Cybersecurity Risk Management for Computing Assets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems fail to effectively identify and manage cybersecurity risks for computing assets, such as medical devices and nuclear facilities, leading to potential hacking and sabotage, as users lack awareness of at-risk assets and appropriate protective measures.

Innovation Solution

A method and system for facilitating cybersecurity risk management, which involves receiving asset information from computing assets, retrieving secondary information from a third-party database, analyzing data based on predetermined criteria, determining risk profiles, generating risk notifications, and transmitting these notifications to user devices, utilizing a communication device, processing device, and storage device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users implement cybersecurity systems to prevent hacking, then security protection is improved, but users cannot identify what assets are at risk and what steps to take for proper protection

Engineering Contradiction:
Improvesecurity protectionVSAvoidasset identification and protection guidance
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system continuously monitors computing assets and provides feedback to users about security risks, vulnerabilities, and recommended protective measures. This closed-loop feedback mechanism enables users to understand their asset risk status and take appropriate actions, resolving the information gap while maintaining security protection

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system acts as an intermediary between cybersecurity threats and users, analyzing risks and translating complex security information into actionable insights. This intermediary function bridges the gap between security systems and end-users, making protection both effective and easy to operate

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If continuous monitoring and risk assessment of computing assets is implemented, then actionable insights for protection are provided, but system complexity increases

Engineering Contradiction:
Improvecybersecurity risk informationVSAvoidmonitoring and assessment system
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system performs multiple functions including asset discovery, vulnerability assessment, risk analysis, and recommendation generation within a single integrated platform. This multi-functionality reduces the need for separate tools and minimizes overall system complexity while comprehensively addressing cybersecurity risk information needs

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20220083652A1Systems and methods for facilitating cybersecurity risk management of computing assets
Publication Date: 2022.03.17 VIRTA LABORATIES INC
  • US20220083652A1 patent drawing
  • US20220083652A1 patent drawing
  • US20220083652A1 patent drawing

AI summary

Disclosed herein is a method for facilitating cybersecurity risk management of computing assets, in accordance with some embodiments. Accordingly, the method may include a step of receiving, using a communication device, asset information from a computing asset. Further, the method may include a step of retrieving, using a storage device, secondary asset information from a third-party database. Further, the method may include a step of analyzing, using a processing device, the asset information and the secondary asset information based on at least one predetermined criterion. Further, the method may include a step of determining, using the processing device, a risk profile corresponding to each predetermined criterion based on the analyzing Further, the method may include a step of generating, using the processing device, a risk notification based on the determining. Further, the method may include a step of transmitting, using the communication device, the risk notification to a user device.