Enterprise Cyber Resource Planning System for Risk Quantification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face increased vulnerability to cyber threats due to lack of effective security infrastructure, inadequate threat management, and inability to quantify exposure, leading to potential data breaches and non-compliance with regulations.

Innovation Solution

An Enterprise Cyber Resource Planning (ECRP) system that collects and processes data from multiple sources to quantify cyber threat exposure and compliance, providing a graphical user interface for authorized personnel to view risk levels and generate optimized security work plans, resource allocation, and compliance reports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprises implement comprehensive security infrastructure to manage cyber threats, then security coverage and threat detection capability are improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the enterprise security infrastructure into multiple hierarchical levels including network perimeter security, endpoint security, application security, and data security. Each level operates semi-independently with specialized security controls, allowing comprehensive coverage while managing complexity through modular organization. Security policies and threat responses are segmented by asset criticality and threat type.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security information and event management (SIEM) systems, centralized policy management platforms, and automated orchestration tools as intermediaries between various security components. These intermediary systems aggregate data from multiple sources, standardize security events, and coordinate responses across different security layers, reducing the operational complexity of managing comprehensive security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If enterprises deploy advanced threat detection and response systems, then threat detection precision is improved, but resource requirements and operational costs increase

Engineering Contradiction:
Improvethreat detection precisionVSAvoidresource requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent implements threat detection resources strategically based on local quality principles, concentrating advanced detection capabilities such as behavioral analysis and machine learning models on high-value assets and critical infrastructure. Lower-risk assets receive standardized detection coverage. This selective deployment of detection precision resources optimizes the balance between detection capability and resource consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent employs partial action by implementing layered detection where not all assets receive the full spectrum of detection methods simultaneously. Instead, detection depth is adjusted based on asset criticality, with excessive detection resources applied only where necessary to achieve acceptable security posture, thereby reducing overall resource requirements while maintaining adequate detection precision for critical assets.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If enterprises conduct frequent security assessments and risk quantification, then risk measurement accuracy is improved, but time consumption and operational disruption increase

Engineering Contradiction:
Improverisk measurement accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements periodic security assessments at multiple frequencies tailored to different asset types and risk profiles. Critical assets undergo continuous or near-continuous monitoring and frequent assessments, while lower-risk assets receive periodic assessments at longer intervals. This differentiated periodic action maintains risk measurement accuracy for critical assets while reducing overall time consumption and operational disruption.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent performs preliminary risk assessments and vulnerability scans continuously in the background before formal security evaluations. This preliminary action pre-identifies and categorizes potential risks, so that when formal assessments are conducted, the time required is reduced because much of the data collection and initial analysis has already been completed. This approach maintains measurement accuracy while minimizing disruption to operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11936676B2Enterprise cyber security risk management and resource planning
Publication Date: 2024.03.19 CISOTERIA LTD
  • US11936676B2 patent drawing
  • US11936676B2 patent drawing
  • US11936676B2 patent drawing

AI summary

A system includes a memory to store network-related security policies and procedures associated with an enterprise, a display and at least one device. The device is configured to monitor enterprise activity associated the enterprise's networked and determine, based on the enterprise activity, whether the enterprise is complying with the security policies and procedures. The device is also configured to calculate a risk exposure metric for an asset of the enterprise based on the enterprise activity and whether the enterprise is complying with the security policies and procedures, and output, to the display, a graphical user interface (GUI) identifying the risk exposure metric. The device may also be configured to receive, via the GUI, an input to initiate a change with respect to at least one of the enterprise's networked devices or initiate the generation of a plan to make a change to at least one of the networked devices.