Cyber Attack Preparedness Assessment Platform for Control Maturity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Larger organizations face difficulties in accurately assessing their cyber preparedness and potential financial impact from cyber attacks due to the complexity of their networks and the ever-evolving nature of cyber threats, making it challenging to implement effective controls and measure their effectiveness.

Innovation Solution

A system and method that models cyber attack preparedness and financial losses by analyzing threat landscapes, cyber maturity status, and information assets, using a platform to assess control maturity, threat activity levels, and predict potential financial impacts through a comprehensive assessment platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive control measures are implemented to protect against cyber attacks, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvecyber security preparednessVSAvoidnetwork control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the cyber security assessment into multiple independent components: control inventory identification, control rating assessment, threat actor identification, and risk calculation. Each component processes specific data independently and contributes to the overall assessment, making the complex security evaluation manageable and scalable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary assessment platform that mediates between the complex network controls and the decision-makers. This platform aggregates control data, applies rating algorithms, and presents simplified risk assessments, acting as a buffer that translates complex security configurations into actionable insights.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If detailed assessments of all network controls are performed, then measurement precision is improved, but loss of time increases

Engineering Contradiction:
Improvecyber preparedness assessment accuracyVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining an ongoing inventory of network controls and their ratings. Rather than conducting complete assessments from scratch, the system continuously updates control data as changes occur, so that when a threat actor is identified, the assessment can be completed quickly using pre-collected information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service mechanisms where the control inventory automatically updates itself as network controls are added, modified, or removed. The system autonomously tracks control changes and maintains current ratings without requiring manual re-assessment, enabling rapid response to new threats using up-to-date information.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If continuous monitoring of threat landscapes is implemented, then adaptability is improved, but use of energy increases

Engineering Contradiction:
Improveresponse to evolving cyber threatsVSAvoidcomputational resource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system employs periodic action by scheduling regular updates of the control inventory and threat assessments rather than continuous monitoring. The system periodically refreshes its understanding of the threat landscape and recalculates risks based on current controls, balancing adaptability with resource conservation through interval-based updates.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20250274472A1Systems and Methods for Use in Assessments in Connection with Cyber Attacks
Publication Date: 2025.08.28 MASTERCARD INT INC
  • US20250274472A1 patent drawing
  • US20250274472A1 patent drawing
  • US20250274472A1 patent drawing

AI summary

Systems and methods are provided for assessing cyber attack preparedness associated with organizations. One example computer-implemented method includes accessing data indicative of multiple controls of an organization, where the organization includes an information network, which includes the controls and where the controls are associated with securing one or more information assets. The data is indicative of the controls including multiple indicators. The method also includes aggregating one or more ratings for at least one of the indicators to a criteria, aggregating the aggregate rating for the criteria to a category, and aggregating the aggregate rating for the category to one of the controls as a control maturity score for said one of the controls. The method then includes displaying the control maturity score for said one of the controls to a first user associated with the organization.