Automated and continuous cybersecurity assessment with measurement and scoring
Abstract
Automated and continuous cybersecurity assessment with measurement and scoring. In an embodiment, a cyber-hygiene score is calculated based on data representing asserted cybersecurity controls within an entity system. The cyber-hygiene score indicates an extent of implementation of cybersecurity controls associated with a cybersecurity standard. In addition, automated cybersecurity test(s) are performed on the entity system, and a cyber-breach score is calculated based on the test scores calculated from the automated cybersecurity test(s). The cyber-breach score indicates an effectiveness of the implemented cybersecurity controls. The automated cybersecurity test(s) may comprise an inside-out controls test, and outside-in controls test, and/or a social-engineering test (e.g., phishing simulation). A cybersecurity assessment is generated based on the cyber-hygiene score and the cyber-breach score.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising using at least one hardware processor to execute a process to:
perform a plurality of automated cybersecurity tests on an entity system, wherein the plurality of automated cybersecurity tests comprises an inside-out controls test, an outside-in controls test, and a social-engineering test; for each of the plurality of automated cybersecurity tests, calculate a test score based on results from the automated cybersecurity test; calculate a cyber-breach score based on the test scores calculated for the plurality of cybersecurity tests, wherein the cyber-breach score indicates an effectiveness of an implementation of one or more cybersecurity controls associated with at least one cybersecurity standard; and generate a cybersecurity assessment based on the cyber-breach score.
2 . The method of claim 1 , wherein the test scores are calculated based on a mapping between the results from the automated cybersecurity tests and security domains of the at least one cybersecurity standard.
3 . The method of claim 1 , further comprising generating a comparison of the cyber-breach score to a benchmark derived from peers of an entity operating the entity system, wherein the cybersecurity assessment comprises the comparison.
4 . The method of claim 1 , wherein the at least one hardware processor automatically executes the process periodically to continually update the cybersecurity assessment.
5 . The method of claim 1 , further comprising generating a graphical user interface that graphically represents the cyber-breach score and is configured for drill-down into contributing factors for the cyber-breach score.
6 . The method of claim 5 , wherein the contributing factors comprise failures in cybersecurity controls and non-compliance with cybersecurity controls, mapped to at least one cybersecurity standard, that were identified in the results from the automated cybersecurity tests.
7 . The method of claim 1 , wherein the cyber-breach score is a value within a range from zero to one hundred.
8 . The method of claim 1 , wherein the inside-out controls test is executed by a software agent on a node within a network of the entity system.
9 . The method of claim 10 , further comprising using the at least one hardware processor to, in response to a triggering event, trigger the inside-out controls test via a call to the software agent.
10 . The method of claim 11 , further comprising using the at least one hardware processor to instantiate and configure a dedicated virtual machine to receive results of the inside-out controls test from the software agent.
11 . The method of claim 1 , wherein the outside-in controls test is performed against Internet-facing assets of the entity system, wherein the method further comprises using the at least one hardware processor to receive one or more Uniform Resource Locators (URLs), and wherein the outside-in controls test is performed on all of the received one or more URLs.
12 . The method of claim 1 , wherein the social-engineering test comprises a phishing simulation against one or more email addresses.
13 . The method of claim 12 , further comprising using the at least one hardware processor to:
receive a specification of a landing page; incorporate a hyperlink to the landing page into an email message; send the email message to each of the one or more email addresses; and track visits to the landing page.
14 . The method of claim 13 , further comprising using the at least one hardware processor to host the landing page.
15 . The method of claim 13 , further comprising using the at least one hardware processor to receive a specification of a domain, wherein the email message is sent from the domain.
16 . The method of claim 1 , further comprising determining a probability of a cybersecurity breach using a machine-learning model that is trained to predict the probability of a cybersecurity breach based on one or more features in the results from the one or more automated cybersecurity tests, wherein the cybersecurity assessment is further based on the probability of a cybersecurity breach.
17 . The method of claim 1 , further comprising detecting one or more failures in the implementation of the plurality of cybersecurity controls associated with the at least one cybersecurity standard, based on the results from the one or more automated cybersecurity tests, wherein the cybersecurity assessment identifies each of the detected one or more failures.
18 . The method of claim 17 , further comprising, in response to detecting the one or more failures, initiating at least one alert to one or more recipients.
19 . A system comprising:
at least one hardware processor; and one or more software modules that are configured to, when executed by the at least one hardware processor,
perform a plurality of automated cybersecurity tests on an entity system, wherein the plurality of automated cybersecurity tests comprises an inside-out controls test, an outside-in controls test, and a social-engineering test,
for each of the plurality of automated cybersecurity tests, calculate a test score based on results from the automated cybersecurity test,
calculate a cyber-breach score based on the test scores calculated for the plurality of cybersecurity tests, wherein the cyber-breach score indicates an effectiveness of an implementation of one or more cybersecurity controls associated with at least one cybersecurity standard, and
generate a cybersecurity assessment based on the cyber-breach score.
20 . A non-transitory computer-readable medium having instructions stored therein, wherein the instructions, when executed by a processor, cause the processor to:
perform a plurality of automated cybersecurity tests on an entity system, wherein the plurality of automated cybersecurity tests comprises an inside-out controls test, an outside-in controls test, and a social-engineering test; for each of the plurality of automated cybersecurity tests, calculate a test score based on results from the automated cybersecurity test; calculate a cyber-breach score based on the test scores calculated for the plurality of cybersecurity tests, wherein the cyber-breach score indicates an effectiveness of an implementation of one or more cybersecurity controls associated with at least one cybersecurity standard; and generate a cybersecurity assessment based on the cyber-breach score.Join the waitlist — get patent alerts
Track US2022224712A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.