Diversity Analysis for Cyber Risk Clustering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively determine and mitigate cyber security risk diversity among entities, leading to increased risk due to similarity in attributes, which can result in cascading losses during cyber events.
Innovation Solution
A method and system that analyze sets of variables indicative of entity attributes, compare them to identify clusters of similar variables, calculate probable maximum loss, and provide actionable feedback to end users to decrease this risk by diversifying attributes and infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If entities share similar attributes and infrastructure, then operational efficiency and cost-effectiveness are improved, but cyber security risk and potential losses increase due to correlated vulnerabilities
Solution Approach 1:
The system segments entities into clusters based on shared attributes and infrastructure characteristics. By identifying groups of entities with similar vulnerabilities (e.g., same cloud provider, CDN, or technology stack), the system enables targeted risk management strategies for each segment while maintaining cost-effective operations within segments.
Solution Approach 2:
The system changes the parameter of risk assessment by calculating probable maximum loss (PML) values that reflect correlated cyber risk across entities with shared attributes. This transforms traditional independent risk assessment into a correlated risk model that accounts for shared vulnerabilities, enabling better-informed decisions about maintaining vs. diversifying entity attributes.
2Object-affected harmful factors
If entities diversify their attributes and infrastructure, then cyber security risk is reduced, but operational efficiency and cost-effectiveness may decrease
Solution Approach 1:
The system provides actionable feedback to entities by calculating their PML values and identifying specific shared attributes that contribute to correlated risk. This feedback loop enables entities to make informed decisions about which shared attributes to maintain (for operational efficiency) and which to diversify (for risk reduction), optimizing the balance between efficiency and security.
Solution Approach 2:
The system performs preliminary risk assessment by calculating probable maximum loss values before cyber events occur. By identifying vulnerable clusters and shared attributes in advance, entities can proactively make strategic decisions about diversification versus consolidation, rather than reacting to losses after events occur.
3Device complexity
If traditional independent risk assessment methods are used, then simplicity and ease of calculation are maintained, but accuracy in assessing aggregate cyber risk is reduced
Solution Approach 1:
The system merges traditional independent risk assessment with correlation analysis by combining entity-specific vulnerability data with shared attribute information. This integration creates a comprehensive PML calculation that accounts for both individual entity risks and correlated risks across entities with shared infrastructure, providing more accurate aggregate risk assessment.
Data Source
AI summary
Various embodiments of the present technology relate to diversity and similarity analysis. In some exemplary embodiments, a method includes, for each of a plurality of entities, receiving a set of variables that are indicative of attributes of an entity. The exemplary method also includes comparing the sets of variables for the plurality of entities to each other, locating clusters of similar variables shared between two or more of the plurality of entities, determining a probable maximum loss for the plurality of entities that share the clusters, the probable maximum loss being a loss value attributed to a cyber event against one or more of the shared variables, receiving feedback from an end user in response to providing the probable maximum loss to the end user, and updating the probable maximum loss in response to the feedback.


