IP Library Granted Patent US 12,688,307
Granted Patent B2
US 12,688,307 · App. 18/947,397 · Granted Jul 21, 2026

Systems and methods for cybersecurity risk assessment

Inventors: Anthony R. Belfiore, Jr. (Mahwah, NJ); Mani Dhesi (London, GB); Adam Peckman (London, GB); Joseph Martinez (Boonton, NJ)
Assignee: Aon Global Operations SE, Singapore Branch
G06F21/577G06Q10/0635H04L63/1433H04L63/20G06F2221/034G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,688,307
App. No.
18/947,397
Filed
Nov 14, 2024
Granted
Jul 21, 2026
Kind
B2
Art Unit
2494
USPC
726/25
Abstract

In an illustrative embodiment, methods and systems for cybersecurity assessment of an organization's technology infrastructure include identifying features of the technology infrastructure and automatically generating a threat profile relevant to both the technology infrastructure and the organization's business (and/or business objectives), where the threat profile includes potential threat actors and threat scenarios applicable to the technology infrastructure. The methods and systems may include evaluating cybersecurity controls of the organization's technology infrastructure in light of the threat profile to identify and rate vulnerabilities within the technology infrastructure.

Claims (50)

1 . A system for automatically evaluating cybersecurity controls deployed by an entity to protect assets of a technological infrastructure, the system comprising:

a non-transitory computer readable data store comprising a plurality of defined cybersecurity threats; and

one or more processors configured to perform operations comprising

obtaining at least one industry of a plurality of industries associated with the entity,

obtaining entity information via analyzing resources connected to a network infrastructure of the entity, the entity information comprising

a plurality of technology infrastructure items of a technology infrastructure of a subject entity, and

a plurality of digital information controls applied by the subject entity to protect data within the technology infrastructure,

analyzing the entity information to identify a set of cybersecurity threats of the plurality of defined cybersecurity threats as a function of criticality to the technology infrastructure, wherein

a portion of the plurality of technology infrastructure items are designated as a set of high priority technology infrastructure items, and

the set of cybersecurity threats is identified based in part on impact to the set of high priority technology infrastructure items,

for each respective threat of the set of cybersecurity threats, calculating a cyber risk score in view of i) a control environment defined by a portion of the technology infrastructure as captured in the entity information, and ii) one or more controls of the plurality of digital information controls relevant to the control environment,

accessing, from at least one non-transitory computer readable medium, a plurality of peer ratings corresponding to a set of peer technology infrastructures of at least a portion of a plurality of technology infrastructures of a plurality of entities, wherein the set of peer technology infrastructures is identified based at least in part on the at least one industry of the entity,

calculating, from the plurality of peer ratings, a plurality of benchmark ratings comprising a respective benchmark rating corresponding to each cybersecurity threat of the set of cybersecurity threats, and

generating, for presentation at a computing device, an infrastructure evaluation comprising, for each respective threat of the set of cybersecurity threats, a graphical comparison of the cyber risk score of the respective threat for the subject entity to a corresponding benchmark rating of the plurality of benchmark ratings.

2 . The system of claim 1 , wherein at least a portion of the entity information is obtained via an interactive graphical user interface.

3 . The system of claim 1 , wherein the entity information comprises at least one geography of a plurality of geographies.

4 . The system of claim 1 , wherein the operations further comprise determining a recommended level of insurance for insuring against cybersecurity loss related to each cybersecurity threat of at least a portion of the set of cybersecurity threats.

5 . The system of claim 4 , wherein the infrastructure evaluation comprises the recommended level of insurance.

6 . The system of claim 4 , wherein the operations further comprise requesting, from one or more computing systems of one or more cybersecurity insurance vendors, at least one quote for cybersecurity insurance.

7 . The system of claim 1 , wherein the set of cybersecurity threats comprises one or more of social engineering, malware, or denial of service attack.

8 . The system of claim 1 , wherein each threat of the set of cybersecurity threats comprises a given threat actor of a plurality of threat actors, a given threat vector of a plurality of threat vectors, and a given threat scenario of a plurality of threat scenarios.

9 . The system of claim 1 , wherein the operations further comprise designating a portion of the plurality of technology infrastructure items as the set of high priority technology infrastructure items.

10 . The system of claim 9 , wherein designating the portion of the plurality of technology infrastructure items as the set of high priority technology infrastructure items comprises assigning, to each item of the portion of the plurality of technology infrastructure items, at least one criticality factor of a set of criticality factors.

11 . The system of claim 10 , wherein the set of criticality factors comprises at least one of confidentiality, integrity, availability, or financial value.

12 . The system of claim 1 , wherein the operations further comprise:

accessing post loss data corresponding to at least one of claims, insurance subscriptions, digital forensics, or incidence responses associated with cyber attacks;

correlating the post loss data with a portion of the plurality of technology infrastructure items; and

automatically identifying one or more additional threats of the plurality of defined cybersecurity threats based upon the correlation of the post loss data with the portion of the plurality of technology infrastructure items.

13 . The system of claim 1 , wherein the operations further comprise:

automatically collecting information on resources connected to a network of the subject entity;

wherein at least a portion of the plurality of technology infrastructure items are added to the entity information via the automatic collection.

14 . The system of claim 1 , wherein the plurality of technology infrastructure items comprises one or more confidential data collections.

15 . The system of claim 1 , wherein each respective subset of one or more subsets of the plurality of technology infrastructure items is associated, in the entity information, with a respective business area of a plurality of business areas of the subject entity.

16 . The system of claim 15 , wherein the plurality of business areas comprises one or more of an intellectual property business area, a customer business area, a human resources business area, a communication business area, a financial business area, or a legal business area.

17 . The system of claim 1 , wherein a subset of the plurality of technology infrastructure items is associated, in the entity information, with delivery of a commercial service.

18 . A method for automatically evaluating cybersecurity controls deployed by an entity to protect assets of a technological infrastructure, the method comprising:

obtaining, by processing circuitry, at least one industry of a plurality of industries associated with the entity;

obtaining, by the processing circuitry, entity information via analyzing resources connected to a network infrastructure of the entity, the entity information comprising

a plurality of technology infrastructure items of a technology infrastructure of a subject entity, and

a plurality of digital information controls applied by the subject entity to protect data within the technology infrastructure;

analyzing, by the processing circuitry, the entity information to identify a set of cybersecurity threats of a plurality of defined cybersecurity threats as a function of criticality to the technology infrastructure, wherein

a portion of the plurality of technology infrastructure items are designated as a set of high priority technology infrastructure items, and

the set of cybersecurity threats is identified based in part on impact to the set of high priority technology infrastructure items;

for each respective threat of the set of cybersecurity threats, calculating, by the processing circuitry, a cyber risk score in view of i) a control environment defined by a portion of the technology infrastructure as captured in the entity information, and ii) one or more controls of the plurality of digital information controls relevant to the control environment;

accessing, from at least one non-transitory computer readable medium, a plurality of peer ratings corresponding to a set of peer technology infrastructures of at least a portion of a plurality of technology infrastructures of a plurality of entities, wherein the set of peer technology infrastructures is identified based at least in part on the at least one industry of the entity;

calculating, by the processing circuitry from the plurality of peer ratings, a plurality of benchmark ratings comprising a respective benchmark rating corresponding to each cybersecurity threat of the set of cybersecurity threats; and

generating, by the processing circuitry for presentation at a computing device, an infrastructure evaluation comprising, for each respective threat of the set of cybersecurity threats, a graphical comparison of the cyber risk score of the respective threat for the subject entity to a corresponding benchmark rating of the plurality of benchmark ratings.

19 . The method of claim 18 , further comprising determining, by the processing circuitry, a recommended level of insurance for insuring against cybersecurity loss related to each cybersecurity threat of at least a portion of the set of cybersecurity threats, wherein

the infrastructure evaluation comprises the recommended level of insurance.

20 . The method of claim 18 , further comprising designating, by the processing circuitry based on evaluating the entity information, a portion of the plurality of technology infrastructure items as the set of high priority technology infrastructure items.

Continuity (6)
Continuation 18367862 · Sep 13, 2023
Continuation 17206630 · Mar 19, 2021
Continuation 16539075 · Aug 13, 2019
Continuation 15820786 · Nov 22, 2017
Provisional Application 62425556 · Nov 22, 2016
Related Publication 20250298903A1 · Sep 25, 2025
References Cited (67)
US 7584508B1 · Kashchenko et al. · 2009 [cited by applicant]
US 9294498B1 · Yampolskiy et al. · 2016 [cited by applicant]
US 10181039B1 · Ranjan et al. · 2019 [cited by applicant]
US 10387657B2 · Belfiore, Jr. et al. · 2019 [cited by applicant]
US 10402788B2 · Morrow et al. · 2019 [cited by applicant]
US 10410158B1 · Yumer · 2019 [cited by examiner]
US 10963572B2 · Belfiore, Jr. et al. · 2021 [cited by applicant]
US 20020049617A1 · Lencki et al. · 2002 [cited by applicant]
US 20020095316A1 · Toan et al. · 2002 [cited by applicant]
US 20020103680A1 · Newman · 2002 [cited by applicant]
US 20020169727A1 · Melnick et al. · 2002 [cited by applicant]
US 20040006704A1 · Dahlstrom et al. · 2004 [cited by applicant]
US 20040138950A1 · Hyman et al. · 2004 [cited by applicant]
US 20050065807A1 · Deangelis et al. · 2005 [cited by applicant]
US 20070016955A1 · Goldberg et al. · 2007 [cited by applicant]
US 20070067846A1 · Mcfarlane et al. · 2007 [cited by applicant]
US 20090106656A1 · Handy et al. · 2009 [cited by applicant]
US 20100114634A1 · Christiansen et al. · 2010 [cited by applicant]
US 20100114635A1 · Watanabe et al. · 2010 [cited by applicant]
US 20110138471A1 · Van De Weyer et al. · 2011 [cited by applicant]
US 20110201902A1 · Shiga et al. · 2011 [cited by applicant]
US 20120296455A1 · Ohnemus et al. · 2012 [cited by applicant]
US 20130227697A1 · Zandani · 2013 [cited by applicant]
US 20130253979A1 · Williams et al. · 2013 [cited by applicant]
US 20130325545A1 · Mordvinova et al. · 2013 [cited by applicant]
US 20140137257A1 · Martinez et al. · 2014 [cited by applicant]
US 20140142990A1 · Manjarekar · 2014 [cited by applicant]
US 20140173739A1 · Ahuja et al. · 2014 [cited by applicant]
US 20140195269A1 · Sircar et al. · 2014 [cited by applicant]
US 20150339446A1 · Sperling et al. · 2015 [cited by applicant]
US 20150356477A1 · Milkman et al. · 2015 [cited by applicant]
US 20160110819A1 · Abramowitz · 2016 [cited by applicant]
US 20160119373A1 · Fausto · 2016 [cited by examiner]
US 20160164892A1 · Satish et al. · 2016 [cited by applicant]
US 20160234247A1 · Ng et al. · 2016 [cited by applicant]
US 20160248800A1 · Ng et al. · 2016 [cited by applicant]
US 20160378932A1 · Sperling et al. · 2016 [cited by applicant]
US 20170046519A1 · Cam · 2017 [cited by applicant]
US 20170154337A1 · Wingate-Whyte et al. · 2017 [cited by applicant]
US 20170244740A1 · Mahabir et al. · 2017 [cited by applicant]
US 20170331840A1 · Ranjan · 2017 [cited by applicant]
US 20170331849A1 · Yu et al. · 2017 [cited by applicant]
US 20170346846A1 · Findlay · 2017 [cited by applicant]
US 20180069889A1 · Beale et al. · 2018 [cited by applicant]
US 20180083999A1 · Cherian · 2018 [cited by applicant]
US 20180124091A1 · Sweeney et al. · 2018 [cited by applicant]
US 20180146004A1 · Belfiore, Jr. et al. · 2018 [cited by applicant]
US 20180270265A1 · Sage · 2018 [cited by applicant]
US 20190164134A1 · Morrow et al. · 2019 [cited by applicant]
US 20200042716A1 · Belfiore, Jr. et al. · 2020 [cited by applicant]
CA 2357268 · 2002 [cited by applicant]
EP 2498198A1 · 2012 [cited by applicant]
EP 3545418A1 · 2019 [cited by applicant]
WO WO2001033410A2 · 2001 [cited by applicant]
WO WO2018098294A1 · 2018 [cited by applicant]
D. J. Bodeau, R. Graubart and J. Fabius-Greene, “Improving Cyber Security and Mission Assurance Via Cyber Preparedness (Cyber Prep) Levels,” 2010 IEEE Second International Conference on Social Computing, Minneapolis, MN… [cited by examiner]
International Search Report and Written Opinion dated Feb. 12, 2018 issued in related International Application No. PCT/US17/63035, 15 pages (submitted in related U.S. Appl. No. 15/820,786)*. [cited by applicant]
International Preliminary Report on Patentability issued in PCT Application No. PCT/US2017/063035 on May 28, 2019. (submitted in related U.S. Appl. No. 16/539,075)*. [cited by applicant]
Supplementary European Search Report issued in EP Application No. 17874349.8 on Jul. 9, 2020.(submitted in related U.S. Appl. No. 16/539,075)*. [cited by applicant]
Chmielecki T., et al., Enterprise-oriented Cybersecurity Management. Proceedings of the 2014 Federated Conference on Computer Science and Information Systems, Sep. 7, 2014, pp. 863-870.*. [cited by applicant]
TailorWell Launches First Online Health Insurance Comparison Tool Targeted Specifically for Unique Needs of Small Businesses in Washington and Oregon, Marketwire, COMTEX News Network, Inc., Nov. 18, 2015. (submitted in … [cited by applicant]
Rawat et al., “Advancement of recommender system based on clickstream data using gradient boosting and random forest classifiers.” 2017 8th International Conference on Computing, Communication and Networking Technologie… [cited by applicant]
International Search Report and Written Opinion issued in PCT Application No. PCT/SG2018/050580 on Feb. 12, 2019. (submitted in related U.S. Appl. No. 16/539,075)*. [cited by applicant]
Non-Final Office Action issued in U.S. Appl. No. 16/539,075 on Feb. 28, 2018. (submitted in related U.S. Appl. No. 16/539,075)*. [cited by applicant]
Final Office Action issued in U.S. Appl. No. 16/539,075 on Nov. 2, 2018 (submitted in related U.S. Appl. No. 16/539,075)*. [cited by applicant]
Notice Of Allowance issued in U.S. Appl. No. 16/539,075 on Apr. 4, 2019. (submitted in related U.S. Appl. No. 16/539,075)*. [cited by applicant]
European Examination Report dated Apr. 15, 2021 in EP Application No. 17 874 349.8. (submitted in related U.S. Appl. No. 17/206,630)*. [cited by applicant]