US2023206184A1PendingUtilityA1

Systems and methods for human resources applications of security awareness testing

Assignee: KNOWBE4 INCPriority: Apr 2, 2020Filed: Feb 23, 2023Published: Jun 29, 2023
Est. expiryApr 2, 2040(~13.7 yrs left)· nominal 20-yr term from priority
G06Q 10/1053H04L 63/1416G06Q 10/0635H04L 63/1433H04L 63/1483H04L 63/083
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are described for facilitating assessment of security awareness of a candidate prior to a decision on whether or not to hire the candidate. Security awareness of the candidate in association with an application for a job may be assessed using responses to one or more simulated phishing communications provided by the candidate. Responses to the one or more simulated phishing communications may be used to determine a risk score for the candidate. Further, the risk score for the candidate may be used to make a decision on whether or not to hire the candidate.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, by one or more servers via one or more application programming interfaces (APIs), information about a candidate from a job application system;   communicating, by the one or more servers, one or more simulated phishing communications to one or more devices of the candidate, the one or more simulated phishing communications created by the one or more servers using the information about the candidate;   determining, by the one or more servers responsive to receiving one or more responses to the one or more simulated phi shing communications from the one or more devices of the candidate, a risk score of the candidate based at least on the one or more responses; and   communicating, by the one or more servers via the one or more APIs, the risk score to the job application system to use in a job application process.   
     
     
         2 . The method of  claim 1 , further comprising receiving, by the one or more servers, the information about the candidate during the job application process. 
     
     
         3 . The method of  claim 1 , further comprising generating, by the one or more servers, the one or more simulated phishing communications to include content personalized by the one or more servers based at least on the information about the candidate. 
     
     
         4 . The method of  claim 1 , further comprising receiving, by the one or more servers, authentication information used by the candidate for the job application system. 
     
     
         5 . The method of  claim 4 , further comprising determining, by the one or more servers, the risk score using the authentication information. 
     
     
         6 . The method of  claim 4 , wherein the authentication information includes at least one of strength of password or type of authentication. 
     
     
         7 . The method of  claim 6 , wherein the type of authentication comprises one-factor authentication or two-factor authentication. 
     
     
         8 . The method of  claim 1 , further comprising determining, by the one or more servers, the risk score using the one or more responses to the simulated phishing communications. 
     
     
         9 . The method of  claim 1 , wherein the job application system uses the risk score in making a hiring decision on the candidate. 
     
     
         10 . The method of  claim 1 , wherein the job application system executes on a second one or more servers. 
     
     
         11 . A system comprising:
 one or more servers comprising one or more processors, coupled to memory and configured to:   receive via one or more application programming interfaces (APIs), information about a candidate from a job application system;   communicate one or more simulated phishing communications to one or more devices of the candidate, the one or more simulated phishing communications created by the one or more servers using the information about the candidate;   determine, responsive to receiving one or more responses to the one or more simulated phishing communications from the one or more devices of the candidate, a risk score of the candidate based at least on the one or more responses; and   communicate via the one or more APIs, the risk score to the job application system to use in a job application process.   
     
     
         12 . The system of  claim 11 , where the one or more servers are further configured to receive the information about the candidate during the job application process. 
     
     
         13 . The system of  claim 11 , where the one or more servers are further configured to generate the one or more simulated phishing communications to include content personalized by the one or more servers based at least on the information about the candidate. 
     
     
         14 . The system of  claim 11 , where the one or more servers are further configured to receive authentication information used by the candidate for the job application system. 
     
     
         15 . The system of  claim 14 , where the one or more servers are further configured to determine the risk score using the authentication information. 
     
     
         16 . The system of  claim 14 , wherein the authentication information includes at least one of strength of password or type of authentication. 
     
     
         17 . The system of  claim 16 , wherein the type of authentication comprises one-factor authentication or two-factor authentication. 
     
     
         18 . The system of  claim 11 , where the one or more servers are further configured to determine the risk score using the one or more responses to the simulated phishing communications. 
     
     
         19 . The system of  claim 11 , wherein the job application system uses the risk score in making a hiring decision on the candidate. 
     
     
         20 . The system of  claim 11 , wherein the job application system executes on a second one or more servers.

Join the waitlist — get patent alerts

Track US2023206184A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.