Prosecution Insights
Last updated: August 15, 2026
Application No. 18/113,372

SYSTEMS AND METHODS FOR HUMAN RESOURCES APPLICATIONS OF SECURITY AWARENESS TESTING

Non-Final OA §103
Filed
Feb 23, 2023
Priority
Apr 02, 2020 — provisional 63/004,217 +1 more
Examiner
ZAIDI, SYED A
Art Unit
2432
Tech Center
2400 — Computer Networks
Assignee
KnowBe4 Inc.
OA Round
5 (Non-Final)
82%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
641 granted / 784 resolved
+23.8% vs TC avg
Moderate +12% lift
Without
With
+12.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
29 currently pending
Career history
821
Total Applications
across all art units

Statute-Specific Performance

§101
13.1%
-26.9% vs TC avg
§103
43.9%
+3.9% vs TC avg
§102
14.1%
-25.9% vs TC avg
§112
20.2%
-19.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 784 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 4/10/2026 has been entered. Response to Arguments In communications filed on 4/10/2026, claims 1-3, 7-13, and 17-23 are presented for examination. Claims 1 and 11 are independent. Amended claims: 1, 7, 11, 17. Applicants’ arguments, see Applicant Arguments/Remarks filed 3/5/2026, with respect to claim(s) rejected under prior art have been considered but are moot in view of new ground(s) of rejection necessitated by Applicants’ amendment to the claim(s). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1-3, 7-13, and 17-23 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 20170293873 A1 (hereinafter ‘Chrapo’) in view of US 20130046704 A1 (hereinafter ‘Patwa’) in view of US 20110047608 A1 (hereinafter ‘Leven’) in view of US 20170244746 A1 (hereinafter ‘Hawthorn’). As regards claim 1, Chrapo (US 20170293873 A1) in combination with Patwa (US 20130046704 A1) teaches: A method comprising: receiving, by one or more servers via one or more application programming interfaces (APIs), information about a candidate from a job application system; (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶68-¶77, ¶94-¶97, ¶134-¶137, i.e., candidate applying for a job through an application system and ¶68-¶80, ¶97, ¶101-¶102, i.e., risk scores are calculated using multiple different sets of information regarding a user including ID information such as facial recognition i.e., authentication information, messages, internet browsing etc, wherein the information is calculated using software i.e., API). Although, Chrapo does not explicitly teach the use of common software building blocks like API, Patwa, in analogous art, teaches using APIs to send/receive a job candidate related information from multiple sources. See Patwa, ¶95-¶108). Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Charpo to include using basic software building blocks such as APIs to send/receive a job candidate related information from sources as taught by Patwa with the motivation to improve the efficiency and quality of the recruitment process (Patwa: ¶12) Charpo et al in combination with Leven (US 20110047608 A1) further teaches: the information comprising an email address and a type of authentication or strength of password the candidate used to authenticate to the job application system to submit an application for a job during a job application process; (Leven: ¶57-¶58, i.e., authentication based on the strength of the authentication password and/or multifactor authentications) Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Chrapo to include authentication information to include strength of the authentication password and/or multifactor authentication as taught by Leven with the motivation to make the authentication stronger (Leven: ¶14) Charpo et al in combination with Hawthorn (US 20170244746 A1) further teaches: generating, by the one or more servers, one or more simulated phishing communications created and personalized to the candidate using the information about the candidate received from the job application system; (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶6, ¶33-¶42, ¶94-¶97, i.e., candidate applying for a job through an application system and ¶70-¶71, ¶97, ¶101-¶102, i.e., risk scores are calculated using multiple different sets of information regarding a user including ID information such as facial recognition i.e., authentication information, network/online/email usage behavior of the user and so forth. See also, Hawthorn: Fig 7, item 708; Fig 9; ¶108]-¶111; ¶115 provides for the security system to obtain employee profiles, etc., from client businesses, Fig 17-18, Fig 20, step 2010; ¶237 provides for calculating a risk score; ¶226-¶230 provides for communicating risk assessment reports to the business client including user-specific risk scores) Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Chrapo to include responses to a simulated phishing campaign to a user as taught by Hawthorn with the motivation to calculate trustworthiness of an individual (Hawthorn: ¶37) communicating, by the one or more servers, one or more simulated phishing communications to one or more devices of the candidate using the email address provided by the candidate to the job application system to submit the application for the job; (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶6, ¶33-¶42, ¶94-¶97, i.e., candidate applying for a job through an application system and ¶70-¶71, ¶97, ¶101-¶102, i.e., risk scores are calculated using multiple different sets of information regarding a user including ID information such as facial recognition i.e., authentication information, network/online/email usage behavior of the user and so forth. See also, Hawthorn: Fig 7, item 708; Fig 9; ¶108]-¶111; ¶115 provides for the security system to obtain employee profiles, etc., from client businesses, Fig 17-18, Fig 20, step 2010; ¶237 provides for calculating a risk score; ¶226-¶230 provides for communicating risk assessment reports to the business client including user-specific risk scores) receiving, by the one or more servers, one or more responses from the one or more devices of the candidate, the one or more responses identifying one or more failure actions in the candidate's interaction with the one or more simulated phishing communications; (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶6, ¶33-¶42, ¶94-¶97, i.e., candidate applying for a job through an application system and ¶70-¶71, ¶97, ¶101-¶102, i.e., risk scores are calculated using multiple different sets of information regarding a user including ID information such as facial recognition i.e., authentication information, network/online/email usage behavior of the user and so forth. See also, Hawthorn: Fig 7, item 708; Fig 9; ¶52-¶53, i.e., user behavior response is received in response to a simulated phishing campaign; ¶108-¶111; ¶115 provides for the security system to obtain employee profiles, etc., from client businesses, Fig 17-18, Fig 20, step 2010; ¶237 provides for calculating a risk score; ¶226-¶230 provides for communicating risk assessment reports to the business client including user-specific risk scores) determining, by the one or more servers responsive to receiving one or more responses to the one or more simulated phishing communications from the one or more devices of the candidate, a risk score of the candidate based at least on the one or more failure actions of the one or more responses and the type of authentication or the strength of password the candidate used to authenticate to the job application system to submit the application for the job; and (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶94-¶97, i.e., candidate applying for a job through an application system and ¶70-¶71, ¶97, ¶101-¶102, i.e., risk scores are calculated using multiple different sets of information regarding a user including ID information such as facial recognition i.e., authentication information, network/online/email usage behavior of the user and so forth. See also, Hawthorn: Fig 7, item 708; Fig 9; ¶108]-¶111; ¶115 provides for the security system to obtain employee profiles, etc., from client businesses, Fig 17-18, Fig 20, step 2010; ¶237 provides for calculating a risk score; ¶226-¶230 provides for communicating risk assessment reports to the business client including user-specific risk scores) communicating, by the one or more servers via the one or more APIs, the risk score to the job application system to use in the job application process. (Chrapo: Figs. 4-7, and ¶3-¶4, ¶33-¶42, ¶94-¶97, ¶134-¶137, i.e., hiring decision determination based on calculating risk scores regarding a potential candidate. Hawthorn: Fig 7, item 708; Fig 9; ¶108]-¶111; ¶115 provides for the security system to obtain employee profiles, etc., from client businesses, Fig 17-18, Fig 20, step 2010; ¶237 provides for calculating a risk score; ¶226-¶230 provides for communicating risk assessment reports to the business client including user-specific risk scores) Claim 11 recites substantially the same features recited in claim 1 above and is rejected based on the aforementioned rationale discussed in the rejection. As regards claim 2, Chrapo et al combination teaches the method of claim 1, further comprising receiving, by the one or more servers, the information about the candidate during the job application process. (Chrapo: Figs. 4-7, and ¶3-¶4, ¶33-¶42, ¶94-¶97, ¶134-¶137, i.e., the job application process) Claim 12 recites substantially the same features recited in claim 2 above and is rejected based on the aforementioned rationale discussed in the rejection. As regards claim 3, Chrapo et al combination teaches the method of claim 1, further comprising generating, by the one or more servers, the one or more simulated phishing communications to include content personalized by the one or more servers based at least on the information about the candidate. (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶94-¶97, i.e., candidate applying for a job through an application system and ¶70-¶71, ¶97, ¶101-¶102, i.e., risk scores are calculated using multiple different sets of information regarding a user including ID information such as facial recognition i.e., authentication information, network/online/email usage behavior of the user and so forth. See also, Hawthorn: ¶64-¶65, i.e., generating trustworthiness level of an individual based on the response to the results of one or more simulated phishing campaigns received from the individual’s device) Claim 13 recites substantially the same features recited in claim 3 above and is rejected based on the aforementioned rationale discussed in the rejection. As regards claim 7, Chrapo et al combination teaches the method of claim 1, wherein the type of authentication comprises one-factor authentication or two-factor authentication. (Leven: ¶57-¶58, i.e., authentication based on the strength of the authentication password and/or multifactor authentications) Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to modify Chrapo to include authentication information to include strength of the authentication password and/or multifactor authentication as taught by Leven with the motivation to make the authentication stronger (Leven: ¶14) Claim 17 recites substantially the same features recited in claim 7 above and is rejected based on the aforementioned rationale discussed in the rejection. As regards claim 8, Chrapo et al combination teaches the method of claim 1, further comprising determining, by the one or more servers, the risk score using the one or more responses to the simulated phishing communications. (Chrapo: Figs. 4-7, and ¶3-¶4, ¶33-¶42, ¶94-¶97, ¶160-¶161) Claim 18 recites substantially the same features recited in claim 8 above and is rejected based on the aforementioned rationale discussed in the rejection. As regards claim 9, Chrapo et al combination teaches the method of claim 1, wherein the job application system uses the risk score in making a hiring decision on the candidate. (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶68-¶77, ¶94-¶97, ¶134-¶137 Claim 19 recites substantially the same features recited in claim 9 above and is rejected based on the aforementioned rationale discussed in the rejection. As regards claim 10, Chrapo et al combination teaches the method of claim 1, wherein the job application system executes on a second one or more servers. (Chrapo: Figs. 1-2, 4-7. Patwa: Fig. 1, ¶37) Claim 20 recites substantially the same features recited in claim 10 above and is rejected based on the aforementioned rationale discussed in the rejection. As regards claim 21, Chrapo et al combination teaches the method of claim 1, wherein generating the one or more simulated phishing communications comprises personalizing content of the one or more simulated phishing communications based on job profile information of the candidate received from the job application system. (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶6, ¶33-¶42, ¶94-¶97, i.e., candidate applying for a job through an application system and ¶70-¶71, ¶97, ¶101-¶102, i.e., risk scores are calculated using multiple different sets of information regarding a user including ID information such as facial recognition i.e., authentication information, network/online/email usage behavior of the user and so forth. See also, Hawthorn: Fig 7, item 708; Fig 9; ¶108]-¶111; ¶115 provides for the security system to obtain employee profiles, etc., from client businesses, Fig 17-18, Fig 20, step 2010; ¶237 provides for calculating a risk score; ¶226-¶230 provides for communicating risk assessment reports to the business client including user-specific risk scores) As regards claim 22, Chrapo et al combination teaches the method of claim 1, wherein generating the one or more simulated phishing communications comprises personalizing content of the one or more simulated phishing communications based on information identifying one or more social media platforms associated with the candidate. (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶6, ¶33-¶42, ¶94-¶97, i.e., candidate applying for a job through an application system and ¶70-¶71, ¶97, ¶101-¶102, i.e., risk scores are calculated using multiple different sets of information regarding a user including ID information such as facial recognition i.e., authentication information, network/online/email usage behavior of the user and so forth. See also, Hawthorn: Fig 7, item 708; Fig 9; ¶108]-¶111; ¶115 provides for the security system to obtain employee profiles, etc., from client businesses, Fig 17-18, Fig 20, step 2010; ¶237 provides for calculating a risk score; ¶226-¶230 provides for communicating risk assessment reports to the business client including user-specific risk scores) As regards claim 23, Chrapo et al combination teaches the method of claim 1, wherein generating the one or more simulated phishing communications comprises configuring the simulated phishing communications to appear as originating from the job application system used by the candidate to submit the application. (Chrapo: Figs. 1-2, 4-7, and ¶3-¶4, ¶6, ¶33-¶42, ¶94-¶97, i.e., candidate applying for a job through an application system and ¶70-¶71, ¶97, ¶101-¶102, i.e., risk scores are calculated using multiple different sets of information regarding a user including ID information such as facial recognition i.e., authentication information, network/online/email usage behavior of the user and so forth. See also, Hawthorn: Fig 7, item 708; Fig 9; ¶108]-¶111; ¶115 provides for the security system to obtain employee profiles, etc., from client businesses, Fig 17-18, Fig 20, step 2010; ¶237 provides for calculating a risk score; ¶226-¶230 provides for communicating risk assessment reports to the business client including user-specific risk scores) Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SYED A ZAIDI whose telephone number is (571)270-5995. The examiner can normally be reached Monday-Thursday: 5:30AM-5:30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SYED A ZAIDI/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Show 10 earlier events
Jun 25, 2025
Applicant Interview (Telephonic)
Jun 27, 2025
Examiner Interview Summary
Sep 02, 2025
Response Filed
Dec 10, 2025
Final Rejection mailed — §103
Mar 05, 2026
Response after Non-Final Action
Apr 10, 2026
Request for Continued Examination
Apr 18, 2026
Response after Non-Final Action
Jul 28, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12688328
DECENTRALIZED PLATFORM AND ARCHITECTURE
2y 2m to grant Granted Jul 21, 2026
Patent 12683765
CERTIFICATE-BASED PAIRING OF KEY FOB DEVICE AND CONTROL UNIT
2y 6m to grant Granted Jul 14, 2026
Patent 12682110
IMAGE DISPLAY APPARATUS, IMAGE CAPTURING APPARATUS, CONTROL METHOD, AND STORAGE MEDIUM
1y 9m to grant Granted Jul 14, 2026
Patent 12676855
METHOD AND SYSTEM FOR AUTHENTICATING A USER ON AN IDENTITY-AS-A-SERVICE SERVER
3y 7m to grant Granted Jul 07, 2026
Patent 12671684
SYSTEMS AND METHODS FOR PROACTIVELY UPGRADING LOW QUALITY ACCESS CREDENTIALS
4y 7m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
82%
Grant Probability
94%
With Interview (+12.4%)
2y 8m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 784 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month