Cybersecurity Risk Manager Aligning Scores to Organizational Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial process control and automation systems face challenges in managing cyber-security risks due to unaddressed vulnerabilities, with operators lacking a complete understanding of equipment and difficulty in quickly determining potential sources of risk, and existing risk quantification lacking alignment with organizational risk policies and methodologies.

Innovation Solution

A risk manager system that ties cyber-security risk analysis to common risk methodologies and levels by using threshold values such as risk appetite and risk tolerance to classify and prioritize vulnerabilities, generating notifications based on these classifications to guide users in mitigating risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If risk quantification is performed without alignment to organizational risk policies, then risk analysis can be conducted, but the results lack practical utility and cannot guide effective risk management decisions

Engineering Contradiction:
Improvealignment with organizational risk policiesVSAvoidrisk classification system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms abstract risk scores into actionable classifications by changing the parameter representation from continuous numerical values to discrete risk levels (low, medium, high). This is achieved by comparing risk scores against threshold values derived from organizational risk appetite and tolerance parameters, making the results directly applicable to risk management decisions while maintaining alignment with organizational policies.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the continuous risk spectrum into distinct risk levels by dividing the risk score range using threshold values. This segmentation creates discrete categories (below risk appetite, between appetite and tolerance, above tolerance) that are easier to interpret and act upon, while the thresholds themselves are configured based on organizational risk policies to ensure alignment.

Inventive Principle:
Principle #1Segmentation

2Productivity

If all cyber-security risks are treated equally, then comprehensive coverage is achieved, but operators cannot prioritize actions and response time increases

Engineering Contradiction:
Improverisk mitigation efficiencyVSAvoidtime to identify and address critical risks
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent applies local quality by treating different risk levels differently based on their severity and impact. Instead of uniform handling, risks are classified into distinct categories (low, medium, high) with different response priorities. Critical risks exceeding risk tolerance are flagged for immediate attention, while lower risks can be addressed during routine maintenance, optimizing resource allocation and response timing.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback by comparing calculated risk scores against organizational thresholds (risk appetite and tolerance) to generate actionable classifications. This feedback mechanism automatically prioritizes risks that exceed thresholds, providing operators with immediate guidance on which vulnerabilities require urgent attention versus those that can be addressed later, thereby improving mitigation efficiency without increasing analysis time.

Inventive Principle:
Principle #23Feedback

3Loss of information

If detailed risk analysis is performed on all devices, then complete risk understanding is achieved, but the complexity of managing and interpreting the data increases significantly

Engineering Contradiction:
Improvecompleteness of risk informationVSAvoidrisk management system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts only the most relevant risk information by comparing comprehensive risk scores against organizational thresholds and extracting only those risks that exceed risk appetite or tolerance. This extraction process filters out low-priority risks, presenting operators with a focused set of actionable findings rather than overwhelming them with complete device-level details, thus reducing management complexity while maintaining essential risk coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter representation from detailed continuous risk scores to simplified discrete classifications based on organizational thresholds. By transforming the data into risk levels (below appetite, between appetite and tolerance, above tolerance), the system maintains complete risk information internally while presenting simplified, policy-aligned results to operators, reducing interpretation complexity without losing essential risk details.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10298608B2Apparatus and method for tying cyber-security risk analysis to common risk methodologies and risk levels
Publication Date: 2019.05.21 HONEYWELL INTERNATIONAL INC
  • US10298608B2 patent drawing
  • US10298608B2 patent drawing
  • US10298608B2 patent drawing

AI summary

This disclosure provides systems and methods for tying cyber-security risk analysis to common risk methodologies and risk levels. A method includes identifying a plurality of connected devices that are vulnerable to cyber-security risks and identifying cyber-security risks in the connected devices. The method includes assigning a risk level to each of the risks and comparing the risk levels to a first threshold and to a second threshold. The method includes assigning each identified cyber-security risk to a risk classification and displaying a user interface that includes a notification according to the identified cyber-security risks and the corresponding assigned risk classifications.