IP Library Granted Patent US 11,438,367
Granted Patent B2
US 11,438,367 · App. 17/024,744 · Granted Sep 6, 2022

Systems and methods for evaluating and training cybersecurity teams

Inventor: Christian Lee Basballe Sorensen (Arlington, VA)
Assignee: SightGain Inc.
H04L63/1433G06Q10/06375G06Q10/06398G06Q10/063112G06Q10/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,438,367
App. No.
17/024,744
Granted
Sep 6, 2022
Kind
B2
Abstract

Techniques for evaluating and optimizing cybersecurity operations in an organization is disclosed. The method includes the step of providing a first set of threat scenarios to a cybersecurity operations team in a live environment and a second set of scenarios in a static environment. The response of the teams including various parameters associated it such as time taken for responding, strategies used, effectiveness of the response, etc., are recorded. Based on the recorded responses, the method further performs the step of determining overall assessment scores. Upon determining the scores, the method further performs the step of contextualizing the scores based on a plurality of parameters. Based on the contextualized scores, the method provides detailed insights and recommendations related to the performance of cybersecurity teams. Furthermore, the technique recommends modifications in processes and technology related to the cybersecurity infrastructure that directly affects the performance of cybersecurity operations personnel.

Claims (49)

1. A computer-implemented method for evaluating preparedness in dealing with cybersecurity threats among cybersecurity personnel in an organization, comprising:

selecting a cybersecurity response team in the organization for evaluation;

after selecting the cybersecurity response team, automatically generating threat scenarios from known security attack scenarios;

providing a first set of threat scenarios from the generated threat scenarios to the cybersecurity response team in a live environment;

recording one or more tactics used by the cybersecurity response team in response to the first set of threat scenarios including: time taken to determine one or more threat types, time taken to prepare and deploy response tactics to overcome each of the one or more threat types, and effectiveness of the response tactics in overcoming each of the one or more threat types;

providing a second set of scenarios from the generated threat scenarios to the cybersecurity response team in a static environment including a plurality of questions related to one or more threat types and associated response tactics;

recording a plurality of responses provided by the cybersecurity response team in response to the second set of scenarios;

automatically generating personnel assessment scores based on the recorded responses provided by the cybersecurity response team in response to the first set of threat scenarios and the second set of threat scenarios;

contextualizing the personnel assessment scores based on parameters including credential access, lateral movement, command and control, and exfiltration;

converting the contextualized personnel assessment scores to dynamic visual representations; and

providing automated recommendations in a configurable dynamic dashboard to improve performance of the cybersecurity response team based on the contextualized personnel assessment scores and the dynamic visual representations, wherein the automated recommendations include information related to performance of each cybersecurity personnel in the cybersecurity team and optimized cybersecurity technology and processes to reduce cybersecurity performance gaps in the organization.

2. The computer-implemented method of claim 1 , wherein the cybersecurity response team comprises one or more cybersecurity personnel associated with the organization.

3. The computer-implemented method of claim 1 , wherein the first set of threat scenarios include predefined threat scenarios, newly created threat scenarios, or a combination of both.

4. The computer-implemented method of claim 1 , wherein the live environment where the first set of threat scenarios are provided includes a production environment.

5. The computer-implemented method of claim 1 , wherein contextualizing the determined personnel assessment scores further comprises transforming the personnel assessment scores into data categories including alert, detect, and protect.

6. The computer-implemented method of claim 5 , wherein alert data is related to cybersecurity performance alerts that are to be sent for alerting probable threat activities, detect data is related to cybersecurity threats that are identified, and protect data is related to cybersecurity threats that were blocked by the cybersecurity response team.

7. A system, comprising:

at least one processor; and

at least one non-transitory computer readable storage medium storing instructions thereon that, when executed by the at least one processor, cause the system to:

select a cybersecurity response team in the organization for evaluation;

after selecting the cybersecurity response team, automatically generate threat scenarios from known security attack scenarios;

provide a first set of threat scenarios from the generated threat scenarios to the cybersecurity response team in a live environment;

record one or more tactics used by the cybersecurity response team in response to the first set of threat scenarios including: time taken to determine one or more threat types, time taken to prepare and deploy response tactics to overcome each of the one or more threat types, and effectiveness of the response tactics in overcoming each of the one or more threat types;

provide a second set of scenarios from the generated threat scenarios to the cybersecurity response team in a static environment including a plurality of questions related to one or more threat types and associated response tactics;

record a plurality of responses provided by the cybersecurity response team in response to the second set of scenarios;

determine personnel assessment scores based on the recorded responses provided by the cybersecurity response team in response to the first set of threat scenarios and the second set of scenarios;

contextualize the personnel assessment scores based on parameters including credential access, lateral movement, command and control, and exfiltration;

convert the contextualized personnel assessment scores to dynamic visual representations; and

provide automated recommendations in a configurable dynamic dashboard to improve performance of the cybersecurity response team based on the contextualized personnel assessment scores and the dynamic visual representations, wherein the automated recommendations include information related to performance of each cybersecurity personnel in the cybersecurity team and optimized cybersecurity technology and processes to reduce cybersecurity performance gaps in the organization.

8. The system of claim 7 , wherein the cybersecurity response team comprises one or more cybersecurity personnel associated with the organization.

9. The system of claim 7 , wherein the first set of threat scenarios include predefined threat scenarios, newly created threat scenarios, or a combination of both.

10. The system of claim 7 , wherein the live environment where the first set of threat scenarios are provided includes a production environment.

11. The system of claim 7 , wherein contextualizing the determined personnel assessment scores further comprises transforming the personnel assessment scores into data categories including alert, detect, and protect.

12. The system of claim 11 , wherein alert data is related to cybersecurity performance alerts that are to be sent for alerting probable threat activities, detect data is related to cybersecurity threats that are identified, and protect data is related to cybersecurity threats that were blocked by the cybersecurity response team.

13. A non-transitory computer readable medium storing instructions thereon that, when executed by at least one processor, cause a computer system to:

select a cybersecurity response team in the organization for evaluation;

after selecting the cybersecurity response team, automatically generate threat scenarios from known security attack scenarios;

provide a first set of threat scenarios from the generated threat scenarios to the cybersecurity response team in a live environment;

record one or more tactics used by the cybersecurity response team in response to the first set of threat scenarios including: time taken to determine one or more threat types, time taken to prepare and deploy response tactics to overcome each of the one or more threat types, and effectiveness of the response tactics in overcoming each of the one or more threat types;

provide a second set of scenarios from the generated threat scenarios to the cybersecurity response team in a static environment including a plurality of questions related to one or more threat types and associated response tactics;

record a plurality of responses provided by the cybersecurity response team in response to the second set of scenarios;

determine personnel assessment scores based on the recorded responses provided by the cybersecurity response team in response to the first set of threat scenarios and the second set of scenarios;

contextualize the personnel assessment scores based on parameters including credential access, lateral movement, command and control, and exfiltration;

converting the contextualized personnel assessment scores to dynamic visual representations; and

provide automated recommendations in a configurable dynamic dashboard to improve performance of the cybersecurity response team based on the contextualized personnel assessment scores and the dynamic visual representations, wherein the automated recommendations include information related to performance of each cybersecurity personnel in the cybersecurity team and optimized cybersecurity technology and processes to reduce cybersecurity performance gaps in the organization.

14. The non-transitory computer readable medium of claim 13 , wherein the first set of threat scenarios include predefined threat scenarios, newly created threat scenarios, or a combination of both.

15. The non-transitory computer readable medium of claim 13 , wherein the live environment where the first set of threat scenarios are provided includes a production environment.

16. The non-transitory computer readable medium of claim 13 , wherein contextualizing the determined personnel assessment scores further comprises transforming the personnel assessment scores into data categories including alert, detect, and protect.

17. The non-transitory computer readable medium of claim 16 , wherein alert data is related to cybersecurity performance alerts that are to be sent for alerting probable threat activities, detect data is related to cybersecurity threats that are identified, and protect data is related to cybersecurity threats that were blocked by the cybersecurity response team.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY'S NAME, ADDRESS AND APPLICATION NO. IN THE ASSIGNMENT DOCUMENT PREVIOUSLY RECORDED AT REEL: 054851 FRAME: 0305. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 4, 2021
From: BASBALLE SORENSEN, CHRISTIAN LEE
To: SIGHTGAIN, INC.
Reel/Frame 056788/0019 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2021
From: BASBALLE SORENSEN, CHRISTIAN LEE
To: SIGHT GAIN INC
Reel/Frame 054851/0305 →
Continuity (3)
Continuation In Part 16888666 · May 30, 2020
Provisional Application 62853767 · May 29, 2019
Related Publication 20210006584A1 · Jan 7, 2021
Cited By (1)
US 12,609,954