IP Library › Granted Patent US 12,355,805
Granted Patent B2
US 12,355,805 · App. 18/511,648 · Granted Jul 8, 2025

Generating trend data for a cybersecurity risk score

Inventors: Philip Kibler (Whiteland, IN); Daniel Wilson (Firestone, CO); Martin Overton (West Sussex, GB); Tracie Grella (Maplewood, NJ); Garin Pace (Darien, CT)
Assignee: AMERICAN INTERNATIONAL GROUP, INC.
H04L63/1433G06F11/301H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,805
App. No.
18/511,648
Filed
Nov 16, 2023
Granted
Jul 8, 2025
Kind
B2
Art Unit
2493
USPC
726/25
Abstract

Systems and methods for assessing cybersecurity risk of a computer network include the use of a risk model application that is configured to determine an initial cyber risk score value based upon an underwriting process. A cyber risk data stream is sent from the client's computer network to the system processor to periodically calculate an updated cyber risk score based upon actual data. The system processor is adapted to use the data stream to generate client information that is accessible by the client via a web-based client portal. In embodiments, the cyber risk data stream can be actively monitored to identify a threat of a cybersecurity breach.

Claims (49)

1. A method comprising:

receiving, by one or more processors, first data corresponding to first operational characteristics of a computer network at a first time;

determining, by the one or more processors using a risk model, a first value of a first cybersecurity risk parameter based on the first data of the computer network, wherein the first value is indicative of a cybersecurity risk level of the computer network;

receiving, by the one or more processors, second data corresponding to second operational characteristics of the computer network at a second time;

determining, by the one or more processors using the risk model, a second value of a second cybersecurity risk parameter based on the second data of the computer network, wherein the second value is indicative of the cybersecurity risk level of the computer network,

wherein one or more application program interfaces (APIs) over the computer network translate the first input data and the second input data into the risk model;

generating, by the one or more processors, risk score trend data of the computer network based upon the first value and the second value; and

monitoring, by the one or more processors, a data feed from the computer network for a threat alert of a cybersecurity threat, wherein the computer network implements a proactive measure configured to reduce the cybersecurity threat, in response to receiving the threat alert.

2. The method of claim 1 , further comprising, in response to receiving a forecast request for a set of cybersecurity controls not present within the computer network, analyzing, by the one or more processors, at least one of the first operational characteristics or the second operational characteristics of the computer network modified by a configuration file through which the set of cybersecurity controls not present within the computer network is implemented in the computer network using the risk model, the analyzing being configured to determine a forecasted value of at least one of the first cybersecurity risk parameter or the second cybersecurity risk parameter.

3. The method of claim 1 , further comprising:

determining, by the one or more processors using the risk model, a threat likelihood value, a business impact value and a control effectiveness value based on the first operational characteristics of the computer network at the first time,

wherein the business impact value is based on asset data associated with an operational configuration of the computer network, and

wherein the control effectiveness value is based on how security controls reduce an implicit risk score;

determining, by the one or more processors, a product of the threat likelihood value and the business impact value; and

deducting, by the one or more processors, the control effectiveness value from the product to create a residual risk score for the first operational characteristics of the computer network at the first time.

4. The method of claim 1 , further comprising determining, by the one or more processors, a forecasted value of at least one of the first cybersecurity risk parameter or the second cybersecurity risk, based on at least one of the first operational characteristics or the second operational characteristics of the computer network modified by a configuration file through which a set of cybersecurity controls not present within the computer network is implemented in the computer network using the risk model.

5. The method of claim 1 , wherein the first time and the second time are different times.

6. The method of claim 1 , further comprising monitoring, by the one or more processors, the data feed from a cybersecurity system installed within the computer network for the threat alert of the cybersecurity threat.

7. The method of claim 1 , further comprising scoring, by the one or more processors, a cyber risk based on information received from the computer network combined with threat intelligence and a potential impact of a cyber breach.

8. The method of claim 1 , further comprising transmitting, by the one or more processors, at least one of the first score or the second score to a client portal.

9. The method of claim 1 , wherein the risk model includes a threat likelihood module, a business impact module, and a control effectiveness module.

10. The method of claim 1 , further comprising determining, by the one or more processors, a cyber risk maturity score.

11. The method of claim 1 , wherein at least one of the first data or the second data associated with the computer network are received via a data feed from a cybersecurity system installed within the computer network.

12. The method of claim 1 , further comprising monitoring, by the one or more processors, a data feed from a cybersecurity system installed within the computer network for the threat alert, and in response to receiving the threat alert, transmitting a threat alert message to a client portal.

13. The method of claim 1 , further comprising implementing, by the one or more processors an additional proactive measure configured to reduce the threat, in response to receiving the threat alert.

14. The method of claim 1 , further comprising, in response to receiving the threat alert concerning the cybersecurity threat, transmitting, by the one or more processors, a threat alert message concerning the cybersecurity threat to a client portal independent of whether the cybersecurity threat is detected within the computer network.

15. The method of claim 1 , further comprising selecting, by the one or more processors, a cybersecurity control from a set of cybersecurity controls not present within the computer network, the selected cybersecurity control determined by calculating a relative effectiveness value for each of the set of cybersecurity controls and identifying a highest relative effectiveness value and transmitting data concerning the selected cybersecurity control to a client portal.

16. The method of claim 1 , further comprising transmitting, by the one or more processors, at least one of the risk score trend data or the forecasted value of the cybersecurity risk parameter to a client portal.

17. The method of claim 1 , further comprising scoring, by the one or more processors, a cyber risk based on information received from the computer network combined with current threat intelligence received from one or more data streams received through a web server and a potential impact of a cyber breach.

18. The method of claim 1 , further comprising determining, by the one or more processors, a cyber risk maturity score measured against a set of predetermined different attack patterns and across a set of selected asset groups.

19. A method comprising:

receiving, by the one or more processors, first data corresponding to first operational characteristics of a computer network at a first time;

determining, by the one or more processors using a risk model, a first value of a first cybersecurity risk parameter based on the first data of the computer network, wherein the first value is indicative of a cybersecurity risk level of the computer network;

receiving, by the one or more processors, second data corresponding to second operational characteristics of the computer network at a second time;

determining, by the one or more processors using the risk model, a second value of a second cybersecurity risk parameter based on the second data of the computer network, wherein the second value is indicative of the cybersecurity risk level of the computer network,

wherein one or more application program interfaces (APIs) over the computer network translate the first input data and the second input data into the risk model;

scoring, by the one or more processors, a cyber risk based on the first value of the first cybersecurity risk parameter, the second value of the second cybersecurity risk parameter, threat intelligence and a potential impact of a cyber breach; and

monitoring, by the one or more processors, a data feed from the computer network for a threat alert of a cybersecurity threat, wherein the computer network implements a proactive measure configured to reduce the cybersecurity threat, in response to receiving the threat alert.

20. A system comprising:

one or more processors; and

one or more tangible, non-transitory memories configured to communicate with the one or more processors,

the one or more tangible, non-transitory memories having instructions stored thereon that, in response to execution by the one or more processors, cause the one or more processors to perform operations comprising:

receiving, by the one or more processors, first data corresponding to first operational characteristics of a computer network at a first time;

determining, by the one or more processors using a risk model, a first value of a first cybersecurity risk parameter based on the first data of the computer network, wherein the first value is indicative of a cybersecurity risk level of the computer network;

receiving, by the one or more processors, second data corresponding to second operational characteristics of the computer network at a second time;

determining, by the one or more processors using the risk model, a second value of a second cybersecurity risk parameter based on the second data of the computer network, wherein the second value is indicative of the cybersecurity risk level of the computer network,

wherein one or more application program interfaces (APIs) over the computer network translate the first input data and the second input data into the risk model;

generating, by the one or more processors, risk score trend data of the computer network based upon the first value and the second value; and

monitoring, by the one or more processors, a data feed from the computer network for a threat alert of a cybersecurity threat, wherein the computer network implements a proactive measure configured to reduce the cybersecurity threat, in response to receiving the threat alert.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2023
From: KIBLER, PHILIP; WILSON, DANIEL; OVERTON, MARTIN; GRELLA, TRACIE; PACE, GARIN
To: AMERICAN INTERNATIONAL GROUP, INC.
Reel/Frame 065590/0282 →
Continuity (5)
Continuation 18098809 · Jan 19, 2023
Continuation 17127347 · Dec 18, 2020
Continuation 16058726 · Aug 8, 2018
Provisional Application 62542655 · Aug 8, 2017
Related Publication 20240098110A1 · Mar 21, 2024
References Cited (66)
US 6574737B1 · Kingsford · 2003 [cited by examiner]
US 8788279B2 · Hayes · 2014 [cited by examiner]
US 9203860B1 · Casillas · 2015 [cited by examiner]
US 9294498B1 · Yampolskiy · 2016 [cited by examiner]
US 9454465B1 · Jhoney · 2016 [cited by examiner]
US 9648036B2 · Seiver · 2017 [cited by examiner]
US 9654489B2 · Thomas · 2017 [cited by applicant]
US 9747570B1 · Vescio · 2017 [cited by applicant]
US 9787709B2 · Doubleday · 2017 [cited by examiner]
US 10467559B1 · Svenson · 2019 [cited by examiner]
US 10546135B1 · Kassoumeh · 2020 [cited by examiner]
US 10607015B1 · Hecht · 2020 [cited by examiner]
US 11611578B2 · Kibler · 2023 [cited by examiner]
US 20060085543A1 · Hrastar · 2006 [cited by examiner]
US 20060123133A1 · Hrastar · 2006 [cited by examiner]
US 20060191012A1 · Banzhof · 2006 [cited by examiner]
US 20060195905A1 · Fudge · 2006 [cited by examiner]
US 20080060071A1 · Hennan · 2008 [cited by examiner]
US 20110197277A1 · Figlin · 2011 [cited by examiner]
US 20120053964A1 · Williams · 2012 [cited by examiner]
US 20120316981A1 · Hoover · 2012 [cited by examiner]
US 20130138447A1 · Nova · 2013 [cited by examiner]
US 20130339457A1 · Freire · 2013 [cited by examiner]
US 20140007206A1 · Carter · 2014 [cited by examiner]
US 20140075564A1 · Singla · 2014 [cited by examiner]
US 20140249856A1 · Moore · 2014 [cited by examiner]
US 20150067143A1 · Babakhan · 2015 [cited by examiner]
US 20150088783A1 · Mun · 2015 [cited by examiner]
US 20150095719A1 · Namkoong · 2015 [cited by examiner]
US 20150163242A1 · Laidlaw · 2015 [cited by examiner]
US 20150324616A1 · Alarabi · 2015 [cited by examiner]
US 20150341795A1 · Tang · 2015 [cited by examiner]
US 20150381649A1 · Schultz · 2015 [cited by examiner]
US 20160042304A1 · Maloney · 2016 [cited by examiner]
US 20160119373A1 · Fausto · 2016 [cited by examiner]
US 20160173520A1 · Foster · 2016 [cited by examiner]
US 20160232465A1 · Kurtz · 2016 [cited by examiner]
US 20160239665A1 · Hamby · 2016 [cited by examiner]
US 20160292464A1 · Alarabi · 2016 [cited by examiner]
US 20160321661A1 · Hammond · 2016 [cited by examiner]
US 20160381074A1 · Ahmed Assem A. S. · 2016 [cited by examiner]
US 20170039326A1 · Stankiewicz · 2017 [cited by examiner]
US 20170048267A1 · Yampolskiy · 2017 [cited by examiner]
US 20170155676A1 · Tamir · 2017 [cited by examiner]
US 20170168921A1 · Jhoney · 2017 [cited by examiner]
US 20170300911A1 · Alnajem · 2017 [cited by examiner]
US 20170337567A1 · Bracher · 2017 [cited by examiner]
US 20180082059A1 · Bender · 2018 [cited by examiner]
US 20180124091A1 · Sweeney · 2018 [cited by examiner]
US 20180203583A1 · Achtner · 2018 [cited by examiner]
US 20180343507A1 · Petri · 2018 [cited by examiner]
US 20190034845A1 · Mo · 2019 [cited by examiner]
US 20190188389A1 · Peled · 2019 [cited by examiner]
US 20190238584A1 · Somasundaram · 2019 [cited by examiner]
US 20190253269A1 · Keane · 2019 [cited by examiner]
US 20200045064A1 · Bindal · 2020 [cited by examiner]
US 20210105296A1 · Kibler · 2021 [cited by examiner]
US 20230185360A1 · Sangiovanni · 2023 [cited by examiner]
USPTO; Notice of Allowance dated Dec. 27, 2023 in U.S. Appl. No. 18/098,809. [cited by applicant]
National Institute of Standards and Technology, U.S. Department of Commerce, “Guide for Conducting Risk Assessments—Information Security,” Computer Security Division Information Technology Laboratory National Institute … [cited by applicant]
USPTO, Non-Final Office Action dated Jun. 8, 2022 in U.S. Appl. No. 17/127,347. [cited by applicant]
USPTO, Final Office Action dated Sep. 28, 2022 in U.S. Appl. No. 17/127,347. [cited by applicant]
USPTO, Notice of Allowance dated Oct. 19, 2022 in U.S. Appl. No. 17/127,347. [cited by applicant]
USPTO, Non-Final Office Action dated Apr. 29, 2020 in U.S. Appl. No. 16/058,726. [cited by applicant]
USPTO, Notice of Allowance dated Sep. 21, 2020 in U.S. Appl. No. 16/058,726. [cited by applicant]
USPTO, Non-Final Office Action dated Aug. 16, 2023 in U.S. Appl. No. 18/098,809. [cited by applicant]