US2023222411A1PendingUtilityA1

Systems and methods for creating and commissioning a security awareness program

Assignee: KNOWBE4 INCPriority: Jun 20, 2017Filed: Mar 2, 2023Published: Jul 13, 2023
Est. expiryJun 20, 2037(~10.9 yrs left)· nominal 20-yr term from priority
G06Q 10/06314H04L 63/1483
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, systems and apparatus for implementing a security awareness program are provided which allow a device of a security awareness system to receive attributes of an implementation of a security awareness program from an entity, such as a company. Responsive to the attributes, the device determines a configuration for each of a baseline simulated phishing campaign, electronic based training of users of the entity for security awareness and one or more subsequent simulated phishing campaigns. The device initiates execution of the baseline simulated phishing campaign to identify a percentage of users of the entity that are phish-prone.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system comprising:
 one or more processors, coupled to memory and configured to:   compare one or more attributes of an entity to one or more attributes of other entities;   determine, based on the comparison, a configuration and schedule of one or more simulated phishing campaigns to be executed to communicate simulated phishing communications to users of the entity to get users to click on one or more links in the simulated phishing communications;   execute according to the schedule the one or more simulated phishing campaigns to communicate simulated phishing communications to devices of users of the entity, receive indications of users clicking on the one or more links in the simulated phishing communications and identify from the received indications a percentage of users of the entity who are phish-prone; and   update one or more graphical representations of each of the one or more simulated phishing campaigns, displayed in an electronic calendar according to the schedule, a status of execution of the one or more simulated phishing campaigns as the one or more simulated phishing campaigns progresses with users clicking on the one or more links in the simulated phishing communications.   
     
     
         2 . The system of  claim 1 , wherein the one or more processors are further configured to display, responsive to selection of the one or more graphical representations, in a user interface a percentage of users of the entity who are phish-prone of the one or more simulated phishing campaign in comparison with a percentage of users of the other entities who are phish-prone. 
     
     
         3 . The system of  claim 1 , wherein the percentage of users of the entity who are phish-prone comprises a first number of users of the entity that clicked on the one or more links of the simulated phishing communications in relation to a second number of users of the entity that received the simulated phishing communications. 
     
     
         4 . The system of  claim 1 , wherein the one or more processors are further configured to execute a second one or more simulated phishing campaigns subsequent to the one or more simulated phishing campaigns based at least on the results of the one or more simulated phishing campaigns. 
     
     
         5 . The system of  claim 1 , wherein the one or more processors are further configured to determine, based on the comparison, electronic based training for users of the entity. 
     
     
         6 . The system of  claim 5 , wherein the one or more processors are further configured to execute the electronic based training to those users identified as phish-prone. 
     
     
         7 . The system of  claim 1 , wherein the one or more processors are further configured to receive attributes of the entity via a user interface presented via a display. 
     
     
         8 . The system of  claim 1 , wherein the one or more processors are further configured to compare the attributes for the entity to attributes of other entities that share at least one of the attributes. 
     
     
         9 . The system of  claim 1 , wherein the one or more processors are further configured to determine, based on a comparison of the percentage of users of the entity who are phish-prone to users of one or more other entities that share at least one of the attributes, the configuration of the one or more simulated phishing campaigns. 
     
     
         10 . The system of  claim 1 , wherein the one or more processors are further configured to generate in the electronic calendar, according to the schedule, the one or more graphical representations of each of the one or more simulated phishing campaigns and an electronic based training. 
     
     
         11 . A method comprising:
 comparing, by one or more processors, one or more attributes of an entity to one or more attributes of other entities;   determining, by the one or more processors based on the comparison, a configuration and schedule of one or more simulated phishing campaigns to be executed to communicate simulated phishing communications to users of the entity to get users to click on one or more links in the simulated phishing communications;   executing, by the one or more processors according to the schedule, the one or more simulated phishing campaigns to communicate simulated phishing communications to devices of users of the entity, receive indications of users clicking on the one or more links in the simulated phishing communications and identify from the received indications a percentage of users of the entity who are phish-prone; and   updating, by the one or more processors, one or more graphical representations of each of the one or more simulated phishing campaigns, displayed in an electronic calendar according to the schedule, a status of execution of the one or more simulated phishing campaigns as the one or more simulated phishing campaigns progresses with users clicking on the one or more links in the simulated phishing communications.   
     
     
         12 . The method of  claim 11 , further comprising displaying, by the one or more processors responsive to selection of the one or more graphical representations, in a user interface a percentage of users of the entity who are phish-prone of the one or more simulated phishing campaign in comparison with a percentage of users of the other entities who are phish-prone. 
     
     
         13 . The method of  claim 11 , wherein the percentage of users of the entity who are phish-prone comprises a first number of users of the entity that clicked on the one or more links of the simulated phishing communications in relation to a second number of users of the entity that received the simulated phishing communications. 
     
     
         14 . The system of  claim 1 , further comprising executing, by the one or more processors, a second one or more simulated phishing campaigns subsequent to the one or more simulated phishing campaigns based at least on the results of the one or more simulated phishing campaigns. 
     
     
         15 . The method of  claim 11 , further comprising determining, by the one or more processors based on the comparison, electronic based training for users of the entity. 
     
     
         16 . The method of  claim 15 , further comprising executing, by the one or more processors, the electronic based training to those users identified as phish-prone. 
     
     
         17 . The method of  claim 11 , further comprising receiving, by the one or more processors, attributes of the entity via a user interface presented via a display. 
     
     
         18 . The method of  claim 11 , further comprising comparing, by the one or more processors the attributes for the entity to attributes of other entities that share at least one of the attributes. 
     
     
         19 . The method of  claim 11 , further comprising determining, by the one or more processors based on a comparison of the percentage of users of the entity who are phish-prone to users of one or more other entities that share at least one of the attributes, the configuration of the one or more simulated phishing campaigns. 
     
     
         20 . The method of  claim 11 , further comprising generating, by the one or more processors in the electronic calendar, according to the schedule, the one or more graphical representations of each of the one or more simulated phishing campaigns and an electronic based training.

Join the waitlist — get patent alerts

Track US2023222411A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.