US2023351456A1PendingUtilityA1

System and methods for vulnerability assessment and provisioning of related services and products for efficient risk suppression

Assignee: AON RISK CONSULTANTS INCPriority: Jan 31, 2018Filed: Dec 21, 2022Published: Nov 2, 2023
Est. expiryJan 31, 2038(~11.5 yrs left)· nominal 20-yr term from priority
G06Q 30/0282G06F 16/9537G06Q 30/0641H04L 63/1433H04L 63/20H04L 63/0209
71
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In an illustrative embodiment, systems and methods for cyber vulnerability assessment include obtaining assessment data including information pertaining to domains of cyber security vulnerability of an enterprise and, for each security domain, a respective domain-level vulnerability score, identifying risk(s) relevant to the enterprise based on domain-level vulnerability score(s), identifying recommended products or services for mitigating each of the risks, and preparing a graphical user interface for selecting a portion of the recommended products or services. A user may select one or more products or services through the user interface for purchase and/or deployment planning. The domain-level vulnerability scores may be compared to peer vulnerabilities scores, target vulnerability scores, or prospective vulnerability scores based upon application of certain recommended products or services.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A system for evaluating and mitigating cybersecurity risk, the system comprising:
 a non-transitory computer-readable medium storing a plurality of questions related to cybersecurity risk exposure; and   processing circuitry configured to perform operations comprising
 determining a subject security domain scheme of a plurality of security domain schemes for an entity, 
 conducting, via network communications with one or more network-connected computing devices remote to the system, a set of interactions with one or more users associated with the entity, the set of interactions comprising
 sending, for display to at least one user of the one or more users, a set of questions of the plurality of questions, wherein the set of questions correspond to the subject security domain scheme, and 
 obtaining information from the at least one user regarding a computing infrastructure of the entity, the information including a set of answers responsive to the set of questions presented by the system to the at least one user, 
 
 calculating one or more vulnerability scores for the entity, wherein the calculating comprises evaluating the set of answers in view of the subject security domain scheme, 
 determining, based at least in part on the subject security domain scheme, one or more target scores for the entity, 
 using the one or more vulnerability scores and the information, identifying a plurality of mitigation options, each mitigation option of the plurality of mitigation options determined to improve, upon implementation, at least one vulnerability score of the one or more vulnerability scores, 
 as part of the set of interactions,
 sending, for display to at least one user of the one or more users, at least one vulnerability score of the one or more vulnerability scores, at least one target score of the one or more target scores, and information regarding at least a portion of the plurality of mitigation options, and 
 receiving, from the at least one user of the one or more users, a selection of at least one mitigation option of the plurality of mitigation options, 
 for each respective mitigation option of the at least one mitigation option, identifying a timing of application of the respective mitigation option, and 
 sending, for display to the at least one user, a graphical roadmap comprising each mitigation option of the at least one mitigation option, wherein the graphical roadmap comprises, for each respective mitigation option of the at least one mitigation option, the timing of the application of the respective mitigation option and at least one of an estimated cost associated with implementing the respective mitigation option, an estimated duration for implementing the respective mitigation option, and a responsible party. 
 
   
     
     
         3 . The system of  claim 2 , wherein the computing infrastructure comprises one or more hardware assets, one or more software assets, and one or more informational assets of the entity. 
     
     
         4 . The system of  claim 2 , wherein the operations comprise, for each respective mitigation option of one or more mitigation options of the at least one mitigation option:
 identifying a dependency mitigation option upon which the respective mitigation option relies; and   determining the timing of the application of the respective mitigation option based in part on the dependency mitigation option.   
     
     
         5 . The system of  claim 2 , wherein receiving the selection of at least one mitigation option comprises receiving an indication of the respective responsible party for each mitigation option of the at least one mitigation option. 
     
     
         6 . The system of  claim 2 , wherein the plurality of mitigation options comprises at least one of a) one or more products or b) one or more services. 
     
     
         7 . The system of  claim 6 , wherein the one or more products comprises at least one cybersecurity insurance product. 
     
     
         8 . The system of  claim 7 , wherein identifying the plurality of mitigation options comprises determining eligibility of the entity for a first cybersecurity insurance product of the at least one cybersecurity insurance product. 
     
     
         9 . The system of  claim 7 , wherein the processing circuitry is further configured to perform operations comprising, as part of the set of interactions, enabling one or more of the one or more users to purchase the at least one cybersecurity insurance product. 
     
     
         10 . The system of  claim 2 , wherein presenting the graphical roadmap comprises modeling, for display to the at least one user, a graphical timeline visually mapping the timing of the application of each mitigation option of the at least one mitigation option. 
     
     
         11 . The system of  claim 2 , wherein each question of the plurality of questions is mapped to at least one security domain of the respective set of security domains corresponding to each security domain scheme of at least a portion of the plurality of security domain schemes. 
     
     
         12 . The system of  claim 2 , wherein each question of the plurality of questions is mapped to two or more potential response values, wherein each response value of the two or more potential response values is associated with a respective score of two or more potential scores. 
     
     
         13 . The system of  claim 2 , wherein the one or more vulnerability scores comprises, for each security domain of the subject security domain scheme, a respective domain-level vulnerability score. 
     
     
         14 . The system of  claim 2 , wherein the plurality of security domain schemes comprises a National Institute of Standards—Cyber Security Framework (NIST CSF) security domain scheme. 
     
     
         15 . A system for evaluating and mitigating cybersecurity risk, the system comprising:
 a non-transitory computer-readable medium storing a plurality of risk calculation schemes for quantifying cybersecurity risks to computing infrastructure components based at least in part on selections from a plurality of sets of multiple choice options; and   processing circuitry configured to perform operations comprising
 obtaining evaluation information regarding a computing infrastructure of an enterprise, the evaluation information including a plurality of selections made responsive to the plurality of sets of multiple choice options presented to one or more users each interacting with the system via a respective user interface at a respective computing device of one or more network-connected external computing devices, 
 calculating, by applying at least one risk calculation scheme of the plurality of risk calculation schemes to the evaluation information, at least one enterprise numeric quantification for the enterprise, 
 determining, based at least in part on the evaluation information, at least one target numeric quantification, 
 identifying, based at least in part on the evaluation information, one or more mitigation options, each mitigation option of the one or more mitigation options determined to improve, upon implementation, one or more enterprise numeric quantifications of the at least one enterprise numeric quantification, and 
 preparing, for review by a representative of the enterprise, a computer-renderable interactive user interface comprising one or more user interface screens configured to
 present one or more enterprise numeric quantifications of the at least one enterprise numeric quantification in visual comparison to one or more target numeric quantifications of the at least one target numeric quantification, 
 present information regarding at least a portion of the one or more mitigation options, and 
 enable adoption of at least one mitigation option of the one or more mitigation options, wherein enabling adoption comprises providing one or more user interface controls for associating, with a selected mitigation option of the at least one mitigation option, one or more of a budget, a timing, or a responsible party, 
 wherein, responsive to the adoption of the selected mitigation option, the computer-renderable interactive user interface is configured to render, in a roadmap display region of a provided screen of the one or more user interface screens, information regarding the selected mitigation option and the associated one or more of the budget, the timing, or the responsible party. 
 
   
     
     
         16 . The system of  claim 15 , wherein, responsive to the adoption of the selected mitigation option:
 the processing circuitry is configured to calculate at least one hypothetical numeric quantification representing an influence of the selected mitigation option on one or more enterprise numeric quantifications of the at least one enterprise numeric quantification; and   the computer-renderable interactive user interface is configured to render, to the provided screen, one or more hypothetical numeric quantifications of the at least one hypothetical numeric quantification.   
     
     
         17 . The system of  claim 15 , wherein the processing circuitry is further configured to perform operations comprising:
 identifying, based on the evaluation information, a plurality of risks to the enterprise, wherein each mitigation option of the one or more mitigation options corresponds to at least one risk of the plurality of risks.   
     
     
         18 . The system of  claim 15 , wherein the at least one enterprise numeric quantification comprises an overall vulnerability score. 
     
     
         19 . The system of  claim 15 , wherein the at least one enterprise numeric quantification comprises a number of risks. 
     
     
         20 . The system of  claim 15 , wherein determining the at least one target numeric quantification comprises identifying a peer benchmark using characteristics of the enterprise. 
     
     
         21 . The system of  claim 15 , wherein the plurality of risk calculation schemes comprises a plurality of weights for applying to the plurality of selections.

Join the waitlist — get patent alerts

Track US2023351456A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.