IP Library Granted Patent US 12,651,201
Granted Patent B2
US 12,651,201 · App. 18/800,852 · Granted Jun 9, 2026

Software application for continually assessing, processing, and remediating cyber-risk in real time

Inventors: Jeffrey J. Engle (Pompano Beach, FL); Thomas R. Neclerio (Fort Lauderdale, FL); Ariel Posada (Coral Springs, FL)
Assignee: Conquest Technology Services Corp.
G06N20/00G06F18/214H04L63/1416H04L63/1425H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,651,201
App. No.
18/800,852
Granted
Jun 9, 2026
Kind
B2
Abstract

A software based application for assessing, processing, and remediating cyber-risk in real time may comprise, without limitation, a profiling component, an analytic component, an evaluation component, and a monitoring component which may, in conjunction therewith, operate to allow an organization to adaptively adjust an organization's network security to continuously improve and mature same. Such components may operate to: (1) determine an organization's operational baseline; (2) identify risks and hazards inherent therein; (3) generate, and verify the efficacy of, remedial controls to such risks and hazards; (4) document and audit such determinations; and (5) continually monitor the organization's network security. In such a manner, the network security architecture of an organization may be remediated according to threat scenario-based control efficacy and residual risk determinations according to the agnostic, risk-focused, and system-based approach disclosed herein.

Claims (41)

1 . A system for processing cyber-risk in real time, the system comprising:

a profiling component configured to determine at least one baseline of a user, the at least one baseline of the user comprising an expected operations for a network's security compliance at least one control level;

an analytic component configured to generate at least one threat framework;

an evaluation component configured to:

utilize the threat framework to organize at least one theoretical threat against an organization's determined baseline network security;

determine at least one theoretical control according to the at least one theoretical threat; and

determine at least one implementation priority according to the at least one theoretical control; and

an implementation component configured to implement at least one remedial control according to the at least one theoretical control and the at least one implementation priority.

2 . The system of claim 1 , wherein utilizing the threat framework includes utilizing golden images in a sandbox environment to determine at least one identified threat from the at least one threat framework applied to the at least one baseline of the user, wherein the golden images are representative of the expected operations for the network's security compliance.

3 . The system of claim 1 , wherein utilizing the threat framework includes accessing a subset of approved nodes, the subset of the approved nodes derived from the at least one baseline of the user, and run the at least one threat framework within the subset of the approved nodes to determine the at least one theoretical threat.

4 . The system of claim 1 , wherein the at least one implementation priority is determined according to a criticality of the at least one theoretical control.

5 . The system of claim 1 , wherein the at least one implementation priority is determined according to a volatility of the at least one theoretical control.

6 . The system of claim 1 , wherein the profiling component is configured to determine the at least one baseline of the user according to at least two data feeds.

7 . The system of claim 1 , wherein the at least one threat framework is determined according to an analytic routine.

8 . The system of claim 1 , wherein the theoretical control is configured to remediate a risk of the at least one theoretical threat.

9 . A system for processing cyber-risk in real time, the system comprising:

a profiling component configured to determine at least one baseline of a user, the at least one baseline of the user comprising an expected operations for a network's security compliance at least one control level;

an analytic component configured to generate at least one threat framework;

an evaluation component configured to:

utilize the threat framework to organize at least one theoretical threat against an organization's determined baseline network security, wherein utilizing the threat framework includes utilizing golden images representative of the expected operations for the network's security compliance in a sandbox environment to determine at least one identified threat from the at least one threat framework applied to the at least one baseline of the user;

determine at least one theoretical control according to the at least one theoretical threat; and

determine at least one implementation priority according to the at least one theoretical control; and

an implementation component configured to implement at least one remedial control according to the at least one theoretical control and the at least one implementation priority.

10 . The system of claim 9 , wherein the at least one implementation priority is determined according to a criticality of the at least one theoretical control.

11 . The system of claim 9 , wherein the at least one implementation priority is determined according to a volatility of the at least one theoretical control.

12 . The system of claim 9 , wherein the profiling component is configured to determine the at least one baseline of the user according to at least two data feeds.

13 . The system of claim 9 , wherein the at least one threat framework is determined according to an analytic routine.

14 . The system of claim 9 , wherein the theoretical control is configured to remediate a risk of the at least one theoretical threat.

15 . A system for processing cyber-risk in real time, the system comprising:

a profiling component configured to determine at least one baseline of a user, the at least one baseline of the user comprising at least one control level;

an analytic component configured to generate at least one threat framework;

an evaluation component configured to:

utilize the threat framework to organize at least one theoretical threat against an organization's determined baseline network security, wherein utilizing the threat framework includes accessing a subset of approved nodes derived from the at least one baseline of the user, and run the at least one threat framework within the subset of the approved nodes to determine the at least one theoretical threat;

determine at least one theoretical control according to the at least one theoretical threat; and

determine at least one implementation priority according to the at least one theoretical control; and

an implementation component configured to implement at least one remedial control according to the at least one theoretical control and the at least one implementation priority.

16 . The system of claim 15 , wherein the at least one implementation priority is determined according to a criticality of the at least one theoretical control.

17 . The system of claim 15 , wherein the at least one implementation priority is determined according to a volatility of the at least one theoretical control.

18 . The system of claim 15 , wherein the profiling component is configured to determine the at least one baseline of the user according to at least two data feeds.

19 . The system of claim 15 , wherein the at least one threat framework is determined according to an analytic routine.

20 . The system of claim 15 , wherein the theoretical control is configured to remediate a risk of the at least one theoretical threat.

Assignments (1)
SECURITY INTEREST Recorded Jul 15, 2025
From: BLUEVOYANT LLC; CONQUEST TECHNOLOGY SERVICES LLC
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 071956/0110 →
Continuity (3)
Continuation 16897779 · Jun 10, 2020
Provisional Application 62859414 · Jun 10, 2019
Related Publication 20250029009A1 · Jan 23, 2025
References Cited (29)
US 4406351A · Littlejohn et al. · 1983 [cited by applicant]
US 5440301A · Evans · 1995 [cited by applicant]
US 9003231B1 · Graves · 2015 [cited by applicant]
US 12086694B2 · Engle · 2024 [cited by examiner]
US 20020057204A1 · Bligh · 2002 [cited by applicant]
US 20070236352A1 · Allen et al. · 2007 [cited by applicant]
US 20080314681A1 · Patel et al. · 2008 [cited by applicant]
US 20130053063A1 · McSheffrey · 2013 [cited by applicant]
US 20130298192A1 · Kumar et al. · 2013 [cited by applicant]
US 20150379862A1 · Jones, Jr. et al. · 2015 [cited by applicant]
US 20160232774A1 · Noland et al. · 2016 [cited by applicant]
US 20160247369A1 · Simmons · 2016 [cited by applicant]
US 20160284174A1 · Connell, II · 2016 [cited by applicant]
US 20170109529A1 · Kraft · 2017 [cited by applicant]
US 20170124842A1 · Sinha et al. · 2017 [cited by applicant]
US 20170295199A1 · Kirti et al. · 2017 [cited by applicant]
US 20180330586A1 · Albreth, Jr. et al. · 2018 [cited by applicant]
US 20180375576A1 · Stout et al. · 2018 [cited by applicant]
US 20180375892A1 · Ganor · 2018 [cited by applicant]
US 20190145648A1 · Sinha et al. · 2019 [cited by applicant]
US 20190207968A1 · Heckman et al. · 2019 [cited by applicant]
US 20190266860A1 · Lakshmipathy et al. · 2019 [cited by applicant]
US 20200145775A1 · Cardinaux et al. · 2020 [cited by applicant]
US 20200162497A1 · Narayan · 2020 [cited by applicant]
US 20200211358A1 · Burke et al. · 2020 [cited by applicant]
US 20200294372A1 · Rodriguez · 2020 [cited by applicant]
WO 2020185742A1 · 2020 [cited by applicant]
WO 2020252001A1 · 2020 [cited by applicant]
International Search Report for Corresponding International Application No. PCT/US2020/036967 mailed Aug. 25, 2020. [cited by applicant]