IP Library Granted Patent US 12,614,139
Granted Patent B2
US 12,614,139 · App. 18/781,942 · Granted Apr 28, 2026

Reducing cybersecurity risk level of a portfolio of companies using a cybersecurity risk multiplier

Inventors: Jue Mo (New York, NY); Luis Vargas (New York, NY); A. Robert Sohval (New York, NY)
Assignee: SecurityScorecard, Inc.
G06Q10/0635H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,614,139
App. No.
18/781,942
Granted
Apr 28, 2026
Kind
B2
Abstract

A multiplier is utilized to quantify a cybersecurity risk level of a portfolio of entities (e.g., companies) and enable actions to mitigate that quantified risk. In doing so, features or attributes of one or more companies in a portfolio are compared to features or attributes of one or more companies that experienced an adverse cybersecurity event (e.g. a data breach). Further, a degree of dependency, such as a matrix of a number of shared vendors and the proximity of those vendors to the companies, can be measured between (1) portfolio companies and one or more companies that experienced a cybersecurity event, and/or (2) the portfolio companies themselves to better quantify the risk. That is, to more meaningfully analyze a cybersecurity event that occurred at one or more companies and better predict the likelihood of an occurrence at portfolio companies, embodiments can determine an n-degree interdependency between companies.

Claims (63)

1 . A method for dynamically scoring a cybersecurity risk of a portfolio of companies, the method comprising:

receiving, by one or more processors, attribute data indicative of cybersecurity risks of companies;

identifying, by the one or more processors and based on the attribute data, at least one attribute that is common to a company that experienced a cybersecurity risk event and the portfolio of companies;

determining, by the one or more processors, a cybersecurity risk multiplier for the portfolio of companies based on a number of the at least one attribute; and

outputting, by the one or more processors, a cybersecurity risk level of the portfolio of companies based on the cybersecurity risk multiplier.

2 . The method of claim 1 , further comprising:

determining, by the one or more processors, an initial cybersecurity risk level of the portfolio of companies based on cybersecurity data related to the portfolio of companies; and

generating, by the one or more processors, the cybersecurity risk level based on the initial cybersecurity risk level and the cybersecurity risk multiplier.

3 . The method of claim 2 , where the cybersecurity risk level is expressed as a product of the initial cybersecurity risk level and the cybersecurity risk multiplier.

4 . The method of claim 1 , further comprising:

outputting, by the one or more processors, one or more actions to reduce the cybersecurity risk level.

5 . The method of claim 4 , where the one or more actions comprise an action to remove a company from the portfolio of companies, an action to replace one of the companies in the portfolio of companies with a company that is not included in the portfolio of companies, or a combination thereof.

6 . The method of claim 4 , further comprising:

receiving, by the one or more processors, user input indicating a selected action of the one or more actions; and

initiating, by the one or more processors, the selected action based on the user input.

7 . The method of claim 1 , further comprising:

prior to determining the cybersecurity risk multiplier, weighting, by the one or more processors, the at least one attribute based on correlation with incidences of cybersecurity risk events.

8 . An apparatus for dynamically scoring a cybersecurity risk of a portfolio of companies, the apparatus comprising:

a memory;

one or more processors coupled to the memory, the one or more processors configured to:

receive attribute data indicative of cybersecurity risks of companies;

identify, based on the attribute data, at least one attribute that is common to a company that experienced a cybersecurity risk event and the portfolio of companies;

determine a cybersecurity risk multiplier for the portfolio of companies based on a number of the at least one attribute; and

output a cybersecurity risk level of the portfolio of companies based on the cybersecurity risk multiplier.

9 . The apparatus of claim 8 , where the company that experienced the cybersecurity risk event is in the portfolio of companies.

10 . The apparatus of claim 8 , where the company that experienced the cybersecurity risk event is not in the portfolio of companies.

11 . The apparatus of claim 8 , where the at least one attribute comprises an internal attribute that is shared by companies in the portfolio of companies.

12 . The apparatus of claim 11 , where the internal attribute comprises a vulnerable host, an obsolete user agent, a number of new malware events, an open port, a slow patching cadence, inadequate use of firewalls, inadequate use of intrusion detection systems, or a combination thereof.

13 . The apparatus of claim 8 , where the at least one attribute comprises an external attribute that is shared by companies in the portfolio of companies and one or more companies that are not in the portfolio of companies.

14 . The apparatus of claim 13 , where the external attribute comprises inadequate use of social media accounts, lost or stolen passwords, inadequate social network sentiment, or a combination thereof.

15 . A method for reducing a cybersecurity risk of a portfolio of companies, the method comprising:

receiving, by one or more processors, attribute data indicative of cybersecurity risks of companies;

assigning weights to attributes associated with the attribute data;

identifying at least one attribute between at least one company in the portfolio and at least one company that has experienced a cybersecurity risk event;

calculating a cybersecurity risk level for the portfolio based on the weights of the common attributes;

outputting one or more actions to reduce the cybersecurity risk level; and

updating the cybersecurity risk level based on the one or more actions.

16 . The method of claim 15 , further comprising:

Adjusting the weights of the attributes based on a new cybersecurity risk event.

17 . The method of claim 15 , where the one or more actions comprise removing a company from the portfolio, adding a company to the portfolio, or modifying cybersecurity measures of companies in the portfolio.

18 . The method of claim 15 , further comprising:

generating, by the one or more processors, a cybersecurity risk multiplier based on the common attributes; and

using the cybersecurity risk multiplier in calculating the cybersecurity risk level.

19 . An apparatus for reducing a cybersecurity risk of a portfolio of companies, the apparatus comprising:

a memory;

one or more processors coupled to the memory, the one or more processors configured to:

receive, by one or more processors, attribute data indicative of cybersecurity risks of companies;

assign weights to attributes associated with the attribute data;

identify at least one attribute between at least one company in the portfolio and at least one company that has experienced a cybersecurity risk event;

calculate a cybersecurity risk level for the portfolio based on the weights of the common attributes;

output one or more actions to reduce the cybersecurity risk level; and

update the cybersecurity risk level based on the one or more actions.

20 . The apparatus of claim 19 , where the one or more processors are further configured to:

adjust the weights of the attributes based on new cybersecurity risk events.

21 . The apparatus of claim 19 , where the one or more actions comprise removing a company from the portfolio, adding a company to the portfolio, or modifying cybersecurity measures of companies in the portfolio.

22 . The apparatus of claim 19 , where the one or more processors are further configured to:

generate a cybersecurity risk multiplier based on the common attributes; and

use the cybersecurity risk multiplier in calculating the cybersecurity risk level.

23 . The apparatus of claim 19 , where the one or more processors are further configured to:

determine degrees of mutuality for the common attributes; and

use the degrees of mutuality in calculating the cybersecurity risk level.

24 . The apparatus of claim 19 , where the one or more processors are further configured to:

output a graphical user interface displaying the cybersecurity risk level and the recommended actions.

Assignments (3)
SECURITY INTEREST Recorded Jul 29, 2025
From: SECURITYSCORECARD, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 071866/0453 →
SECURITY INTEREST Recorded Jul 29, 2025
From: SECURITYSCORECARD, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 072261/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2024
From: MO, JUE; VARGAS, LUIS; SOHVAL, A. ROBERT
To: SECURITYSCORECARD, INC.
Reel/Frame 068064/0696 →
Continuity (8)
Continuation 18299582 · Apr 12, 2023
Continuation 17240058 · Apr 26, 2021
Continuation 16889741 · Jun 1, 2020
Continuation 16537321 · Aug 9, 2019
Continuation 16244862 · Jan 10, 2019
Continuation 16019243 · Jun 26, 2018
Continuation 15663541 · Jul 28, 2017
Related Publication 20240378535A1 · Nov 14, 2024
References Cited (30)
US 8484066B2 · Miller · 2013 [cited by examiner]
US 8918883B1 · Boyle · 2014 [cited by examiner]
US 9294498B1 · Yampolskiy et al. · 2016 [cited by applicant]
US 10389738B2 · Muddu et al. · 2019 [cited by applicant]
US 10417614B2 · Johnson et al. · 2019 [cited by applicant]
US 10419450B2 · Muddu et al. · 2019 [cited by applicant]
US 10419465B2 · Muddu et al. · 2019 [cited by applicant]
US 10445496B2 · Gershoni et al. · 2019 [cited by applicant]
US 20040015376A1 · Zhu et al. · 2004 [cited by applicant]
US 20050066195A1 · Jones · 2005 [cited by applicant]
US 20060253709A1 · Cheng et al. · 2006 [cited by applicant]
US 20070006315A1 · Bushnaq · 2007 [cited by applicant]
US 20080034424A1 · Overcash et al. · 2008 [cited by applicant]
US 20080133531A1 · Baskerville et al. · 2008 [cited by applicant]
US 20080168529A1 · Anderson et al. · 2008 [cited by applicant]
US 20080288330A1 · Hildebrand et al. · 2008 [cited by applicant]
US 20140337973A1 · Foster et al. · 2014 [cited by applicant]
US 20150207813A1 · Reybok et al. · 2015 [cited by applicant]
US 20150229664A1 · Hawthorn et al. · 2015 [cited by applicant]
US 20170048267A1 · Yampolskiy et al. · 2017 [cited by applicant]
US 20170078315A1 · Allen et al. · 2017 [cited by applicant]
US 20170346839A1 · Peppe et al. · 2017 [cited by applicant]
US 20170346846A1 · Findlay · 2017 [cited by applicant]
US 20180124114A1 · Woods et al. · 2018 [cited by applicant]
US 20180146004A1 · Belfiore, Jr. et al. · 2018 [cited by applicant]
US 20180359264A1 · Sweet et al. · 2018 [cited by applicant]
US 20190034641A1 · Gil · 2019 [cited by examiner]
US 20190141063A1 · Hamdi · 2019 [cited by applicant]
WO WO2008140683A2 · 2008 [cited by applicant]
Patent Cooperation Treaty, International Search Report and Written Opinion issued for PCT Application No. PCT/US2018/042957, issued on Sep. 19, 2018; 7 pages. [cited by applicant]