Prosecution Insights
Last updated: August 17, 2026
Application No. 18/953,041

AUTOMATED INCIDENT TOKEN MONITORING AND DECISION PATHSYSTEM FOR CYBERSECURITY THREAT RESPONSE

Non-Final OA §101§102§112
Filed
Nov 19, 2024
Priority
May 31, 2022 — provisional 63/347,389 +2 more
Examiner
LOPEZ, MIGUEL ALEXANDER
Art Unit
Tech Center
Assignee
As0001 Inc.
OA Round
1 (Non-Final)
7%
Grant Probability
At Risk
1-2
OA Rounds
1y 5m
Est. Remaining
18%
With Interview

Examiner Intelligence

Grants only 7% of cases
7%
Career Allowance Rate
2 granted / 29 resolved
-53.1% vs TC avg
Moderate +11% lift
Without
With
+11.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
23 currently pending
Career history
60
Total Applications
across all art units

Statute-Specific Performance

§101
6.9%
-33.1% vs TC avg
§103
34.6%
-5.4% vs TC avg
§102
22.6%
-17.4% vs TC avg
§112
34.2%
-5.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 29 resolved cases

Office Action

§101 §102 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Applicant has not complied with one or more conditions for receiving the benefit of an earlier filing date under 35 U.S.C. 119(e) as follows: The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original nonprovisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994). The disclosure of the prior-filed applications, Application No. 63/457,671, 63/347,389, and 18/203,630 fail to provide adequate support or enablement in the manner provided by 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph for one or more claims of this application. None of the relied upon applications provide adequate written description support for the claim limitations “determining, by the one or more processing circuits, at least one vulnerability, threat, or security gap of the at least one entity based at least on the cybersecurity landscape” found in claims 1, 10, and 19. None of the relied upon applications provide adequate written description support for the claim limitations “determining, by the one or more processing circuits, the at least one incident” found in claims 2, 11, and 20. None of the relied upon applications provide adequate written description support for the claim limitations “and verifying, by the one or more processing circuits, the security posture using a public address corresponding with the security posture” found in claims 8 and 17. Accordingly, claims 1-20 are not entitled to the benefit of the prior-filed applications. Information Disclosure Statement The information disclosure statement (IDS) submitted on 11/19/2024, 01/21/2026, 03/30/2026, and 04/26/2026 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner. Drawings The drawings are objected to as failing to comply with 37 CFR 1.84(p)(4) because reference character “700” has been used to refer to different interfaces of Figures 7A-7J. Similarly, Figures 8A-8E utilize the same reference character “800” to refer to different interfaces, reference character “900” for Figures 9A-9H respectively, and so on. This deficiency is found in the following figures: Figures 7A-7J, 7L-7O, 8A-8E, 9A-9H, 10A-10E, 11A-11D, 13A-13E, 14A-14B, 15A-15G, 16A-16D, 18A-18C, 20A-20B, and 21A-21B with the respective reference characters 700, 800, 900, 1000, 1100, 1200, 1300, 1400, 1500, 1600, 1800, 2000, and 2100. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Specification The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification. The disclosure is objected to because of the following informalities: Paragraphs [0037] and [0041] refer to “Figure 1” generically, while there is no Figure 1 specifically, there is Figure 1A and Figure 1B. The citation to “Figure 1” should be amended such that it properly references the correct figures. Paragraphs [0049] refers to “FIGS. 2-49” while the originally filed figure numbers only go up to Figure 24. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Regarding Claims 1, 10, and 19: Independent claim 1, 10, and 19 recite the limitations “determine at least one vulnerability, threat, or security gap of the at least one entity based at least on the cybersecurity landscape” and “generate a first graphical element to display on the interface comprising at least one interactable element to perform, by the at least one entity, at least one of (i) update a configuration or (ii) maintain the configuration”. There is no support in the disclosure regarding how the inventor intended to perform these various claimed functionalities. The algorithm or steps/procedures for these claimed functions is not explained at all or is not explained in sufficient detail (simply restating the function recited in the claim is not necessarily sufficient) so that one of ordinary skill in the art would recognize that the applicant had possession of the claimed invention. The originally filed disclosure is silent with respect to how the claimed invention determines vulnerabilities, threats or security gaps based on a “cybersecurity landscape”; and is silent with respect to how the claimed displayed “graphical element to display on the interface comprising at least one interactable element” per se, as currently claimed, causes “to perform, by the at least one entity, at least one of (i) update a configuration or (ii) maintain the configuration”. Throughout the originally filed disclosure, the original figures describer various user interfaces (dashboards) for example; however, the graphical elements themselves are not described as comprising at least one interactable element to perform at least one of (i) update a configuration or (ii) maintain the configuration per se as recited in claims 1, 10, and 19. The limitations in question do not satisfy the written description requirement under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph. The specification does not describe the limitation in sufficient detail so that one of ordinary skill in the art would recognize that the applicant had possession of the claimed invention. In MPEP 2161.01, "computer-implemented functional claim language must still be evaluated for sufficient disclosure under the written description". And MPEP 2161.01(I) "generic claim language in the original disclosure does not satisfy the written description requirement if it fails to support the scope of the genus claimed." For computer-implemented inventions, the determination of the sufficiency of disclosure will require an inquiry into the sufficiency of both the disclosed hardware and the disclosed software due to the interrelationship and interdependence of computer hardware and software. The critical inquiry is whether the disclosure of the application relied upon reasonably conveys to those skilled in the art that the inventor had possession of the claimed subject matter as of the filing date. As in MPEP 2161.01 (I), "The description requirement of the patent statute requires a description of an invention, not an indication of a result that one might achieve if one made that invention." It is not enough that one skilled in the art could write a program to achieve the claimed function because the specification must explain how the inventor intends to achieve the claimed function to satisfy the written description requirement. See, e.g., Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-683, 114 USPQ2d 1349, 1356, 1357 (Fed. Cir. 2015). AS in MPEP 2161.01 “For instance, generic claim language in the original disclosure does not satisfy the written description requirement if it fails to support the scope of the genus claimed. Ariad, 598 F.3d at 1349-50, 94 USPQ2d at 1171 ("[A]n adequate written description of a claimed genus requires more than a generic statement of an invention’s boundaries.") (citing Eli Lilly, 119 F.3d at 1568, 43 USPQ2d at 1405-06); Enzo Biochem, Inc. v. Gen-Probe, Inc., 323 F.3d 956, 968, 63 USPQ2d 1609, 1616 (Fed. Cir. 2002) (holding that generic claim language appearing in ipsis verbis in the original specification did not satisfy the written description requirement because it failed to support the scope of the genus claimed); Fiers v. Revel, 984 F.2d 1164, 1170, 25 USPQ2d 1601, 1606 (Fed. Cir. 1993) (rejecting the argument that "only similar language in the specification or original claims is necessary to satisfy the written description requirement").” “The Federal Circuit has explained that a specification cannot always support expansive claim language and satisfy the requirements of 35 U.S.C. 112 "merely by clearly describing one embodiment of the thing claimed." LizardTech v. Earth Resource Mapping, Inc., 424 F.3d 1336, 1346, 76 USPQ2d 1731, 1733 (Fed. Cir. 2005). The issue is whether a person skilled in the art would understand applicant to have invented, and been in possession of, the invention as broadly claimed. In LizardTech, claims to a generic method of making a seamless discrete wavelet transformation (DWT) were held invalid under 35 U.S.C. 112, first paragraph, because the specification taught only one particular method for making a seamless DWT and there was no evidence that the specification contemplated a more generic method. "[T]he description of one method for creating a seamless DWT does not entitle the inventor . . . to claim any and all means for achieving that objective." LizardTech, 424 F.3d at 1346, 76 USPQ2d at 1733.” Regarding Claims 2, 11, and 20: Claims 2, 11, and 20 recite “determining, by the one or more processing circuits, the at least one incident”. There is no support in the disclosure regarding how the inventor intended to perform these various claimed functionalities. The algorithm or steps/procedures for these claimed functions is not explained at all or is not explained in sufficient detail (simply restating the function recited in the claim is not necessarily sufficient) so that one of ordinary skill in the art would recognize that the applicant had possession of the claimed invention. The originally filed disclosure is silent with respect to the invented intended to achieve the claimed determination of the at least one incident. It is not enough that one skilled in the art could write a program to achieve the claimed function because the specification must explain how the inventor intends to achieve the claimed function to satisfy the written description requirement. See, e.g., Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-683, 114 USPQ2d 1349, 1356, 1357 (Fed. Cir. 2015). Regarding Claims 8 and 17: Claims 8 and 17 recite “and verifying, by the one or more processing circuits, the security posture using a public address corresponding with the security posture”. There is no support in the disclosure regarding how the inventor intended to perform these various claimed functionalities. The algorithm or steps/procedures for these claimed functions is not explained at all or is not explained in sufficient detail (simply restating the function recited in the claim is not necessarily sufficient) so that one of ordinary skill in the art would recognize that the applicant had possession of the claimed invention. The originally filed disclosure is silent with respect to how the inventor intended to configure the claimed invention’s processing circuits to verify the “the security posture using a public address corresponding with the security posture”. It is not enough that one skilled in the art could write a program to achieve the claimed function because the specification must explain how the inventor intends to achieve the claimed function to satisfy the written description requirement. See, e.g., Vasudevan Software, Inc. v. MicroStrategy, Inc., 782 F.3d 671, 681-683, 114 USPQ2d 1349, 1356, 1357 (Fed. Cir. 2015). Respective dependent claims fall together accordingly. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. The term “cybersecurity landscape” in claims 1, 10, and 19 is a relative term which renders the claim indefinite. The term “cybersecurity landscape” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. The term “cybersecurity landscape” is not a term of the art, and one of ordinary skill would not be appraised of the scope as to what a “cybersecurity landscape” would comprise as claimed, and there is no definition of the term provided in the originally filed disclosure. Independent claims 1, 10, and 19 further recite “a first graphical element to display on the interface comprising at least one interactable element to perform, by the at least one entity, at least one of (i) update a configuration or (ii) maintain the configuration”. The recited function does not follow from the structure recited in the claim, so it is unclear whether the function requires some other structure or is simply a result of operating the “device” in a certain manner. Here, it is unclear whether the claimed updating or maintaining of the configuration is performed by the entity or by generating the claimed first graphical element to display on the interface comprising at least one interactable element. Thus, one of ordinary skill in the art would not be able to draw a clear boundary between what is and is not covered by the claim. See MPEP 2173.05(g) for more information. Dependent claims 3 and 12 recite “wherein generating the first graphical element to display on the interface further comprises the at least one interactable element to perform, by the at least one entity, at least one of (iii) transmit the at least one vulnerability, threat, or security gap to a third-party, or (iv) request input, and wherein the monitoring is continuous”. The recited function does not follow from the structure recited in the claim, so it is unclear whether the function requires some other structure or is simply a result of operating the “device” in a certain manner. Thus, one of ordinary skill in the art would not be able to draw a clear boundary between what is and is not covered by the claim. See MPEP 2173.05(g) for more information. Dependent claims 7 and 16 recite “wherein the at least one additional cyber incident affecting a plurality of third parties”. The recited function does not follow from the structure recited in the claim, so it is unclear whether the function requires some other structure or is simply a result of operating the “device” in a certain manner. Thus, one of ordinary skill in the art would not be able to draw a clear boundary between what is and is not covered by the claim. See MPEP 2173.05(g) for more information. Respective dependent claims fall together accordingly. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-7, 10-16, and 18-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract idea without significantly more. Independent claim(s) 1 recite(s) A method for modeling cyber data corresponding with at least one incident, the method comprising: generating, by one or more processing circuits, an interface comprising at least a security posture stream corresponding with a security posture of at least one entity; generating, by the one or more processing circuits, the security posture stream in the interface comprising a timeline of cyber incidents, changes in the security posture, and corresponding cybersecurity threat levels; monitoring, by the one or more processing circuits, a cybersecurity landscape based on receiving or identifying at least one security vulnerability, cyberattack information, or incident information; determining, by the one or more processing circuits, at least one vulnerability, threat, or security gap of the at least one entity based at least on the cybersecurity landscape; and in response to determining the at least one vulnerability, threat, or security gap, generating, by the one or more processing circuits, a first graphical element to display on the interface comprising at least one interactable element to perform, by the at least one entity, at least one of (i) update a configuration or (ii) maintain the configuration. Under the 2019 Revised Patent Subject Matter Eligibility Guidance (“2019 PEG”), effective January 7, 2019, independent claim 1 is directed to an abstract idea without being significantly more nor being integrated into a practical application. The claimed invention generates a generically recited interface comprising “a security posture stream of at least one entity”, further generates “the security posture stream” in the generically recited interface comprising incidents, changes in “posture”, and cybersecurity threat levels, “monitor[s]” a “cybersecurity landscape” based on further receiving more security information, “determin[es]” “at least one vulnerability, threat, or security gap of the at least one entity based at least on the cybersecurity landscape”, and in response to the determination further generates a “graphical element” to display on the generically recited interface “at least one interactable element to perform” and intended use of “(i) update a configuration or (ii) maintain the configuration”. The claim limitations identified above, as drafted, under the broadest reasonable interpretation, are broad enough to encompass limitations that can practically be performed in the human mind, including for example, observations, evaluations, judgments, and opinions. Except for the by one or more processing circuits and the generically recited interface generation language in the independent claim 1, which does no more than generally link the use of the judicial exception to a particular technological environment or field of use. This judicial exception is not integrated into a practical application. The additional generically recited computer elements beyond the abstract idea, taken both individually and as a combination, in independent claim 1 does not integrate the judicial exception into a practical application. The limitations of generating, by one or more processing circuits, an interface…, generating, by the one or more processing circuits, the security posture stream in the interface… and generating, by the one or more processing circuits, a first graphical element to display on the interface comprising at least one interactable element to perform, by the at least one entity, at least one of (i) update a configuration or (ii) maintain the configuration are recited at a high level of generality (i.e. in the context of these claims, as a general way of obtaining information, reciting numerous generic user interfaces, and a generic graphical element with generic output interface elements/data) and amounts to mere data gathering, which is a form of insignificant extra-solution activity. See MPEP 2106.05(g). Insignificant extra-solution activity and mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. For example, the originally filed disclosure and claims do not recite a specific improvement to computer technology (a new or novel interface or graphical element). Accordingly, independent claim 1 is directed to an abstract idea. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional computer elements of using processing circuits and generically recited interface elements amounts to no more than mere instructions to apply the exception using generic computer components. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claims are not patent eligible. Therefore, independent claim(s) 10 and 19 are rejected under 35 U.S.C. § 101 as being directed to non-statutory subject matter for the same reasons identified above for independent claim 1. Thus, the claims 1-7, 10-16, and 18-20 are rejected under 35 U.S.C. § 101 as being directed to non-statutory subject matter as the claims do not contain any element or combination of elements that is sufficient enough to ensure that the patent in practice amounts to significantly more than a patent upon the ineligible concept itself. Dependent claims 2, 11 and 20 do not contain any element or combination of elements sufficient to incorporate the abstract idea into a practical application because they only describe that the at least one incident is determined, data is stored in a generically recited distributed ledger or database, and that a second generically recited graphical element corresponding to the incident is presented. Dependent claims 3 and 12 do not contain any element or combination of elements sufficient to incorporate the abstract idea into a practical application because they only describe what the generically recited graphical elements further comprise and their intended use. Dependent claims 4 and 13 do not contain any element or combination of elements sufficient to incorporate the abstract idea into a practical application because they only describe that a generically recited configuration is updated or maintained responsive to an interaction with the generically recited interface, which amounts to a further recitation of mere data gathering, which is a form of insignificant extra-solution activity. Dependent claims 5 and 14 do not contain any element or combination of elements sufficient to incorporate the abstract idea into a practical application because they only describe that an incident readiness of the at least one entity based on the configuration and the at least one incident which is recited at a high level and is broad enough to encompass limitations that can practically be performed in the human mind, including for example, observations, evaluations, judgments, and opinions. Dependent claims 6 and 15 do not contain any element or combination of elements sufficient to incorporate the abstract idea into a practical application because they only describe what kind of data is displayed in “the security posture stream”. Dependent claims 7 and 16 do not contain any element or combination of elements sufficient to incorporate the abstract idea into a practical application because they only describe further generically recited interfaces and graphical elements and what the respective interfaces and elements comprise. Dependent claim 18 does not contain any element or combination of elements sufficient to incorporate the abstract idea into a practical application because it only describes further updating the security posture and providing generically recited “visual indicators” in the previously recited generically interface corresponding with the security posture stream, which amounts to a further recitation of mere data gathering, which is a form of insignificant extra-solution activity. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Berger et. al. (US Publication No. US 2023/0283521 A1) hereinafter Berger. Regarding Claims 1, 10, and 19: Claim 10. Berger discloses a system for modeling cyber data corresponding with at least one incident, the system comprising: one or more processing circuits configured to (Berger [0217], [0268-0269], [0273-0274]): generate an interface comprising at least a security posture stream corresponding with a security posture of at least one entity (Berger [0071-0078]); generate the security posture stream in the interface comprising a timeline of cyber incidents, changes in the security posture, and corresponding cybersecurity threat levels (Berger [0071-0078] “In generating cybersecurity status interface 300, the user interface unit 160 or some other component of the cybersecurity assessment system 120 may analyze past and present assessments and remediation completions, and generate displays of the cybersecurity status. In some embodiments, the cybersecurity status interface 300 may incorporate data from previous and current cybersecurity reports, and present a dynamic visualization of the change in cybersecurity status over time”); monitor a cybersecurity landscape based on receiving or identifying at least one security vulnerability, cyberattack information, or incident information (Berger [0071-0073] continuous monitoring disclosed); determine at least one vulnerability, threat, or security gap of the at least one entity based at least on the cybersecurity landscape (Berger [0058] “The cybersecurity assessment system can also provide information regarding cybersecurity events in substantially real time”, [0076] “In some embodiments, portal interface 200 may also include cybersecurity event ticker 224. Cybersecurity event ticker 224 can present real-time alerts, warnings, and notifications of cybersecurity events and risks detected during continuous cybersecurity monitoring, event scanning, and vulnerability scanning. In some embodiments, ticker 224 displays cybersecurity event display objects 226A, 226B, 226C, 226D, and 226E in the order in which each event is detected by the cybersecurity assessment system 120. In some embodiments, selection of a cybersecurity event object—or the ticker 224 in general—may cause display of ticker interface 500, discussed in greater detail below. While the ticker 224 is portrayed as a component of portal interface 200, it will be appreciated that in some embodiments the alerts and warnings presented in ticker 224 may be transmitted to a client system on the target network 100, stored in a database within the cybersecurity assessment system 120, or transmitted to a remote device”); and in response to determining the at least one vulnerability, threat, or security gap, generate a first graphical element to display on the interface comprising at least one interactable element to perform, by the at least one entity, at least one of (i) update a configuration or (ii) maintain the configuration (Berger Figs. 2-4, [0058], [0075-0080] “Selection of option 222 may cause presentation of an interface, such as vulnerabilities interface 400, that utilizes vulnerability data to identify and present vulnerabilities detected on the target network 100, to present remediation recommendations to address the vulnerabilities, to provide export of vulnerability data to other systems, etc.”). Claims 1 and 19 disclose substantially the same content and are therefore rejected under the same rationales. Berger further discloses a method (Berger [0102], [0275], claim 1). Berger further discloses A non-transitory computer readable medium (CRM) comprising one or more instructions stored thereon and executable by one or more processors (Berger [0268-0269], [0275]). Regarding Claims 2, 11, and 20: Claim 11. Berger further discloses the system of claim 10 (Berger [0217], [0268-0269], [0273-0274]), the one or more processing circuits configured to: determine the at least one incident (Berger [0058] “The cybersecurity assessment system can also provide information regarding cybersecurity events in substantially real time”, [0076] “In some embodiments, portal interface 200 may also include cybersecurity event ticker 224. Cybersecurity event ticker 224 can present real-time alerts, warnings, and notifications of cybersecurity events and risks detected during continuous cybersecurity monitoring, event scanning, and vulnerability scanning. In some embodiments, ticker 224 displays cybersecurity event display objects 226A, 226B, 226C, 226D, and 226E in the order in which each event is detected by the cybersecurity assessment system 120. In some embodiments, selection of a cybersecurity event object—or the ticker 224 in general—may cause display of ticker interface 500, discussed in greater detail below. While the ticker 224 is portrayed as a component of portal interface 200, it will be appreciated that in some embodiments the alerts and warnings presented in ticker 224 may be transmitted to a client system on the target network 100, stored in a database within the cybersecurity assessment system 120, or transmitted to a remote device”); store data corresponding with the at least one incident in a distributed ledger or database (Berger [0176-0177]; [0214-0215]); and present, using the interface, a second graphical element corresponding with the at least one incident (Berger [0058], [0076]). Claims 2 and 20 disclose substantially the same content and are therefore rejected under the same rationales. Regarding Claims 3 and 12: Claim 12. Berger further discloses the system of claim 10 (Berger [0217], [0268-0269], [0273-0274]), further comprising the at least one interactable element to perform, by the at least one entity, at least one of (iii) transmit the at least one vulnerability, threat, or security gap to a third-party, or (iv) request input, and wherein the monitoring is continuous (Berger Figs. 2-4, [0058], [0071-0080] “Selection of option 222 may cause presentation of an interface, such as vulnerabilities interface 400, that utilizes vulnerability data to identify and present vulnerabilities detected on the target network 100, to present remediation recommendations to address the vulnerabilities, to provide export of vulnerability data to other systems, etc.”). Claim 3 discloses substantially the same content and is therefore rejected under the same rationales. Regarding Claims 4 and 13: Claim 13. Berger further discloses the system of claim 10 (Berger [0217], [0268-0269], [0273-0274]), the one or more processing circuits configured to: receive, responsive to an interaction via the interface, a selection of the at least one interactable element (Berger [0071-0078], [0140], [0246-0248], [0270] “Features disclosed herein that include obtaining user input and/or providing output to users are not limited to the specific examples described and shown in the figures. In some embodiments, other methods of input, output, and interactivity may be used”); and updating or maintaining, by the one or more processing circuits, the configuration (Berger Figs. 2-4, [0058], [0071-0080] “Selection of option 222 may cause presentation of an interface, such as vulnerabilities interface 400, that utilizes vulnerability data to identify and present vulnerabilities detected on the target network 100, to present remediation recommendations to address the vulnerabilities, to provide export of vulnerability data to other systems, etc.”). Claim 4 discloses substantially the same content and is therefore rejected under the same rationales. Regarding Claims 5 and 14: Claim 14. Berger further discloses the system of claim 10 (Berger [0217], [0268-0269], [0273-0274]), the one or more processing circuits configured to: determine an incident readiness of the at least one entity based on the configuration and the at least one incident (Berger Fig. 22 and [0225] tasks being completed; Figs. 27-28 and [0247-0251] compliance tasks; [0178]). Claim 5 discloses substantially the same content and is therefore rejected under the same rationales. Regarding Claims 6 and 15: Claim 15. Berger further discloses the system of claim 10 (Berger [0217], [0268-0269], [0273-0274]), wherein the timeline of the security posture stream comprises cybersecurity effectiveness, coverages, and requirements corresponding with the at least one entity (Berger [0071-0078] “In generating cybersecurity status interface 300, the user interface unit 160 or some other component of the cybersecurity assessment system 120 may analyze past and present assessments and remediation completions, and generate displays of the cybersecurity status. In some embodiments, the cybersecurity status interface 300 may incorporate data from previous and current cybersecurity reports, and present a dynamic visualization of the change in cybersecurity status over time”), and wherein the at least one vulnerability, threat, or security gap of the at least one entity corresponds with the at least one incident (Berger [0071-0078]). Claim 6 discloses substantially the same content and is therefore rejected under the same rationales. Regarding Claims 7 and 16: Claim 16. Berger further discloses the system of claim 10 (Berger [0217], [0268-0269], [0273-0274]), the one or more processing circuits configured to: generate, using the interface, a third graphical element and a fourth graphical element, the third graphical element comprising data of the at least one incident (Berger [0071-0078] “In generating cybersecurity status interface 300, the user interface unit 160 or some other component of the cybersecurity assessment system 120 may analyze past and present assessments and remediation completions, and generate displays of the cybersecurity status. In some embodiments, the cybersecurity status interface 300 may incorporate data from previous and current cybersecurity reports, and present a dynamic visualization of the change in cybersecurity status over time”), and the fourth graphical element comprising data of at least one additional cyber incident, wherein the at least one additional cyber incident affecting a plurality of third parties (Berger [0071-0078] “In generating cybersecurity status interface 300, the user interface unit 160 or some other component of the cybersecurity assessment system 120 may analyze past and present assessments and remediation completions, and generate displays of the cybersecurity status. In some embodiments, the cybersecurity status interface 300 may incorporate data from previous and current cybersecurity reports, and present a dynamic visualization of the change in cybersecurity status over time”; [0069] “A single cybersecurity assessment system 120 may be configured to assess the cybersecurity status of any number of target networks 100. In some embodiments, a single target network 100 may be assessed by multiple cybersecurity assessment systems 120”, [0078] statistics regarding requirements compliance; [0098] “In some embodiments, the cybersecurity assessment system 120 may be configured to assess target networks for compliance with multiple distinct cybersecurity frameworks. Each cybersecurity framework may or may not share individual cybersecurity factors or subsets thereof with any number other cybersecurity frameworks. A single target network may be assessed for compliance with any or all of the cybersecurity frameworks available to the cybersecurity assessment system 120”). Claim 7 discloses substantially the same content and is therefore rejected under the same rationales. Regarding Claims 8 and 17: Claim 17. Berger further discloses the system of claim 10 (Berger [0217], [0268-0269], [0273-0274]), the one or more processing circuits configured to: update the security posture based on the at least one incident (Berger [0213], [0259], [0261-0262]); record the security posture in a distributed ledger or database (Berger [0176-0177]; [0214-0215]); and verify the security posture using a public address corresponding with the security posture (Berger [0214-0215] blockchain address to maintain “facts, solutions, threats, or remediation data or documents”). Claim 8 discloses substantially the same content and is therefore rejected under the same rationales. Regarding Claims 9 and 18: Claim 18. Berger further discloses the system of claim 10 (Berger [0217], [0268-0269], [0273-0274]), the one or more processing circuits configured to: update the security posture stream to comprise the security posture and a corresponding time (Berger [0082] and [0198] time of events contemplated; [0213] “At block 1975, the cybersecurity AI/ML service 1742 may provide information regarding the determined remediation(s). Illustratively, the information regarding the determined remediation(s) may be presented in any of a variety of modalities, such as: text-based and/or graphic-based presentations via a GUI; text-based output provided via a chatbot; audio output via a voice-based system using pre-recorded or synthesized speech; etc. The information may identify the highest-probability remediation(s), information about implementing the remediations, etc. In some embodiments, a recommended remediation may be automatically implemented without manual intervention”, [0259] “At block 2614, the computing system performing the process 2600 may update an overall assessment score (also referred to as the cybersecurity status score) for the target network. The update may be performed so that the cybersecurity status score for the target network reflects compliance or noncompliance with the objective evidenced by the artifact approved during process 2600. Subsequently, when a user accesses an interface to review cybersecurity status information, such as interfaces 300, 1400, and/or 2500, the cybersecurity status score that is displayed will reflect compliance or noncompliance with the objective”; [0261-0262]); and provide a plurality of visual indicators in the interface corresponding with the security posture stream (Berger [0213] “At block 1975, the cybersecurity AI/ML service 1742 may provide information regarding the determined remediation(s). Illustratively, the information regarding the determined remediation(s) may be presented in any of a variety of modalities, such as: text-based and/or graphic-based presentations via a GUI; text-based output provided via a chatbot; audio output via a voice-based system using pre-recorded or synthesized speech; etc. The information may identify the highest-probability remediation(s), information about implementing the remediations, etc. In some embodiments, a recommended remediation may be automatically implemented without manual intervention”, [0259] “At block 2614, the computing system performing the process 2600 may update an overall assessment score (also referred to as the cybersecurity status score) for the target network. The update may be performed so that the cybersecurity status score for the target network reflects compliance or noncompliance with the objective evidenced by the artifact approved during process 2600. Subsequently, when a user accesses an interface to review cybersecurity status information, such as interfaces 300, 1400, and/or 2500, the cybersecurity status score that is displayed will reflect compliance or noncompliance with the objective”; [0261-0262]). Claim 9 discloses substantially the same content and is therefore rejected under the same rationales. Conclusion The prior art made of record in the submitted PTO-892 Notice of References Cited and not relied upon is considered pertinent to applicant’s disclosure. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MIGUEL A LOPEZ whose telephone number is (703)756-1241. The examiner can normally be reached 8:00AM-5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached on 5712727624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /M.A.L./ Examiner, Art Unit 2496 /KEVIN AYALA/Primary Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Nov 19, 2024
Application Filed
Jul 30, 2026
Non-Final Rejection mailed — §101, §102, §112 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
7%
Grant Probability
18%
With Interview (+11.1%)
3y 2m (~1y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 29 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month