Loss Calculation System for Data Breach Risk Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods lack a comprehensive and accurate approach to estimating losses from data privacy and security breach events, leading to inconsistent and inefficient risk management communication and collaboration within organizations.

Innovation Solution

A system and method for calculating loss data associated with data privacy and security breach events, using inputs such as affected individuals, time spent managing the event, credit monitoring services, productivity loss, and legal counsel costs, to provide a comprehensive set of line items and consistent data collection, facilitating effective risk management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current methods are used to estimate losses from data privacy and security breach events, then the process is simple, but the accuracy and consistency of loss estimation is poor

Engineering Contradiction:
Improveloss estimation accuracyVSAvoidcalculation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the loss estimation process into multiple distinct components including direct costs (notification costs, credit monitoring services, legal counsel), indirect costs (productivity loss, asset loss), and third-party costs (computer forensics, call center activities). Each component is calculated separately using specific formulas and then aggregated to produce the total loss amount, improving measurement precision through systematic breakdown of complex loss estimation into manageable segments.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If comprehensive data collection is implemented for loss estimation, then the completeness of risk management data is improved, but the time and resources required for data collection increase

Engineering Contradiction:
Improverisk management data completenessVSAvoiddata collection time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent establishes predefined calculation formulas and data collection templates before breach events occur. The system pre-configures the types of data needed for each cost component (e.g., number of affected individuals, enrollment rates for credit monitoring, productivity metrics) and the methods for calculating each component. This preliminary preparation enables rapid data collection and processing when a breach event actually occurs, reducing the time and resources required while maintaining comprehensive data collection.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If multiple cost components are calculated separately, then the accuracy of individual loss categories is improved, but the overall calculation process becomes more complex

Engineering Contradiction:
Improveindividual cost category accuracyVSAvoidcalculation process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple separate cost component calculations into a unified loss estimation system. Individual cost categories (direct costs, indirect costs, third-party costs) are calculated separately using specific formulas, then aggregated through a centralized calculation process that produces both detailed breakdowns and a total loss amount. This merging approach maintains the precision of individual category calculations while providing an integrated view of total losses, managing complexity through systematic aggregation rather than isolated calculations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11361267B1System and method for determining loss resulting from data privacy and security breach
Publication Date: 2022.06.14 NATIONWIDE MUTUAL INSURANCE CO
  • US11361267B1 patent drawing
  • US11361267B1 patent drawing
  • US11361267B1 patent drawing

AI summary

A system and method for calculating loss data associated with a data privacy and security breach event occurring within an organization based on collected data. Data describing a number of individuals affected by the event; an estimated number of hours spent by the organization on managing the event; enrollment by individuals affected by the event in a credit monitoring service; an estimated amount spent on communications within the organization relating to the event; an estimated number of hours of loss of productivity by the organization; an estimated credit monitoring service call center volume; an estimated amount spent on computer forensics; and an estimated amount spent on legal counsel is received. Data describing (i) an amount spent by the organization in managing the event; (ii) an amount spent by the organization in notifying individuals affected by the event; (iii) an amount spent by the organization on the credit monitoring service; (iv) an amount spent on loss of productivity; (v) an amount spent on loss of assets; and (vi) an amount spent on credit monitoring service call center activities is calculated. Data describing a total loss amount associated with the event is calculated based on the received data received and the calculations.