A cybersecurity management system and method
Patent Information
- Application Number
- PCT/SG2025/050224
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2026-10-01
Smart Images

Figure SG2025050224_01102026_PF_FP_ABST
Abstract
Description
DESCRIPTIONTITLE OF INVENTION: [A CYBERSECURITY MANAGEMENT SYSTEM AND METHOD]TECHNICAL FIELDThe present disclosure relates generally to the field of cybersecurity management and, more specifically, to a cybersecurity management system designed for ease of use and operation, including by small and medium-sized enterprises (SMEs).BACKGROUND
[0001] The following discussion of the background to the invention is intended to facilitate an understanding of the present invention only. It should be appreciated that the discussion is not an acknowledgement or admission that any of the material referred to was published, known or part of the common general knowledge of the person skilled in the art in any jurisdiction as at the priority date of the invention.
[0002] In today's digital age, cybersecurity has become a critical concern for businesses across all sectors. With the increasing reliance on digital information and the internet for business operations, the threat landscape has expanded, making organizations vulnerable to a wide range of cyber threats. These threats can range from data breaches and ransomware attacks to more sophisticated forms of cyber espionage and sabotage. As businesses strive to protect their sensitive information and maintain operational integrity, the need for robust cybersecurity measures has never been more pressing.
[0003] SMEs, in particular, face unique challenges in managing cybersecurity risks. Unlike larger corporations, SMEs often lack the resources and expertise to implement comprehensive cybersecurity strategies. This makes them attractive targets for cybercriminals who exploit these vulnerabilities. Moreover, SMEs must navigate complex regulatory environments, ensuring compliance with industry standards and legal requirements while managing limited budgets. The balance between maintaining security and meeting business objectives is delicate, and the consequences of a cybersecurity incident can be devastating, affecting not only financial stability but also reputation and customer trust. As such, there is a growing demand for cybersecurity solutions that are not only effective but also align with business priorities and are accessible to organizations with varying levels of resources. However, conventional approaches in this field continue to face several drawbacks, including complex deployment, reliance on specialized cybersecurity expertise, and inefficient resource utilization, making them less practical for SMEs with limited IT capabilities.
[0004] For example, U. S. Patent Application US20170195349A1, titled “Platform for Protecting Small and Medium Enterprises from Cybersecurity Threats,” discloses a device for auditing network devices, generating cybersecurity reports, and providing security recommendations. While the system automates monitoring, scanning, and compliance assessment, its multi-layered auditing process, administrator access requirements, and reliance on compliance frameworks introduce complexity that may beimpractical for SMEs with limited cybersecurity expertise and IT resources. The system still requires specialists to configure, manage, and interpret its outputs, making it less accessible for SME managers seeking a simplified cybersecurity solution.
[0005] There exists a need to develop a more efficient and effective cybersecurity management system, addressing at least one of the problems associated with conventional systems.SUMMARY
[0006] Specifically, to address the above-mentioned technical problems, the present invention specifically uses the following technical solutions:
[0007] Accordingly, an aspect of the invention refers to a cybersecurity management system, comprising: a file analysis module configured to analyze a plurality of information asset files, wherein the information asset files comprise both digital and non-digital forms of information; an event detection module configured to detect a cybersecurity event; and, a cybersecurity analysis module configured to generate cybersecurity intelligence for the cybersecurity event; wherein the file analysis module is operable to analyze each information asset file and assign a plurality of asset traits; wherein the event detection module is operable to analyze each cybersecurity event to identify a plurality of cybersecurity traits associated with the cybersecurity event and one or more relevant information asset files affected by the cybersecurity event; wherein each relevant information asset file is assigned the identified cybersecurity traits; wherein the cybersecurity analysis module is operable to retrieve the plurality of asset traits and the plurality of cybersecurity traits associated with each relevant information asset file, and to generate the cybersecurity intelligence based on both the plurality of asset traits and the plurality of cybersecurity traits.
[0008] In some embodiments, the plurality of asset traits comprises an asset identifier and an asset value indicator.
[0009] In some embodiments, the plurality of asset traits further comprises an asset type indicator.
[0010] In some embodiments, the plurality of asset traits further comprises an asset risk level indicator and an asset risk type indicator.
[0011] In some embodiments, the asset risk type indicator comprises one or more selected from the group consisting of a legal risk indicator, a regulatory / compliance risk indicator, a business risk indicator, a technological risk indicator, and a financial risk indicator.
[0012] In some embodiments, the plurality of asset traits further comprise corporate traits associated with each relevant information asset file.
[0013] In some embodiments, the corporate traits comprise information related to a business entity that directly owns, indirectly owns, or partially owns each relevant information asset file.
[0014] In some embodiments, the cybersecurity analysis module is operable to obtain the plurality of asset traits and the plurality of cybersecurity traits associated with each relevant information asset file of a business entity of interest and to generate cybersecurity intelligence for the business entity of interest.
[0015] In some embodiments, the plurality of asset traits further comprise accessor traits associated with the each relevant information asset file.
[0016] In some embodiments, the accessor traits comprise information related to user having access rights to the each relevant information asset file.
[0017] In some embodiments, the cybersecurity analysis module is operable to obtain the plurality of asset traits and the plurality of cybersecurity traits associated with each relevant information asset file of an accessor of interest and to generate cybersecurity intelligence for the accessor of interest.
[0018] In some embodiments, the plurality of asset traits further comprise geographical traits associated with the each relevant information asset file.
[0019] In some embodiments, the geographical traits comprise information related to originating location of the cybersecurity event; wherein the originating location comprises network and / or sever location.
[0020] In some embodiments, the plurality of asset traits further comprises operation system traits associated with the each relevant information asset file.
[0021] In some embodiments, the plurality of cybersecurity traits comprises one or more selected from the group consisting of an event type indicator, an event damage indicator, an event risk level indicator, an event timestamp and event origin location.
[0022] In some embodiments, the plurality of cybersecurity traits further comprise actor information associated with the cybersecurity event.
[0023] In some embodiments, the plurality of cybersecurity traits further comprise mitigation information associated with the cybersecurity event.
[0024] In some embodiments, the mitigation information comprises mitigation cost, mitigation implementation, and mitigation assignment.
[0025] In some embodiments, the cybersecurity management system further comprises a cybersecurity mitigation module configured to mitigate impact on the each relevant information asset file exerted by the cybersecurity event; wherein the cybersecurity mitigation module is operable to implement a mitigation action based on the cybersecurity intelligence generated using both the plurality of asset traits and the plurality of cybersecurity traits.
[0026] In some embodiments, the cybersecurity mitigation module is configured to comprise a mitigation suggestion module operable to analyse cybersecurity intelligence and generate one or more mitigation suggestions based on the cybersecurity intelligence associated with each relevant information asset file.
[0027] In some embodiments, the cybersecurity mitigation module is configured to comprise a mitigation implementation module operable to execute one or more selectedmitigation actions based on the mitigation suggestions generated by the mitigation suggestion module.
[0028] In some embodiments, the cybersecurity mitigation module is configured to comprise a mitigation result assessment module operable to assess status of the each relevant information asset file after the one or more selected mitigation action has been executed on the each relevant information asset file.
[0029] In some embodiments, the cybersecurity management system further comprises a cybersecurity simulation module configured to simulate a cybersecurity event on one or more information asset files to test security and vulnerability of the plurality of information asset files.
[0030] In some embodiments, the cybersecurity analysis module is operable to retrieve the plurality of digital asset traits and the plurality of cybersecurity traits for the one or more relevant information asset files; the cybersecurity analysis module is operable to classify the one or more relevant information asset files according to a first classification criteria.
[0031] In some embodiments, the first classification criteria comprise a hierarchical order of business impact based on the asset value indicators.
[0032] In some embodiments, the first classification criteria comprise a hierarchical order of business risk based on the asset level risk indicators.
[0033] In some embodiments, the cybersecurity analysis module is operable to classify the one or more relevant information asset files according to a second classification criteria.
[0034] In some embodiments, the second classification criteria comprise one or more business entities of interests.
[0035] In some embodiments, the second classification criteria comprise one or more accessor of interests.
[0036] In some embodiments, the second classification criteria comprise one or more compliance requirements.
[0037] In some embodiments, the cybersecurity intelligence is generated using an artificial intelligence-based approach.
[0038] In some embodiments, the artificial intelligence-based approach comprises using an artificial intelligence model.
[0039] Other aspects and features of the present invention will become apparent to those of ordinary skill in the art upon review of the following description of specific embodiments of the invention in conjunction with the accompanying figures.BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In the figures, which illustrate, by way of non-limiting examples only, embodiments of the present invention,
[0041] [FIG. 1]: illustrates, in a block diagram, a cybersecurity management system (100) according to various embodiments of the present invention.
[0042] [FIG. 2]: illustrates in a block diagram, a cybersecurity mitigation module (104) according to various embodiments of the present invention.
[0043] [FIG. 3a]: illustrates examples of dashboards displaying cybersecurity intelligence in accordance with various embodiments of the present invention.
[0044] [FIG. 3b]: illustrates examples of dashboards displaying cybersecurity intelligence in accordance with various embodiments of the present invention. FIG. 3b displays the same set of dashboards as FIG. 3a, but captured at different time points to illustrate changes over time.
[0045] [FIG. 4a]: illustrates examples of dashboards displaying cybersecurity intelligence in accordance with various embodiments of the present invention.
[0046] [FIG. 4b]: illustrates examples of dashboards displaying cybersecurity intelligence in accordance with various embodiments of the present invention.
[0047] [FIG. 4c]: illustrates examples of dashboards displaying cybersecurity intelligence in accordance with various embodiments of the present invention.
[0048] [FIG. 5]: illustrates the two different compliance and regulatory requirements (A & B) applied across a plurality of information asset files.
[0049] [FIG. 6]: illustrates the generation of the cybersecurity intelligence using an information asset-file centric approach in the present invention.
[0050] [FIG. 7]: illustrates the details of cybersecurity events that are displayed when a number within the Business Impact and Risk Chart, as shown in FIG. 3a & 3b, is clicked.
[0051] [FIG.8a]: illustrates the cybersecurity analysis module of the present invention, according to an embodiment of the present invention, wherein the cybersecurity analysis module comprises a proactive module, a reactive module and a compliance module.
[0052] [FIG.8b]: illustrates the cybersecurity analysis module of the present invention, according to an embodiment of the present invention, with more details on the proactive module.
[0053] [FIG.8c]: illustrates the cybersecurity analysis module of the present invention, according to an embodiment of the present invention, with more details on the reactive module.
[0054] [FIG.8d]: illustrates the cybersecurity analysis module of the present invention, according to an embodiment of the present invention, with more details on the compliance module.
[0055] DETAILED DESCRIPTION
[0056] Throughout this document, unless otherwise indicated to the contrary, the terms “comprising”, “consisting of’, “having” and the like, are to be construed as non-exhaustive, or in other words, as meaning “including, but not limited to”.
[0057] Furthermore, throughout the document, unless the context requires otherwise, the word “include” or variations such as “includes” or “including” will be understood to imply the inclusion of a stated integer or group of integers but not the exclusion of any other integer or group of integers.
[0058] Throughout this document, unless the context requires otherwise, the term “information asset file” refers to any structured or unstructured repository of information that constitutes a valuable digital or non-digital asset for an organization. This term encompasses both electronic and physical records, including paper-based documents, human-readable archives, and other non-electronic forms of information storage.
[0059] As detailed in the following sections, each information asset file within the cybersecurity management system is analyzed and assigned a plurality of asset traits, enabling the system to assess its business value, risk exposure, and security requirements. The cybersecurity management system processes both digital and non-digital information asset files, ensuring that cybersecurity intelligence generation incorporates all relevant sources of sensitive or business-critical information.
[0060] Unless defined otherwise, all other technical and scientific terms used herein have the same meaning as is commonly understood by a skilled person to which the subject matter herein belongs.
[0061] EMBODIMENT 1
[0062] An aspect of the present disclosure relates to a cybersecurity management system designed to provide effective cybersecurity risk management and mitigation by integrating business-focused cybersecurity intelligence with technical risk analysis. The system is suitable for businesses of all sizes, including SMEs, ensuring that cybersecurity threats are assessed and addressed in alignment with business priorities, compliance requirements, and operational risks.
[0063] The cybersecurity management system utilizes a structured approach to cybersecurity intelligence by analyzing information asset files, detecting cybersecurity events, classifying security risks, and implementing mitigation strategies. The system operates by retrieving and processing asset traits and cybersecurity traits to generate cybersecurity intelligence, which in turn informs mitigation actions and business risk assessments.
[0064] As illustrated in FIG.1, in some embodiments of the present invention, the cybersecurity management system (100) comprises the several modules:
[0065] (i) a File Analysis Module (101), which is configured to analyze a plurality of information asset files, which may include both digital and non-digital forms of information. Each information asset file is analyzed and assigned a plurality of asset traits, allowing the system to categorize and assess information assets based on their significance to business operations and security risks. In some embodiments, when determining the asset trait to be assigned to a particular information asset file or a group of informationasset files (i.e., first information asset file), the File Analysis Module (101) may be configured to identify similar information asset files (i.e., second information asset file), retrieve one or more asset traits associated with the second information asset file, and assign those retrieved asset traits to the first information asset file. By leveraging this approach, the cybersecurity management system (100) can automatically infer the potential impacts and relevance of an information asset file in cybersecurity management without requiring manual or detailed annotations for each file. Instead, asset traits from similar files can be utilized for annotation, streamlining the analysis process. This feature can be advantageous for SMEs, where manually classifying and annotating a large number of information asset files can be resource-intensive, impractical and prone to errors, (ii) an Event Detection Module (102), which is configured to detect cybersecurity events and identify a plurality of cybersecurity traits associated with each cybersecurity event. The event detection module is operable to map affected information asset files (i.e., termed as “relevant information asset file”) to the corresponding cybersecurity traits, ensuring that cybersecurity risks are assessed in relation to specific business assets. According to some embodiments of the present invention, as illustrated in FIG. 7, each cybersecurity event is assigned a summary title that encapsulates key information related to the event. Additionally, the “Key” serves as a universal reference number within the cybersecurity management system (100), enabling the unique identification of a particular cybersecurity event. The “Key” could be applied to (i) facilitate the linking of the cybersecurity event to affected information asset files, (ii) support the mitigation and tracking of the cybersecurity event, and (iii) serve various other cybersecurity management purposes. Furthermore, the “IP address” indicates the location where the corresponding information asset file is stored or accessed, (iii) the Cybersecurity analysis module (103) is configured to retrieve and process asset traits (obtained from the File Analysis Module (101)) and cybersecurity traits (obtained from the Event Detection Module (102)) to generate cybersecurity intelligence. This intelligence can then be used to classify risks, prioritize mitigation actions, and inform cybersecurity strategies. In other words, the Cybersecurity Analysis Module (103) is configured to associate each cybersecurity event with one or more specific information asset files, enabling cybersecurity analysis and intelligence generation through a file-centric approach. For example, in some embodiments, the Cybersecurity analysis module (103) is operable to identify threats requiring mitigation and provide actionable intelligence to guide mitigation actions, which are then executed by the Cybersecurity Mitigation Module (104). In some embodiments, the analysis results can be presented as easy-to-understand recommendations, enabling the cybersecurity management system's administrator or manager to conveniently review, adjust if necessary, and implement mitigation measures accordingly. In some embodiments, the Cybersecurity analysis module (103) is further operable to provide risk assessment data that defines simulation parameters for proactive security testing initiated by the Cybersecurity Simulation Module (105).
[0066] (iv) a Cybersecurity Mitigation Module (104) configured to mitigate the impact of cybersecurity events on each relevant information asset file. Examples of mitigation actions may include removing a corrupted digital information file, identifying a compromised accessor, or enhancing the confidentiality level of a digital information file when unauthorized access attempts are detected. The Cybersecurity Mitigation Module (104) is operable to implement mitigation actions based on cybersecurity intelligence, which is generated by analyzing both asset traits and cybersecurity traits.
[0067] In some embodiments, the Cybersecurity Mitigation Module (104) further comprises: a Mitigation Suggestion Module (201), configured to analyze cybersecurityintelligence and generate recommended mitigation actions based on identified risks; a Mitigation Implementation Module (202), configured to execute the recommended mitigation measures / actions in response to detected cybersecurity threats; and a Mitigation Result Assessment Module, configured to evaluate the effectiveness of the implemented mitigation actions and refine future mitigation strategies accordingly.
[0068] Examples of mitigation measures / actions may include, but not limited to: removing a corrupted information asset file to prevent further compromise; restricting or revoking an unauthorized accessor’s access rights to prevent unauthorized activities; restoring a compromised information asset file from a secure backup to ensure business continuity; applying security patches or updates to eliminate system vulnerabilities; isolating a compromised system or endpoint to contain a cybersecurity event; blocking unauthorized network traffic or suspicious IP addresses to prevent further attacks; and enforcing stricter authentication measures, such as multi-factor authentication (MFA), for at-risk accounts.
[0069] (v) a Cybersecurity Simulation Module (105) configured to simulate cybersecurity events on one or more information asset files. This simulation allows organizations to identify security vulnerabilities and evaluate the resilience of their cybersecurity posture without the occurrence of an actual cybersecurity event. The Cybersecurity Simulation Module is operable to simulate cybersecurity events tailored to specific business needs. For example, it may simulate cybersecurity events with the potential to cause the most severe business impacts, thereby enabling a proactive assessment of potential consequences. This facilitates management decision-making by providing insights into cybersecurity risks, allowing organizations, even those without specialized expertise in cybersecurity management, to adopt appropriate mitigation strategies in a cost-effective manner. Such functionality is particularly valuable for resource-limited SMEs, enabling them to prioritize cybersecurity investments based on business impact assessments, the Cybersecurity Simulation Module (105) can be configured to support the Mitigation Result Assessment Module by mounting simulated cyberattacks onto mitigated information asset files. This allows for a more rigorous evaluation of the effectiveness of mitigation actions, ensuring that security measures are thoroughly tested and validated for resilience against potential future threats.
[0070] In some embodiments, the cybersecurity management system (100) may be configured to include additional specialized modules (107) that operate based on the intelligence and insights generated by the Cybersecurity Analysis Module (103). One example of such a specialized module is a Compliance Assessment Module (107), specifically designed to assess whether relevant compliance requirements have been met, identify potential cybersecurity risks, and evaluate the extent of such risks. This Compliance Assessment Module (107) is operable to provide clear and easily understandable results for compliance managers responsible for regulatory compliance, even if they lack expertise in cybersecurity. By offering direct insights into which compliance requirements are at risk, the Compliance Assessment module (107) is operable to enable the compliance manager to identify affected information asset files and take necessary mitigation actions. If the automated mitigation solutions within the cybersecurity management system are insufficient to fully address the identified cybersecurity risks, the manager can then escalate the issue by engaging specialized cybersecurity experts to ensure proper resolution. Accordingly, the Compliance Assessment Module (107) enables efficient and convenient monitoring of compliance requirements while conserving critical resources, ensuring that external support isreserved only for serious cybersecurity events that necessitate specialized intervention. In some embodiments, additional specialized modules (107) can be incorporated into the cybersecurity management system to address various business objectives, further enhancing the system’s extensibility and adaptability. This flexibility is particularly beneficial for SMEs with diverse operational needs and industry-specific requirements, allowing the system to be tailored to different cybersecurity challenges and business contexts.
[0071] In some embodiments, the cybersecurity management system is configured to classify information asset files and cybersecurity events based on multiple classification criteria to ensure that risk assessments align with business priorities and operational needs.
[0072] For example, the multiple classification criteria may include a first classification criterion, which categorizes information asset files based on business impact and business risk. This classification utilizes asset-specific indicators, such as: Asset Value Indicator, which assesses the financial impact of an asset’s compromise; and Asset Risk Level Indicator, which evaluates the cybersecurity risk associated with each asset. This classification approach enables the system to prioritize cybersecurity intelligence generation and mitigation actions based on an asset's business significance and security risk level. This further helps SME managers efficiently prioritize limited cybersecurity resources, ensuring that efforts are focused on issues with the highest business impact and risk levels.
[0073] For example, the multiple classification criteria may also include a second classification criterion, which refines the classification based on business entities of interest, accessors of interest, and compliance requirements. This is particularly relevant for business sectors where compliance is critical to operations, such as the financial and medical sector, where businesses must adhere to strict regulatory and compliance requirements. In such cases, cybersecurity management efforts should be prioritized for information asset files associated with compliance-related obligations, ensuring that security measures align with regulatory frameworks and industry standards.
[0074] Collectively, these classification mechanisms ensure that cybersecurity intelligence and mitigation actions are prioritized effectively based on business needs, security policies, and compliance requirements. To enable efficient and user-friendly cybersecurity threat management without requiring specialized cybersecurity expertise, the present invention utilizes a comprehensive set of asset traits and cybersecurity traits to establish a file-centric approach to managing cybersecurity events. Specifically, the cybersecurity management system is configured to analyze and assign asset traits to information asset files and cybersecurity traits to cybersecurity events. These traits are then collectively utilized for risk classification and mitigation decisions, leveraging both conventional software analysis techniques and artificial intelligence-based approaches to enhance accuracy and efficiency.
[0075] EMBODIMENT 2
[0076] According to some embodiments of the present invention, each information asset file is assigned a plurality of asset traits, including but not limited to:
[0077] Asset Identifier, which uniquely identifies an asset.
[0078] Asset Value Indicator, which measures the business impact of the asset.
[0079] Asset Type Indicator, which classifies the asset by type.
[0080] Asset Risk Level Indicator, which quantifies the asset’s risk exposure.
[0081] Asset Risk Type Indicator, which categorizes risks as legal, regulatory, business, technological, or financial risks.
[0082] Corporate Traits, which describe the business entity ownership structure of an asset.
[0083] Accessor Traits, which define user access rights associated with an asset.
[0084] Geographical Traits, which describe the origination location of an asset in terms of network and server location.
[0085] Operating System Traits, which identify operating system-related characteristics of an asset.
[0086] According to some embodiments of the present invention, each detected cybersecurity event is analyzed and assigned a plurality of cybersecurity traits, including:
[0087] Event Type Indicator, which classifies the type of cybersecurity event.
[0088] Event Damage Indicator, which quantifies the impact of the event.
[0089] Event Risk Level Indicator, which evaluates the severity of the event.
[0090] Event Timestamp, which records when the event occurred.
[0091] Event Origin Location, which identifies the network or system source of the cybersecurity event.
[0092] Actor Information, which provides details about threat actors involved in the cybersecurity event.
[0093] Mitigation Information, which includes mitigation cost, implementation details, and assignment responsibilities.
[0094] It will be clear to a skilled person that the various traits utilized in the present invention can be calculated, characterized, or defined using established methodologies, particularly in assessing business risks and business impacts.
[0095] For instance, business risks may be evaluated based on financial exposure, regulatory compliance requirements, operational dependencies, reputational damage, and potential legal liabilities. These risks can be quantified using risk matrices, Monte Carlo simulations, probabilistic risk assessments, or frameworks such as ISO 31000, NIST Risk Management Framework (RMF), or FAIR (Factor Analysis of Information Risk). Additionally, risk scoring models may be used to prioritize threats based on their likelihood and potential severity in a given business context.
[0096] Similarly, business impacts may be calculated by assessing the criticality of aninformation asset file in relation to business continuity, revenue loss, legal implications, regulatory penalties, intellectual property protection, and customer trust erosion. Common methodologies such as cost-benefit analysis, business impact analysis (BIA), weighted scoring models, or impact severity classifications can be applied to evaluate the potential consequences of cybersecurity events.
[0097] For example, if a cybersecurity event compromises a financial transaction system, the business impact may be measured in terms of lost revenue per hour of downtime, potential regulatory fines, and customer attrition. If a breach affects a healthcare system, the impact assessment may focus on patient data exposure, legal non-compliance (e.g., HIPAA violations), and reputational harm.
[0098] By integrating these established risk assessment and impact evaluation techniques, the present invention provides a structured, data-driven approach to cybersecurity intelligence, prioritization, and mitigation, ensuring that cybersecurity measures align seamlessly with business priorities and operational resilience strategies.
[0099] EMBODIMENT 3
[0100] As shown in FIG. 3a and 3b, the cybersecurity intelligence generated in some embodiments of the present invention is displayed on a dashboard with four key charts, including: (i) Company Risk Chart (top-left); (ii) Alarm Chart (top-right); (iii) Business Impact and Risk Chart (bottom-left); and (iv) Cybersecurity Event Rating Chart (bottomright).
[0101] In this specific example of FIG. 3a and 3b, the Company Risk Chart provides an overview of the overall risk level of a business entity, which may include a specific business subsidiary, business unit, or a corporation comprising multiple entities. This chart offers a concise visualization of an organization’s overall cybersecurity risk exposure, assisting managers in gauging the urgency of cybersecurity threats and determining the level of attention and resources required for cybersecurity management. In the present invention, the overall risk level of a particular business entity (e.g., M2Fintech, GroupIT, M2Telecom) is calculated based on the information asset files associated with that entity. Depending on the organizational structure, the scope of information asset files considered relevant to a specific business entity (e.g., GroupIT) may be configured differently, potentially extending beyond conventional asset categorization.
[0102] Accordingly, as the present invention employs an information asset file-based approach to analyzing cybersecurity events and generating cybersecurity intelligence, it offers flexibility in producing high-level, managerial-level cybersecurity intelligence for a business entity. The system of the present invention enables users to configure the scope of information asset files under control or relevant to the business entity of interest, tailoring cybersecurity intelligence generation to specific organizational needs. This capability is particularly beneficial for SMEs that lack a rigid or established organizational structure or for companies that have internally designed organizational frameworks based on unique business and commercial considerations. By adapting cybersecurity intelligence monitoring and assessment to organizational configurations, the present invention enhances cybersecurity security decision-making for both structured enterprises and dynamically evolving businesses, without requiring a complex technical setup or the extensive involvement of cybersecurity professionals. Furthermore, from FIG.3a to FIG. 3b, the overall company risk level increases from 36.99% to 45.40%, indicatinga heightened cybersecurity risk across all monitored business entities. Since the cybersecurity intelligence and risk levels are generated based on various sets of information asset files, the risk level of each business subsidiary can also be computed, providing detailed insights into the cybersecurity status of individual entities.
[0103] In this specific example from FIG. 3a and FIG. 3b, the risk level of GroupIT has experienced the most significant increase, rising from 34.20% to 61.63%. This sharp increase suggests that the cybersecurity manager of the present system should prioritize the inspection, resolution, and mitigation of cybersecurity issues affecting GroupIT. By doing so, the manager can allocate cybersecurity resources, which are often limited for SMEs in terms of financial and technical capacity, to address the most critical threats, thereby maximizing the impact of mitigation efforts and reducing the overall company risk level.
[0104] In this specific example of FIG. 3a and 3b, the Alarm Chart displays the types of cybersecurity events (e.g., through Event Type Indicators) that have occurred within a specified time period, such as the current day or week. By providing a holistic view of the total number and frequency of attacks, this chart enables the cybersecurity manager to quickly assess the severity of recent cybersecurity threats currently and recently. The ability to track trends in attack frequency and type allows managers to make informed decisions on whether immediate mitigation actions are necessary.
[0105] In this specific example from FIG. 3a and FIG. 3b, the Alarm Chart in FIG. 3b displays 56 cybersecurity events for the week, representing a sharp increase compared to the status in FIG. 3a. This notable surge alerts the cybersecurity manager to take immediate action to investigate and mitigate the escalating cybersecurity threats. Additionally, the Alarm Chart in FIG. 3b provides further intelligence on the nature of these cybersecurity events, revealing that while some attacks are related to system compromise, the majority are linked to environmental awareness issues. By combining these insights, the Alarm Chart not only highlights the increasing trend of cybersecurity threats but also provides critical information on the specific types of cybersecurity risks that require attention, enabling the cybersecurity manager to make more informed and targeted mitigation decisions. In this specific example from FIG. 3a and FIG. 3b, the Business Impact and Risk Chart can be particularly useful for SME managers, who often operate with limited cybersecurity resources. This chart classifies cybersecurity events (examples of cybersecurity events as shown in FIG. 7) based on business impact and risk, using the multi-criteria classification approach adopted by the present invention. The severity of cybersecurity events is measured not only by their technical implications but also by their business consequences, such as disruptions to business operations and severe non-compliance issues that could jeopardize business continuity. For example, in the given chart of FIG. 3a, eleven (11) cybersecurity events are identified at both critical business impact and critical business risk levels (top-right corner box of the chart), signaling an urgent need for immediate mitigation actions for the eleven (11) cybersecurity events. This is particularly beneficial for SME managers who may lack specialized cybersecurity expertise, as the chart provides clear and actionable guidance on which cybersecurity events should be prioritized. Furthermore, the cybersecurity management system of the present invention is operable to provide suggested mitigation solutions (e.g., for the eleven most critical cybersecurity events), easing the manager’s reliance on specialized cybersecurity knowledge to determine the mitigation solutions / actions required. The Mitigation Result Assessment Module further enhances system reliability by analyzing the effectiveness of implemented mitigation actions. This could help address concernsthat automated mitigation solutions may not fully resolve cybersecurity threats.
[0106] Furthermore, since cybersecurity events are associated with information asset files, addressing the most critical events (i.e., those with the highest business impact and business risk) effectively “fixes” the associated information asset files. This, in turn, helps resolve other interconnected concerns in an efficient and structured manner. For example, if a particular information asset file linked to an important regulatory requirement is compromised, and the associated cybersecurity event is classified as critical in both business impact and business risk, it should then be prioritized for immediate or prioritized mitigation. By resolving the cybersecurity issue affecting this specific information asset file, the regulatory requirement is automatically met, ensuring compliance. This structured approach streamlines decision-making, allowing the cybersecurity manager to efficiently focus on the most pressing issues, thereby optimizing cybersecurity resource allocation and risk mitigation.
[0107] In this specific example from FIG. 3a and FIG. 3b, the Cybersecurity Event Rating Chart ranks cybersecurity events based on their criticality, taking into account both asset traits and cybersecurity traits. This ranking helps direct the manager’s attention to the most critical issues that require immediate mitigation. Additionally, the chart provides a concise overview of the profiles of various cybersecurity events encountered by the organization within a given time period, enabling quick situational awareness and informed decision-making.
[0108] As shown in FIG. 4a, various embodiments of the present invention provide a dashboard comprising three charts: Alarms by Country, Asset Risks, and Tracking of Mitigation Measures / Actions. In this specific example, the Alarms by Country chart is designed to present a world map that visualizes the originating locations of cybersecurity events, such as servers or networks involved in the attacks. By identifying the geographic sources of these threats, managers can quickly assess potential attack origins, which may also provide business intelligence insights, such as identifying potential competitor-driven threats or high-risk market regions that warrant further attention.
[0109] In this specific example of FIG. 4a, the Asset Risks chart classifies cybersecurity events based on asset risk profiles, offering an asset-centric perspective on cybersecurity threats. As discussed above in relation to other charts, by viewing cybersecurity risks from an asset-level perspective, managers can prioritize mitigation efforts based on the criticality and exposure of affected assets. This chart offers an additional perspective for the cybersecurity manager to prioritize mitigation actions. While the Business Impact and Risk Charts in FIG. 3a and FIG. 3b guide the manager in addressing cybersecurity events in a prioritized manner (e.g., mitigating critical events first), the Asset Risk Chart provides further insights by focusing on the specific information asset files affected by cybersecurity threats.
[0110] For example, if cybersecurity events classified as critical in both business impact and business risk have been successfully mitigated, the number of information asset files with critical risks should logically decrease. However, if the number of critical-risk information asset files remains unchanged or shows minimal reduction, it may prompt the manager to investigate the underlying causes, by, for example, examining the Asset Risks Chart in details. This could be due to various factors, such as certain cybersecurity-threatened information asset files not being directly linked to critical business functions, meaning they do not require immediate mitigation.
[0111] Additionally, the Asset Risk Chart can help identify critical information asset files requiring mitigation that may have been overlooked in the Business Impact and Risk Charts. For example, cybersecurity events associated with these overlooked information asset files may be classified under a high-risk and high-impact category rather than a critical-risk and critical-impact category, potentially leading to delayed mitigation. By cross-referencing different dashboards, the system enhances cybersecurity issue management and minimizes potential inaccuracies that may arise from relying on a single chart or a limited set of charts. In this way, the present invention achieves a balance between operational efficiency (e.g., summarizing cybersecurity events from a managerial perspective) and analytical accuracy (e.g., accounting for possible misclassifications or oversights in cybersecurity event categorization). By providing cybersecurity intelligence from multiple perspectives, the system ensures a more comprehensive and reliable approach to risk assessment and mitigation, as represented through various dashboard charts. In this specific example of FIG. 4a, the Tracking of Mitigation Measures / Actions chart provides real-time updates on the status of cybersecurity events being addressed. It tracks the progression of mitigation efforts, from initial incident reporting to mitigation in progress, and categorizes cybersecurity events based on their resolution status, such as remediated events, risk-accepted events, and events that remain unresolved even after mitigation efforts (e.g., “not fixed”). By offering a live overview of the mitigation progress and final outcomes, this tracking chart allows managers to efficiently monitor ongoing cybersecurity responses and assess whether further intervention is required.
[0112] As illustrated in FIG. 4b and FIG. 4c, various embodiments of the present invention provide additional dashboard charts that classify cybersecurity events and their relevance to business operations from multiple perspectives. For example, FIG.4b shows the vulnerable systems (top left panel), according to the systems relevant to the information asset files being affected by the cybersecurity events.
[0113] Also, FIG. 4b shows the Impact Type chart, summarizing the types of impacts, such as whether it is financial, reputational or regulatory. The example as illustrated in FIG. 4b shows that the reputational impacts are currently the most severely affected by the recent cybersecurity events, as well as the cybersecurity events that could affect the compliance requirements the business entity needs to follow. This Impact Type chart could give manager a convenient overlook of the severity of the cybersecurity events on business operations, from a managerial perspective, easily conceivable to a manager, who does not require extensive cybersecurity expertise.
[0114] The Impact Type Chart in the present invention is made possible by its information asset file-based approach to characterizing and managing cybersecurity events. By defining cybersecurity events based on the affected information asset files, the present invention significantly simplifies the classification of impact types, as the business relevance and implications of an information asset file are generally straightforward to determine. For example, if an information asset file is associated with a biomedical device subject to health regulatory requirements, its impact classification would at least include “non-compliance impact”. Alternatively, each information asset file can be manually assigned an impact type in the event of a compromise, further refining the classification process. By simplifying impact classification, the present invention enables more efficient and intuitive cybersecurity event management, allowing organizations to effectively navigate and address complex cybersecurity challenges with greater ease.
[0115] FIG. 4b and FIG. 4c present additional charts covering key cybersecurity metrics, including Confidentiality, Integrity, and Availability (CIA), user authentication status (authenticated vs. unauthenticated), The Common Vulnerability Scoring System (CVSS), timeline trends (tracking the creation and resolution of cybersecurity issues), network vector analysis (internal network vs. internet network), and The Open Web Application Security Project (OWASP). These charts provide comprehensive cybersecurity intelligence, enabling efficient and streamlined management of cybersecurity events.
[0116] EMBODIMENT 4
[0117] Different permutations in the presentation of cybersecurity intelligence can be implemented based on specific business needs. However, a fundamental aspect of the present invention is its information asset file-centric approach to cybersecurity event management, which closely aligns cybersecurity events and their traits with business aspects and asset traits. This enables managers, even those without specialized cybersecurity expertise, to make informed decisions and take appropriate actions to address the most pressing cybersecurity issues affecting the company.
[0118] As illustrated in FIG. 5, when a company needs to comply with a specific set of compliance or regulatory requirements (A), certain information asset files (e.g., Group 1 and Group 3) are associated with these requirements. Consequently, cybersecurity events linked to these information asset files are analyzed in relation to compliance requirements A, ensuring regulatory adherence and generating cybersecurity intelligence specific to compliance requirements A. This approach allows the cybersecurity manager to efficiently monitor and manage cybersecurity issues, particularly when compliance with requirements A is a critical priority, ensuring that cybersecurity measures align with regulatory obligations and business needs in a structured and convenient manner.
[0119] Furthermore, as the company expands its business operations to include another set of compliance or regulatory requirements (B), the scope of relevant information asset files adjusts accordingly. In this scenario, Group 3 remains relevant, while additional information asset files from Group 2 are also incorporated into the analysis. With this expanded scope, cybersecurity intelligence can now be specifically generated for compliance requirements B, enabling efficient and streamlined management of regulatory adherence. This approach ensures that cybersecurity measures remain aligned with evolving compliance obligations, simplifying the process of maintaining and demonstrating compliance with requirements B.
[0120] This example further highlights the advantages of an information asset filebased approach in cybersecurity event management, as information asset files can be flexibly grouped and structured according to various business functions or regulatory requirements. This adaptability allows the system to generate cybersecurity intelligence tailored to specific business objectives, ensuring that cybersecurity management remains responsive to evolving compliance obligations and operational needs.
[0121] As illustrated in FIG. 6, the present invention adopts an information asset filecentric approach to managing cybersecurity events (602). In this approach, information asset files (601) affected by cybersecurity events (602) are identified, and cybersecurity traits and asset traits are associated accordingly. By leveraging asset traits, information asset files (601) can be dynamically grouped based on various business considerations, functions, and purposes. As a result, cybersecurity events (602) are directly linked tobusiness priorities, enabling a context-aware cybersecurity management system that aligns technical threats with operational impact. In other words, the present invention allows the cybersecurity management system to translate complex and highly technical cybersecurity issues into actionable intelligence that is easily understandable to managers and users. By doing so, the present invention ensures that effective cybersecurity management does not require extensive expertise, making cybersecurity decision-making more accessible and efficient.
[0122] Furthermore, in some embodiments, the File Analysis Module (101) may be configured to annotate first information asset files with asset traits derived from second information asset files when the two are determined to be “similar” or “related” based on factors such as nature, type, security level, or associated business unit.
[0123] For example, in a biomedical company that must comply with a specific medical standard for certain components of a biomedical apparatus, two information asset files may serve different purposes yet still reference one or more components covered under the standard. In this case, the system considers these files “similar” or “related” for compliance purposes.
[0124] This feature ensures that even if a first information asset file was not initially designated as relevant to compliance or regulatory requirements, it may still be flagged for compliance considerations if a second information asset file has been specifically marked as relevant. When this occurs, the first information asset file is automatically identified as potentially relevant and alerted to the manager for review, ensuring that compliance oversight is not overlooked.
[0125] This feature further highlights the advantages of the information asset filecentric approach in analysing and managing cybersecurity events. By leveraging asset trait similarities, this approach enhances the discovery of potential cybersecurity risks and compliance implications, even without requiring detailed manual annotations for every cybersecurity event or information asset file. Furthermore, as described above, the present invention also incorporates various features, including the Mitigation Result Assessment Module, which tracks the progress and effectiveness of mitigation implementations / actions (e.g., reported in the dashboard as the “Tracking of Mitigation Measures / Actions chart”). This functionality helps overcome the limitations of automatically suggested mitigation actions by ensuring that cybersecurity threats are effectively addressed, mitigation strategies are continuously refined based on their actual impact, and external cybersecurity specialists are engaged only when necessary for the most critical issues.
[0126] EMBODIMENTS
[0127] According to some embodiments of the present invention, as illustrated in FIG.8a - 8d, the Cybersecurity Analysis Module (103) is configured to comprise a Proactive Module (801), a Reactive Module (802), a Compliance Module (803), a Core Processing Engine (804), and a Data Analytics and Intelligence Module (805). Additionally, the Cybersecurity Analysis Module (103) includes an Application Programming Interface (API) Gateway (806), which facilitates the reception and integration of inputs into the module. The Proactive Module (801), Reactive Module (802), and Compliance Module (803) are configured to be in data communication with one another. The outputs generated by these modules are then processed by the Core Processing Engine (804), which serves as the foundation for data analytics and cybersecurity intelligence generation in the dataanalytics and intelligence module (805). The resulting intelligence is represented through various dashboard charts (807), as previously described, to support effective cybersecurity management and decision-making.
[0128] As illustrated in FIG. 8b, in this specific embodiment, the Proactive Module (801) is configured to receive data from the File Analysis Module (101) and the Event Detection Module (102), allowing it to organize information asset files associated with cybersecurity events.
[0129] For example, the Proactive Module (801) may further comprise: (i) an Asset Inventory Module (AIM), responsible for organizing and maintaining an inventory of information asset files; (ii) a Vulnerability Analysis Module (VAM), which analyzes information asset files to identify potential cybersecurity vulnerabilities; (iii) a Ticketing Management Module (TMM), which manages mitigation tickets assigned to address information asset files affected by cybersecurity events; (iv) a Business and Risk Module (BRM), which classifies and categorizes information asset files based on their asset traits, allowing for business impact and risk assessments.
[0130] As illustrated in FIG. 8c, in this specific embodiment, the reactive module (802) is configured to receive data from the file analysis module (101) and the event detection module (102), and operable to organize the cybersecurity events. For example, the Reactive Module (802) may further comprise: (i) an Alarm Management Module (AMM), which is configured to generate and manage alarms for detected cybersecurity events; and (ii) an Alarm Correlation Module (ACM), which correlates cybersecurity event alarms with specific information asset files, ensuring that security alerts are properly associated with the relevant assets.
[0131] As illustrated in FIG. 8d, in this specific embodiment, the Compliance Module (803) is configured to receive input data from the Proactive Module (801), which has analyzed information asset files in relation to cybersecurity events to identify vulnerable assets, business risks, and cybersecurity threats. Based on this data, the Compliance Module (803) comprises: (i) a Framework and Controls Management Module, which is configured for storing, managing, and aligning compliance and regulatory requirements relevant to a particular business entity; and (ii) a Gap and Risk Management Module, which is configured to analyze cybersecurity intelligence associated with information asset files and evaluates their compliance against established frameworks and regulatory standards. This Gap and Risk Management module is operable to identify gaps and risks in regulatory compliance that may arise due to compromised information asset files or those exposed to cybersecurity threats.
[0132] As illustrated in FIG. 8b - 8d, with input data from the Proactive Module (801), the Reactive Module (802), and the Compliance Module (803), the Core Processing Engine (804) is configured to generate cybersecurity intelligence, including, for example, business risks and impacts, access rights associated with information asset files, and correlations between business risks, impacts, and cybersecurity events. The analysis results generated by the Core Processing Engine (804) are further processed by the Data Analytics and Intelligence Module (805) to generate dashboard charts (807), offering a clear and actionable visualization of cybersecurity intelligence. This facilitates efficient interpretation of cybersecurity insights, enabling informed decision-making and proactive cybersecurity threat management. In summary, by systematically organizing cybersecurity events based on their impact and risk at the level of information asset files,the present invention enables managers to logically and efficiently allocate cybersecurity resources, ensuring that threats are mitigated in a cost-effective and structured manner. While the invention is particularly beneficial for resource-limited SMEs, it is evident to a person skilled in the art that it can also be adopted by companies and corporations of various sizes. As a cost-effective and convenient cybersecurity management tool, the present invention offers equal value to large enterprises seeking an efficient way to manage cybersecurity risks and optimize their security operations.
[0133] In some embodiments, the cybersecurity management system is operable to utilize artificial intelligence (AI) to enhance cybersecurity intelligence, ensuring that risk assessments, classification models, and mitigation strategies continuously adapt to emerging cybersecurity threats.
[0134] For example, AI can be applied to analyze cybersecurity traits and asset traits, enabling the system to identify patterns, predict cybersecurity threats, and dynamically adjust risk classifications. In some embodiments, AI-driven risk assessment enhances prioritization by continuously refining cybersecurity intelligence to address evolving threats.
[0135] In some embodiments, the AI engine may support various functions, including: (i) Threat Detection, wherein AI algorithms can be applied to analyze historical cybersecurity incidents to detect emerging threats and attack patterns in real time; (ii) Classification Optimization, wherein AI can be applied to dynamically adjust asset classifications based on new security data, shifting business risks, and changing threat landscapes; (iii) Mitigation Adaptation, wherein AI can be applied to refine mitigation recommendations by learning from past cybersecurity events, ensuring that mitigation strategies evolve continuously for improved risk management. By leveraging AI, the cybersecurity management system of the present invention is operable to enable proactive threat detection, adaptive classification, and intelligent mitigation, ensuring continuous improvement in cybersecurity intelligence and risk response.
[0136] Overall, the cybersecurity management system of the present invention provides a comprehensive framework for cybersecurity intelligence generation, asset classification, risk assessment, and mitigation. By analyzing asset traits and cybersecurity traits, the system ensures that cybersecurity intelligence is business-aligned, actionable, and adaptive.
[0137] The integration of real-time cybersecurity event detection, multi-tiered classification models, automated mitigation actions, and AI-driven threat intelligence allows businesses to proactively address cybersecurity risks and enhance security resilience. The system is configured for seamless integration with existing security infrastructure, making it scalable and adaptable for businesses of all sizes, including SMEs.
[0138] The approach of the present invention also ensures that cybersecurity management is not only technical in nature but also aligned with business priorities, financial risk considerations, and regulatory requirements.
[0139] It should be further appreciated by the person skilled in the art that variations and combinations of features described above, not being alternatives or substitutes, may be combined to form yet further embodiments falling within the intended scope of the invention.
[0140] As would be understood by a person skilled in the art, each embodiment, may be used in combination with other embodiment or several embodiments.
Claims
1.ClaimsClaim 1. A cybersecurity management system, comprising:a file analysis module configured to analyse a plurality of information asset files, wherein the information asset files comprise both digital and non-digital forms of information;an event detection module configured to detect a cybersecurity event; and, a cybersecurity analysis module configured to generate cybersecurity intelligence for the cybersecurity event;wherein the file analysis module is operable to analyse each information asset file and assign a plurality of asset traits;wherein the event detection module is operable to analyse each cybersecurity event to identify a plurality of cybersecurity traits associated with the cybersecurity event and one or more relevant information asset files affected by the cybersecurity event; wherein each relevant information asset file is assigned the identified cybersecurity traits;wherein the cybersecurity analysis module is operable to retrieve the plurality of asset traits and the plurality of cybersecurity traits associated with each relevant information asset file, and to generate the cybersecurity intelligence based on both the plurality of asset traits and the plurality of cybersecurity traits.Claim 2. The cybersecurity management system according to claim 1, wherein the plurality of asset traits comprise an asset identifier and an asset value indicator.Claim 3. The cybersecurity management system according to claim 1 or 2, wherein the plurality of asset traits further comprise an asset type indicator.Claim 4. The cybersecurity management system according to any one of the preceding claims, wherein the plurality of asset traits further comprise an asset risk level indicator and an asset risk type indicator.Claim 5. The cybersecurity management system according to claim 4, wherein the asset risk type indicator comprises one or more selected from the group consisting of a legal risk indicator, a regulatory / compliance risk indicator, a business risk indicator, a technological risk indicator, and a financial risk indicator.Claim 6. The cybersecurity management system according to any one of the preceding claims, wherein the plurality of asset traits further comprise corporate traits associated with each relevant information asset file..Claim 7. The cybersecurity management system according to claim 6, wherein the corporate traits comprise information related to a business entity that directly owns, indirectly owns, or partially owns each relevant information asset file.Claim 8. The cybersecurity management system according to claim 7, wherein the cybersecurity analysis module is operable to obtain the plurality of asset traits and the plurality of cybersecurity traits associated with each relevant information asset file of a business entity of interest and to generate cybersecurity intelligence for the business entity of interest.Claim 9. The cybersecurity management system according to any one of the preceding claims, wherein the plurality of asset traits further comprise accessor traits associated with the each relevant information asset file.Claim 10. The cybersecurity management system according to claim 9, wherein the accessor traits comprise information related to user having access rights to the each relevant information asset file.Claim 11. The cybersecurity management system according to claim 9 or 10, wherein the cybersecurity analysis module is operable to obtain the plurality of asset traits and the plurality of cybersecurity traits associated with each relevant information asset file of an accessor of interest and to generate cybersecurity intelligence for the accessor of interest. Claim 12. The cybersecurity management system according to any one of the preceding claims, wherein the plurality of asset traits further comprise geographical traits associated with the each relevant information asset file.Claim 13. The cybersecurity management system according to any one of the preceding claims, wherein the geographical traits comprise information related to originating location of the cybersecurity event; wherein the originating location comprises network and / or sever location.Claim 14. The cybersecurity management system according to any one of the preceding claims, wherein the plurality of asset traits further comprises operation system traits associated with the each relevant information asset file.Claim 15. The cybersecurity management system according to any one of the preceding claims, wherein the plurality of cybersecurity traits comprise one or more selected from the group consisting of an event type indicator, an event damage indicator, an event risk level indicator, an event timestamp and event origin location.Claim 16. The cybersecurity management system according to any one of the preceding claims, wherein the plurality of cybersecurity traits further comprise actor information associated with the cybersecurity event.Claim 17. The cybersecurity management system according to any one of the preceding claims, wherein the plurality of cybersecurity traits further comprise mitigation information associated with the cybersecurity event.Claim 18. The cybersecurity management system according to claim 17, wherein the mitigation information comprises mitigation cost, mitigation implementation, and mitigation assignment.Claim 19. The cybersecurity management system according to any one of the preceding claims, further comprising a cybersecurity mitigation module configured to mitigate impact on the each relevant information asset file exerted by the cybersecurity event; wherein the cybersecurity mitigation module is operable to implement a mitigation action based on the cybersecurity intelligence generated using both the plurality of asset traits and the plurality of cybersecurity traits.Claim 20. The cybersecurity management system according to claim 19, wherein the cybersecurity mitigation module is configured to comprise a mitigation suggestion module operable to analyse cybersecurity intelligence and generate one or more mitigation suggestions based on the cybersecurity intelligence associated with each relevant information asset file.Claim 21. The cybersecurity management system according to claim 19 or 20, wherein the cybersecurity mitigation module is configured to comprise a mitigation implementation module operable to execute one or more selected mitigation actions based on the mitigation suggestions generated by the mitigation suggestion module.Claim 22. The cybersecurity management system according to any one of claims 19-21, wherein the cybersecurity mitigation module is configured to comprise a mitigation result assessment module operable to assess status of the each relevant information asset file after the one or more selected mitigation action has been executed on the each relevant information asset file.Claim 23. The cybersecurity management system according to any one of claims 19-22, further comprising a cybersecurity simulation module configured to simulate a cybersecurity event on one or more information asset files to test security and vulnerability of the plurality of information asset files.Claim 24. The cybersecurity management system according to any one of the preceding claims, wherein the cybersecurity analysis module is operable to retrieve the plurality of digital asset traits and the plurality of cybersecurity traits for the one or more relevant information asset files; the cybersecurity analysis module is operable to classify the one or more relevant information asset files according to a first classification criteria.Claim 25. The cybersecurity management system according to claim 24, wherein the first classification criteria comprises a hierarchical order of business impact based on the asset value indicators.Claim 26. The cybersecurity management system according to claim 24 or 25, wherein the first classification criteria comprises a hierarchical order of business risk based on the asset level risk indicators.Claim 27. The cybersecurity management system according to any one of claims 24 - 26, wherein the cybersecurity analysis module is operable to classify the one or more relevant information asset files according to a second classification criteria.Claim 28. The cybersecurity management system according to claim 27, wherein the second classification criteria comprises one or more business entities of interests.Claim 29. The cybersecurity management system according to claim 27 or 28, wherein the second classification criteria comprises one or more accessor of interests.Claim 30. The cybersecurity management system according to any one of claims 27 - 29, wherein the second classification criteria comprise one or more compliance requirements.Claim 31. The cybersecurity management system according to any one of the preceding claims, wherein the file analysis module is configured to assign one or more asset traits from a second information asset file to a first information asset file.Claim 32. The cybersecurity management system according to any one of the preceding claims, wherein the cybersecurity intelligence is generated using an artificial intelligence-based approach.Claim 33. The cybersecurity management system according to claim 32, wherein the artificial intelligence-based approach comprises using an artificial intelligence model.