Automated Vendor Security Risk Assessment via Computational Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for assessing vendor security practices in client-vendor relationships are manual, time-consuming, and often rely on self-reporting, making it difficult for clients to accurately evaluate and manage information security risks.

Innovation Solution

A computational risk analysis system that collects and analyzes security information from vendors, creates a standardized vendor security profile, and dynamically evaluates client-specific vendor security risks based on interaction details, using automated processes and machine learning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual approaches are used to investigate vendor security profiles, then clients can assess vendor security practices, but the process becomes time-consuming and expensive

Engineering Contradiction:
Improvesecurity risk assessment accuracyVSAvoidtime required for security investigation
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical investigation processes with automated computational systems. The system uses machine learning models and automated data collection to assess vendor security profiles, eliminating the need for manual security professional involvement while maintaining or improving assessment accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary automated risk analysis system that mediates between clients and vendors. This system collects security information from multiple sources, processes it through computational models, and provides risk assessments to clients, thereby reducing the time and cost of direct manual investigations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If clients rely on self-reporting and internet research to assess vendor security, then the assessment process is simplified, but the accuracy and reliability of security risk evaluation deteriorates

Engineering Contradiction:
Improvesimplicity of security assessment processVSAvoidreliability of vendor security evaluation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a universal automated assessment system that performs multiple functions: collecting security information from various sources, validating the information through cross-referencing, analyzing risks using machine learning models, and generating comprehensive risk profiles. This multi-functional system maintains simplicity for clients while ensuring reliable evaluations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously collects security information from multiple sources, compares it against established security standards and benchmarks, and adjusts risk assessments based on the consistency and quality of the information received. This feedback loop enhances reliability while maintaining operational simplicity.

Inventive Principle:
Principle #23Feedback

3Productivity

If computational approaches are used to determine vendor security practices, then the process becomes automated and efficient, but the complexity of the system increases

Engineering Contradiction:
Improvespeed of security risk assessmentVSAvoidcomplexity of risk analysis system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the complex risk analysis system into distinct functional modules: data collection from multiple sources, information validation, risk factor identification, machine learning-based analysis, and report generation. Each module handles a specific aspect of the assessment, making the overall complex system manageable and maintainable while achieving high productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables the system to automatically collect, validate, and analyze security information without requiring manual intervention. The machine learning models self-adjust and improve based on the data they process, and the system automatically generates risk assessments and recommendations, thereby achieving high productivity despite internal complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250181725A1Dynamic evaluation of information security risk for vendor and subvendor computing systems
Publication Date: 2025.06.05 VALENTE SHERMAN INC
  • US20250181725A1 patent drawing
  • US20250181725A1 patent drawing
  • US20250181725A1 patent drawing

AI summary

Provided are mechanisms and processes for computational risk analysis and intermediation. Security practices information characterizing security measures in place at a first computing system may be received from the first computing system via a network. Computing services interaction information characterizing data transmitted from a second computing system to the first computing system may be received from the second computing system via the network. A processor may determine a risk profile for the first computing system based on the security practices information. Based on the risk profile and the computing services interaction information, the processor may then determine an estimate of the information security risk associated with transmitting the data from the second computing system to the first computing system. A risk assessment message including the estimate of the information security risk may be transmitted to the second computing system.