DETAILED ACTION
Notice of Pre-AIA or AIA Status
[1] The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Notice to Applicant
[2] This communication is in response to the amendment filed 28 May 2026. Claims 1, 6, 11, and 15 have been amended. Claims 1-15 are pending.
Claim Rejections - 35 USC § 101
[3] Previous rejection(s) of claims 1-15 under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter, specifically an abstract idea without significantly more has/have been overcome by the amendments to the subject claims and is/are withdrawn.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
[4] Claim(s) 1-15 is/are rejected under 35 U.S.C. 103 as being unpatentable over (United States Patent Application Publication No. 2019/0236661 hereinafter ‘Hogg’) in view of Duessel (United States Patent Application Publication No. 2022/0366332 hereinafter ‘Duessel’) and further in view of Thompson (United States Patent Application Publication No. 2024/0340301 hereinafter ‘Thompson’).
With respect to (currently amended) claim 1, Hogg discloses a for cybersecurity risk assessment, comprising: acquiring information of an industrial environment and operations of an entity (Hogg et al.; paragraphs [0015] [0050] [0059] [0087] [0121]; See at least acquiring information about the business entity/environment including analysis targeting network security, i.e., information pertaining to a network); determining an engagement scope through facilitated sessions, wherein the engagement scope comprises a set of processes vulnerable to cybersecurity attacks (Hogg et al.; paragraphs [0015] [0050] [0059] [0087] [0121]; See at least acquiring information about the business entity. See further information pertaining to specified domains. The domains of Figs. 4a and 4b are reasonably selections of scope of processes vulnerable to attacks, e.g., network security, endpoint protection etc.); performing cybersecurity review and gap assessment to generate a control gap report and a control effectiveness report (Hogg et al.; paragraphs [0064] [0067]; See at least controls); performing cybersecurity threat analysis to generate an operational threat profile (Hogg et al.; paragraphs [0184] [0185] [0224]; See at least threat profile); performing the cybersecurity risk assessment, by using the operational threat profile, to generate an operational risk profile (Hogg et al.; paragraphs [0073] [0074]; See at least risk profile); performing an impact assessment, by using the operational risk profile, to generation an operational impact profile indicating an impact of security breach materialization on a process of the set of processes vulnerable to cybersecurity attacks (Hogg et al.; paragraphs [0070]-[0071] [0150]-[0154]; See at least vulnerabilities across sector, i.e., potential impacts. See further specific analysis of individual processes within a domain and evaluations of hazards associated with specific processes, e.g., endpoint control and password authentication processes within security domain); and providing the cyber security risk assessment to business sectors of the business entity (Hogg et al.; paragraphs [0146]-[0155]; See at least reports.).
Claim 1 has been amended to specify that the previously recited “performing a cybersecurity control review” is “…performing a cybersecurity control review to determine a cybersecurity control gap comprising a network deficiency identifying a vulnerable portion of the network and leading to a risk exposure associated to a security breach, where the cybersecurity control review comprises a comparison of current internal controls safeguarding network security to control objectives…”.
With respect to these elements, Hogg discloses a cyber security assessment process which identifies and assesses the adequacy of access controls on network endpoints with respect to specific cyber-attacks, i.e., “associated to a security breach” (Hogg et al.; paragraphs [0070]-[0071] [0185]). While Hogg determines presence of specified controls in determining vulnerabilities, Hogg fails to specify that the assessment and determined control gap are specifically directed to a determined network deficiency identifying a vulnerable portion of the network and that the controls are compared to control objectives.
However, Duessel discloses a cybersecurity assessment process which enables the user to define a specific network segment to evaluate a specific control risk associated with the specified segment (Duessel et al.; paragraphs [0062] [0071] [0073]; See at least user interface interactions allow user to define the scope/environment of the control gap analysis to a define set of assets associated with a specified network segment). Duessel further indicates that current controls are compared to a defined target controls in accordance with a maturity analysis in which a gap between current controls and the target controls is generated based on stated organization risk/control priorities and risk reduction objectives (Duessel et al.; paragraphs [0073]-[0075] [0100]; See at least current controls and target controls determined based on risk reduction goals).
With respect to the previously recited step of “…applying one or more mitigation measures…”, claim 1 has been amended to further specify “…the one or more mitigation measures comprising updating the network associated with the process, by isolating a portion of the network, through segmentation, to separate the portion of the network from the remaining parts of the network to limit a potential impact of a cybersecurity attack targeting the security breach and thereby to adjust the operational impact profile…”.
With respect to these elements, as noted above, Hogg fails to specify that mitigation efforts are specified network updates. While Duessel discloses tools to define the scope/environment of the control gap analysis to a define set of assets associated with a specified network segment and further provides control gap analysis targeting network segments, Duessel fails to explicitly state that isolation of network segments via network segmentation is applied to mitigate the control gap risk.
However, as evidenced by Thompson, it is well-known in the art to implement network segmentation test to generate recommendations to properly isolate portions of the network which may be more vulnerable to attacks (Thompson et al.; paragraphs [0142]-[0143] [0186]-[0187]; See at least identification of security gaps and performance of network segmentation tests and recommendations in response to simulated phishing emails).
It would have been obvious to one of ordinary skill in the art at the time the invention was made to have modified the control assessments and mitigations of Hogg by further including network segment directed evaluation of control risk and comparison of current controls to a defined target controls in accordance with stated organization risk/control priorities and risk reduction objectives as taught by Duessel. The instant invention is directed to a system and method of assessing cybersecurity risks and recommending mitigation efforts. As Hogg discloses the use of control assessments and mitigations in the context of a system and method for assessing cybersecurity risks and recommending mitigation efforts and Duessel similarly discloses the utility of network segment directed evaluation of control risk and comparison of current controls to a defined target controls in accordance with stated organization risk/control priorities and risk reduction objectives in the context of a system and method for assessing cybersecurity risks and recommending mitigation efforts, the teachings are reasonably considered to have been derived from analogous references and applied in the manner disclosed by the respective references. Accordingly, one of ordinary skill in the art would have been motivated to make the noted combination/modification as rationalized by combining prior art elements accordingly to known methods to yield the predictable results of ensuring that information and computing systems are secure by determining which controls should be improved and the manner in which the controls should be improved such that client computing systems have increased compliance with the control-based cybersecurity security objectives.
Regarding the combination that further includes Thompson, it would have been obvious to one of ordinary skill in the art at the time the invention was made to have modified the control assessments and mitigations of Hogg by further including identification of network vulnerabilities and in the form of gaps and implementing network segmentation tests to generate recommendations to properly isolate portions of the network which may be more vulnerable to attacks as taught by Thompson. The instant invention is directed to a system and method of assessing cybersecurity risks and recommending mitigation efforts. As Hogg discloses the use of control assessments and mitigations in the context of a system and method for assessing cybersecurity risks and recommending mitigation efforts and Thompson similarly discloses the utility of implementing network segmentation tests to generate recommendations to properly isolate portions of the network which may be more vulnerable to attacks in the context of a system and method for assessing cybersecurity risks and recommending mitigation efforts, the teachings are reasonably considered to have been derived from analogous references and applied in the manner disclosed by the respective references. Accordingly, one of ordinary skill in the art would have been motivated to make the noted combination/modification as rationalized by combining prior art elements accordingly to known methods to yield the predictable results of ensuring that information and computing systems are secure by determining which controls should be improved to ensure that critical systems are properly isolated from less critical systems thereby minimizing exposure to a constantly evolving threat landscape (Thompson; paragraph [0033]).
With respect to claim 2, Hogg discloses a method further comprising deploying one or more mitigation measures to address cybersecurity risks included in the cybersecurity risk assessment (Hogg et al.; paragraphs [0184] [0185]; See at least mitigation recommendations).
With respect to claim 3, Hogg discloses a method wherein the information of the industrial environment and the operations comprise an operational profile (Hogg et al.; paragraphs [0184] [0185]; See at least threat profile regional).
With respect to claim 4, Hogg discloses a method wherein the operational threat profile comprises threat actors, threat vectors, vulnerabilities, and attack techniques (Hogg et al.; paragraphs [0184] [0185] [0224]; See at least threat profile).
With respect to claim 5, while Hogg discloses a method including updating the network (Hogg et al.; paragraphs [0239] [0240]; See at least countermeasures including firewalls), as noted above, Hogg fails to specify that mitigation measures further comprise patching, and upgrading the network.
However, Duessel further indicates that current controls are compared to a defined target controls in accordance with a maturity analysis in which a gap between current controls and the target controls is generated based on stated organization risk/control priorities and risk reduction objectives (Duessel et al.; paragraphs [0073]-[0075] [0100]; See at least current controls and target controls determined based on risk reduction goals).
Regarding claim 5, the conclusions of obviousness and rationale to modify as established for claim 1 above are applicable to claim 5 and are hereby incorporated by reference.
Claims 6-10 and 11-15, as presented by amendment, substantially repeat the subject matter addressed above with respect to claims 1-5 as directed to the enabling systems/apparatus and computer-readable medium storing computer-executable instructions. With respect to these elements, Hogg et al. disclose enabling the disclosed method employing analogous systems and executable instructions Accordingly, claims 6-10 and 11-15 are rejected under the applied teachings, conclusions obviousness, and rationale to modify as discussed above with respect to claims 1-5.
Response to Remarks/Amendment
[5] Applicant's remarks filed 28 May 2026 have been fully considered and are addressed as follows:
[i] Applicant’s remarks in response to previous rejection(s) of claim(s) 1-15 under 35 U.S.C. 101 as being directed to non-statutory subject matter as set forth in the previous Office Action mailed 11 March 2026 have been fully considered and are convincing in light of the present amendments to the pending claims. In particular, the network segment-directed analysis and mitigating isolation of an identified network segment via the gap analysis process and active segmentation of the network constitutes an integrating technical element under Step 2A prong 2 in accordance with the framework for determining patent subject matter eligibility under 35 U.S.C. 101 established in the decisions of the Supreme Court in Mayo Collaborative Services v. Prometheus Labs., Incorporated and Alice Corporation Pty. Ltd. v. CLS Bank International, et al. (See MPEP 2106 subsection III and 2106.03-2106.05). The previous rejection of pending claims 1-15 under 35 U.S.C. 101 has/have been overcome by the amendments to the pending claims and is/are withdrawn.
[ii] Applicant’s remarks directed to previous rejection(s) of claim(s) 1-15 under 35 U.S.C. 103 as being unpatentable as set forth in the previous Office Action mailed 11 March 2026 have been fully considered and are moot in light of newly added grounds of rejection responsive to the amendments to the subject claims. See revised rejection under 35 U.S.C. 103 presented above.
Conclusion
[6] The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Cited PATENT Literature:
Sweeney et al., CONTROL MATURITY ASSESSMENT IN SECURITY OPERATIONS ENVIRONMENTS, United States Patent Application Publication No. 2019/0207981, paragraphs [0067]-[0072]: Relevant Teachings: Sweeney discloses a system/method that includes steps/functions analyzing cybersecurity status of network systems by evaluating current and desired control measures.
Fainberg, CENTRALIZED NETWORK RESPONSE TO MITIGATE A DATA-BASED SECURITY RISK, United States Patent Application Publication No. 2023/0208848, paragraphs [0011]-[0018]: Relevant Teachings: Fainberg discloses a system/method that includes steps/functions segmenting networks in response to an identified threat using both physical and logical segmentation processes.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ROBERT D RINES whose telephone number is (571)272-5585. The examiner can normally be reached M-F 9am - 5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Beth V Boswell can be reached at 571-272-6737. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ROBERT D RINES/Primary Examiner, Art Unit 3625