Security Maturity Assessment for Phishing Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in accurately evaluating the effectiveness of security awareness training programs due to varying security maturity levels among users, leading to inadequate training and potential security breaches from phishing attacks.

Innovation Solution

A system and method for determining security maturity by assessing security knowledge, awareness, and culture levels of users, grouping them based on predetermined ranges, and benchmarking their phish-prone percentages to provide targeted training and incentives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations conduct security awareness training programs for all users, then security awareness should improve, but the varying security maturity levels among users lead to inadequate training effectiveness

Engineering Contradiction:
Improvesecurity awareness training effectivenessVSAvoidtraining customization to user maturity levels
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments users into different maturity groups (novice, intermediate, expert) based on their security maturity assessments. This segmentation allows the system to provide customized training content and phishing simulations appropriate to each user's current knowledge level, thereby improving training effectiveness while accounting for varying maturity levels across the organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by tailoring training materials, phishing simulation complexity, and educational content to match the specific maturity level of each user group. Rather than using a one-size-fits-all approach, the training quality is adapted locally to each user's needs, ensuring that novice users receive foundational training while expert users receive advanced, specialized content.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If organizations evaluate user performance against other users, then security awareness can be measured, but inadequate assessment methods fail to account for different starting maturity levels

Engineering Contradiction:
Improvesecurity awareness evaluation accuracyVSAvoidevaluation method flexibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements segmentation by creating separate evaluation benchmarks for each maturity group. Users are assessed against peers in their same maturity category rather than against all users uniformly. This allows for precise measurement of improvement within each group while maintaining the flexibility to compare progress across different starting points, thereby achieving both measurement precision and adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the evaluation parameters dynamically based on user maturity level. Different metrics, phishing simulation types, and assessment criteria are applied to different maturity groups. This parameter adaptation enables accurate measurement of security awareness while accommodating the diverse needs and capabilities of users at various stages of security maturity development.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If organizations implement comprehensive security assessments, then security maturity can be determined, but the complexity of assessing multiple dimensions (knowledge, awareness, culture) increases system complexity

Engineering Contradiction:
Improvesecurity maturity assessment accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the comprehensive security assessment into three distinct but integrated dimensions: security knowledge, security awareness, and security culture. Each dimension is assessed separately using specialized instruments and methods, then combined to form an overall security maturity determination. This segmentation reduces the complexity of implementing the full assessment by breaking it into manageable components while maintaining measurement precision across all dimensions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230259861A1Methods and systems for security maturity determination
Publication Date: 2023.08.17 KNOWBE4 INC
  • US20230259861A1 patent drawing
  • US20230259861A1 patent drawing
  • US20230259861A1 patent drawing

AI summary

Systems and methods are described for security maturity determination. Initially, first value for security knowledge level and second value for security awareness level of a user are determined. Further, third value for security culture level of a group of the user is determined. Thereafter, fourth value of security maturity of user is determined based at least on function of first value, second value, and third value. The user is then grouped into class of users comprising one or more additional users, wherein the fourth value of security maturity of the user falls within a predetermined range of security maturity values associated with class of users, class of users comprising one or more additional users. A phish prone percentage of user is benchmarked with phish phone percentage of one of one or more additional users of class of users. The benchmarking of phish prone percentage of user is displayed.