Personalized Phishing Risk Interfaces for Adaptive Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-phishing systems focus on blocking or quarantining phishing messages, failing to provide personalized risk assessment and proactive security measures based on individual susceptibility, leading to inefficient resource allocation and limited awareness training.

Innovation Solution

A system that generates personalized phishing exposure risk scores for individuals within an enterprise network, incorporating dynamic visual interfaces and adaptive security protocols based on individual metrics, including past interactions and organizational attributes, to proactively manage and communicate risk levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing anti-phishing software blocks or quarantines suspected phishing messages, then phishing message blocking is improved, but personalized risk assessment and proactive security measures are lacking

Engineering Contradiction:
Improvephishing message blockingVSAvoidpersonalized risk assessment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the enterprise network into individual user profiles, assessing phishing risk separately for each user based on their specific attributes, roles, and behaviors. This enables personalized risk assessment while maintaining organization-wide phishing blocking capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different security measures and risk assessments to different users based on their local characteristics such as job role, department, and historical behavior. High-risk users receive enhanced monitoring and targeted training while low-risk users receive standard protection.

Inventive Principle:
Principle #3Local quality

2Ease of manufacture

If security resources are allocated uniformly across all users, then implementation simplicity is improved, but resource allocation efficiency decreases

Engineering Contradiction:
Improveimplementation simplicityVSAvoidresource allocation efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The system dynamically changes security resource allocation parameters based on calculated risk scores. Users with higher phishing exposure risk receive more intensive security training, monitoring, and protective measures, while lower-risk users receive standard protection, optimizing resource distribution across the organization.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If generic security training is provided to all users, then training delivery simplicity is improved, but security awareness effectiveness decreases

Engineering Contradiction:
Improvetraining delivery simplicityVSAvoidsecurity awareness effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary risk assessment and analyzes user attributes before delivering security training. Based on this pre-analysis, users receive customized training content that addresses their specific risk factors and vulnerabilities, making training more effective while maintaining efficient delivery through automated personalization.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If personalized risk assessment is implemented for each user, then security awareness effectiveness is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity awareness effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically collects user attributes, analyzes phishing exposure risk, and generates personalized assessments without requiring manual intervention. The system self-configures security measures and training recommendations based on calculated risk scores, reducing operational complexity while maintaining personalized effectiveness.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260032142A1Personalized visual interfaces for quantifying and communicating personalized phishing exposure risk for increased security
Publication Date: 2026.01.29 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US20260032142A1 patent drawing
  • US20260032142A1 patent drawing
  • US20260032142A1 patent drawing

AI summary

System, method, and computer program product embodiments quantify and communicate phishing exposure risk to increase enterprise security. The phishing exposure risk management system may retrieve metrics for a user related to real-world and simulated phishing attempts and the user's organizational attributes to quantify the user's risk of being targeted by phishing attempts. The phishing exposure risk management system may use a score calculation service to quantify a user's risk of being targeted in phishing attempts. The score calculation service may use phishing data stored in a database and metric extraction service to quantify the risk for a recipient user in a phishing exposure risk score. Upon request or update of the score, the user may receive a notification with a message including the user's phishing exposure risk score and the details of the metrics contributing to their phishing exposure risk score. Network security protocols may be automatically adjusted based on the phishing exposure risk score.