Prosecution Insights
Last updated: August 15, 2026
Application No. 18/116,404

SYSTEMS AND METHODS FOR CREATING AND COMMISSIONING A SECURITY AWARENESS PROGRAM

Final Rejection §101§112
Filed
Mar 02, 2023
Priority
Jun 20, 2017 — provisional 62/522,455 +2 more
Examiner
LEE, PO HAN
Art Unit
3623
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
KnowBe4 Inc.
OA Round
4 (Final)
31%
Grant Probability
At Risk
5-6
OA Rounds
2m
Est. Remaining
71%
With Interview

Examiner Intelligence

Grants only 31% of cases
31%
Career Allowance Rate
51 granted / 164 resolved
-20.9% vs TC avg
Strong +40% interview lift
Without
With
+40.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
32 currently pending
Career history
213
Total Applications
across all art units

Statute-Specific Performance

§101
44.4%
+4.4% vs TC avg
§103
37.0%
-3.0% vs TC avg
§102
11.3%
-28.7% vs TC avg
§112
5.8%
-34.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 164 resolved cases

Office Action

§101 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Status of the Application The following is a Final Office Action. In response to Examiner's communication of 1/28/2026, Applicant responded on 4/27/2026. Amended claim 1, 11. Claims 1-20 are pending in this application and have been examined. Response to Amendment Applicant's amendments to claims 1, 11 are sufficient to overcome the nonstatutory double patent rejection set forth in the previous action. The nonstatutory double patent rejection is hereby withdrawn. Applicant's amendments to claims 1, 11 are not sufficient to overcome the 35 USC 101 rejections set forth in the previous action. Applicant's amendments to claims 1, 11 are sufficient to overcome the prior art rejections set forth in the previous action. The nonstatutory double patent rejections are hereby withdrawn. Response to Arguments – 35 USC § 101 Applicant’s arguments with respect to the rejections have been fully considered, but they are not persuasive. Applicant submits, “…Applicant respectfully contends that the Examiner has not considered the Claims as a whole, and that the Claims as amended recite specific, non-abstract technical implementations that are not performable by a human mind or with pen and paper. The amended Claims now recite, among other things, the following non-mental, technologically- rooted elements: generating a security awareness program comprising a plurality of actions including simulated phishing campaigns and electronic based training; automatically scheduling, in an electronic calendar of a selected account, each of the plurality of actions as one of a meeting or a reminder based on a type of action; generating in the electronic calendar of the selected account graphical representations of each simulated phishing campaign that are selectable to display metrics and configured to be updated in real-time as campaigns progress; automatically executing according to the schedule simulated phishing campaigns to communicate simulated phishing communications to devices of users, receiving indications of users clicking on links, and identifying a percentage of users who are phish-prone; and automatically updating in real-time the graphical representations in the electronic calendar of the selected account showing execution status and metrics as campaigns progress with users clicking on links. Even under the broadest reasonable interpretation, the Examiner cannot maintain the above elements as mental processes or as methods of organizing human activity. A human using pen and paper cannot: (i) automatically schedule a plurality of security awareness program actions as meetings or reminders in an electronic calendar of a selected account based on a type of action; (ii) generate selectable graphical representations of simulated phishing campaigns in an electronic calendar that are configured to be updated in real-time; (iii) automatically execute simulated phishing campaigns that communicate simulated phishing communications to electronic devices of users and receive indications of users clicking on links; or (iv) automatically update in real-time graphical representations in the electronic calendar showing execution status and campaign metrics as users interact with simulated phishing communications. These limitations are necessarily rooted in computer technology and cannot practically be performed in the human mind. Because the Claims as a whole are not directed to a mental process or methods of organizing human activity, and thus not directed to a judicial exception, the eligibility analysis should stop here and the Claims determined to be patent eligible. If the Examiner maintains the Claims as a whole are directed to a judicial exception, the Claims as amended are integrated into a practical application under Step 2A(ii). The additional elements, when evaluated individually and in combination, integrate any judicial exception into a practical application. Specifically, the Claims recite a specific improvement to the functioning of electronic calendar technology integrated with simulated phishing campaign management technology. The Claims do not merely automate a manual process on a generic computer; rather, they recite a particular technological solution to a technological problem, that is, the problem of efficiently scheduling, visualizing, and tracking multi-faceted security awareness programs comprising different types of actions (simulated phishing campaigns and electronic training) within an electronic calendar interface. The claimed solution addresses this problem by (a) automatically scheduling each action in the security awareness program as one of a meeting or a reminder in an electronic calendar of a selected account based on the type of action, (b) generating in that same electronic calendar selectable graphical representations of the simulated phishing campaigns that display campaign metrics, and (c) automatically updating those graphical representations in real-time as campaigns progress. This is analogous to the claims found eligible in Core Wireless Licensing S.A.R.L. v. LG Electronics, Inc., 880 F.3d 1356, 1362-63 (Fed. Cir. 2018), where the Federal Circuit held that claims reciting a specific improvement to the user interface of electronic devices providing a particular manner of summarizing and accessing data were not directed to an abstract idea. Like Core Wireless, the present Claims recite a specific manner of displaying and interacting with security awareness program data within an electronic calendar that provides an improved user interface, not merely the abstract idea of organizing or scheduling campaigns. The specification confirms this improvement, disclosing that the electronic calendar represents a proposed program schedule with meetings and reminders (Specification [0010], [0136]-[0137]), that the calendar can be overlaid against what has been implemented to show compliance ([0137]), and that graphical representations are updated in real-time as campaigns progress ([0177]). These are not generic computer functions but rather specific technological improvements to how electronic calendars function when integrated with security awareness program management. Furthermore, these Claims effect a transformation of data from the execution of simulated phishing campaigns into a dynamically updated graphical representation in the electronic calendar that provides an innovative way to visualize, schedule, and interact with campaign data. In view of these additional elements, any judicial exception is integrated into a practical application, and thus the Claims should be found patent eligible. Only if a claim (1) recites a judicial exception and (2) does not integrate that exception into a practical application, does one then look to whether the claim adds a specific limitation beyond the judicial exception that is not "well-understood, routine, conventional" in the field (see MPEP § 2106.05(d)); or simply appends well-understood, routine, conventional activities previously known to the industry, specified at a high level of generality, to the judicial exception. Applicant submits that the patent eligibility analysis should have concluded before this step. However, if the Examiner continues the analysis, Applicant submits these Claim elements are not conventional or routine and not previously known to the industry. In particular, the following elements that are integrated parts of the Claims as a whole and not merely post-solution activity are not conventional or routine: automatically scheduling, to electronically represent a proposed schedule of a security awareness program, in an electronic calendar of a selected account, each of a plurality of actions as one of a meeting or a reminder based on a type of action; generating in the electronic calendar of the selected account selectable graphical representations of simulated phishing campaigns configured to be updated in real-time; and automatically updating in real-time those graphical representations in the electronic calendar showing execution status and metrics as simulated phishing campaigns progress with users clicking on links in simulated phishing communications. It is non-conventional and not routine to automatically schedule security awareness program actions as meetings or reminders in an electronic calendar of a selected account based on a type of action, and to generate and automatically update in real-time selectable graphical representations of simulated phishing campaigns within that electronic calendar showing execution status and campaign metrics. Neither electronic calendar technology nor simulated phishing campaign technology, alone or in combination, conventionally performs these functions. The Examiner has cited Applicant's specification at [0075] for the proposition that the computing elements are conventional, but [0075] merely describes the generic computing hardware (processors, memory, network interfaces) on which the invention operates-it does not address whether the specific integration of security awareness program scheduling as meetings and reminders in an electronic calendar with real-time graphical campaign tracking is conventional. The Examiner has not provided evidence, as required by the Berkheimer Memo, that this specific integration of electronic calendar functionality with security awareness program management is well-understood, routine, or conventional. As such, Applicant submits that the Claims recite specific limitations beyond the judicial exception that are not "well-understood, routine, conventional" in the field and thus the Claims should be found patent eligible for this reason as well.….” The Examiner respectfully disagrees. Unlike Core Wireless, the claims and the argued elements, recites and directs to, …scheduling, monitoring, reminding humans’ security awareness with calendars…, which is a problem directed to organizing human activity (i.e. human organizing and scheduling activity campaigns on paper calendars for human to observing human behavior and evaluating human behavior, mitigating human social engineering risks) and a mental process (i.e. humans observing human interactions in training scenarios, human evaluating human behaviors in training scenarios, human scheduling training events on paper calendars for humans that were observed to need additional training from the training scenarios), as established in Step 2A Prong 1. This problem does not specifically arise in the realm of computer technology, but rather, this problem existed and was addressed long before the advent of computers. Thus, the claims do not recite a technical improvement to a technical problem or necessarily roots in computing technologies. Additionally, pursuant to the broadest reasonable interpretation, as an ordered combination, each of the additional elements are computing elements recited at high level of generality implementing the abstract idea, and thus, are no more than applying the abstract idea with generic computer components. Further, these additional elements generally link the abstract idea to a technical environment, namely the environment of a computer and user interface, performing extra solution activities. Therefore, as a whole, the additional elements do not integrate the abstract ideas into a practical application in Step 2A Prong 2 (i.e apply it and general link). Furthermore, as a whole, the additional elements do not amount to significantly more under Step 2B (i.e. apply it and WURC), since the additional elements are no more than mere instructions to implement the idea using generic computer components (i.e. apply it) and the additional elements append the recited abstract idea to well-understood, routine, and conventional activities in the field as individually evinced by the applicant’s own disclosure, as required by the Berkheimer Memo, see at least [0075]. Further, many of the argued “unconventional” limitations are part of the abstract ideas, and were properly identified and treated under Step 2A Prong 1. The remaining limitations merely provide for generic computer implementation and application of these abstract concepts (apply it). Generic computer implementation of abstract ideas does not amount to a practical application in Step 2A Prong 2 or significantly more than the abstract idea in Step 2B. As stated in the MPEP, "an improvement in the abstract idea itself ... is not an improvement in technology." MPEP 2106.05(a). Mere automation of a manual process or a business method being applied on a general purpose computer is not sufficient to show an improvement in computers or other technology, and the claim must include more than mere instructions to perform the method on a generic component or machinery to qualify as an improvement to an existing technology. MPEP 2106.05(a). Further, “the transformation is extra-solution activity or a field-of-use (i.e., the extent to which (or how) the transformation imposes meaningful limits on the execution of the claimed method steps). A transformation that contributes only nominally or insignificantly to the execution of the claimed method (e.g., in a data gathering step or in a field-of-use limitation) would not provide significantly more (or integrate a judicial exception into a practical application).” MPEP 2106.05(c). Thus, Applicant’s claims do not recite an improvement in technology or integrate into a practical application, but rather mental processes and certain methods of organizing human activities implemented using generic computer components. The limitations are abstract elements that are part of and directed to the recited abstract idea as described above with respect to the first prong of Step 2A, i.e. mental process and organizing human activities, generally linked to a technical environment, i.e. computer and user interface. Even novel and newly discovered judicial exceptions are still exceptions, despite their novelty. July 2015 Update, p. 3; see SAP America Inc. v. Investpic, LLC, No. 2017-2081, slip op. at 2 (Fed Cir. May 15, 2018). Simply reciting specific limitations that narrow the abstract idea does not make an abstract idea non-abstract. 79 Fed. Reg. 74631; buySAFE Inc. v. Google, Inc., 765 F.3d 1350, 1355 (2014); see SAP America at p. 12. As discussed in SAP America, no matter how much of an advance the claims recite, when “the advance lies entirely in the realm of abstract ideas, with no plausibly alleged innovation in the non-abstract application realm,” “[a]n advance of that nature is ineligible for patenting.” Id. at p. 3. [E]xamples where the courts have found the additional elements to be mere instructions to apply an exception, because they do no more than merely invoke computers or machinery as a tool to perform an existing process include: i. A commonplace business method or mathematical algorithm being applied on a general purpose computer, Alice Corp. Pty. Ltd. V. CLS Bank Int’l, 573 U.S. 208, 223, 110 USPQ2d 1976, 1983 (2014); Gottschalk v. Benson, 409 U.S. 63, 64, 175 USPQ 673, 674 (1972); Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015); ii. Generating a second menu from a first menu and sending the second menu to another location as performed by generic computer components, Apple, Inc. v. Ameranth, Inc., 842 F.3d 1229, 1243-44, 120 USPQ2d 1844, 1855-57 (Fed. Cir. 2016); iii. A process for monitoring audit log data that is executed on a general-purpose computer where the increased speed in the process comes solely from the capabilities of the general-purpose computer, FairWarning IP, LLC v. Iatric Sys., 839 F.3d 1089, 1095, 120 USPQ2d 1293, 1296 (Fed. Cir. 2016); v. Requiring the use of software to tailor information and provide it to the user on a generic computer, Intellectual Ventures I LLC v. Capital One Bank (USA), 792 F.3d 1363, 1370-71, 115 USPQ2d 1636, 1642 (Fed. Cir. 2015); Response to Arguments – Prior Art Applicant’s arguments with respect to the rejections have been fully considered, but they are not persuasive. However, Applicant’s amendments are sufficient in overcoming the cited prior art references. The closest prior art are US Patent Publication to US20170244746A1 to Hawthorn et al., (hereinafter referred to as “Hawthorn”) in view of US Patent Publication to US20080318197A1 to Dion et al., (hereinafter referred to as “Dion”) However, the teachings of the references do not teach the specific ordered sequence of limitations of independent claims 1, 11, compare one or more attributes of an entity to one or more attributes of other entities; determine, based on the comparison of the one or more attributes of the entity to the one or more attributes of the other entities, a configuration and schedule of one or more simulated phishing campaigns and an electronic based training of users of the entity for security awareness, to be executed to communicate simulated phishing communications to users of the entity to get users to click on one or more links in the simulated phishing communications; generate a security awareness program comprising a plurality of actions, wherein at least one of the plurality of actions comprises the one or more simulated phishing campaigns and wherein at least another of the plurality of actions comprises the electronic based training; automatically schedule, to electronically represent a proposed schedule of the security awareness program, in an electronic calendar of a selected account, each of the plurality of actions as one of a meeting or a reminder based on a type of action; generate in an electronic calendar of the selected account each of one or more graphical representations of each of the one or more simulated phishing campaigns according to the schedule, each of the one or more graphical representations selectable to display metrics of a corresponding simulated phishing campaign of the one or more phishing campaigns and configured to be updated in real-time as each of the one or more simulated phishing campaigns progresses; automatically execute according to the schedule the one or more simulated phishing campaigns to communicate simulated phishing communications to devices of users of the entity, receive indications of users clicking on the one or more links in the simulated phishing communications and identify from the received indications a percentage of users of the entity who are phish-prone; and automatically update in real-time the one or more graphical representations of each of the one or more simulated phishing campaigns, while displayed in the electronic calendar of the selected account according to the schedule as each of the one or more simulated phishing campaigns progresses, a status of execution and metrics of the one or more simulated phishing campaigns as the one or more simulated phishing campaigns progresses with users clicking on the one or more links in the simulated phishing communications. No Non-Patent literature teach the specific ordered sequence of limitations of independent claims 1, 11. The prior art rejection is hereby withdrawn. Claim Rejections - 35 USC § 112(b) The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 1-20 are rejected under is/are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as failing to set forth the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant(s) regard as their invention. Claim 1, 11 recites “…in an electronic calendar of a selected account…”, ‘’… generate in an electronic calendar of the selected account…”, “…displayed in the electronic calendar of the selected account…”, it is not clear if these elements refer to the same calendar. Appropriate correction is required. Claims 2-10, 12-20 depend on claim 1, 11 and do not cure the aforementioned deficiencies of claim 1, 11, and thus, claims 2-10, 12-20 is/are rejected for the reasons set forth above regarding claim 1, 11 as a result. Claim Rejections – 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 is/are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claim 1 (similarly 11) recite, “ compare one or more attributes of an entity to one or more attributes of other entities; determine, based on the comparison of the one or more attributes of the entity to the one or more attributes of the other entities, a configuration and schedule of one or more simulated phishing campaigns and an … based training of users of the entity for security awareness to be executed to communicate simulated phishing communications to users of the entity to get users to … in the simulated phishing communications; generate a security awareness program comprising a plurality of actions, wherein at least one of the plurality of actions comprises the one or more simulated phishing campaigns and wherein at least another of the plurality of actions comprises the … based training; automatically schedule, to … represent a proposed schedule of the security awareness program, in an … calendar of a selected account, each of the plurality of actions as one of a meeting or a reminder based on a type of action; generate in an … calendar of the selected account each of one or more graphical representations of each of the one or more simulated phishing campaigns according to the schedule, each of the one or more graphical representations … to display metrics of a corresponding simulated phishing campaign of the one or more phishing campaigns and configured to be updated in real-time as each of the one or more simulated phishing campaigns progresses; automatically execute according to the schedule the one or more simulated phishing campaigns to communicate simulated phishing communications to devices of users of the entity, receive indications of users … in the simulated phishing communications and identify from the received indications a percentage of users of the entity who are phish-prone; and automatically update in real-time the one or more graphical representations of each of the one or more simulated phishing campaigns, while displayed in the … calendar of the selected account according to the schedule as each of the one or more simulated phishing campaigns progresses, a status of execution and metrics of the one or more simulated phishing campaigns as the one or more simulated phishing campaigns progresses with users … in the simulated phishing communications.“ Analyzing under Step 2A, Prong 1: The limitations regarding, …compare one or more attributes of an entity to one or more attributes of other entities; determine, based on the comparison of the one or more attributes of the entity to the one or more attributes of the other entities, a configuration and schedule of one or more simulated phishing campaigns and an … based training of users of the entity for security awareness to be executed to communicate simulated phishing communications to users of the entity to get users to … in the simulated phishing communications; generate a security awareness program comprising a plurality of actions, wherein at least one of the plurality of actions comprises the one or more simulated phishing campaigns and wherein at least another of the plurality of actions comprises the … based training; automatically schedule, to … represent a proposed schedule of the security awareness program, in an … calendar of a selected account, each of the plurality of actions as one of a meeting or a reminder based on a type of action; generate in an … calendar of the selected account each of one or more graphical representations of each of the one or more simulated phishing campaigns according to the schedule, each of the one or more graphical representations … to display metrics of a corresponding simulated phishing campaign of the one or more phishing campaigns and configured to be updated in real-time as each of the one or more simulated phishing campaigns progresses; automatically execute according to the schedule the one or more simulated phishing campaigns to communicate simulated phishing communications to devices of users of the entity, receive indications of users … in the simulated phishing communications and identify from the received indications a percentage of users of the entity who are phish-prone; and automatically update in real-time the one or more graphical representations of each of the one or more simulated phishing campaigns, while displayed in the … calendar of the selected account according to the schedule as each of the one or more simulated phishing campaigns progresses, a status of execution and metrics of the one or more simulated phishing campaigns as the one or more simulated phishing campaigns progresses with users … in the simulated phishing communications..…, under the broadest reasonable interpretation, can include a human using their mind and using pen and paper to perform the these identified limitations; therefore, the claims recite a mental process. Further, …compare one or more attributes of an entity to one or more attributes of other entities; determine, based on the comparison of the one or more attributes of the entity to the one or more attributes of the other entities, a configuration and schedule of one or more simulated phishing campaigns and an … based training of users of the entity for security awareness to be executed to communicate simulated phishing communications to users of the entity to get users to … in the simulated phishing communications; generate a security awareness program comprising a plurality of actions, wherein at least one of the plurality of actions comprises the one or more simulated phishing campaigns and wherein at least another of the plurality of actions comprises the … based training; automatically schedule, to … represent a proposed schedule of the security awareness program, in an … calendar of a selected account, each of the plurality of actions as one of a meeting or a reminder based on a type of action; generate in an … calendar of the selected account each of one or more graphical representations of each of the one or more simulated phishing campaigns according to the schedule, each of the one or more graphical representations … to display metrics of a corresponding simulated phishing campaign of the one or more phishing campaigns and configured to be updated in real-time as each of the one or more simulated phishing campaigns progresses; automatically execute according to the schedule the one or more simulated phishing campaigns to communicate simulated phishing communications to devices of users of the entity, receive indications of users … in the simulated phishing communications and identify from the received indications a percentage of users of the entity who are phish-prone; and automatically update in real-time the one or more graphical representations of each of the one or more simulated phishing campaigns, while displayed in the … calendar of the selected account according to the schedule as each of the one or more simulated phishing campaigns progresses, a status of execution and metrics of the one or more simulated phishing campaigns as the one or more simulated phishing campaigns progresses with users … in the simulated phishing communications…, under the broadest reasonable interpretation, are human organizing and scheduling activity campaigns on paper calendars for human to observing human behavior and evaluating human behavior, therefore it is, managing interactions between people. Thus, the claims recite certain methods of organizing human activity. Accordingly, the claims are directed to a mental process, certain methods of organizing human activity, and thus, the claims are directed to an abstract idea under the first prong of Step 2A. Analyzing under Step 2A, Prong 2: This judicial exception is not integrated into a practical application under the second prong of Step 2A. In particular, the claims recite the additional elements beyond the recited abstract idea identified under Step 2A, Prong 1, such as: Claim 1, 11: A system comprising: one or more processors, coupled to memory, devices of users, electronic, clicking on the one or more links, electronic calendar each of one or more graphical representations, selectable, electronically Claim 2, 7, 12, 17: user interface , and pursuant to the broadest reasonable interpretation, as an ordered combination, each of the additional elements are computing elements recited at high level of generality implementing the abstract idea, and thus, are no more than applying the abstract idea with generic computer components. Further, these additional elements generally link the abstract idea to a technical environment, namely the environment of a computer. Additionally, with respect to, “compare…”, “receive…”, “clicking on the one or more links”, “update…,” “display…”, “generate…”, these elements do not add a meaningful limitations to integrate the abstract idea into a practical application because they are extra-solution activity, pre and post solution activity - i.e. data gathering – “compare…”, “receive…”, “clicking on the one or more links”,, data output – “update…,” “display…”, “generate…” Analyzing under Step 2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception under Step 2B. As noted above, the aforementioned additional elements beyond the recited abstract idea are not sufficient to amount to significantly more than the recited abstract idea because, as an order combination, the additional elements are no more than mere instructions to implement the idea using generic computer components (i.e. apply it). Additionally, as an order combination, the additional elements append the recited abstract idea to well-understood, routine, and conventional activities in the field as individually evinced by the applicant’s own disclosure, as required by the Berkheimer Memo, in at least: [0075] The client102 and server106 may be deployed as and/or executed on any type and form of computing device, e.g. a computer, network device or appliance capable of communicating on any type and form of network and performing the operations described herein. FIGs.1C and 1D depict block diagrams of a computing device100 useful for practicing an embodiment of the client102 or a server106. As shown in FIGS. 1C and 1D, each computing device100 includes a central processing unit (CPU)121, and a main memory unit122. As shown in FIG. 1C, a computing device100 may include a storage device128, an installation device116, a network interface118, an I/O controller123, display devices 124a-124n, a keyboard126, and a pointing device127, e.g. a mouse. The storage device128 may include, without limitation, an operating system129, a software131, and a software of a simulated phishing attack system120. As shown in FIG. 1D, each computing device100 may also include additional optional elements, e.g. a memory port103, a bridge170, one or more input/output devices 130a-130n (generally referred to using reference numeral130), I/O ports 142a-142b, and a cache memory140 in communication with the central processing unit121. [0085] Computing device100 (e.g., client device102) may also install software or application from an application distribution platform. Examples of application distribution platforms include the App Store for iOS provided by Apple, Inc., the Mac App Store provided by Apple, Inc., GOOGLE PLAY for Android OS provided by Google Inc., Chrome Webstore for CHROME OS provided by Google Inc., and Amazon Appstore for Android OS and KINDLE FIRE provided by Amazon.com, Inc. An application distribution platform may facilitate installation of software on a client device102. An application distribution platform may include a repository of applications on a server106 or a cloud108, which the clients 102a-102n may access over a network104. An application distribution platform may include application developed and provided by various developers. A user of a client device102 may select, purchase and/or download an application via the application distribution platform. [0087] A computing device100 of the sort depicted in FIGS. 1B and 1C may operate under the control of an operating system, which controls scheduling of tasks and access to system resources. The computing device100 can be running any operating system such as any of the versions of the MICROSOFT WINDOWS operating systems, the different releases of the Unix and Linux operating systems, any version of the MAC OS for Macintosh computers, any embedded operating system, any real-time operating system, any open source operating system, any proprietary operating system, any operating systems for mobile computing devices, or any other operating system capable of running on the computing device and performing the operations described herein. Typical operating systems include, but are not limited to: WINDOWS2000, WINDOWS Server2012, WINDOWS CE, WINDOWS Phone, WINDOWS XP, WINDOWS VISTA, and WINDOWS7, WINDOWS RT, and WINDOWS8 all of which are manufactured by Microsoft Corporation of Redmond, Washington; MAC OS and iOS, manufactured by Apple, Inc. of Cupertino, California; and Linux, a freely-available operating system, e.g. Linux Mint distribution ("distro") or Ubuntu, distributed by Canonical Ltd. of London, United Kingdom; or Unix or other Unix-like derivative operating systems; and Android, designed by Google, of Mountain View, California, among others. Some operating systems, including, e.g., the CHROME OS by Google, may be used on zero clients or thin clients, including, e.g., CHROMEBOOKS. [0088] The computing device100 (i.e., computer system) can be any workstation, telephone, desktop computer, laptop or notebook computer, netbook, ULTRABOOK, tablet, server, handheld computer, mobile telephone, smartphone or other portable telecommunications device, media playing device, a gaming system, mobile computing device, or any other type and/or form of computing, telecommunications or media device that is capable of communication. The computing device100 has sufficient processor power and memory capacity to perform the operations described herein. In some embodiments, the computing device100 may have different processors, operating systems, and input devices consistent with the device. The Samsung GALAXY smartphones, e.g., operate under the control of Android operating system developed by Google, Inc. GALAXY smartphones receive input via a touch interface. [0152] The server106 includes a user interface291 and a display293. The user interface291 enables a security awareness program system administrator to interact with the simulated phishing campaign manager250, the security awareness program manager280, the security awareness program creator270, and the query module271. [0153] The system200 also includes client102. A client102 may be a target of any simulated phishing attack or actual phishing attack. For example, the client may be an employee, member, or independent contractor working for a company that is performing a security checkup or conducts ongoing simulated phishing attacks to maintain security. The client102 may be any device used by the client. The client need not own the device for it to be considered a client device102. The client102 may be any computing device, such as a desktop computer, a laptop, a mobile device, or any other computing device. In some embodiments, the client102 may be a server or set of servers accessed by the client. For example, the client may be the employee or a member of a company. The client may access a server that is e.g. owned or managed or otherwise associated with the company. Such a server may be a client102. [0154] In some embodiments, the client102 may further include a user interface266 such as a keyboard, a mouse, a touch screen, or any other appropriate user interface. This may be a user interface that is e.g. connected directly to a client102, such as, for example, a keyboard connected to a mobile device, or may be connected indirectly to a client102, such as, for example, a user interface of a client device102 used to access a server client102. The client102 may include a display268, such as a screen, a monitor connected to the device in any manner, or any other appropriate display. [0199] While various embodiments of the methods and systems have been described, these embodiments are exemplary and in no way do they limit the scope of the described methods or systems. Those having skill in the relevant art can effect changes to form and details of the described methods and systems without departing from the broadest scope of the described methods and systems. Thus, the scope of the methods and systems described herein should not be limited by any of the exemplary embodiments and should be defined in accordance with the accompanying claims and their equivalents. Furthermore, as an ordered combination, these elements amount to generic computer components receiving or transmitting data over a network, performing repetitive calculations, electronic record keeping, and storing and retrieving information in memory, which, as held by the courts, are well-understood, routine, and conventional. See MPEP 2106.05(d). Moreover, the remaining elements of dependent claims do not transform the recited abstract idea into a patent eligible invention because these remaining elements merely recite further abstract limitations that provide nothing more than simply a narrowing of the abstract idea recited in the independent claims. Looking at these limitations as an ordered combination adds nothing additional that is sufficient to amount to significantly more than the recited abstract idea because they simply provide instructions to use a generic arrangement of generic computer components to “apply” the recited abstract idea, perform insignificant extra-solution activity, and generally link the abstract idea to a technical environment. Thus, the elements of the claims, considered both individually and as an ordered combination, are not sufficient to ensure that the claim as a whole amounts to significantly more than the abstract idea itself. Since there are no limitations in these claims that transform the exception into a patent eligible application such that these claims amount to significantly more than the exception itself, claims 1-20 are rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to PO HAN MAX LEE whose telephone number is (571)272-3821. The examiner can normally be reached on Mon-Thurs 8:00 am - 7:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rutao Wu can be reached on (571) 272-6045. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /PO HAN LEE/Primary Examiner, Art Unit 3623
Read full office action

Prosecution Timeline

Show 2 earlier events
Jun 26, 2025
Response Filed
Aug 27, 2025
Final Rejection mailed — §101, §112
Oct 27, 2025
Response after Non-Final Action
Nov 17, 2025
Request for Continued Examination
Nov 25, 2025
Response after Non-Final Action
Jan 28, 2026
Non-Final Rejection mailed — §101, §112
Apr 27, 2026
Response Filed
Jun 15, 2026
Final Rejection mailed — §101, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12620040
VALUATION OF HOMES USING GEOGRAPHIC REGIONS OF VARYING GRANULARITY
2y 4m to grant Granted May 05, 2026
Patent 12619941
TECHNICAL CANDIDATE CERTIFICATION SYSTEM
1y 11m to grant Granted May 05, 2026
Patent 12602629
USING MACHINE LEARNING TO PREDICT FLEET MOVES IN HYDRAULIC FRACTURING OPERATIONS
3y 2m to grant Granted Apr 14, 2026
Patent 12548089
OPTIMIZATION OF HYBRID GROWING INFRASTRUCTURE FOR DIFFERENT WEATHER PROFILES AND MARKET CONDITIONS
3y 3m to grant Granted Feb 10, 2026
Patent 12548046
SYSTEM FOR ACCURATE PREDICTIONS USING A PREDICTIVE MODEL
2y 0m to grant Granted Feb 10, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
31%
Grant Probability
71%
With Interview (+40.1%)
3y 7m (~2m remaining)
Median Time to Grant
High
PTA Risk
Based on 164 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month