Data Security Evaluation System for M&A Due Diligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for evaluating data security during mergers and acquisitions rely heavily on self-reporting and publicly available data, which fail to identify undisclosed or undiscovered data breaches in target systems, leading to potential risks for acquiring parties.

Innovation Solution

A data security evaluation computing device that queries multiple data sources, including fraud report databases, web resource reviews, illicit threat assessments, and compliance reviews, to generate a comprehensive data security score and report, highlighting vulnerabilities and recommendations for the target system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If self-reporting and publicly available data are used for security review, then the review process is simple and fast, but the detection precision of data breaches is insufficient

Engineering Contradiction:
Improvedetection precision of data breachesVSAvoidcomplexity of review system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent combines multiple data sources including fraud report databases, web resource review systems, illicit threat assessment systems, and compliance review systems into a unified data security evaluation system. This merging of previously separate review mechanisms enables comprehensive detection of data breaches while maintaining systematic coordination among different data sources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The evaluation system is designed to perform multiple functions simultaneously: querying fraud reports, conducting web resource reviews, assessing illicit threats, and evaluating compliance. This multi-functional approach allows a single system to address various aspects of data security evaluation, improving detection precision without requiring separate specialized systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If multiple data sources are queried to evaluate data security, then the detection precision improves, but the complexity of the evaluation system increases

Engineering Contradiction:
Improveaccuracy of data security evaluationVSAvoidnumber of data sources and processing components
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the evaluation system into distinct functional modules: a fraud report database for historical breach data, a web resource review system for current security assessment, an illicit threat assessment system for emerging threats, and a compliance review system for regulatory adherence. Each module independently queries its designated data source and contributes specific findings to the overall evaluation, making the complex system manageable and maintainable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a central data security score generation mechanism that acts as an intermediary between multiple data sources and the final evaluation report. This intermediary component receives data from various sources, processes and standardizes the information, generates a comprehensive security score, and produces unified recommendations. This mediator simplifies the complexity by providing a single point of integration rather than requiring direct coordination among all data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive data aggregation from multiple sources is performed, then the reliability of security assessment improves, but the time required for evaluation increases

Engineering Contradiction:
Improvereliability of security assessmentVSAvoidtime required for due diligence review
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing connections to multiple data sources and maintaining ready-access caches of security data. The system proactively queries fraud report databases, web resource reviews, illicit threat assessments, and compliance reviews in parallel rather than sequentially, and pre-processes this data into standardized formats. This preliminary preparation significantly reduces the time required during actual due diligence while maintaining comprehensive data aggregation for reliable assessment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11468385B2Systems and methods for evaluating data security of a target system
Publication Date: 2022.10.11 MASTERCARD INT INC
  • US11468385B2 patent drawing
  • US11468385B2 patent drawing
  • US11468385B2 patent drawing

AI summary

A data security evaluation computing device for evaluating data security of a target system is coupled to a plurality of data sources including the target system, and receives a request message requesting data security review, the request message including an identifier of the target system. The computing device queries a first data source to receive data representing whether the target system has previously breached, and locally caches the data. The computing device queries a second data source to receive data associated with a potential for a future data breach, and locally caches the data. The computing device also generates a data security score by analyzing the locally cached data, the data security score representing a likelihood the target system was or will be the subject of a data breach, compiles the data security score and additional data into a data security report, and transmits a response message including the report.