Cyber Risk Score for OT Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and integration of Operational Technology (OT) systems in Smart Buildings make them highly vulnerable to cyber-attacks, posing significant risks to cybersecurity, regulatory compliance, and brand reputation.

Innovation Solution

A method and system for determining a cyber risk score for entities with multiple network devices, involving data collection from individual devices and external risk data sources, normalization, correlation, and aggregation to assess individual and overall cyber risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If OT systems are integrated with IT ecosystems for economic and practical reasons, then system functionality and connectivity are improved, but cybersecurity vulnerability and system complexity increase

Engineering Contradiction:
Improvesystem connectivityVSAvoidcybersecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the cybersecurity assessment into device-level and system-level evaluations. Individual OT devices are assessed separately for their security health status, then aggregated to determine overall system risk. This segmentation allows targeted security measures without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cybersecurity assessment system as an intermediary layer between OT devices and IT ecosystems. This intermediary evaluates security risks, collects device data, and provides compensation controls, acting as a buffer that enables integration while managing vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Duration of action of stationary object

If legacy OT devices are retained without retrofitting, then device availability and operational continuity are maintained, but security risk and compliance vulnerability increase

Engineering Contradiction:
Improvedevice availabilityVSAvoidsecurity risk
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent applies beforehand cushioning by implementing compensation controls and security assessments before legacy devices become critical vulnerabilities. The system continuously evaluates security health and prepares mitigation strategies in advance, cushioning against potential security incidents without requiring immediate device replacement.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Measurement precision

If comprehensive security assessment of all OT devices is performed, then cybersecurity risk identification is improved, but management complexity and resource requirements increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidmanagement complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by tailoring security assessment depth to individual device characteristics and risk profiles. Not all devices receive identical assessment intensity; instead, resources are allocated based on device criticality, vulnerability level, and security health status, optimizing assessment precision while managing complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes parameters by dynamically adjusting assessment frequency, depth, and scope based on device security health status. Devices with deteriorating security health receive more intensive assessment, while stable devices receive routine monitoring. This parameter adaptation maintains assessment accuracy while reducing overall management burden.

Inventive Principle:
Principle #35Parameter changes

4Productivity

If OT devices are tightly integrated with IT ecosystems, then operational efficiency and functionality are improved, but cascading threat propagation and system vulnerability increase

Engineering Contradiction:
Improveoperational efficiencyVSAvoidcascading threats
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback mechanisms that continuously monitor device security health and system-wide risk levels. When security degradation is detected in individual devices, the system provides feedback to increase assessment intensity and activate compensation controls, preventing local vulnerabilities from propagating as cascading threats while maintaining operational efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12328333B2System and method for managing the security health of a network device
Publication Date: 2025.06.10 TYCO FIRE & SECURITY GMBH
  • US12328333B2 patent drawing
  • US12328333B2 patent drawing
  • US12328333B2 patent drawing

AI summary

A method for determining and using a security risk score for devices includes searching a network to automatically identify devices associated with potential security risks, collecting a first set of data from the devices including at least one of a device configuration, an IP address, a MAC address, or data related to software operated on the devices, collecting a second set of data from an external data source including risk data, comparing the second set of data to the first set of data to evaluate a potential security risk and determine a risk score for the devices, and using the risk score to perform an automated action including at least one of (i) providing an alert to a user identifying the potential security risk, (ii) generating a dashboard identifying the potential security risk, or (iii) initiating a corrective action responsive to the potential security risk based on the risk score.