Network security device and method for detecting cybersecurity threats and risks across network devices in a network

The network security device addresses the limitations of existing scanning technologies by automatically scanning private networks, generating scores and sub-scores, and offering proactive threat resolution, enhancing network security and reducing vulnerabilities.

AU2024394819A1Pending Publication Date: 2026-07-16CYBERROCK LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
AU · AU
Patent Type
Applications
Current Assignee / Owner
CYBERROCK LTD
Filing Date
2024-12-04
Publication Date
2026-07-16

AI Technical Summary

Technical Problem

Existing network scanning devices, such as CyberGuardian and CyberAlarm, fail to provide detailed information on cybersecurity risks within private networks, and network scanning tools like Network Mapper are limited to external IP addresses, leaving internal networks vulnerable.

Method used

A network security device that automatically scans private networks, generates and processes scan information to detect cybersecurity threats and risks, and generates scores and sub-scores for automated resolution, optionally including features like F-DNS service, honeypot detection, and remote control operations.

Benefits of technology

Enables automatic scanning and detection of cybersecurity threats and risks across multiple network devices, providing detailed risk assessments and actionable insights for proactive mitigation, reducing vulnerabilities and enhancing network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The present disclosure provides a network security device and method for detecting cybersecurity threats and risks across a plurality of network devices in a private network using a server. The network security device is connected to the private network, and the server is communicatively connected to the network security device via the internet. The network security device is configured to automatically scan the plurality of network devices in the private network, generate and obtain scan information of the plurality of network devices, and transmit the scan information to the server. The server is configured to receive the scan information from the network security device, detect the cybersecurity threats and risks in the scan information and then generate a plurality of scores, sub-scores, reports and an intervention plan based on the identified cyber threats and cyber risks, and enable one or more operations to resolve the cybersecurity threats and risks. This approach automates and scales up the process of monitoring, alerting and improving network device and network security, thereby meeting the growing threats from cyber criminals.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD The present disclosure relates generally to cybersecurity; more specifically, the present disclosure relates to a network security device and method for detecting cybersecurity threats and risks across a plurality of network devices in a network. BACKGROUND Cybersecurity refers to the practice of protecting computer systems, networks, and digital infrastructure from theft, damage, unauthorized access, and other cyber threats. Cybersecurity in a network involves implementing measures, processes, and technologies to ensure the confidentiality, integrity, and availability of information and systems within the network. Cybersecurity threats are constantly evolving including in the network and typical attacks include Malware, Phishing, Ransomware, and the like. Network auditing and scanning is a process aimed at mitigating numerous cybersecurity risks and challenges inherent in the network. Currently, there are several network scanning devices available in the market, primarily designed for enterprise use and installed in server racks at server hosting centres. Cyber-Guardian is one of the existing network scanning devices designed to alert network managers when there are alterations within the network. Nevertheless, a limitation of the Cyber Guardian lies in an inability to provide specific information regarding the risks associated with these changes. Cybersecurity services, like CyberAlarm, scan external IP addresses to identify potential threats. However, it's important to note that these scanning services are limited to external IP addresses. Cyber-Alarm does not extend its monitoring capabilities to the internal private network, which also results in potential vulnerabilities and risks. Network scanning tools, such as Network Mapper and NMAP are designed to compile lists of hosts and identify potential threats within the network. Typically utilized by Information Technology (IT) professionals or cybersecurity experts, often on a commissioned basis, these professionals interpret the results generated by the scanning tools. The professionals' expertise allows them to discern the significance of findings and provide detailed written reports to clients. Therefore, there arises a need to address the aforementioned technical drawbacks in existing technologies in detecting cybersecurity threats and risks, understanding the potential financial impact, and acting to resolve them automatically, in a self-service manner, or with guided human intervention. SUMMARY The present disclosure seeks to provide a network security device and method for detecting cybersecurity threats and risks across a plurality of network devices in a private network. An aim of the present disclosure is to provide a solution that overcomes at least partially the limitations encountered in the prior art. - 3 - According to a first aspect, there is provided a network security device that is connected to a private network for detecting cybersecurity threats and risks across a plurality of network devices in the private network, wherein the network security device is configured to: automatically scan the plurality of network devices in the private network; generate and obtain scan information of the plurality of network devices; transmit the scan information to a server; process the scan information at the server, to detect the cybersecurity threats and risks in the scan information and generate a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions; and enable one or more operations to resolve the cybersecurity threats and risks. Optionally, the network security device is configured to automatically scan and detect a local network configuration, wherein the local network configuration includes a route out to public internet via infrastructure components selected from at least one of: DNS, router, firewall. Optionally, the network security device is configured to: detect potentially unauthorized network scans in the private network; - 4 - detect default credentials for services and applications operating on the plurality of network devices in the private network; detect accesses to honeypot services operated on the network security device; and report such detected network scans, detected default credentials, and honeypot services accesses to the network owner. Optionally, the network security device is configured to offer a forwarding DNS (F-DNS) service to the local network for the purposes of providing additional cybersecurity features. Optionally, the network security device is configured to: compress and encrypt the scan information; upload the encrypted scan information to the server for generating the plurality of scores, sub-scores, reports and intervention plans; and download and display the plurality of scores and sub-scores generated in the server. Optionally, the one or more operations comprise: determine an urgency and priority of the cybersecurity threats and risks by analyzing the scanned information, the plurality of scores and sub-scores of the detected cybersecurity threats and risks; determine financial impact and probability of potential cyberattacks by analyzing scanned information, plurality of scores and sub-scores, external threat data and company related data; - 5 - generate an intervention report detailing the list of potential cybersecurity threats and risks in priority order, and financial impact and probability of potential cyberattacks; enable the network owner to resolve the detected cybersecurity threats and risks in the private network, and financial impact and detected cyberattacks; and enable a cybersecurity support helpdesk operator to resolve the detected cybersecurity threats and risks in the private network, and financial impact and detected cyberattacks. Optionally, the network security device is configured to: allow remote control operation by an authorized cybersecurity support helpdesk agent to (a) trigger ad-hoc network scans using configurable control parameters, (b) allow remote control access to a web browser on the network security device to access internal web services (c) optionally have a sandboxed Secure Shell, SSH terminal access to the network security device, (d) optionally have Virtual Private Network, VPN termination or Internet Protocol, IP tunnel connection on the network security device to directly access the private network. Optionally, the network security device is configured to: perform a plurality of scan modes comprising a rapid scan mode and a deeper and longer scan mode to execute in the private network. Optionally, the network security device is configured to: detect an external public IP in the private network during scanning the private network; - 6 - execute an external port scan at the server to identify open ports, services and vulnerabilities; and include external IP address cyber threats and risk factors in the generation of scores, sub-scores and reports and intervention plans. According to a second aspect, there is provided a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network using a server, the method comprising performing the steps of: generating and obtaining scan information of the plurality of network devices from a network security device; detecting, using the server, the cybersecurity threats and risks in the scan information by generating a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions; and enabling one or more operations to be performed in the private network. Optionally, the method comprises generating and obtaining scan data of a local network configuration, wherein the local network configuration includes a route out to public internet via infrastructure components selected from at least one of: DNS, router, firewall. Optionally, wherein the method comprises: converting the scan information into the plurality of scores and subscores using an algorithm of the server. The network security device and method for detecting cybersecurity threats and risks using a server illustrated in an embodiment of the present disclosure enables the network security device to automatically scan a plurality of network devices in the private network, generate and obtain scan information, transmit the scan information to the server, process the scan information at the server to detect the cybersecurity risks and threats in the scan information by generating a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions, and enable one or more operations to resolve the cybersecurity threats and risks. The network security device and the method of the present disclosure provide an improved solution in the detection and resolution of the cybersecurity threats and risks as the network security device automatically scans the private network, detects the cybersecurity threats and risks by generating the plurality of scores and sub-scores, creates a bespoke cybersecurity improvement plan, and enables one or more operations to resolve the cybersecurity threats and risks. It will be appreciated that the aforesaid present method is not merely "software for a computer, as such", or "methods of doing a mental act, as such", but has a technical effect in that the network security device and method include enabling automatic scanning, scores, and sub-scores generating, cybersecurity threats and risks detecting, and connecting with the cybersecurity support helpdesk to resolve the cybersecurity threats and risks. The present disclosure works as a combination of software and hardware for detecting and resolving the cybersecurity threats and risks in the private network. Additional aspects, advantages, features, and objects of the present disclosure are made apparent from the drawings and the detailed - 8 - description of the illustrative embodiments construed in conjunction with the appended claims that follow. It will be appreciated that features of the present disclosure are susceptible to being combined in various combinations without departing from the scope of the present disclosure as defined by the appended claims. BRIEF DESCRIPTION OF THE DRAWINGS The summary above, as well as the following detailed description of illustrative embodiments, is better understood when read in conjunction with the appended drawings. For the purpose of illustrating the present disclosure, exemplary constructions of the disclosure are shown in the drawings. However, the present disclosure is not limited to specific methods and instrumentalities disclosed herein. Moreover, those in the art will understand that the drawings are not to scale. Wherever possible, like elements have been indicated by identical numbers. Embodiments of the present disclosure will now be described, by way of example only, with reference to the following diagrams wherein: FIG. 1 is a flow diagram that illustrates a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure; FIG. 2 is an illustration of a system for detecting cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure; - 9 - FIG. 3 is an exploded view of a network security device of the system in FIG. 2 in accordance with an embodiment of the present disclosure; FIG. 4 is an exploded view of a server of the system of FIG. 2 in accordance with an embodiment of the present disclosure; FIG. 5 shows an exemplary tabular view of weights to calculate a master score from the plurality of sub-scores in the server in accordance with an embodiment of the present disclosure; FIG. 6 is an interaction diagram of a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure; FIGS. 7A and 7B are flow diagrams that illustrate a process of detecting cybersecurity threats and risks, doing analysis, generating reports, and resolving the cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure; FIG. 8 is an illustration of a computing arrangement that is used in accordance with an embodiment of the present disclosure; FIG. 9 is an illustration of a flowchart depicting steps of a Large Language Model (LLM) chaining; and FIG. 10 is an illustration of a flowchart depicting steps of financial impact estimation by a network security device. In the accompanying drawings, an underlined number is employed to represent an item over which the underlined number is positioned or an item to which the underlined number is adjacent. A non-underlined - 10 - number relates to an item identified by a line linking the non-underlined number to the item. When a number is non-underlined and accompanied by an associated arrow, the non-underlined number is used to identify a general item at which the arrow is pointing. DETAILED DESCRIPTION OF EMBODIMENTS The following detailed description illustrates embodiments of the present disclosure and ways in which they can be implemented. Although some modes of carrying out the present disclosure have been disclosed, those skilled in the art would recognize that other embodiments for carrying out or practicing the present disclosure are also possible. The present disclosure provides a network security device that is connected to a private network for detecting cybersecurity threats and risks across a plurality of network devices in the private network, wherein the network security device is configured to: automatically scan the plurality of network devices in the private network; generate and obtain scan information of the plurality of network devices; transmit the scan information to a server; process the scan information at the server, to detect the cybersecurity threats and risks in the scan information and generate a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions; and - 11 - enable one or more operations to resolve the cybersecurity threats and risks. The present network security device provides Al-powered cybersecurity enabling automatic scanning of the private network and generating the plurality of scores and sub-scores for cybersecurity threats and risks at the server. The present server providing the plurality of scores and subscores can be used to purchase cyber insurance and to validate that the private network is maintained and secured against cybersecurity threats and risks. The network security device may be a physical device or an application running on a user device. Optionally, the user device is at least one of a mobile phone, a smartwatch, a router, a switch, a firewall, a modem, a Kindle device, Personal Digital Assistant, PDA, a tablet, a desktop computer, an electronic notebook, a smartphone, or a server. The network security device can be installed in the private network. The private network may be an Internet Protocol (IP network), managed by a network router or modem or firewall or network switch. Optionally, the private network can be an internal network or an external network. In an embodiment, the network security device is connected to the private network through a wired network or a wireless network. In another embodiment, the network security device is connected to the private network through an ethernet cable. In yet another embodiment, the network security device is connected to the private network through a Bluetooth module. Optionally, the application running on the user device configures the wireless network connection of the device if required. The plurality of network devices is connected to the private network through a wired network or a wireless network. The plurality of network devices - 12 - connected in the private network may be at least one of a mobile phone, a Kindle device, Personal Digital Assistant, PDA, a tablet, a desktop computer, an electronic notebook, loT device, smart home device, or a smartphone. The network security device scans the private network searching for hosts to detect anomalies in the plurality of network devices and configurations of the plurality of network devices, obtains the scan information comprising a host list with host information and any detected anomalies, and reports the scanned information to the server through an internet connection. The anomalies may be abnormal network activity and configurations in the private network. The network security device may collect (i) an IP address of the plurality of network devices, (ii) information relating to open ports comprising User Datagram Protocol, UDP, and Transmission Control Protocol, TCP, (iii) a Media Access Control, MAC address of the plurality of network devices, (iv) a manufacturer name and details, (v) a hostname, (vi) a last seen status, (vii) a status comprising online or offline, (viii) a device type comprising a make and model of the plurality of network devices, (ix) an Operating System (OS) and version, (x) services running on the open ports and their version, of the plurality of network devices, when scanning the private network. In an embodiment, if the open port is configured to link with an active server, the network security device obtains a page title and page content of the active server and uploads it to the server. The active server may be a Hypertext Transfer Protocol, HTTP web server. Optionally, if the open port links to a Secure Shell, SSH, or Telnet service, or web login, or other login, the network security device is configured to attempt a plurality of password combinations to identify vulnerabilities in the private network. The plurality of password combinations may be a list of default usernames and passwords. Results of the plurality of password combinations may be uploaded to the server. Optionally, the network security device enables network scans to identify an active intrusion. In an embodiment, the network security device probes the host for open ports. The network security device gathers detailed data from the scan process, creating a comprehensive report of the network's security status. This provides data such as device details (such as device type, operating systems, roles withing the network, and so on), vulnerabilities (such as unpatched software, weak credentials, and outdated firmware), threat indicators (for example suspicious activities, such as unusual traffic or unauthorized access attempts), and so on. The scan information is securely transferred over secure protocols (e.g., HTTPS, SSH tunnels) to a centralized (or decentralized) server for advanced processing to identify risks and threats and generate actionable insights. Optionally, the server compares the received scan data against external threat databases to identify potential attack vectors, and generates scores, sub-scores, and intervention recommendations. The network security device is configured to use the intervention recommendations from server, as actionable operations to mitigate the detected threats and improve the network's security posture. In an implementation, the network security device performs an automated scan of a corporate network, detecting 50 connected devices, and the scan information reports details of two critical vulnerabilities and several low-risk issues. The server analyses the data, correlates it with global threat intelligence, and assigns scores, such as "overall risk score: 8 / 10 (High Risk)". Sub-scores highlight critical issues in the server and moderate issues in the loT devices. The network security device provides a prioritized list of recommendations comprising "Patch the server's operating system", "Change default credentials on loT cameras", "Close unused open ports on laptops". Beneficially, the aforementioned workflow ensures continuous protection and enables proactive mitigation of cybersecurity threats. Optionally, the network security device is configured to automatically scan and detect a local network configuration, wherein the local network configuration includes a route out to public internet via infrastructure components selected from at least one of: DNS, router, firewall. In this regard, the term "local network" refers to a network that is geographically and logically confined to a specific area or organization, such as a home, office, or campus. It is typically managed internally and often relies on private IP address ranges that are not routable over the public Internet. When a network security device is configured to automatically scan and detect a local network configuration, it identifies the structure, connected devices, and communication patterns within this local environment to secure it effectively. Typically, the network security device that scans the local network configuration may perform operations selected from at least one of: discovery of network topology (i.e. identifies all devices connected to the network (e.g. computers, printers, loT devices)); maps the relationships between devices (e.g. switch or router connections); detection of unauthorized devices or devices that are not compliant with security policies; vulnerability identification (to detect unpatched systems, weak passwords, and misconfigured devices); traffic pattern analysis (to establish baselines and identify anomalies); configuration validation (to verify whether devices follow the required network - 15 - configuration standards (e.g. IP assignments, DNS settings, subnet masks)); threat detection (e.g. ARP spoofing, unauthorized access attempts, or rogue DHCP servers). Beneficially, employing the network security devices to automatically scan and detect a local network configuration ensures that all devices are accounted for and protected for improved security for the entire network security process. It also enhances the operational efficiency by reducing manual effort in mapping and securing the network. Moreover, it mitigates threat by quickly identifying vulnerabilities or threats before they can be exploited. Furthermore, it ensures adherence to security standards and policies and helps administrators resolve misconfigurations or connectivity issue. Notably, the local network provides devices, such as DNS, router, firewall, and so on, within the local network access to the Internet. A DNS server can be hosted locally or provided by the Internet Service Provider (ISP) or third-party providers like Google DNS or Cloudflare DNS. The devices on the local network are configured to query the DNS server for name resolution, allowing them to access external websites and services. The routers act as the primary gateway for the local network, directing outbound traffic to the public Internet and managing inbound traffic from the Internet. In this regard, the router may implement Network Address Translation (NAT) to allow the network devices with private IP addresses to communicate with public IP addresses on the Internet. The firewall monitors and filters traffic between the local network and the public Internet based on predefined security policies. In an example, it blocks unauthorized or malicious traffic while allowing legitimate traffic to pass through. Beneficially, such configuration ensures that devices in the local - 16 - network can communicate securely and efficiently with external systems while minimizing vulnerabilities. In an embodiment, for an outbound traffic flow, when a user in the local network tries to access a website, the request first goes to the local DNS server to resolve the domain name, the router forwards the resolved IP address request to the Internet via the ISP, and the firewall checks the request against its security rules and permits or denies it based on the policy. Similarly, for an inbound traffic flow (e.g. loading a webpage), the router receives the data packet and directs it to the appropriate device in the local network using NAT, and the firewall examines the incoming packet to ensure it is legitimate and not part of an attack. It may be appreciated that the network security device having an integrated device scan feature makes it a novel implementation. However, alternatively, device scan feature may be implemented on a smartphone or an loT device as an app instead of the network security device. Such an application would function as a network security tool, providing similar functionality to a physical network security device but optimized for mobile hardware or loT hardware and software environments. In this regard, for smartphones or loT devices, such as those working with IOS, a suitable app may be designed to comply with the potential / restrictions of that OS on socket-based operations. In an example, the app enables to run a local scan of the smartphone or loT device, to scan for vulnerabilities, such as outdated apps, insecure configurations, or malware. Moreover, the app enables to run a network-wide scan to detect all devices connected to the same Wi-Fi network, and identify their IP addresses, open ports, and potential vulnerabilities. Moreover, connected devices may be analysed for default credentials, unpatched software or firmware, unauthorised devices or activities, and so forth. Furthermore, such apps enable displaying scores, sub-scores, and prioritized risks for both the smartphone or the loT device and the Wi-Fi network. Furthermore, the apps may be integrated with or communicably couple to remote servers, to enable encryption and uploading of the scan information and scan data to a cloud-based server for advanced analysis, and / or retrieve recommendations and intervention plans generated on the server. Additionally, such apps provide actionable advice to resolve detected issues, such as updating software, changing configurations, or blocking malicious devices. Optionally, such app is implemented as a standalone app, a companion app for a network security device, or a cloud-integrated solution. Herein, the stand-alone app operates independently on the smartphone or loT device, and is ideal for personal users and small networks. The companion app creates a mobile app as a companion to a physical network security device. The users can control and monitor the device remotely via the app. The cloud-integrated solution combines the smartphone app with a cloud-based cybersecurity platform, to offload heavy computation (e.g. deep analysis and scoring) to the cloud. Beneficially, by converting the scanning features of the network security device into a smartphone or loT app offers several benefits, especially for personal and small-scale use. Moreover, the app eliminates the need for a separate physical security device and provides similar functionality using existing smartphone or loT hardware. Optimizing the app and cloud integration makes the app a practical and effective cybersecurity solution for mobile users in processing power, operating system restrictions, and scope of functionality. - 18 - Optionally, the network security device is configured to: detect potentially unauthorized network scans in the private network; detect default credentials for services and applications operating on the plurality of network devices in the private network; detect accesses to honeypot services operated on the network security device; and report such detected network scans, detected default credentials, and honeypot services accesses to an admin of the private network. In an embodiment, the network security device comprises an inbuilt scanning detection that detects any abnormal or unexpected activity comprising scanning or probing the private network, and reports to the server. Optionally, the built-in network activity detection can be a honeypot detection, which enables the network security device to detect unauthorized network activity in the private network. In an embodiment, the network security device runs honeypot services, honeypot web pages, and honeypot files or file servers including files containing honeypot Uniform Resource Locators, URLs to detect unauthorized network accesses. Notably, default credentials are the pre-configured credentials that come with hardware devices or software applications, intended for initial setup and testing. Typically, the default credentials comprise a default username and a default password. Herein, the default password is a preset password, typically generic and not unique, that is assigned to a device, system, or account during initial setup by the manufacturer or developer. Optionally, the some passwords may be weak, hence referred to as weak password. Herein, the weak password is indicative of its simplicity, common usage, or lack of complexity. Usually, the default and weak passwords are publicly documented in user manuals or online resources, making them easily accessible to attackers. Moreover, inability to update default and weak passwords, leaves devices, such as private network devices or local network devices, exposed to unauthorized access. In this regard, optionally, the network security device is configured to authenticate with commonly known default credentials (from a built-in database of defaults) for various devices and services. If authentication is successful, the device is flagged as using default credentials. It may be appreciated that other methods of authentication may be adopted by the network security device for detecting default credentials, as known to a person skilled in the art. The network security device sends an alert to the system administrator, identifying the device and the risk, and provides recommendations for resolving the issue, such as changing the password to a strong, unique one. Moreover, the network security device logs the detection event for audit purposes, supporting compliance with security policies or regulations. Optionally, the network security device is configured to: perform a plurality of scan modes comprising a rapid scan mode, and a deeper and longer scan mode to execute in the private network; and - 20 - control the timing, and scan control parameters of the automatic network scans to maximize the likelihood of detecting hosts and any malicious code running on network hosts designed to avoid detection. In an embodiment, the network security device executes the rapid scan of hosts in the private network on a regular basis with random interval periods. Scanning the hosts in the private network with random interval periods may confuse any potential installed threats that might sleep during certain periods of the day or be active during certain foreign time zones. The plurality of scan modes may control the timing, and scan control parameters of the automatic network scans to maximize the likelihood of detecting hosts and any malicious code running on network hosts designed to avoid detection. Beneficially, the rapid scans ensure quick identification of threats with minimal resource usage. Moreover, randomized intervals in rapid scans make detection patterns less predictable, increasing overall network security. The deeper and longer scan mode provides a more thorough analysis of the network to uncover latent vulnerabilities, misconfigurations, or advanced threats that might be missed during rapid scans. Optionally, the deeper and longer scans run less frequently (e.g. weekly or monthly) to minimize impact on network performance. Beneficially, deeper scans uncover complex vulnerabilities or advanced persistent threats (APTs). In reference to controlling the timing, optionally, the network security device dynamically calculates intervals for rapid scans based on recent network activity patterns, device behaviour, detection of unusual traffic patterns, historical scan data indicating periods of higher risk, randomized algorithms to determine scan timing, and so on. In this regard, the scans are conducted at varied intervals rather than following a fixed schedule to make it harder for malicious actors or malware to anticipate and avoid detection. For example, if most network activity occurs during business hours, a scan might be triggered outside of these hours to detect dormant malware or compromised devices operating during low-activity periods. In an example, instead of scanning every 24 hours at 2:00 AM, the network security device might perform scans at varying times, such as 10:00 AM, 3:30 PM, or 1:00 AM. In reference to controlling the scan control parameters, optionally, the network security device may prioritize scanning areas of the network or specific hosts that exhibit suspicious behaviour, such as unusual traffic volumes, inconsistent uptime patterns, and so on. Moreover, hosts with high-value data or critical functions may also be scanned more frequently or deeply. Additionally, scans can be automatically initiated based on behavioural anomalies detected in network traffic or device activity, such as repeated failed login attempts, sudden spikes in outbound data, and so on. In an implementation, if a rapid scan detects unusual activity, such as an unfamiliar device on the network, it can trigger a deeper scan to investigate the anomaly further to determine the unfamiliar device's purpose and security posture. Beneficially, by employing a combination of rapid and deeper scan modes with randomized intervals, the network security device ensures both efficiency and thoroughness in detecting and mitigating cybersecurity threats. This dual-mode scanning strategy addresses both immediate risks and long-term vulnerabilities, enhancing the overall security of the private network. Moreover, by combining realtime detection by using rapid scan mode with periodic in-depth analysis by using deeper and longer scan mode, provides a holistic approach to - 22 - threat management. Additionally, the separation of lightweight, namely the rapid scan, and resource-intensive scans, namely the deeper and longer scan, ensures that routine monitoring does not disrupt normal network operations. Optionally, the network security device is configured to offer a forwarding DNS (F-DNS) service to the local network for the purposes of providing additional cybersecurity features. Herein, the F-DNS serves as an intermediary between the local network devices (or local DNS server) and external DNS servers, for providing cybersecurity enhancements by filtering, monitoring, and controlling DNS requests, which are essential for accessing Internet resources. In this regard, the F-DNS server processes local DNS requests to resolve domain names into IP addresses required for internet connections. The F-DNS server forwards these requests to a trusted DNS server, typically managed by the ISP, network provider, or a third-party service like Google. The F-DNS service can optionally filter or process these requests before forwarding them. For example, it can block access to specific types of websites, such as social media platforms, in workplace settings. Herein, the network security device leverages the F-DNS feature for advanced cybersecurity tasks, offering robust protection and enhanced functionality. The F-DNS service is an additional service feature that can be pre-installed on the network security device. Optionally, key features of the F-DNS service includes, but is not limited to, advanced device identification (by analysing DNS traffic on the network, thereby, enhancing visibility and control over connected assets); anti-phishing and anti-spear-phishing protection (by detecting and flagging suspicious domains, including those with misspellings that mimic - 23 - legitimate websites, thereby reducing the risk of phishing attacks); and malware prevention (by actively blocking access to websites known to host malware or other malicious activities, thereby, protecting users and systems from compromise). It may be appreciated that the F-DNS service is optional and requires a more advanced setup during the installation of the network security device. Typically, main network router is configured to publish the network service device's IP address as the primary DNS server for the network, while the network service device itself must be assigned a static IP address by the router, thereby making the F-DNS activation more suitable for advanced users or IT professionals with networking expertise. However, the present disclosure provides an innovative device identification, by integrating the F-DNS feature with the network service device's automatic device identification process. By combining DNS traffic data with device metadata collected during network scans, the network service devices achieve a higher level of accuracy in identifying devices, including loT devices. In this regard, the F-DNS logs help correlate network activity with specific devices, offering a more advanced approach to device management compared to relying solely on scan data. Beneficially, by incorporating the F-DNS service, the network security device not only facilitates reliable Internet access but also strengthens the local network's defences against evolving DNS-based cyber threats. Additionally, F-DNS incorporation with the disclosed network security device ensures that businesses can maintain a secure network, safeguard against cyber threats, and enhance operational resilience. In an implementation, when a device in the local network sends a DNS query (e.g. www.example.com) to the F-DNS service provided by the network security device, the F-DNS service checks its database for known malicious domains or applies the configured security policies. If the query is safe, the F-DNS service forwards the request to an external DNS server (e.g. Google DNS, Cloudflare DNS). The external server resolves the domain and sends the IP address back to the F-DNS service, which then forwards it to the client. However, if the domain is flagged as malicious or violates a policy (e.g. blocked category), the F-DNS server denies the request and can redirect the user to a warning page. Optionally, the network security device is configured to: detect an external public Internet Protocol, IP address in the private network during scanning the private network; execute an external port scan at the server to identify open ports, services and vulnerabilities; and include external IP address cyber threats and risk factors in the generation of scores, sub-scores and reports and intervention plans. In this regard, the network security device scans the private network and identifies devices or network components that are assigned a public Internet Protocol (IP) address. It may be appreciated that the presence of a public IP address within the private network is unusual and may indicate a misconfigured device (e.g. a server bypassing the firewall) and / or a security risk, as the device is directly exposed to the Internet, making it vulnerable to attacks. Typically, a public IP address gains access of the private network through an open port in the firewall or router that leads to the network. Therefore, port scan is initiated by the network security device to identify open ports (that are accessible and accept external connections), services (applications or protocols listening on these ports (e.g., HTTP, SSH, FTP)), and vulnerabilities (such as outdated software or weak authentication mechanisms). Optionally, the port scan is at a pre-defined interval, routinely, or continuously. Moreover, the network security device reports out the identified open ports, running services and vulnerabilities to a risk assessment framework of the network security device, for further processing, including generation of scores, sub-scores and reports and intervention plans. Herein, the open ports, running services and vulnerabilities may constitute the external IP address cyber threats (e.g. lists of compromised IPs, malware distribution points, or botnet hosts) and risk factors. Herein, the scores quantify the level of risk associated with the external IP address. In an example, a high score is assigned for a server with open R.DP port and outdated software. The sub-scores further breakdown the overall score into specific risk areas, such as exposure risk (e.g. how many open ports are there?), vulnerability risk (e.g. are the services patched and secure?), and threat intelligence risk (e.g. is the IP associated with known attacks?). The reports document the findings, providing administrators with actionable insights. For example, "a server at public IP 203.0.113.5 has open two ports, is running outdated Apache 2.4.9, and is flagged in threat databases for suspicious activity". Based on the findings, the network security device suggests or automates actions to mitigate the risks by, for example, closing unnecessary ports, patching vulnerable services, reconfiguring the device to remove the public IP, and implementing additional defences like web application firewalls (WAFs) or intrusion prevention systems (IPS). Beneficially, by determining external IP address cyber threats and risk factors, the network security devices enhanced security posture by: identifying and mitigating risks associated with Internet-facing devices in the private network; detecting potential threats before they are exploited by attackers; providing a detailed view of internal and external risks, enabling better decision-making for risk assessment / management; ensuring that publicly accessible devices comply with security standards like PCI-DSS, GDPR, or HIPAA; and enhancing operational efficiency by reducing manual effort by automating detection, scanning, and reporting. Optionally, the network security device comprises a storage disk to store the scan information comprising the host list. The host list may be compressed and encrypted to report to the server. The network security device may upload the compressed and encrypted host list to the server through the internet. Optionally, the one or more operations comprise: determining the urgency and priority of the cybersecurity threats and risks by analysing the plurality of network scan information, scores and sub-scores of the detected cybersecurity threats and risks; determining financial impact and probability of potential cyberattacks by analysing scanned information, plurality of scores and sub-scores, external threat data and company related data; generating an intervention report detailing the list of potential cyber security threats and risks in priority order, and financial impact and probability of potential cyber-attacks; enabling the network owner to resolve the detected cybersecurity threats and risks in the private network, and financial impact and detected cyberattacks; and - 27 - enabling a cybersecurity support helpdesk to resolve or help resolve the detected cybersecurity threats and risks in the private network, and financial impact and detected cyberattacks. In this regard, the one or more operations are designed to address the complexity and variety of cyber threats while providing actionable insights for effective resolution. In this regard, the network security device may utilize a multi-layered analysis framework to assign urgency and priority levels to detected cybersecurity threats and risks. In this regard, the one or more operations include correlating data from multiple scans, including vulnerability scans, behavioural anomaly detections, and configuration compliance checks; aggregating risk scores and sub-scores assigned to each threat; and assigning a priority level (e.g., critical, high, medium, low) to each threat based on its aggregated score and relevance to network operations. In this regard, the network security device evaluates detected threats using pre-determined scoring metrics. For example, a high-priority alert may be assigned to an unpatched critical vulnerability in a public-facing web server, whereas a low-priority alert may correspond to a minor configuration issue in a backup system. Herein, the network security device and server to assess cyber risks and estimate the financial impact of potential cyberattacks in a 'one stop' process. In this regard, the financial impact calculation uses the network security device to gather technical cyber risk factors and integrates said data with other external cyber risk data, threat data, business type and financial information to calculate a potential financial loss expectancy. This innovative process enables the quantification of financial exposure to cyber threats with precision. It dynamically updates attack type probabilities and financial impact calculations using real-time data. It - 28 - combines technical cybersecurity metrics with financial modelling to produce actionable financial risk assessments. It supports decisionmaking for cybersecurity investments, budgeting, and insurance underwriting. Optionally, the network security device may incorporate financial modelling and predictive analytics to assess the potential impact of detected threats. In this regard, the network security device extracts details about exposed systems, sensitive data, and business-critical assets from the scanned information, and factors in threat severity, exploitability, and likelihood scores to estimate the potential cost of an attack from the plurality of scores and sub-scores, and the external threat data. Moreover, by leveraging company data, such as business revenue mode, cost of downtime, data breach penalties, etc., the network security device can estimate the direct and indirect costs of a potential cyberattack, including data loss, operational disruption, regulatory fines, reputational damage, and so on. In an implementation, the assessment of network & other cyber risks to estimate the financial impact of potential cyber-attacks includes steps of: Step 1. Gather risk data: The network security device scans data such as unpatched systems, open ports, default credentials, user engagement in training, and other available cyber risk data, and provides quantification of the coverage, strength and reliability of cyber risk controls. Step 2. Profile business to determine likely attacks: The business profile data sourced dynamically from external databases, internal databases, questionnaire responses are gleaned from device interface. A corresponding business profile type (e.g. Healthcare, Energy, Manufacturing, Financial services etc.), probabilities of being attacked by category of attack, assigning probabilities (0 to 1) to categories including ransomware, data and IP exfiltration, monetary theft, system outage and DDoS attacks, and so forth are provided. Profiles and probabilities of being attacked are refined using external data sources (e.g. breach reports, market trends, financial records) and user-provided inputs, enabling realtime updates. Step 3. Calculate asset valuation: Detailed description of company assets including sensitive data, intellectual property data are received by the network security device and a list of the asset types and value of each asset are provided as input into risk exposure. Step 4. Gather financial metrics: Revenue data, operational impact data, systems outage impact data, quantified cyber risk controls, and asset data are obtained and associated vulnerability, estimated financial impact of various attack scenarios is determined. Step 5. Calculate financial loss expectancy: Threat data gathered from internal and external sources, quantified cyber risk controls, financial impact of various attack scenarios, Monte Carlo simulation of results are used to provide a potential financial loss expectancy, providing a range of potential financial losses with associated probabilities created using a proprietary algorithm that uses probabilistic models. Step 6. Reporting: Based on the financial loss expectancy, risk breakdowns by attack type, actionable insights and prioritized recommendations to mitigate vulnerabilities in order to reduce financial loss expectancy and probability are generated and reported to the user of the network security device. Beneficially, the network security device and server have the ability, in a 'one stop' solution, to integrate cyber risk data from inside the network with other risk data, financial metrics and asset valuations, to enable precise calculations of financial exposure to cyberattacks. By dynamically profiling businesses and attack types with real-time updates from external data sources, the system ensures highly accurate and tailored risk assessments. Its use of advanced probabilistic models, such as Monte Carlo simulations, provides reliable financial loss expectancy predictions with actionable insights. This scalable 'one stop' solution offers prioritized recommendations to mitigate vulnerabilities, reduce financial risk, and optimize cybersecurity investments. Furthermore, the network security device generates a comprehensive intervention report that summarizes the detected threats and risks. The intervention report may typically include, but is not limited to, a list of potential threats and risks, in priority order based on urgency and impact; the estimated financial impact and likelihood of each potential cyberattack; recommendations or actionable suggestions to mitigate each threat, such as patching vulnerabilities, configuring access controls, isolating compromised devices, and so on. Such recommendations or actionable suggestions serve as tools and guidance to the network owner for resolving identified threats. In an example, an actionable alert may help in delivering real-time notifications with step-by-step remediation instructions. In another example, interactive dashboards allow the network owner to view threat details, implement recommended actions directly through the interface, automated mitigation options, automatically apply patches, block suspicious traffic, disable compromised accounts, and so on. The network security device facilitates collaboration with a cybersecurity support team, namely the cybersecurity helpdesk, to ensure effective resolution of complex or critical issues. This involves allowing helpdesk personnel to securely access the device for in-depth analysis, enabling the device to escalate high-priority incidents to specialized support teams, offering expert advice and advanced mitigation strategies tailored to the organization's infrastructure and threat landscape. In an implementation, if a zero-day vulnerability is detected, the network security device might escalate the issue to the cybersecurity support helpdesk for immediate containment and long-term mitigation planning. Beneficially, the one or more operations performed by the network security device combines technical, financial, and operational metrics to deliver a holistic view of cybersecurity risks. Moreover, it simplifies mitigation through automation and guided support by focusing resources on addressing the most urgent and impactful threats. Furthermore, the network security device helps organizations understand the financial implications of cybersecurity issues, aiding in resource allocation and decision-making by bridging the gap between network administrators and cybersecurity experts for efficient incident resolution. Therefore, by integrating these capabilities, the network security device ensures robust detection, analysis, and resolution of cybersecurity threats and risks, empowering organizations to safeguard their private networks effectively. This invention addresses the growing complexity of cyber threats while minimizing operational and financial disruptions. Optionally, the one or more operations comprise: - 32 - prioritize the cyber risks and cybersecurity threats by analyzing the plurality of scores and sub-scores of the detected cybersecurity threats and risks; and enable a cybersecurity support helpdesk to resolve the detected cybersecurity threats and risks in the private network. Herein, the one or more operations of the network security device is to organize detected cybersecurity threats and risks based on their severity, urgency, and potential impact, enabling targeted and efficient mitigation, based on only the plurality of scores and sub-scores of the detected cybersecurity threats and risks. In an example, a malware detected on a non-critical device is scored as low-risk due to limited impact and containment, and unpatched vulnerability in a server hosting sensitive customer data is scored as high-risk due to potential data breach implications. Then, the action focus is placed on resolving unpatched vulnerability in a server, immediately. In this example, the cybersecurity support helpdesk implements system patches to close vulnerabilities. Beneficially, by incorporating score and sub-score based prioritization and the cybersecurity support helpdesk enablement, the network security device ensures a comprehensive approach to identifying, analysing, and resolving cybersecurity threats effectively and efficiently. Optionally, the network security device is configured to: compress and encrypt the scan information; - 33 - upload the encrypted scan information to the server for generating the plurality of scores, sub-scores, reports and intervention plans; and download and display the plurality of scores and sub-scores generated in the server. Herein, the network security device processes scan information, secures it, and communicates with a central server to leverage advanced analysis and reporting capabilities. In this regard, the network security device reduces the size of scan data for improving efficiency during upload and minimizing bandwidth usage. Optionally, the network security device employs GZIP or ZIP algorithms for reducing the size of the scan information. Moreover, it secures, by using robust encryption protocols (such as AES-256, TLS, etc.) scan data to prevent unauthorized access during transmission. In an example, the network security device collects detailed data about vulnerabilities, open ports, and configurations in a private network. This data is compressed and encrypted before being sent to the server, preventing interception or unauthorized disclosure. The compressed and encrypted scan data is securely transferred over secure protocols (e.g. HTTPS, SSH tunnels) to a centralized (or decentralized) server for advanced processing, such as risk analysis and report generation. Optionally, the server compares the receives scan data against external threat databases to identify potential attack vectors, and generates scores, sub-scores, and intervention recommendations. The network security device is configured to download the plurality of scores and sub-scores from the server. In an embodiment, the network security device comprises at least one output interface to display the plurality of scores and sub-scores of the host list. The at least one output interface in the network security device may be a display screen. Optionally, the display screen is configured to display a status of the network security device, and risk of the detected cybersecurity threats and risks. The status of the network security device comprises any of network scanning status, a firmware upgrading status, configuration and authentication details of the network security device, call verification details with the cybersecurity support helpdesk, potential vulnerabilities, and potential threats. Optionally, when the hosts are detected that match pre-determined criteria running pre-determined services while scanning the private network, the network security device logs into the hosts using a database of a plurality of username and passwords. In an embodiment, the predetermined criteria comprise any of specified hubs, specified routers, specified web admin panels, specified types of hosts, and the like, and the pre-determined services comprise any of web servers, file servers, terminal login protocols, and the like. In yet another embodiment, the database of the plurality of usernames and passwords comprises default usernames and passwords and common passwords. Optionally, when the network security device logs into the hosts with any of the default passwords and / or common passwords or weak passwords, the specific hosts list will be updated and uploaded to the server. The plurality of network devices found on the private network may be shown to the user through the application running on the user device, which enables the user to confirm the validity and presence of the plurality of network devices on the private network. Optionally, the network security device comprises a button that enables an inbound call to the cybersecurity support helpdesk. In an embodiment, the display in the network security device views a name of an agent of the cybersecurity support helpdesk, namely, the authorized cybersecurity support helpdesk agent, and a password that will be provided by the cybersecurity support helpdesk to verify the registered user. Optionally, the network security device comprises a fingerprint scanner that is configured to access configurations of the network security device. The fingerprint scanner provides enhanced user security when accessing configurations and enabling the inbound call with the cybersecurity support helpdesk. The fingerprint scanner may be positioned on a case of the network security device to provide easy access. Optionally, the network security device comprises a microphone that is configured to detect ultrasonic sounds often used to gain unauthorized access or control of voice-controlled devices or voice recognition systems in any of home or office, thereby avoiding dolphin attacks. Optionally, one or more profiling questionnaires have to be inputted when one of the pluralities of network devices needs to be registered, which enables the network security device to determine a type of test to be executed on the private network. The one or more profiling questionnaires may comprise any of "Do you host online game servers", "Is this a home network, a work network, or a network used for home and home working", "Do you have a qualified network administrator", and the like, which enables the network security device to determine the cybersecurity threats and risks based on inputs of the one or more profiling questionnaires. The one or more profiling questionnaires provide a major - 36 - context for an analysis of the scanning of the private network with the network security device. Optionally, the network security device is configured to allow remote control operation by an authorized cybersecurity support helpdesk agent to (a) trigger ad-hoc network scans using configurable control parameters, (b) allow remote control access to a web browser on the network security device to access internal web services (c) optionally have a sandboxed Secure Shell, SSH terminal access to the network security device, (d) optionally have Virtual Private Network, VPN termination or Internet Protocol, IP tunnel connection on the network security device to directly access the private network. Herein, the authorized cybersecurity support helpdesk agent refers to an individual or entity granted explicit permission to access and manage the network security device and the associated private network for the purpose of identifying, analysing, and mitigating cybersecurity threats and risks. The authorization ensures that the individual operates within predefined roles and responsibilities while adhering to strict security protocols. The authorized cybersecurity support helpdesk agent remotely manages and operates the network security device, to ensure flexibility, enhanced security, and streamlined threat mitigation while maintaining the integrity of the private network. In this regard, access is strictly limited to authorized cybersecurity support helpdesk agents via secure authentication mechanisms, such as multi-factor authentication (MFA), to prevent unauthorized access. Moreover, all remote operations are logged to ensure accountability and auditing. Herein, the phrase "trigger ad-hoc network scans" refer to on-demand scans triggered or initiated by the authorized cybersecurity support helpdesk agent in response to emerging threats or anomalies. Such scans may include, but are not limited to, investigating specific threats flagged by real-time alerts, assessing newly connected devices for vulnerabilities, running focused scans during suspected breach incidents. Optionally, such scans are based on configurable parameters such as scope of scan (e.g. subnets, specific hosts), depth of scan (e.g. rapid vs. detailed scans), protocol focus (e.g. scanning for open TCP / UDP ports), and so on. Moreover, the authorized cybersecurity support helpdesk agent can remotely access a web browser running on the device to access the device's web-based management interface and interact with internal web services, such as dashboards or logs, to ensure access to critical tools without exposing internal services to the public internet. Furthermore, the sandboxed SSH access provides a restricted environment where the authorized cybersecurity support helpdesk agents can perform tasks without risking broader network exposure, for updating device software, manually configuring scan parameters or network settings, debugging device-specific issues, and so on. In an example, the authorized cybersecurity support helpdesk agent connects via SSH to modify firewall rules or analyse logs for a detected anomaly. Furthermore, the authorized cybersecurity support helpdesk agents are allowed to establish secure, direct access to the private network for troubleshooting or managing resources, via VPN Termination or IP Tunnel Connection. In an example, the authorized cybersecurity support helpdesk agent establishes a VPN session through the device to access an internal application server to verify its patch level after a vulnerability scan. In an implementation, when a network anomaly is detected, such as suspicious traffic originating from an internal host, the authorized cybersecurity support helpdesk agent remotely triggers a detailed ad-hoc scan of the suspected host, using custom parameters to focus on active connections and open ports. The authorized cybersecurity support helpdesk agent accesses the internal web interface via the sandboxed browser to review scan results and identify potential threats. The authorized cybersecurity support helpdesk agent uses the SSH terminal to block malicious IP addresses or update firewall rules. If deeper access is required, the authorized cybersecurity support helpdesk agent establishes a VPN connection to troubleshoot the affected host directly. The authorized cybersecurity support helpdesk agent resolves the issue and documents the actions taken, ensuring network security is restored. Beneficially, by enabling the remote control features by authorized cybersecurity support helpdesk agent, the network security device empowers the authorized cybersecurity support helpdesk agents to perform a wide range of critical cybersecurity operations with speed, precision, and security, thereby enhancing the resilience of the private network. Optionally, the network security device is configured to: compress and encrypt the scan information; upload the encrypted scan information to the server for generating the plurality of scores, sub-scores, reports and intervention plans; and download and display the plurality of scores and sub-scores generated in the server. Optionally, the network security device employs Large Language Models (LLMs) chaining. The Large Language Model (LLM) chaining, is a technique in which multiple prompts or interactions with a language model (like GPT) are sequenced or interconnected to accomplish complex tasks or workflows. Each step in the chain builds upon the outputs from the previous steps, allowing for more structured reasoning, multi-step problem-solving, or the generation of complex outputs. Herein, the process begins with an initial input or prompt to the language model to generate an initial response or data. The output from the first interaction is processed or directly used as input for the next prompt. This sequence continues, with each step refining, analysing, or expanding upon previous outputs. The final output is the result of multiple iterations or stages of reasoning, analysis, or creative generation. LLM chaining ensures that each linked LLM focuses on a highly specific, domain-defined task. This makes the network security device easier to manage, test, and validate. By segmenting tasks and defining precise roles for each LLM, better and more accurate outcomes compared to using a single LLM as a monolithic, "black box" solution, are achieved. Herein, multiple LLM Ais are connected in a sequential process to achieve highly specific and reliable outcomes. Glue logic seamlessly links these LLMs, ensuring smooth data flow between agents, and all intermediary data is stored for quality assurance and audit purposes. In this regard, the LLM chaining is configured to: analyse the scan information and the scan data, prompt in case of a network and device-specific threat data, and generate a list of identified threats based on the specific network and device configurations; - 40 - contextualize, based on the analysis output, business-specific data such as company type, market, size, financial details, customer types, and regulatory requirements, a refined list of threats for the business, including the potential impact and importance of each threat; generate a risk mitigation list of threats, based on the contextualization output and best practice guides for cybersecurity, data protection, and security policy compliance, as well as technical guidance for issue resolution, wherein each threat is assigned a difficulty rating (easy, medium, hard) to help with prioritization and scheduling; provide a prioritization task list for the network or business owner, based on risk mitigation output and instructions to prioritize tasks based on risk severity, business impact, and technical difficulty, wherein the prioritization of tasks is ranked by urgency and feasibility; and provide a time-based schedule for assigning tasks and communicating actionable items to the customer, based on the prioritization output and guidelines for creating a schedule tailored to the company's size and type, including motivational "nudges" and reminders for task completion, for ensuring timely mitigation of identified risks. Beneficially, by chaining specialized LLMs, the network security device delivers a structured and precise cybersecurity process that minimizes risks and enhances outcomes for businesses. This approach ensures clarity, accountability, and effectiveness at each step, providing network owners with actionable insights and a clear path to improving their cybersecurity posture. It may be appreciated that the disclosed network security device and automates and scales up the process of monitoring, alerting and improving network device and network security, thereby meeting the growing threats from cyber criminals. In this regard, the disclosed network security device automates the scanning and interpretation of various components and their functions, and resulting mitigations as much as possible using AI / LLMs / GPT technologies and so forth. Moreover, the use of AI / LLMs enables putting in "human like" analysis of the complex scan data to reduce the manual labour. The present disclosure also provides a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network using a server, the method comprising performing the steps of: generating and obtaining scan information of the plurality of network devices from a network security device; detecting, using the server, the cybersecurity threats and risks in the scan information to generate a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions; and enabling one or more operations to be performed in the private network. The advantages of the present method are thus identical to those disclosed above in connection with the present network security device and the embodiments listed above in connection with the network security device apply mutatis mutandis to the method. The server receives the compressed and encrypted host list from the network security device. The server may be an Artificial Intelligence, AI server. In an embodiment, the server decrypts and decompresses the compressed and encrypted host list. The server detects the cybersecurity threats and risks and generates the plurality of scores and sub-scores in the decrypted host list based on cyber threats and cyber risk along with device configurations and vulnerabilities. The device configuration may be a pre-determined arrangement and settings of a plurality of security measures and protocols within the private network. The vulnerabilities may be flaws in the implementation of the device configurations within the private network. The server may generate a tailored report detailing the plurality of network devices and any issues detected in the private network, which enables the server to create a bespoke cybersecurity improvement plan for the user. In an embodiment, the scores and the sub-scores can be improved while the user interacts and responds to the tailored report. In yet another embodiment, a process of generating the tailored report and interaction with the user is known as an intervention program. The server may generate the plurality of scores by analysing (i) internal network scan data, (ii) external IP address scan data, (iii) engagement of the user with tailored reports and suggestions, (iv) diversity of the plurality of network devices on the private network, (v) a quantity of the plurality of network devices on the private network, (vi) a quantity, diversity, and validity of services running on each of the plurality of network devices, (v) specific vulnerabilities identified on the plurality of network devices, (vi) any active threats detected on the private network through scan detection, honeypot service accesses, (vii) information provided by the admin of the network comprising name, skills, and certifications, and (viii) specific cyber threats and risks that intersect with the plurality of network devices or services operating with the private network. The server may generate the plurality of sub-scores by analysing, not limited to, (i) a diversity comprising a number of unique host types on the private network, (ii) a size comprising a total number of hosts on the private network, (iii) services comprising a number of unique services or ports on the private network, (iv) potential threats comprising a count of number of non-standard or unknown ports on hosts on the private network, number of unidentified hosts from the database comprising MAC address, re-used MAC address on the private network, (v) network scan identifying active threats including a detection of a specific malware port and trigger of the honeypot service, (vi) active vulnerabilities comprising weak and / or default passwords identified, unprotected exposed files detected, public IP exposure of services, public IP with weak password, unprotected PI, Personal Information data found, and (vii) proactive user engagement comprising whether the user is regularly accessing the application and the network security device and services, providing information when requested, and interacting with the tailored intervention report. Optionally, each sub-score ranges from 1-100 where 100 represents least risk, and 1 represents high risk. In an embodiment, calibration data for converting measured input values into scores can be derived from aggregate measured input data and can be calculated to move output scores into ranges based on pre-determined percentile ranges. Some subscores can be straight forward % values. Optionally, each score can be weighted average based on the sub-scores utilized and range from 11000. In an embodiment, the specific sub-scores and weights can vary from time to time. Optionally, the server comprises an algorithm that is configured to convert the scan information into the plurality of scores and sub-scores. In an embodiment, the algorithm can be accessed using a cloud-hosted Application Program Interface, API. In yet another embodiment, the algorithm can be trained with historical data of scanned information in the private network. The server transmits the plurality of scores and subscores of the host list to the network security device. The server is configured to tabulate and report the plurality of scores and sub-scores of the detected cybersecurity threats and risks to an admin of the private network, and cybersecurity support helpdesk, and enable the cybersecurity support helpdesk to resolve the detected cybersecurity threats and risks in the private network. In an embodiment, the server tabulates and reports the host list comprising the scan information to the cybersecurity support helpdesk through a web portal. The cybersecurity support helpdesk may comprise selected Information Technology, IT professionals to resolve the cybersecurity threats and risks. Optionally, the server enables the cybersecurity support helpdesk to remotely access (i) the user device on the private network, or (ii) the network security device. The server may provide features comprising a scanning control, and remote web browser control to access the plurality of network devices within the private network. The plurality of scores and sub-scores and the host list enables determining of the safety of the private network connected with the plurality of network devices. The plurality of scores and sub-scores may be used to demonstrate cyber-hygiene and cyber security effectiveness to other parties comprising an insurance company, an investor, a company board or shareholders, a potential business acquirer, or the - 45 - general public. Optionally, the plurality of scores or sub scores of the cybersecurity threats and risks of the private network can be published in a leaderboard, which enables similar companies or providers to quickly compare their cyber-hygiene and cyber security effectiveness. Optionally, data from one or more users of the plurality of network devices can be used to determine normal ground truth data for specific devices. For example, LG television include a web server port that is open, which can be learned by the server. If a new service comprising the web server port is determined on the television with the same make and model of the existing LG television, the server may indicate that the television has been compromised. Optionally, the method comprises generating and obtaining scan data of a local network configuration, wherein the local network configuration includes a route out to public internet via infrastructure components selected from at least one of: DNS, router, firewall. Optionally, the method comprises converting the scan information into the plurality of scores and sub-scores using an algorithm of the server. Optionally, the method comprises: compressing and encrypting the scan information; generating the plurality of scores, sub-scores, reports and intervention plans using the server by uploading the encrypted scan information thereat; and downloading and displaying the plurality of scores and sub-scores generated in the server. - 46 - Optionally, the one or more operations comprise: determine an urgency and priority of the cybersecurity threats and risks by analysing the scanned information, the plurality of scores and sub-scores of the detected cybersecurity threats and risks; determine financial impact and probability of potential cyberattacks by analysing scanned information, plurality of scores and sub-scores, external threat data and company related data; generate an intervention report detailing the list of potential cybersecurity threats and risks in priority order, and financial impact and probability of potential cyberattacks; enable the network owner to resolve the detected cybersecurity threats and risks in the private network, and financial impact and detected cyberattacks; and enable a cybersecurity support helpdesk operator to resolve the detected cybersecurity threats and risks in the private network, and financial impact and detected cyberattacks. Optionally, the method comprises allowing remote control operation by an authorized cybersecurity support helpdesk agent to (a) trigger ad-hoc network scans using configurable control parameters, (b) allow remote control access to a web browser on the network security device to access internal web services (c) optionally have a sandboxed Secure Shell, SSH terminal access to the network security device, (d) optionally have Virtual Private Network, VPN termination or Internet Protocol, IP tunnel connection on the network security device to directly access the private network. - 47 - Optionally, the method comprises configuring the network security device to perform a plurality of scan modes comprising a rapid scan mode and a deeper and longer scan mode to execute in the private network. Optionally, the method comprises: detecting an external public IP in the private network during scanning the private network; executing an external port scan at the server to identify open ports, services and vulnerabilities; and including external IP address cyber threats and risk factors in the generation of scores, sub-scores and reports and intervention plans. Embodiments of the present disclosure substantially eliminate or at least partially address the aforementioned technical drawbacks in existing technologies in detecting cybersecurity threats and risks across the plurality of network devices in the private network. DETAILED DESCRIPTION OF THE DRAWINGS Modifications to embodiments of the present disclosure described in the foregoing are possible without departing from the scope of the present disclosure as defined by the accompanying claims. Expressions such as "including", "comprising", "incorporating", "have", "is" used to describe and claim the present disclosure are intended to be construed in a nonexclusive manner, namely allowing for items, components, or elements not explicitly described also to be present. Reference to the singular is also to be construed to relate to the plural. FIG. 1 is a flow diagram that illustrates a method for detecting cybersecurity threats and risks across a plurality of network devices in a private network in accordance with an embodiment of the present disclosure. At a step 102, the plurality of network devices in the private network is automatically scanned using a network security device. At a step 104, scan information of the plurality of network devices is generated and obtained in the network security device. At a step 106, the scan information is transmitted to a server. At a step 108, the cybersecurity threats and risks are detected in the scan information and a plurality of scores and sub-scores are generated based on cyber risks and potential or active cyber intrusions using the server. At a step 110, one or more operations are enabled to resolve the cybersecurity threats and risks. FIG. 2 is an illustration of a system 200 for detecting cybersecurity threats and risks across a plurality of network devices 204A-N in a private network 202 in accordance with an embodiment of the present disclosure. The system 200 comprises the private network 202, the plurality of network devices 204A-N, a network security device 206, a server 208, a cybersecurity support helpdesk 210, and an internet 212. The private network 202 may be a network router, firewall, broadband modem, or network switch. The plurality of network devices 204A-N, and the network security device 206 are connected to the private network 202 through a wired network or a wireless network. The private network 202 is communicatively connected with the server 208 through the internet 212. The network security device 206 is configured to (i) automatically scan the plurality of network devices 204A-N, (ii) generate and obtain scan information of the plurality of network devices 204A-N (iii) - 49 - compress and encrypt the scan information, and (iv) upload the encrypted scan information to the server 208. The server 208 is configured to receive the scan information from the network security device 206 and detect the cybersecurity threats and risks in the scan information and will generate a plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions. The server 208 comprises an algorithm that is configured to convert the scan information into the plurality of scores and sub-scores. The server 208 transmits the plurality of scores and sub-scores based on the plurality of network devices 204A-N to the network security device 206. The network security device 206 is configured to download and display the plurality of scores and sub-scores generated in the server 208. The network security device 206 is configured to enable one or more operations to resolve the cybersecurity threats and risks. The one or more operations comprise any of (i) determine a prioritized list of cyber risks and cybersecurity threats by analyzing the plurality of scores and sub-scores of the detected cyber threats and risks, and (ii) enable the cybersecurity support helpdesk 210 to resolve the detected cybersecurity threats and risks in the private network 202. The server 208 is configured to tabulate and report the plurality of scores and sub-scores of the detected cybersecurity threats and risks to the cybersecurity support helpdesk 210. The server 208 enables the cybersecurity support helpdesk 210 to resolve the detected cybersecurity threats and risks in the private network 202. FIG. 3 is an exploded view of the network security device 206 of the system 200 in FIG. 2 in accordance with an embodiment of the present disclosure. The exploded view of the network security device 206 includes a screen 302, one or more buttons 304A-N, an operating system and firmware 306, a Central Processing Unit, CPU 308, a Random-Access Memory, RAM 310, an Internet Protocol, IP networking module 312, a Bluetooth module 314, and a microphone 316. The screen 302 is a display screen that is configured to display a status of the network security device 206. The screen 302 may display a scanning status of the network security device 206. The one or more buttons 304A-N enable a user to control the network security device 206 and switch screen modes to display the specific details in the screen 302. In an embodiment, the one or more buttons 304A-N trigger an inbound call with the cybersecurity support helpdesk 210. The operating system and firmware 306 is configured to control the network security device 206 and facilitate scanning and sensing of the private network 202, and display updates on the screen 302. The CPU 308 is configured to execute a code to control the network security device 206. The Random-Access Memory, RAM 310 is a temporary memory used to store the scan information. The IP networking module 312 enables the network security device 206 to connect to the private network 202 through a wired network comprising an ethernet, or a wireless network. The Bluetooth module 314 enables the users to manage the network security device 206 remotely with a user device. The user device may comprise any of a mobile phone, smart watch, a router, a Kindle device, Personal Digital Assistant, PDA, a tablet, a desktop computer, an electronic notebook, smartphone, or a server. The microphone 316 is configured to detect ultrasonic sounds often used to gain unauthorized access or control of voice-controlled devices or voice recognition systems in any of home or office, thereby avoiding dolphin attacks. - 51 - The network security device 206 further comprises a network scanning module that enables automatic scanning of the plurality of network devices 204A-N in the private network 202. The network security device 206 further comprises a scan detection module that detects unauthorized network scans in the private network 202. The network security device 206 further comprises a multi-tiered and random time offset scanning module that is configured to execute a plurality of scan modes in the private network 202. The plurality of scan modes may comprise a rapid scan, and a deeper more detailed longer scan. The network security device 206 further comprises a password scanning module that logs into hosts in the private network 202 using a database of a plurality of passwords comprising default usernames and passwords and common passwords. The network security device 206 further comprises a fingerprint scanner that is configured to access configurations of the network security device 206 and enable the inbound call with the cybersecurity support helpdesk 210. FIG. 4 is an exploded view of the server 208 of the system 200 of FIG. 2 in accordance with an embodiment of the present disclosure. The exploded view of the server 208 includes a webserver and website module 402, a score algorithm module 404, a data storage 406, a cybersecurity support portal 408, a device identification Artificial Intelligence, AI model 410, a device services prediction AI model 412, and an analysis and report generation AI module 414. The webserver and website module 402 is primary web and Application Program Interfaces, APIs for exposing services to the world. The score algorithm module 404 is configured to convert the scan information from the network security device 206 and - 52 - other collected data into the plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions. The data storage 406 is configured to store user data, historic scan data, metadata and reports. The cybersecurity support portal 408 is the API and web portal that enables the cybersecurity support helpdesk 210 to contact the users. In an embodiment, the cybersecurity support portal 408 enables the cybersecurity support helpdesk 210 to view the cybersecurity threats and risks detected in the score algorithm module 404 and resolve the cybersecurity threats and risks. The device identification AI model 410 is a Machine Learning, ML model to predict a network device from the plurality of network devices 204A-N based on the network data collected individually and aggregation of all the plurality of network devices 204A-N. Optionally, the device identification AI model 410 is an Artificial Neural Network (ANN) but not limited to. In this regard, an Artificial Neural Network (ANN) is a machine learning model inspired by the human brain's neural structure as well known in the art. The device services prediction AI model 412 is a ML model that predicts ports or services running on the plurality of network devices 204A-N based on a determined device identification ID. Optionally, the device services prediction AI model 412 is an Artificial Neural Network (ANN) but not limited to. The analysis and report generation AI module 414 is a large language model trained with cybersecurity database comprising cybersecurity knowledge. The analysis and report generation AI module 414 comprises generation of an intervention program. The analysis and report generation AI module 414 is configured to generate factual reports based on the scan information and identify specific vulnerabilities and priorities to create a bespoke intervention program for the user. FIG. 5 shows an exemplary tabular view of weights to calculate a master score from the plurality of sub-scores in the server 208 accordance with an embodiment of the present disclosure. The server 208 is configured to calculate the plurality of scores and sub-scores with a sub-score factor comprising a diversity, a size, services, potential threats, active threats, active vulnerabilities, and proactive user engagement with the interventions. In this embodiment, to calculate the master score of 100%, weights of the sub-scores comprising the diversity is 5%, the size is 10%, the services are 10%, the potential threats are 20%, the active threats are 30%, the active vulnerabilities are 20%, and the proactive user engagement is 5%. The sub-score factors and % weights may vary from time to time. FIG. 6 is an interaction diagram of a method for detecting cybersecurity threats and risks across the plurality of network devices 204A-N in the private network 202 in accordance with an embodiment of the present disclosure. At a step 602, the network security device 206 automatically scans the plurality of network devices 204A-N connected in the private network 202. At a step 604, the network security device 206 generates, and receives the scan information of the plurality of network devices 204A-N connected in the private network 202 At a step 606, the network security device 206 transmits the scan information to the server 208. At a step 608, the server 208 is configured to detect the cybersecurity threats and risks in the scan information and generates the plurality of scores and sub-scores based on cyber risks and potential or active cyber intrusions. At a step 610, the server 208 transmits the generated plurality of scores and sub-scores to the network security device 206. At a step 612, the server 208 analyzes, tabulates and reports the plurality of scores and sub-scores of the detected cybersecurity threats and risks - 54 - to the cybersecurity support helpdesk 210. At a step 614, the cybersecurity support helpdesk 210 initiates the inbound call to the network security device 206 and resolves the detected cybersecurity threats or risks in the private network 202. FIGS. 7A and 7B are flow diagrams that illustrates a process of detecting cybersecurity threats and risks, doing analysis, generating reports, and resolving the cybersecurity threats and risks across the plurality of network devices 204A-N in the private network 202 in accordance with an embodiment of the present disclosure. At a step 702, the private network 202 is scanned with the network security device 206. The network security device 206 scans the private network 202 every 24 hours. In an embodiment, scanning includes a network host scan and a host port scan. The scan information obtained in the network security device 206 is uploaded to the server 208 for analysis. At a step 704, device identification information is obtained by identifying the plurality of network devices 204A-N in the server 208. The server 208 identifies each of the plurality of network devices 204A-N with available data. In an embodiment, the server 208 identifies the make and model, and operating system including versions of the plurality of network devices 204A-N. At a step 706, open ports and services are predicted and compared with the device identification information in the server 208. The server 208 predicts which ports and services should be open by using the the-device identification information, and compares with the ports and services discovered. In an embodiment, the server 208 identifies exceptions in the discovered ports and services. At a step 708, the plurality of scores and sub-scores are calculated based on the cyber risks and potential or active cyber intrusions in the server 208. The server 208 may also perform network scan sensing and honeypot service access - 55 - detection for calculating the plurality of sub-scores and generating the plurality of scores with the plurality of sub-scores. The plurality of scores and sub-scored may enable calibration of the server 208 for detecting the cybersecurity threats and risks. At a step 710, a report, and intervention program actions are generated and transmitted to the network security device 206 or a user device from the server 208. The report may be a written report describing the scanned private network. The intervention program actions are generated by identifying and prioritizing necessary actions to increase the plurality of scores and sub-scores. The server 208 transmits the report to the user using PDF, HTML or interactive reports and to the application running on the user device, which enables the server 208 to measure interactions with the suggested actions. At a step 712, the interactions and actions of the user are measured. The server 208 is configured to measure the interactions with proposed interventions using the application, web portal, or email. In an embodiment, any direct corrections to configurations of the network devices 206 can be measured during the next scan. In yet another embodiment, the server 208 enables the interactions to update the plurality of scores and sub-scores. At a step 714, the cybersecurity support helpdesk 210 can be connected using the server 208 to resolve the cybersecurity threats and risks. The cybersecurity support helpdesk 210 may access the latest scan data and reports and control the user device remotely to perform additional scans, or remote control a web browser. In an embodiment, the user controls and allows third-party access. The screen 302 of the network security device 206 may act as a security mechanism that allows the cybersecurity support helpdesk 210 to provide a secure password to the user and vice versa. At a step 716, the cybersecurity threats and risks are resolved, or the cyber risk is reduced. The user remedies the cybersecurity threats and risks by (a) responding to the intervention messages and reports, for example, setting a password where a default and / or weak password is detected, (b) addressing an issue with the help of the cybersecurity support helpdesk 210, for example, finding an unauthorized device on the private network 202, or (c) answering questions to enable the server 208 learn more about the plurality of network devices 204A-N, for example, answering questions about the plurality of network devices 204A-N identify make and model information, to revise the risk or threat analysis. The cybersecurity threats and risks may be resolved by the admin of the private network 202. For example, if an unidentified device is identified in the private network 202, the network security device 206 reports the scan information about the unidentified device to the admin, and confirms whether the unidentified device is legitimate with an input of the admin. If the unidentified device is not legitimate, the admin may provide instructions to remove. When the cybersecurity threats and risks occur, (i) the network security device 206 automatically fixes the issue, (ii) the admin of the network 202 fixes the issues with help from the cybersecurity support helpdesk, or (iii) an agent from the cybersecurity support helpdesk fixes or helps to fix the issues. FIG. 8 is an illustration of an exemplary system 800 in which the various architectures and functionalities of the various previous embodiments may be implemented. As shown, the system 800 includes at least one processor 804 that is connected to a bus 802, wherein the system 800 may be implemented using any suitable protocol, such as PCI (Peripheral Component Interconnect), PCI-Express, AGP (Accelerated Graphics Port), - 57 - HyperTransport, or any other bus or point-to-point communication protocol (s). The system 800 also includes a memory 806. Control logic (software) and data are stored in the memory 806 which may take the form of random-access memory (RAM). In the present description, a single semiconductor platform may refer to a sole unitary semiconductor-based integrated circuit or chip. It should be noted that the term single semiconductor platform may also refer to multi-chip modules with increased connectivity which simulate on-chip modules with increased connectivity which simulate on-chip operation and make substantial improvements over utilizing a conventional central processing unit (CPU) and bus implementation. Of course, the various modules may also be situated separately or in various combinations of semiconductor platforms per the desires of the user. The system 800 may also include a secondary storage 810. The secondary storage 810 includes, for example, a hard disk drive and a removable storage drive, representing a floppy disk drive, SD card, a magnetic tape drive, a compact disk drive, digital versatile disk (DVD) drive, recording device, universal serial bus (USB) flash memory. The removable storage drives at least one of reads from and writes to a removable storage unit in a well-known manner. Computer programs, or computer control logic algorithms, may be stored in at least one of the memory 806 and the secondary storage 810. Such computer programs, when executed, enable the system 800 to perform various functions as described in the foregoing. The memory 806, the secondary storage 810, and any other storage are possible examples of computer-readable media. In an embodiment, the architectures and functionalities depicted in the various previous figures may be implemented in the context of the processor 804, a graphics processor coupled to a communication interface 812, an integrated circuit (not shown) that is capable of at least a portion of the capabilities of both the processor 804 and a graphics processor, a chipset (i.e., a group of integrated circuits designed to work and sold as a unit for performing related functions, etc.). Furthermore, the architectures and functionalities depicted in the various previous figures may be implemented in the context of a general computer system, a circuit board system, a single board computer, a game console system dedicated for entertainment purposes, an application-specific system. For example, the system 800 may take the form of a desktop computer, a laptop computer, a server, a workstation, a game console, an embedded system. Furthermore, the system 800 may take the form of various other devices including, but not limited to a personal digital assistant (PDA) device, a mobile phone device, a smart phone, a smart watch, a television, etc. Additionally, although not shown, the system 800 may be coupled to a network (e.g., a telecommunications network, a local area network (LAN), a wireless network, a wide area network (WAN) such as the Internet, a peer-to-peer network, a cable network, a home automation network such as ZWave or Zigbee, or the like) for communication purposes through an I / O interface 808. FIG. 9 is an illustration of a flowchart 900 depicting steps of a Large Language Model (LLM) chaining. At step 902, the scan information and the scan data, and a prompt in case of a network and device-specific threat data is analyzed, and a list of identified threats based on the specific network and device configurations is generated based on the analysis. At step 904, based on the analysis output, business-specific data such as company type, market, size, financial details, customer types, and regulatory requirements, a refined list of threats for the business, including the potential impact and importance of each threat, is contextualized. At step 906, a risk mitigation list of threats is generated, based on the contextualization output and best practice guides for cybersecurity, data protection, and security policy compliance, as well as technical guidance for issue resolution, wherein each threat is assigned a difficulty rating (easy, medium, hard) to help with prioritization and scheduling. At step 908, a prioritization task list for the network or business owner is provided, based on risk mitigation output and instructions to prioritize tasks based on risk severity, business impact, and technical difficulty, wherein the prioritization of tasks is ranked by urgency and feasibility. At step 910, a time-based schedule for assigning tasks and communicating actionable items is provided to the customer, based on the prioritization output and guidelines for creating a schedule tailored to the company's size and type, including motivational "nudges" and reminders for task completion, for ensuring timely mitigation of identified risks. FIG. 10 is an illustration of a flowchart 1000 depicting steps of financial impact estimation by the network security device 206. At step 1002, data, such as unpatched systems, open ports, default credentials, user engagement in training, and other available cyber risk data, is scanned by the network security device 206, and quantification of the coverage, strength and reliability of cyber risk controls is provided as an output by the network security device 206. At step 1004, the business profile data sourced dynamically from external databases, internal databases, questionnaire responses are gleaned from device interface. At step 1006, detailed description of company assets including sensitive data, intellectual property data are received by the network security device 206 and a list of the asset types and value of each asset are provided as input into risk exposure. At step 1008, revenue data, operational impact data, systems outage impact data, quantified cyber risk controls, and asset data are obtained and associated vulnerability, estimated financial impact of various attack scenarios is determined. At step 1010, threat data gathered from internal and external sources, quantified cyber risk controls, financial impact of various attack scenarios, Monte Carlo simulation of results are used to provide a potential financial loss expectancy, providing a range of potential financial losses with associated probabilities created using a proprietary algorithm that uses probabilistic models. At step 1012, based on the financial loss expectancy, risk breakdowns by attack type, actionable insights and prioritized recommendations to mitigate vulnerabilities in order to reduce financial loss expectancy and probability are generated and reported to the user of the network security device 206. It should be understood that the arrangement of components illustrated in the figures described are exemplary and that other arrangement may be possible. It should also be understood that the various system components (and means) defined by the claims, described below, and illustrated in the various block diagrams represent components in some systems configured according to the subject matter disclosed herein. For example, one or more of these system components (and means) may be realized, in whole or in part, by at least some of the components illustrated in the arrangements illustrated in the described figures. - 61 - In addition, while at least one of these components are implemented at least partially as an electronic hardware component, and therefore constitutes a machine, the other components may be implemented in software that when included in an execution environment constitutes a machine, hardware, or a combination of software and hardware. Although the present invention and its advantages have been described in detail, it should be understood that various changes, substitutions and alterations can be made herein without departing from the spirit and scope of the invention as defined by the appended claims.

Claims

1. A network security device £206) that is connected to a private network for detecting cybersecurity threats and risks across a plurality of network devices (204A-N) in the private network (202), wherein the network security device is configured to:automatically scan the plurality of network devices in the private network;generate and obtain scan information of the plurality of network devices;transmit the scan information to a server (208);process the scan information at the server, to detect the cybersecurity threats and risks from the scan information, and generate a plurality of scores, sub-scores, based on cyber risks and potential or active cyber intrusions; andenable one or more operations to resolve the cybersecurity threats and risks.

2. The network security device (206) according to claim 1, wherein the network security device is configured to:detect potentially unauthorized network scans in the private network (202); anddetect default credentials for services and applications operating on the plurality of network devices (204A-N) in the private network (202);- 63 -detect accesses to honeypot services operated on the network security device; andreport such detected network scans, detected default credentials, and honeypot services accesses to the network owner.

3. The network security device (206) according to claim 1 or 2, wherein the network security device is configured to:compress and encrypt the scan information;upload the encrypted scan information to the server (208) for generating the plurality of scores, sub-scores, reports and intervention plans; anddownload and display the plurality of scores and sub-scores generated in the server.

4. The network security device (206) according to claims 1 to 3, wherein the one or more operations comprise:determine the urgency and priority of the cybersecurity threats and risks by analysing the plurality of network scan information, scores and sub-scores of the detected cybersecurity threats and risks;-aMdetermine financial impact and probability of potential cyberattacks by analysing scanned information, plurality of scores and sub-scores, external threat data and company related data;generate an intervention report detailing the list of potential cyber security threats and risks in priority order, and financial impact and probability of potential cyberattacks;- 64 -enable the network owner to resolve the detected cybersecurity threats and risks in the private network (202), and financial impact and detected cyberattacks; andenable a cybersecurity support helpdesk (210) to resolve or help resolve the detected cybersecurity threats and risks in the private network (202), and financial impact and detected cyberattacks.

5. The network security device (206) according to claims 1 to 4, wherein the network security device is configured to:allow remote control operation by an authorized cybersecurity support helpdesk agent to; (a) trigger ad-hoc network scans using configurable control parameters, (b) allow remote control access to a web browser on the network security device to access internal web services (c) optionally have a sandboxed Secure Shell, SSH terminal access to the network security device, (d) optionally have Virtual Private Network, VPN termination or Internet Protocol, IP tunnel connection on the network security device to directly access the private network (202).

6. The network security device (206) according to claims 1 to 5, wherein the network security device is configured to:perform a plurality of scan modes comprising a rapid scan mode and a deeper and longer scan mode to execute in the private network (202); andcontrol the timing, and scan control parameters of the automatic network scans to maximize the likelihood of detecting hosts and any malicious code running on network hosts designed to avoid detection.- 65 -7. The network security device (206) according to claims 1 to 6, wherein the network security device is configured to:detect an external public Internet Protocol, IP address in the private network (202) during scanning the private network;execute an external port scan at the server (208) to identify open ports, services and vulnerabilities; andinclude external IP address cyber threats and risk factors in the generation of scores, sub-scores and reports and intervention plans.

8. The network security device (206) according to claims 1 to 7, wherein the network security device is configured to automatically scan and detect a local network configuration, wherein the local network configuration includes a route out to public internet (212) via infrastructure components selected from at least one of: DNS, router, firewall.

9. The network security device (206) according to claim 8, wherein the network security device is configured to offer a forwarding DNS (F-DNS) service to the local network for the purposes of providing additional cybersecurity features.

10. The network security device (206) according to claims 1 to 9, wherein the network security device employs Large Language Models (LLMs) chaining.

11. A method for detecting cybersecurity threats and risks across a plurality of network devices (204A-N) in a private network (202) using a server (208), the method comprising performing the steps of:- 66 -generating and obtaining scan information of the plurality of network devices from a network security device (206);detecting, using the server, the cybersecurity threats and risks in the scan information and generating a plurality of scores, sub-scores, reports and intervention plans based on these cyber threats and cyber risks; andenabling one or more operations to be performed in the private network.

12. A method according to claim 11, wherein the method comprises performing the steps of:detecting potentially unauthorized network scans in the private network (202);detecting default credentials for services and applications operating on the plurality of network devices (204A-N) in the private network;detecting accesses to honeypot services operated on the network security device; andreporting such detected network scans, detected default credentials, and honeypot services accesses to the network owner.

13. The method according to claims 9-11 or 12, wherein the method further comprises performing the steps of:compressing and encrypting the scan information;- 67 -uploading the encrypted scan information to the server (208) for generating the plurality of scores, sub-scores, reports and intervention plans; anddownloading and displaying the plurality of scores and sub-scores generated in the server.

14. The method according to claims 11 to 13, wherein the one of more operations comprise:determining the urgency and priority of the cybersecurity threats and risks by analyzing the plurality of network scan information, scores and sub-scores of the detected cybersecurity threats and risks;determining financial impact and probability of potential cyberattacks by analyzing scanned information, plurality of scores and sub-scores, external threat data and company related data;generating an intervention report detailing the list of potential cybersecurity threats and risks in priority order, and financial impact and probability of potential cyberattacks;enabling the network owner to resolve the detected cybersecurity threats and risks in the private network (202), and financial impact and detected cyberattacks; andenabling a cybersecurity support helpdesk (210) to resolve or help resolve the detected cybersecurity threats and risks in the private network, and financial impact and detected cyberattacks.

15. The method according to claims 11 to 14, wherein the method further comprises performing the step of:- 68 -allowing remote control operation by an authorized cybersecurity support helpdesk agent to; (a) trigger ad-hoc network scans using configurable control parameters, (b) allow remote control access to a web browser on the network security device (206) to access internal web services (c) optionally have a sandboxed Secure Shell, SSH terminal access to the network security device, (d) optionally have Virtual Private Network, VPN termination or Internet Protocol, IP tunnel connection on the network security device to directly access the private network (202).

16. The method according to claims 8-11 to 15, wherein the method further comprises performing the steps of:performing a plurality of scan modes comprising a rapid scan mode and a deeper and longer scan mode to execute in the private network (206); andcontrolling the timing, and scan control parameters of the automatic network scans to maximize the likelihood of detecting hosts and any malicious code running on network hosts designed to avoid detection.

17. The method according to claims 11 to 16, wherein the method further comprises performing the steps of:detecting an external public Internet Protocol, IP address in the private network (202) during scanning the private network;executing an external port scan at the server (208) to identify open ports, services and vulnerabilities; andincluding external IP address cyber threats and risk factors in the generation of scores, sub-scores and reports and intervention plans.- 69 -18. The method according to claims 11 to 17, wherein the method comprises automatically scanning and detecting a local network configuration, wherein the local network configuration includes a route out to public internet (212) via infrastructure components selected from at least one of: DNS, router, firewall.

19. The method according to claim 18, wherein the method comprises offering a forwarding DNS (F-DNS) service to the local network for the purposes of providing additional cybersecurity features.

20. The method according to claims 11 to 19, further comprises employing Large Language Models (LLMs) chaining.