US2023319077A1PendingUtilityA1

Data breach monitoring and remediation

Assignee: WELLS FARGO BANK NAPriority: Dec 11, 2019Filed: Jun 2, 2023Published: Oct 5, 2023
Est. expiryDec 11, 2039(~13.4 yrs left)· nominal 20-yr term from priority
H04L 63/1416G06Q 50/265G06Q 20/108H04L 63/10G06Q 30/0248G06Q 30/01G06Q 30/0201
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Sharing of user data of customers of a first party with a third party can be monitored. The data can be presented to customers to enable transparency with respect to what data is provided to whom. Furthermore, remediation can be promptly triggered in response to a third-party data breach. After breach detection, customers and data affected by the breach can be determined. The type of remediation can be determined based on the risk as determined based on the customers affected and the data involved.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system, comprising:
 a processor coupled to a memory that includes instructions that when executed by the processor cause the processor to:   record, by a first party, a plurality of instances of electronic user data sharing by customers of the first party with a third party, wherein the electronic user data sharing occurs in response to the customers engaging with one or more digital promotions of the third party within a digital space of the first party;   convey, to a first customer of the customers, a graphical data monitoring dashboard providing a data sharing history to the first customer in real-time, wherein the graphical data monitoring dashboard indicates at least one of first electronic user data of the first customer that has been shared with the third party, a volume of the first electronic user data, and a sensitivity level of the first electronic user data;   identify, by the first party and based on an identified data breach associated with the third party, the customers having engaged with the one or more digital promotions of the third party and particular electronic user data of the customers that was shared with the third party based on the recorded plurality of instances; and   initiate remediation in response to the data breach based on the identified customers and the particular electronic user data that was shared with the third party.   
     
     
         2 . The system of  claim 1 , wherein the instructions, when executed, further cause the processor to:
 adjusting a trusted status of the third party in relation to the first party based on the data breach.   
     
     
         3 . The system of  claim 1 , wherein the instructions, when executed, further cause the processor to:
 onboard, by the first party, the third party to enable the one or more digital promotions of the third party to be presented within the digital space of the first party.   
     
     
         4 . The system of  claim 1 , wherein initiating remediation comprises triggering automatic monetary reimbursement for an impact caused by the data breach. 
     
     
         5 . The system of  claim 4 , wherein initiating remediation further comprises determining a monetary amount to reimburse for the impact caused by the data breach based on at least one of (i) an amount of the electronic user data shared with the third party and (ii) a sensitivity of the electronic user data shared with the third party, and
 wherein triggering the automatic monetary reimbursement for the impact caused by the data breach comprises crediting the monetary amount to at least one account associated with the customers affected by the data breach.   
     
     
         6 . The system of  claim 1 , wherein the graphical data monitoring dashboard is conveyed in response to a request associated with the first customer. 
     
     
         7 . The system of  claim 1 , wherein the first party comprises a financial institution and wherein the third party comprises a vendor. 
     
     
         8 . The system of  claim 1 , wherein the instructions, when executed, further cause the processor to:
 automatically detect the data breach based on analysis of news reports.   
     
     
         9 . The system of  claim 1 , wherein the instructions, when executed, further cause the processor to:
 receive a breach report from the third party identifying an occurrence of the data breach.   
     
     
         10 . The system of  claim 1 , wherein initiating remediation comprises providing a notification of the data breach to the customers having engaged with the one or more digital promotions of the third party. 
     
     
         11 . A method comprising:
 recording, by a first party, a plurality of instances of electronic user data sharing by customers of the first party with a third party, wherein the electronic user data sharing occurs in response to the customers engaging with one or more digital promotions of the third party within a digital space of the first party;   conveying, to a first customer of the customers, a graphical data monitoring dashboard providing a data sharing history to the first customer in real-time, wherein the graphical data monitoring dashboard indicates at least one of first electronic user data of the first customer that has been shared with the third party, a volume of the first electronic user data, and a sensitivity level of the first electronic user data;   identifying, by the first party and based on an identified data breach associated with the third party, the customers having engaged with the one or more digital promotions of the third party and particular electronic user data of the customers that was shared with the third party based on the recorded plurality of instances; and   initiating remediation in response to the data breach based on the identified customers and the particular electronic user data that was shared with the third party.   
     
     
         12 . The method of  claim 11 , further comprising:
 adjusting a trusted status of the third party in relation to the first party based on the data breach.   
     
     
         13 . The method of  claim 11 , further comprising:
 onboarding, by the first party, the third party to enable the one or more digital promotions of the third party to be presented within the digital space of the first party.   
     
     
         14 . The method of  claim 11 , wherein initiating remediation comprises triggering automatic monetary reimbursement for an impact caused by the data breach. 
     
     
         15 . The method of  claim 14 , wherein initiating remediation further comprises determining a monetary amount to reimburse for the impact caused by the data breach based on at least one of (i) an amount of the electronic user data shared with the third party and (ii) a sensitivity of the electronic user data shared with the third party, and
 wherein triggering the automatic monetary reimbursement for the impact caused by the data breach comprises crediting the monetary amount to at least one account associated with the customers affected by the data breach.   
     
     
         16 . The method of  claim 11 , wherein the graphical data monitoring dashboard is conveyed in response to a request associated with the first customer. 
     
     
         17 . The method of  claim 11 , wherein the first party comprises a financial institution and wherein the third party comprises a vendor. 
     
     
         18 . The method of  claim 11 , further comprising:
 automatically detecting the data breach based on analysis of news reports.   
     
     
         19 . The method of  claim 11 , further comprising:
 receiving a breach report from the third party identifying an occurrence of the data breach.   
     
     
         20 . The method of  claim 11 , wherein initiating remediation comprises providing a notification of the data breach to the customers having engaged with the one or more digital promotions of the third party.

Join the waitlist — get patent alerts

Track US2023319077A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.