Third-Party Cyber Risk Assessment via Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively evaluate and mitigate the cyber security risks of third-party entities, leading to potential breaches and increased costs for organizations, with 90% of large organizations experiencing breaches through third-party vulnerabilities.

Innovation Solution

A computerized method using machine learning and artificial intelligence to analyze cyber and non-cyber risk indicators, training a software model on a large dataset of organizations to predict and rank cyber security risks, enabling organizations to manage and mitigate third-party risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If organizations rely on third-party entities for business operations, then organizational productivity and service capability are improved, but cyber security risk exposure increases

Engineering Contradiction:
Improveorganizational productivityVSAvoidcyber security risk exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a risk assessment system that acts as an intermediary between organizations and third-party entities. This system collects security indicators from third parties, processes them through machine learning models, and provides risk scores that mediate the relationship between organizational productivity needs and security risk concerns, enabling informed decisions about third-party engagements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary risk assessment actions before organizations engage with third-party entities. By collecting security indicators and generating risk scores in advance, the system enables organizations to proactively identify and mitigate potential security risks before they can impact organizational operations, rather than reacting to breaches after they occur

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If organizations implement comprehensive third-party security monitoring, then cyber security risk detection capability is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improverisk detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces complex manual monitoring mechanisms with machine learning models that automatically process security indicators. The ML models substitute for traditional rule-based or manually-operated monitoring systems, achieving high detection precision through automated pattern recognition while reducing operational complexity and resource requirements

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system transforms multiple diverse security indicators from third-party entities into a standardized risk score parameter. By changing the parameters from raw, heterogeneous security data into a unified risk assessment metric, the system simplifies the monitoring output while maintaining comprehensive detection capability across different third-party contexts

Inventive Principle:
Principle #35Parameter changes

3Reliability

If organizations evaluate security risk of multiple third-party entities, then overall security posture is improved, but time and computational resources required increase

Engineering Contradiction:
Improvesecurity postureVSAvoidevaluation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing risk assessment efforts on the most critical third-party entities and security indicators. The machine learning models identify and prioritize the subset of indicators that have the greatest impact on risk assessment, allowing organizations to achieve improved security posture for key third parties without investing excessive time and resources in evaluating every single indicator for every third-party entity

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4175226B1A system and method for evaluating an organization's risk for exposure to cyber security events
Publication Date: 2026.03.18 CYBERWRITE INC
  • EP4175226B1 patent drawingFigure 1
  • EP4175226B1 patent drawingFigure 2
  • EP4175226B1 patent drawingFigure 3

AI summary

A computerized method for evaluating an organization's risk to be exposed to cyber security events, the method including receiving a request to evaluating a specific organization's risk to be exposed to cyber security event, the request including information about the specific organization, collecting security-based risk indicators about the specific organization, inputting the security-based risk indicators about the specific organization into a model, said model obtains weights to classifiers that represent an impact of a specific organization to be exposed to a security event, computing a specific risk value for the specific organization according to values of the specific organization and the weights of the classifiers.