IP Library Granted Patent US 12,443,724
Granted Patent B2
US 12,443,724 · App. 18/392,911 · Granted Oct 14, 2025

System and method for displaying a scalable cyber-risk assessment of a computer system

Inventors: Candan Bolukbas (Stone Ridge, VA); Robert Maley (Chandler, AZ); Ferhat Dikbiyik (Hopkinton, MA)
Assignee: NormShield, Inc.
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,443,724
App. No.
18/392,911
Granted
Oct 14, 2025
Kind
B2
Abstract

A method of displaying a cyber risk assessment includes receiving a request for a quantitative cyber risk assessment of an entity associated with a domain name. A digital footprint of the entity is discovered based on the domain name using non-intrusive information gathering. An entity classification is determined based on the digital footprint. An entity technical finding is determined. A loss event frequency is computed using the entity classification and the entity technical finding. A loss magnitude is computed using the entity classification and the entity technical finding. A probable financial impact of a cyber risk based on the loss event frequency and on the loss magnitude is computed. Recommendations for remediating the cyber risk based on the computed probable financial impact is displayed.

Claims (38)

1. A method of displaying a cyber risk assessment, the method comprising:

a) receiving a request for a quantitative cyber risk assessment of an entity associated with a domain name;

b) discovering a digital footprint of the entity based on the domain name using non-intrusive information gathering;

c) determining an entity classification based on a digital footprint;

d) determining an entity technical finding;

e) computing a loss event frequency using the entity classification and the entity technical finding, wherein computing the loss event frequency comprises computing using data that contains statistical information about a frequency of financial loss for certain industries;

f) computing a loss magnitude using the entity classification and the entity technical finding, wherein computing the loss magnitude comprises computing a primary loss that represents a direct cost associated with a cyber incident and computing a secondary loss that represents an indirect cost associated with the cyber incident;

g) computing a probable financial impact in financial terms of a cyber risk based on the loss event frequency and on the loss magnitude; and

h) displaying recommendations for remediating the cyber risk based on the computed probable financial impact.

2. The method of claim 1 , wherein the displaying recommendations for remediating the cyber risk based on the computed probable financial impact comprises displaying with a graphical user interface.

3. The method of claim 1 , wherein the determining an entity classification comprises determining an entity classification comprising a size and an industry based on the digital footprint.

4. The method of claim 1 , wherein the determining an entity classification comprises determining an entity classification comprising a size and a country based on the digital footprint.

5. The method of claim 1 , further comprising providing an input to allow users to manipulate the recommendations for remediating the cyber risk by changing a parameter affecting the computed probable financial impact.

6. The method of claim 5 , wherein the input is provided by a graphical user interface.

7. The method of claim 1 , further comprising displaying parameters taken into consideration while computing the probable financial impact of the cyber risk.

8. The method of claim 1 , wherein the determining the entity technical finding comprises determining an asset vulnerability.

9. The method of claim 1 , wherein the determining the entity technical finding comprises determining a threat.

10. The method of claim 1 , wherein the determining the entity technical finding comprises determining data loss.

11. The method of claim 1 , wherein the determining the entity technical finding comprises determining a cyber event.

12. The method of claim 1 , wherein the computing the loss event frequency comprises computing a level of difficulty a threat agent must overcome.

13. The method of claim 1 , wherein computing the loss event frequency comprises computing a probability of action for a threat agent.

14. The method of claim 1 , wherein the computing the loss event frequency comprises computing a contact frequency of a threat agent.

15. The method of claim 1 , wherein the computing the loss event frequency comprises computing an entity vulnerability parameter based on the entity classification.

16. The method of claim 1 , wherein the computing the loss event frequency comprises computing a threat event frequency based on the entity technical findings.

17. The method of claim 1 , wherein the computing the loss event frequency comprises computing a threat event frequency based on the entity classification.

18. The method of claim 1 , wherein the computing the loss magnitude comprises computing a financial loss resulting from the entity technical finding.

19. The method of claim 1 , wherein the computing the probable financial impact of the cyber risk based on the loss event frequency and on the loss magnitude comprises calculating a minimum and a maximum risk exposure using a likelihood function.

20. The method of claim 1 , further comprising providing a user interface to initiate the received request for the quantitative cyber risk assessment of the entity associated with the domain name.

21. The method of claim 1 , further comprising validating the received request for the quantitative cyber risk assessment.

22. The method of claim 1 , further comprising prioritizing third parties with respect to at least one of the loss event frequency and the loss magnitude.

23. The method of claim 1 , further comprising providing off-or on-site audits.

24. A system for displaying cyber risk assessment, the system comprising:

a) a first hardware processor coupled to a network that receives a request for a quantitative cyber risk assessment of an entity associated with a domain name and that discovers a digital footprint of the entity based the domain name using non-intrusive information gathering;

b) a second hardware processor in communication with the first hardware processor that: determines an entity classification based on the digital footprint; determines an entity technical finding; computes a loss event frequency and a loss magnitude using the entity classification and the entity technical finding, wherein the loss event frequency computation comprises computing using data from a loss event frequency by industry table that contains statistical information about a frequency of financial loss for certain industries and the loss magnitude computation comprises computing a primary loss that represents a direct cost associated with a cyber incident and computing a secondary loss that represents an indirect cost associated with the cyber incident; computes a probable financial impact of a cyber risk based on the loss event frequency and the loss magnitude; and determines recommendations for remediating the risks based on the computed probably financial impact; and

c) a display in communication with the second hardware processor that displays recommendations for remediating the risks based on the computed probably financial impact.

25. The system of cyber risk assessment of claim 24 wherein the first and second hardware processor comprise the same hardware processor.

26. The system of cyber risk assessment of claim 24 wherein at least one of the first and second hardware processors comprise an engine.

27. The system of cyber risk assessment of claim 26 wherein the engine comprises at least one of software, a CPU, a memory, and input/output device, and a communication adapter.

Assignments (1)
SECURITY INTEREST Recorded Aug 16, 2024
From: NORMSHIELD INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 068671/0314 →
Continuity (3)
Continuation 17174307 · Feb 11, 2021
Continuation 16855282 · Apr 22, 2020
Related Publication 20240126892A1 · Apr 18, 2024
References Cited (52)
US 9294498B1 · Yampolskiy · 2016 [cited by examiner]
US 9830569B2 · Dahlberg · 2017 [cited by applicant]
US 9973524B2 · Boyer et al. · 2018 [cited by applicant]
US 10257219B1 · Geil et al. · 2019 [cited by applicant]
US 10268976B2 · Rosumov · 2019 [cited by applicant]
US 10425380B2 · Dahlberg et al. · 2019 [cited by applicant]
US 10438001B1 · Hariprasad · 2019 [cited by applicant]
US 10546135B1 · Kassoumeh et al. · 2020 [cited by applicant]
US 10949543B1 · Bolukbas et al. · 2021 [cited by applicant]
US 10951658B2 · Putz et al. · 2021 [cited by applicant]
US 10963572B2 · Belfiore, Jr. et al. · 2021 [cited by applicant]
US 10984112B2 · Agarwal · 2021 [cited by applicant]
US 10986117B1 · Agbabian et al. · 2021 [cited by applicant]
US 11886598B2 · Bolukbas et al. · 2024 [cited by applicant]
US 20050066195A1 · Jones · 2005 [cited by applicant]
US 20110252479A1 · Beresnevichiene et al. · 2011 [cited by applicant]
US 20150381649A1 · Schultz · 2015 [cited by examiner]
US 20170187745A1 · Ng et al. · 2017 [cited by applicant]
US 20170346846A1 · Findlay · 2017 [cited by applicant]
US 20180115577A1 · Shukla et al. · 2018 [cited by applicant]
US 20180146004A1 · Belfiore, Jr. et al. · 2018 [cited by applicant]
US 20180181761A1 · Sinha et al. · 2018 [cited by applicant]
US 20180351976A1 · Shitrit-efergan et al. · 2018 [cited by applicant]
US 20190034845A1 · Mo et al. · 2019 [cited by applicant]
US 20190182289A1 · White · 2019 [cited by applicant]
US 20190207981A1 · Sweeney et al. · 2019 [cited by applicant]
US 20190364073A1 · Jones · 2019 [cited by applicant]
US 20200090197A1 · Rodriguez et al. · 2020 [cited by applicant]
US 20200162485A1 · Jevans et al. · 2020 [cited by applicant]
US 20200193018A1 · Van Dyke · 2020 [cited by examiner]
US 20200204574A1 · Christian · 2020 [cited by applicant]
US 20200404012A1 · Pichetti et al. · 2020 [cited by applicant]
US 20210075814A1 · Bulut et al. · 2021 [cited by applicant]
US 20210099477A1 · Hunt · 2021 [cited by applicant]
US 20210110319A1 · Gourisetti · 2021 [cited by examiner]
US 20210216630A1 · Karr · 2021 [cited by applicant]
US 20210264034A1 · Jones · 2021 [cited by examiner]
US 20210334387A1 · Bolukbas et al. · 2021 [cited by applicant]
US 20220050896A1 · Ahmed · 2022 [cited by applicant]
WO 2018216000A1 · 2018 [cited by applicant]
WO 2019051507A1 · 2019 [cited by applicant]
WO 2019144039A1 · 2019 [cited by applicant]
WO 2021216307A1 · 2021 [cited by applicant]
Cyber Threat Susceptibility Assessment; https://www.mitre.org/publications/systems-engineering-guide/enterpriseengineering/ systems-engineering-for-mission-assurance/cyber-threat-susceptibility-assessment, The Mitre Cor… [cited by applicant]
Examiner Report Received in Canadian Patent Application No. 3179196, mailed on Jan. 24, 2023, 4 pages. [cited by applicant]
Examiner Report Received in corresponding Canadian Patent Application No. 3179196, mailed on Nov. 2, 2023, 4 pages. [cited by applicant]
https://attack.mitre.org, retrieved Apr. 22, 2020, 3 pages. [cited by applicant]
International Preliminary Report on Patentability, Chapter 1 of the Patent Cooperation Treaty, Received in PCT Application No. PCT/US2021/026751 mailed on Nov. 3, 2022, 7 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2021/026751, mailed on Aug. 19, 2021, 10 pages. [cited by applicant]
Office Action received in Chinese Application No., 202180030129.5, dated Feb. 25, 2023, 10 pages including 6 pages of English Translation. [cited by applicant]
Scarfone et al., “Technical Guide to Information Security Testing and Assessment”, National Institute of Standards 8 and Technology Special Publication 800-115, Sep. 2008, 80 pages. [cited by applicant]
First Examination Report received for Indian Patent Application No. 202217065560, mailed on Mar. 17, 2025, 9 pages. [cited by applicant]