US 12,443,724 B2
System and method for displaying a scalable cyber-risk assessment of a computer system
Candan Bolukbas, Stone Ridge, VA (US); Robert Maley, Chandler, AZ (US); and Ferhat Dikbiyik, Hopkinton, MA (US)
Assigned to NormShield, Inc., Boston, MA (US)
Filed by NormShield, Inc., Boston, MA (US)
Filed on Dec. 21, 2023, as Appl. No. 18/392,911.
Application 18/392,911 is a continuation of application No. 17/174,307, filed on Feb. 11, 2021, granted, now 11,886,598.
Application 17/174,307 is a continuation of application No. 16/855,282, filed on Apr. 22, 2020, granted, now 10,949,543, issued on Mar. 16, 2021.
Prior Publication US 2024/0126892 A1, Apr. 18, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 21/00 (2013.01); G06F 21/57 (2013.01)
CPC G06F 21/577 (2013.01) [G06F 2221/034 (2013.01)] 27 Claims
OG exemplary drawing
 
1. A method of displaying a cyber risk assessment, the method comprising:
a) receiving a request for a quantitative cyber risk assessment of an entity associated with a domain name;
b) discovering a digital footprint of the entity based on the domain name using non-intrusive information gathering;
c) determining an entity classification based on a digital footprint;
d) determining an entity technical finding;
e) computing a loss event frequency using the entity classification and the entity technical finding, wherein computing the loss event frequency comprises computing using data that contains statistical information about a frequency of financial loss for certain industries;
f) computing a loss magnitude using the entity classification and the entity technical finding, wherein computing the loss magnitude comprises computing a primary loss that represents a direct cost associated with a cyber incident and computing a secondary loss that represents an indirect cost associated with the cyber incident;
g) computing a probable financial impact in financial terms of a cyber risk based on the loss event frequency and on the loss magnitude; and
h) displaying recommendations for remediating the cyber risk based on the computed probable financial impact.