from at least one location of the one or more locations.

12. The apparatus of claim 9 , wherein the computer-readable instructions that, when executed, cause the computer system to remediate one or more items of sensitive data found at one or more locations during the scan include instructions that, when executed, cause the computer system to encrypt at least one item of sensitive data of the one or more items of sensitive data.

13. The apparatus of claim 9 , wherein the memory has computer-readable instructions that, when executed, cause the computer system to output a cybersecurity risk score report to a user.

14. The apparatus of claim 9 , wherein the memory is a non-volatile storage.

15. A non-transitory computer-readable medium encoded with instructions that, when executed by a processor of a computer system, cause the computer system to:

receive results from a sensitive data scan of information technology (IT) infrastructure of an organization, the results including indications of a volume of sensitive data found during the scan, types of the sensitive data found during the scan, and locations at which the sensitive data was found during the scan;

determine a cybersecurity risk score for the IT infrastructure of the organization, wherein determining the cybersecurity risk score includes calculating the cybersecurity risk score based on the volume of sensitive data found during the scan, value of the sensitive data found during the scan, and vulnerability of the locations at which the sensitive data was found during the scan; and wherein the value of the sensitive data found during the scan represents relative worth to the organization of the sensitive data, determining the cybersecurity risk score includes parsing out data from the results of the sensitive data scan and applying weighting coefficients in calculating the cybersecurity risk score, and the weighting coefficients applied include vulnerability coefficients for the locations at which the sensitive data was found during the scan and value coefficients for the types of the sensitive data found during the scan;

compare the cybersecurity risk score to a threshold value;

based on the comparison of the cybersecurity risk score to the threshold value, remediate one or more items of sensitive data found at one or more locations during the scan; and

after remediating the one or more items of sensitive data found at the one or more locations during the scan, determine an updated cybersecurity risk score for the IT infrastructure of the organization.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2025
From: SPIRION LLC
To: ARCHTIS US, INC.
Reel/Frame 072880/0800 →
RELEASE OF SECURITY INTEREST Recorded Oct 10, 2025
From: FREEPORT FINANCIAL PARTNERS LLC, AS ADMINISTRATIVE AGENT
To: SPIRION LLC
Reel/Frame 072538/0223 →
SECURITY INTEREST Recorded Jul 12, 2024
From: SPIRION LLC
To: FREEPORT FINANCIAL PARTNERS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 067974/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2023
From: COPPINS, KEVIN T.; IRISH, LIAM; VORE, SPENCER
To: SPIRION, LLC
Reel/Frame 065251/0869 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2023
From: RETHERFORD, CORY P.
To: SPIRION, LLC
Reel/Frame 065252/0041 →
Continuity (2)
Provisional Application 63279251 · Nov 15, 2021
Related Publication 20230153443A1 · May 18, 2023
References Cited (32)
US 9648046B2 · Boss et al. · 2017 [cited by applicant]
US 10326778B2 · Gong et al. · 2019 [cited by applicant]
US 10579803B1 · Mueller · 2020 [cited by examiner]
US 11194903B2 · Edwards et al. · 2021 [cited by applicant]
US 11238176B1 · Vax et al. · 2022 [cited by applicant]
US 11503043B2 · Sancheti et al. · 2022 [cited by applicant]
US 11783062B2 · Lounsberry · 2023 [cited by examiner]
US 11831670B1 · Molls et al. · 2023 [cited by applicant]
US 20060173663A1 · Langheier · 2006 [cited by examiner]
US 20060195905A1 · Fudge · 2006 [cited by examiner]
US 20140136941A1 · Avrahami et al. · 2014 [cited by applicant]
US 20140279294A1 · Field-Darragh · 2014 [cited by examiner]
US 20180157842A1 · Holz · 2018 [cited by examiner]
US 20190179490A1 · Barday et al. · 2019 [cited by applicant]
US 20190286839A1 · Mutha et al. · 2019 [cited by applicant]
US 20200050966A1 · Enuka et al. · 2020 [cited by applicant]
US 20200057864A1 · Parthasarathy · 2020 [cited by examiner]
US 20200104046A1 · Hopper · 2020 [cited by examiner]
US 20200184104A1 · Barday et al. · 2020 [cited by applicant]
US 20210037038A1 · Alsharif · 2021 [cited by examiner]
US 20210264056A1 · Irish et al. · 2021 [cited by applicant]
US 20210272031A1 · Brannon et al. · 2021 [cited by applicant]
US 20210350001A1 · Alturaifi · 2021 [cited by examiner]
US 20210390470A1 · Clearwater · 2021 [cited by examiner]
US 20220345483A1 · Shua · 2022 [cited by examiner]
US 20230205921A1 · Irish · 2023 [cited by applicant]
WO WO2018084808A1 · 2018 [cited by examiner]
“Guide for Conducting Risk Assessments,” NIST Special Publication 800-30 Revision 1, dated Sep. 2012, Information Technology Laboratory, National Institute of Standards and Technology, Gaithersburg, MD (95 pages). [cited by applicant]
Cronin et al., “CIS RAM Version 1.0 Center for Internet Security Risk Assessment Method,” dated Apr. 2018, Center for Internet Security, East Greenbush, NY (154 pages). [cited by applicant]
“An Introduction to the FAIR Controls Analytics Model,” dated 2021, FAIR Institute, Spokane, WA (32 pages). [cited by applicant]
“Falcon Identity Protection Risk Score,” dated 2022, CrowdStrike, Inc., Austin, TX (7 pages). [cited by applicant]
“An Introduction to the FAIR Materiality Assessment Model,” dated 2023, FAIR Institute, Spokane, WA (11 pages). [cited by applicant]