Microsoft · Filed Mar 7, 2025 · Published Sep 10, 2026 · verified — real USPTO data

Microsoft Patents a Security Scoring System That Ranks Threats by How Critical Each Computer Is

Not all computers in a company are equally important, but most security dashboards treat them as if they were. Microsoft has patented a way to score threats that accounts for which machines actually matter most.

A security scoring system evaluates computing, storage, and power systems, using scope definitions and asset criticality to generate a security score. Drawing from patent filing US 2026/0267991 A1.
A security scoring system evaluates computing, storage, and power systems, using scope definitions and asset criticality to generate a security score.
See all 4 drawings from this filing ↓
Publication number US 2026/0267991 A1
Applicant Microsoft Technology Licensing, LLC
Filing date Mar 7, 2025
Publication date Sep 10, 2026
Inventors Asaf HARARI, Yaron David FRUCHTMANN, Shay Chriba SAKAZI, Idan HEN, Tamer SALMAN, Evengy BOGOKOVSKY, Ram Haim PLISKIN
CPC classification 726/25
Grant likelihood Medium
Examiner WANG, HARRIS C (Art Unit 2439)
Status Non Final Action Mailed (Jun 3, 2026)
Document 20 claims

How Microsoft's security score weights each machine's importance

Most companies run hundreds or thousands of computers, servers, and devices, and when something goes wrong, security teams have to decide which problem to fix first. Today, that triage is often manual, inconsistent, or based purely on how severe a vulnerability looks in isolation, without factoring in how important the affected machine actually is to the business.

Microsoft's patent describes a scoring system that changes that. It assigns each machine two numbers: one for how bad its security problems are, and one for how critical that machine is to the organization. A server that runs your company's payroll, for example, gets a higher importance weight than an employee's rarely-used test laptop. The system then combines those two numbers into a single overall score for a group of machines, like a department or an entire organization.

The practical payoff is that security teams get a prioritized to-do list rather than a raw dump of alerts. Fixing the most critical machine's problems improves the overall score the most, so the math itself points IT staff toward the highest-impact fixes first.

From the filing · CLAIM 1
… generating a first asset level security score for the first computing asset of the system of the computing assets as a function of at least first security issue type risk weights corresponding to the first security issue instances …

Translation: The system calculates a safety score for each individual device based on the specific security problems found on it.

How asset criticality and issue weights combine into one score

The patent describes a method for generating layered security scores across a fleet of computing assets (any device, server, or cloud resource in an organization's network).

At the lowest layer, each asset gets an asset-level security score. The system identifies every security problem on that machine and maps each problem to a category, such as "unpatched software" or "weak passwords." Each category carries a pre-assigned risk weight (a number reflecting how dangerous that class of problem is). Those weights are combined into a single score for the machine.

At the higher layer, each machine is also assigned a criticality weight reflecting how important it is to the organization, independent of its current security state. A database server holding customer records would score higher than a test environment machine. The patent then combines the asset-level score and the criticality weight to produce a scope-level score, which represents the security health of a defined group of assets, like a business unit or the whole company.

Finally, the system works backward: it identifies which machine, if fixed, would improve the overall scope score the most. This gives operators a ranked action list rather than an undifferentiated pile of alerts.

From the filing · THE ABSTRACT
A scope level security score is generated as a function of the first criticality weight and the first asset level security score.

Translation: It then combines individual device scores with how important those computers are to calculate an overall risk level.

What this means for IT teams managing sprawling networks

For an IT administrator managing dozens or hundreds of machines, the hardest part of security is not finding problems; it's deciding which ones to fix today. A long list of vulnerabilities with no priority ordering is nearly useless under real time pressure. A score that bakes in both severity and business importance turns that list into something actionable.

The reader-facing payoff is indirect but real. When your employer's security team patches the right machine first because a scoring system pointed them there, a breach becomes less likely. Microsoft's steady investment in enterprise security tooling suggests this fits into a broader push to make products like Microsoft Defender and Azure Security Center more prescriptive, telling administrators what to do rather than just what is wrong.

That makes this Microsoft's 400th filing in our Microsoft coverage since May, a corpus that spans work like locking down shared chip settings and hiding clicks from your PC.

Editorial take

When a company's systems get breached, the post-mortem almost always reveals the same thing: the vulnerable machine was sitting in a long queue because nobody had formally decided it mattered more than the others. This scoring system makes that decision automatically, weighing each machine by how critical it is and how badly it is exposed, then surfacing which fix would do the most good across the whole organization.

The practical payoff arrives the moment a security team opens their morning dashboard. Instead of triaging hundreds of alerts by instinct, they see a ranked list where the most dangerous combination of "important machine plus serious flaw" rises to the top.

For a person whose job is keeping a company safe, that reordering is the whole game. The breach you prevent is invisible, but it is also the one that does not end careers or make the news.

There are more where this came from

We read every patent application Big Tech publishes and send you the ones worth knowing. Plain English, free, every week.

The drawings

4 drawing sheets from US 2026/0267991 A1 · click any drawing to enlarge

Patent filing page

Source. Full patent text and figures from the official USPTO publication PDF.