Third-Party Cyber Risk Assessment via Machine Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to effectively evaluate and mitigate the cyber security risks of third-party entities, leading to potential breaches and increased costs for organizations, with 90% of large organizations experiencing breaches through third-party vulnerabilities.
Innovation Solution
A computerized method using machine learning and artificial intelligence to analyze cyber and non-cyber risk indicators, training a software model on a large dataset of organizations to predict and rank cyber security risks, enabling organizations to manage and mitigate third-party risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If organizations rely on third-party entities for business operations, then organizational productivity and service capability are improved, but cyber security risk exposure increases
Solution Approach 1:
The patent introduces a risk assessment system that acts as an intermediary between organizations and third-party entities. This system collects security indicators from third parties, processes them through machine learning models, and provides risk scores that mediate the relationship between organizational productivity needs and security risk concerns, enabling informed decisions about third-party engagements
Solution Approach 2:
The system performs preliminary risk assessment actions before organizations engage with third-party entities. By collecting security indicators and generating risk scores in advance, the system enables organizations to proactively identify and mitigate potential security risks before they can impact organizational operations, rather than reacting to breaches after they occur
2Measurement precision
If organizations implement comprehensive third-party security monitoring, then cyber security risk detection capability is improved, but system complexity and resource requirements increase
Solution Approach 1:
The patent replaces complex manual monitoring mechanisms with machine learning models that automatically process security indicators. The ML models substitute for traditional rule-based or manually-operated monitoring systems, achieving high detection precision through automated pattern recognition while reducing operational complexity and resource requirements
Solution Approach 2:
The system transforms multiple diverse security indicators from third-party entities into a standardized risk score parameter. By changing the parameters from raw, heterogeneous security data into a unified risk assessment metric, the system simplifies the monitoring output while maintaining comprehensive detection capability across different third-party contexts
3Reliability
If organizations evaluate security risk of multiple third-party entities, then overall security posture is improved, but time and computational resources required increase
Solution Approach 1:
The patent applies partial action by focusing risk assessment efforts on the most critical third-party entities and security indicators. The machine learning models identify and prioritize the subset of indicators that have the greatest impact on risk assessment, allowing organizations to achieve improved security posture for key third parties without investing excessive time and resources in evaluating every single indicator for every third-party entity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A computerized method for evaluating an organization's risk to be exposed to cyber security events, the method including receiving a request to evaluating a specific organization's risk to be exposed to cyber security event, the request including information about the specific organization, collecting security-based risk indicators about the specific organization, inputting the security-based risk indicators about the specific organization into a model, said model obtains weights to classifiers that represent an impact of a specific organization to be exposed to a security event, computing a specific risk value for the specific organization according to values of the specific organization and the weights of the classifiers.