Cybersecurity Risk Assessment With Threat Profiles and Network Crawling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity standards and survey tools lack a holistic understanding of cyber exposures across different business units within organizations, failing to link risks to specific threats, identify areas of weakness, and provide actionable improvement recommendations, thereby hindering risk financing and insurance coverage.

Innovation Solution

A cybersecurity risk assessment system that analyzes an organization's technology infrastructure and software system utilization to identify vulnerabilities by collecting information through surveys and network crawling, identifying threat profiles, and evaluating cybersecurity controls to generate a risk profile report.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing cybersecurity standards and survey tools are used, then basic security assessment is provided, but holistic understanding of cyber exposures across different business units is lacking

Engineering Contradiction:
Improvecomprehensive understanding of cyber exposuresVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the cybersecurity assessment into multiple specialized modules: technology infrastructure assessment, information technology infrastructure assessment, threat profile identification, and cybersecurity control evaluation. Each module focuses on specific aspects of cyber risk, allowing comprehensive coverage while maintaining manageable complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The assessment system is designed to be universally applicable across different business units and organizational structures. It evaluates both technology infrastructure and information technology infrastructure using common frameworks and standards, enabling consistent risk assessment methodology throughout the organization while adapting to specific unit requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive risk assessment is implemented, then actionable recommendations are provided, but linking risks to specific threats requires extensive data collection

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiddata collection volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system performs preliminary data collection through structured surveys and automated network crawling before the actual risk assessment. This preliminary action gathers essential information about technology infrastructure, software systems, and security controls, reducing the data collection burden during the main assessment phase and improving overall efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediate assessment layers that process raw data into structured risk indicators. Survey results and network crawl data are processed through standardized evaluation frameworks that translate extensive raw data into actionable risk profiles, reducing the complexity of linking risks to specific threats while maintaining assessment accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If detailed vulnerability identification is performed, then specific areas of weakness are identified, but the assessment process becomes more time-consuming

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system employs automated network crawling and self-assessment surveys that allow the organization's own infrastructure and personnel to provide assessment data without requiring extensive external auditor involvement. This self-service approach accelerates data collection while maintaining detailed vulnerability identification through automated analysis tools.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual assessment procedures with automated computational methods. Network crawling tools automatically discover and evaluate infrastructure components, while software algorithms analyze survey responses and control evaluations to identify vulnerabilities, significantly reducing assessment time while maintaining or improving identification accuracy compared to manual methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250298903A1Systems and methods for cybersecurity risk assessment
Publication Date: 2025.09.25 AON GLOBAL OPERATIONS LTD (SINGAPORE BRANCH)
  • US20250298903A1 patent drawing
  • US20250298903A1 patent drawing
  • US20250298903A1 patent drawing

AI summary

In an illustrative embodiment, methods and systems for cybersecurity assessment of an organization's technology infrastructure include identifying features of the technology infrastructure and automatically generating a threat profile relevant to both the technology infrastructure and the organization's business (and/or business objectives), where the threat profile includes potential threat actors and threat scenarios applicable to the technology infrastructure. The methods and systems may include evaluating cybersecurity controls of the organization's technology infrastructure in light of the threat profile to identify and rate vulnerabilities within the technology infrastructure.