IP Library › Granted Patent US 11,550,924
Granted Patent B2
US 11,550,924 · App. 16/914,791 · Granted Jan 10, 2023

Automated and continuous risk assessment related to a cyber liability insurance transaction

Inventor: Stephen G. Hamby (Hoschton, GA)
Assignee: G-Software, Inc.
G06F21/577G06Q40/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,550,924
App. No.
16/914,791
Granted
Jan 10, 2023
Kind
B2
Abstract

Systems, methods, and computer program products for evaluating situational awareness of a cyberspace operational environment in a security control server in connection with a cyber-liability insurance transaction. The system may include a security control server that generates a model representing a cyber-liability insurance transaction. The security control server may further generate a ranked list of recommended security controls that are designed to reduce cyber-risks, and thereby the premium, associated with the cyber-liability insurance transaction model. Additionally, the security control server may continuously and automatically monitor one or more security controls implemented by a cyber-liability insurance consumer to insured information technology assets to evaluate compliance with the cyber-liability insurance transaction model.

Claims (30)

1. A method performed by an insured device in electronic communication with a security control server over an electronic communications network to assess risk associated with a cyber-liability insurance transaction pertaining to the insured device, the method comprising the steps of:

operating, on the insured device, one or more security controls for mitigating a cyber-risk associated with a policy axiom generated by the security control server;

operating, on the insured device, a security control monitoring agent; and

receiving, from the security control server via the electronic communications network, an external monitoring configuration for the security control monitoring agent;

wherein operating the security control monitoring agent comprises monitoring, by the monitoring agent, the one or more security controls on the insured device in accordance with the external monitoring configuration received from the security control server.

2. The method of claim 1 , wherein the external monitoring configuration received from the security control server comprises, for each policy axiom associated with a security control, a name of a process that implements the security control, a port number that the security control listens to, a host identifier, and an alert mechanism that the monitoring agent should use to notify the security control server.

3. The method of claim 1 , further comprising transmitting, from the insured device to the security control server, an alert that one or more security controls for the mitigated risk is not operational in accordance with the policy axiom generated by the security control server.

4. The method of claim 3 , wherein the alert is only transmitted if there is no operational backup or alternate security control on the insured device that addresses the cyber-risk.

5. The method of claim 3 , wherein the alert is also transmitted to a cyber-liability insurance customer.

6. An insured device in electronic communication with a security control server over an electronic communications network to assess risk associated with a cyber-liability insurance transaction pertaining to the insured device, the insured device comprising:

a processor;

a memory coupled to the processor;

a network interface coupled to a network, wherein the processor is configured to:

operate one or more security controls for mitigating a cyber-risk associated with a policy axiom generated by the security control server;

operate a security control monitoring agent; and

receive, from the security control server via the network, an external monitoring configuration for the security control monitoring agent;

wherein the security control monitoring agent is operated to monitor the one or more security controls on the insured device in accordance with the external monitoring configuration received from the security control server.

7. The device of claim 6 , wherein the external monitoring configuration received from the security control server comprises, for each policy axiom associated with a security control, a name of a process that implements the security control, a port number that the security control listens to, a host identifier, and an alert mechanism that the monitoring agent should use to notify the security control server.

8. The device of claim 6 , wherein the processor is further configured to transmit, from the insured device to the security control server, an alert that one or more security controls for the mitigated risk is not operational in accordance with the policy axiom generated by the security control server.

9. The device of claim 8 , wherein the processor is configured to transmit the alert only if there is no operational backup or alternate security control on the insured device that addresses the cyber-risk.

10. The device of claim 8 , wherein the alert is also transmitted to a cyber-liability insurance customer.

11. A computer program product for assessing risk associated with a cyber-liability insurance transaction pertaining to an insured device, the computer program product comprising a non-transitory computer readable medium containing instructions for a processor to:

operate one or more security controls on an insured device for mitigating a cyber-risk associated with a policy axiom generated by a security control server;

operate a security control monitoring agent o the insured device; and

receive, from the security control server via the network, an external monitoring configuration for the security control monitoring agent;

wherein the security control monitoring agent is operated to monitor the one or more security controls on the insured device in accordance with the external monitoring configuration received from the security control server.

12. The computer program product of claim 11 , wherein the external monitoring configuration received from the security control server comprises, for each policy axiom associated with a security control, a name of a process that implements the security control, a port number that the security control listens to, a host identifier, and an alert mechanism that the monitoring agent should use to notify the security control server.

13. The computer program product of claim 11 , wherein the non-transitory computer readable medium further comprises instructions executable by a processor to transmit, from the insured device to the security control server, an alert that one or more security controls for the mitigated risk is not operational in accordance with the policy axiom generated by the security control server.

14. The computer program product of claim 13 , wherein the non-transitory computer readable medium further comprises instructions executable by the processor to transmit the alert only if there is no operational backup or alternate security control on the insured device that addresses the cyber-risk.

15. The computer program product of claim 13 , wherein the non-transitory computer readable medium further comprises instructions executable by the processor to transmit the alert to a cyber-liability insurance customer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2020
From: HAMBY, STEPHEN G.
To: G-SOFTWARE, INC.
Reel/Frame 053072/0815 →
Continuity (4)
Continuation 15042742 · Feb 12, 2016
Provisional Application 62129247 · Mar 6, 2015
Provisional Application 62116717 · Feb 16, 2015
Related Publication 20200394314A1 · Dec 17, 2020
Cited By (1)
US 12,223,057