Cybersecurity Risk Manager Aligning Scores to Organizational Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial process control and automation systems face challenges in managing cyber-security risks due to unaddressed vulnerabilities, with operators lacking a complete understanding of equipment and difficulty in quickly determining potential sources of risk, and existing risk quantification lacking alignment with organizational risk policies and methodologies.
Innovation Solution
A risk manager system that ties cyber-security risk analysis to common risk methodologies and levels by using threshold values such as risk appetite and risk tolerance to classify and prioritize vulnerabilities, generating notifications based on these classifications to guide users in mitigating risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If risk quantification is performed without alignment to organizational risk policies, then risk analysis can be conducted, but the results lack practical utility and cannot guide effective risk management decisions
Solution Approach 1:
The patent transforms abstract risk scores into actionable classifications by changing the parameter representation from continuous numerical values to discrete risk levels (low, medium, high). This is achieved by comparing risk scores against threshold values derived from organizational risk appetite and tolerance parameters, making the results directly applicable to risk management decisions while maintaining alignment with organizational policies.
Solution Approach 2:
The patent segments the continuous risk spectrum into distinct risk levels by dividing the risk score range using threshold values. This segmentation creates discrete categories (below risk appetite, between appetite and tolerance, above tolerance) that are easier to interpret and act upon, while the thresholds themselves are configured based on organizational risk policies to ensure alignment.
2Productivity
If all cyber-security risks are treated equally, then comprehensive coverage is achieved, but operators cannot prioritize actions and response time increases
Solution Approach 1:
The patent applies local quality by treating different risk levels differently based on their severity and impact. Instead of uniform handling, risks are classified into distinct categories (low, medium, high) with different response priorities. Critical risks exceeding risk tolerance are flagged for immediate attention, while lower risks can be addressed during routine maintenance, optimizing resource allocation and response timing.
Solution Approach 2:
The patent implements feedback by comparing calculated risk scores against organizational thresholds (risk appetite and tolerance) to generate actionable classifications. This feedback mechanism automatically prioritizes risks that exceed thresholds, providing operators with immediate guidance on which vulnerabilities require urgent attention versus those that can be addressed later, thereby improving mitigation efficiency without increasing analysis time.
3Loss of information
If detailed risk analysis is performed on all devices, then complete risk understanding is achieved, but the complexity of managing and interpreting the data increases significantly
Solution Approach 1:
The patent extracts only the most relevant risk information by comparing comprehensive risk scores against organizational thresholds and extracting only those risks that exceed risk appetite or tolerance. This extraction process filters out low-priority risks, presenting operators with a focused set of actionable findings rather than overwhelming them with complete device-level details, thus reducing management complexity while maintaining essential risk coverage.
Solution Approach 2:
The patent changes the parameter representation from detailed continuous risk scores to simplified discrete classifications based on organizational thresholds. By transforming the data into risk levels (below appetite, between appetite and tolerance, above tolerance), the system maintains complete risk information internally while presenting simplified, policy-aligned results to operators, reducing interpretation complexity without losing essential risk details.
Data Source
AI summary
This disclosure provides systems and methods for tying cyber-security risk analysis to common risk methodologies and risk levels. A method includes identifying a plurality of connected devices that are vulnerable to cyber-security risks and identifying cyber-security risks in the connected devices. The method includes assigning a risk level to each of the risks and comparing the risk levels to a first threshold and to a second threshold. The method includes assigning each identified cyber-security risk to a risk classification and displaying a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications.


