CUPP Cybersecurity v. Symantec: 9-Patent Cybersecurity Dispute Transferred to Delaware
CUPP Cybersecurity LLC filed suit against Symantec Corporation in the Eastern District of California, asserting nine US patents spanning endpoint security, network security, and encryption technology against Norton and Symantec’s flagship product lines. After 1,853 days of proceedings, the case was transferred unopposed to the District of Delaware, where litigation continues.
A heavyweight cybersecurity IP dispute finds a new venue after five years
CUPP Cybersecurity LLC filed this infringement action against Symantec Corporation on January 17, 2019 in the Eastern District of California, asserting nine issued US patents against Symantec’s most commercially significant product lines: Norton Security, Symantec Endpoint Security, Symantec Network Security, and Symantec’s Endpoint Encryption products. The patents-in-suit span multiple cybersecurity disciplines — from endpoint behavioral monitoring and network threat detection to data encryption — suggesting a broad-based assertion strategy rather than a single-claim attack.
Rather than reaching a merits decision, the case concluded in the Eastern District of California through a court-granted transfer to the District of Delaware. The plaintiffs filed an unopposed motion to transfer (Dkt. No. 123), with Symantec’s non-opposition confirmed by surrounding docket filings (Dkt. Nos. 121, 124). Judge William H. Orrick agreed that transfer was appropriate and ordered the Clerk to close the E.D. Cal. file. The absence of opposition from Symantec — a defendant with substantial litigation resources — is commercially significant and may suggest strategic alignment on venue by both parties.
The case ran for 1,853 days before transfer — over five years — without a final merits ruling. That extended timeline, combined with a consensual venue change, suggests the parties may have been engaged in substantive claim construction and discovery activity prior to the strategic decision to consolidate or continue proceedings in Delaware, a jurisdiction historically preferred for complex patent litigation. The public record does not disclose whether settlement negotiations were concurrent with the transfer motion, nor what specific factor triggered the timing of the venue change in early 2024.
Filing to Case Transferred in 1853 days
1,853 days in E.D. Cal. before transfer — well above the median time-to-resolution for patent cases in that district
What a transfer to the District of Delaware means for both parties
Unopposed transfer: jurisdiction shifts, claims survive intact
A case transfer under 28 U.S.C. § 1404(a) moves the action to a new federal district without dismissing or resolving any claims. All pending motions, discovery record, and claim construction proceedings carry over. Judge Orrick’s grant of the transfer here was predicated on both parties agreeing — a relatively unusual posture that typically accelerates the transfer process and leaves the merits entirely open for the receiving court.
No dismissal — claims fully preservedCUPP retains all nine patent claims in a plaintiff-friendly venue
The District of Delaware is among the most active patent litigation venues in the United States and is generally regarded as well-versed in complex, multi-patent technology disputes. For CUPP, securing transfer to Delaware — and doing so unopposed — preserves all nine asserted patents and positions the case before judges with deep familiarity with patent claim construction, making it potentially advantageous for a patent assertion entity with a broad portfolio.
All 9 patents remain liveSymantec’s non-opposition suggests a deliberate venue strategy
Symantec’s decision not to oppose the transfer is notable. Large defendants typically contest venue changes when they view the original forum as unfavorable. The non-opposition here may suggest that Symantec perceived Delaware as preferable to E.D. Cal. for the merits phase, or that broader litigation coordination — potentially involving related cases — made Delaware consolidation strategically attractive. No costs were awarded, leaving Symantec’s financial exposure entirely in the Delaware proceeding.
Non-opposition is commercially significantNine cybersecurity patents now active in Delaware’s patent docket
With nine patents covering endpoint security, network threat detection, and encryption now before the District of Delaware, competitors and licensees in the cybersecurity sector should treat this as an active IP risk. Norton and Symantec Endpoint Security remain the named products, but the breadth of the asserted patent claims — spanning behavioral monitoring, network security, and encryption — means the relevant freedom-to-operate questions extend well beyond Symantec’s specific implementations.
Broad claim scope — sector-wide relevanceFull party and counsel information
| Role | Name | Type | Detail |
|---|---|---|---|
| Plaintiff | CUPP Cybersecurity, LLC | Company | Cybersecurity patent licensing entity — holder of US9747444B1 and 8 related security patentsSearch in Eureka ↗ |
| Defendant | Symantec Corporation | Company | Symantec Corporation — developer of Norton, Endpoint Security, Network Security, and Encryption productsSearch in Eureka ↗ |
| Plaintiff counsel | Austin W Manes | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff counsel | James R. Hannah | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Kristopher B. Kastens | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Kristopher Benjamin Kastens | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Lisa Kobialka | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Mark C. Nelson | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Mark Christopher Nelson | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Paul J. Andre | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Paul Joseph Andre | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff counsel | Phuong Diem Nguyen | Attorney | Counsel for CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff law firm | Barnes & Thornburg LLP | Law Firm | Representing CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Plaintiff law firm | Kramer, Levin, Naftalis & Frankel LLP | Law Firm | Representing CUPP Cybersecurity, LLCSearch in Eureka ↗ |
| Defendant counsel | Alex Nelson Hadduck | Attorney | Counsel for Symantec CorporationSearch in Eureka ↗ |
| Defendant counsel | Eugene Marder | Attorney | Counsel for Symantec CorporationSearch in Eureka ↗ |
| Defendant counsel | Jerry R. Selinger | Attorney | Counsel for Symantec CorporationSearch in Eureka ↗ |
| Defendant counsel | Michael A. Jacobs | Attorney | Counsel for Symantec CorporationSearch in Eureka ↗ |
| Defendant counsel | Michael Guo | Attorney | Counsel for Symantec CorporationSearch in Eureka ↗ |
| Defendant counsel | Nathaniel Bryan Sabri | Attorney | Counsel for Symantec CorporationSearch in Eureka ↗ |
| Defendant counsel | Robin L. Brewer | Attorney | Counsel for Symantec CorporationSearch in Eureka ↗ |
| Defendant counsel | Robin Lynn Brewer | Attorney | Counsel for Symantec CorporationSearch in Eureka ↗ |
| Defendant counsel | Stefani Elise Shanberg | Attorney | Counsel for Symantec CorporationSearch in Eureka ↗ |
| Defendant law firm | Morrison & Foerster LLP | Law Firm | Representing Symantec CorporationSearch in Eureka ↗ |
| Defendant law firm | Patterson & Sheridan LLP | Law Firm | Representing Symantec CorporationSearch in Eureka ↗ |
| Defendant law firm | Perkins Coie LLP | Law Firm | Representing Symantec CorporationSearch in Eureka ↗ |
| Presiding judge | Judge William H. Orrick | Judge | California Eastern District CourtSearch in Eureka ↗ |
Official order — verbatim text
Judge Orrick’s transfer order is procedural rather than substantive — it resolves no claim on the merits and issues no finding on infringement, validity, or damages. The court’s reliance on both parties’ non-opposition (confirmed by Dkt. Nos. 121 and 124) indicates this was an administratively straightforward §1404(a) transfer. For CUPP, all nine patents survive intact. For Symantec, the transfer resets the procedural posture before a Delaware judge, with no E.D. Cal. findings to carry forward.
US9747444B1 and 8 further patents — cybersecurity endpoint, network, and encryption
The nine patents-in-suit — including lead patent US9747444B1 (App. No. 15/586,176) — form a cohesive portfolio addressing multiple layers of enterprise cybersecurity infrastructure. The patents span endpoint behavioral monitoring, network threat detection, encrypted data protection, and security policy enforcement. Filing dates range from 2008 (US8365272B2, App. No. 12/130,914) through 2016 (US9843595B2, App. No. 15/371,164), reflecting a sustained R&D programme in cybersecurity systems over nearly a decade.
For the enterprise cybersecurity sector, this portfolio’s breadth is strategically significant. Rather than protecting a single product feature, the patents collectively cover architectural elements — agent-based endpoint monitoring, network anomaly detection, encryption management — that are foundational to virtually every major endpoint and network security platform. That makes FTO clearance for competing products non-trivial and elevates the settlement value of the portfolio for any vendor whose products touch these technology domains.
Should you run an FTO analysis against US9747444B1 and the CUPP portfolio?
Any organisation developing or marketing endpoint security software, network threat detection platforms, or enterprise encryption products should treat the CUPP portfolio as an active FTO priority. With nine patents now before the District of Delaware and all claims preserved, the risk is not theoretical. The named products — Norton Security, Symantec Endpoint Security, Symantec Network Security, and Endpoint Encryption — are market-wide reference implementations, and claim scope in these patents may extend to competing architectures.
PatSnap Eureka’s FTO Search Agent can map each of the nine CUPP patents against your product’s technical architecture, identify independent claims most likely to read on endpoint agent behaviour and network monitoring components, and surface prior art that may support invalidity arguments. Running a portfolio-level FTO analysis now — before the Delaware case reaches claim construction — gives your legal and R&D teams the lead time to design around or prepare a challenge strategy.
Run a freedom-to-operate analysis on US9747444B1 to assess your product’s exposure
Run FTO in Eureka →Similar cybersecurity patent infringement cases in U.S. federal courts
Explore related multi-patent cybersecurity infringement actions in U.S. district courts, including comparable endpoint security and network security portfolio assertions.
Related patent case — similar technology
Comparable case in the same technology domain. Patent holder and defendant reached resolution after proceedings.
SettledRelated infringement action — same court
Comparable Norton Security Products-adjacent infringement action. Patent enforcement dynamics analysed in depth.
Active · District CourtRelated invalidity challenge — appellate outcome
Combined invalidity and infringement action in the same technology space. Decided after substantive proceedings.
DecidedCUPP Cybersecurity, LLC’s broader IP enforcement history
CUPP Cybersecurity, LLC’s full litigation history covering prior enforcement, licensing activity, and inter partes review proceedings.
Portfolio viewWhat this case signals for the cybersecurity IP enforcement landscape
Nine asserted patents, a five-year timeline, and a consensual transfer to Delaware together suggest a high-stakes, strategically managed cybersecurity IP dispute.
Multi-patent cybersecurity assertions are increasing in complexity and duration
Cases asserting nine or more patents against enterprise security products routinely run five-plus years before resolution. CUPP’s strategy — broad assertion across endpoint, network, and encryption disciplines — makes early summary judgment difficult and increases settlement leverage. IP teams at security vendors should expect extended timelines in similar multi-patent disputes.
Delaware is becoming the de facto venue for enterprise cybersecurity IP disputes
The consensual transfer from E.D. Cal. to D. Del. reinforces Delaware’s status as the preferred jurisdiction for complex patent litigation involving enterprise software and security products. Parties in the cybersecurity sector should audit their litigation strategy and corporate structure with Delaware’s procedural norms in mind from case inception.
CUPP’s 9-patent portfolio signals a structured licensing enforcement programme
Asserting nine patents spanning distinct cybersecurity sub-domains against a single defendant’s product suite is consistent with a portfolio-level licensing strategy, not a one-off infringement claim. Security vendors with products touching endpoint behavior, network anomaly detection, or data encryption should treat CUPP’s portfolio as a monitored risk and conduct proactive FTO analysis before product launches.
Transfer timing and non-opposition may foreshadow a settlement or consolidation
When both parties agree to a venue change after five years of district court proceedings — without a cost award or merits ruling — it frequently precedes either settlement or consolidation with a related proceeding in the new venue. Practitioners monitoring CUPP v. Symantec in D. Del. should watch for early case management orders that may reveal parallel proceedings or licensing discussions.
CUPP v Symantec — key questions answered
CUPP Cybersecurity LLC sued Symantec Corporation in the Eastern District of California in January 2019, asserting nine US patents against Norton Security, Symantec Endpoint Security, Symantec Network Security, and Symantec Endpoint Encryption products. After 1,853 days, the case was transferred unopposed to the District of Delaware in February 2024. No merits ruling was issued by the E.D. Cal. court.
CUPP asserted nine US patents: US9747444B1, US10084799B2, US9106683B2, US8365272B2, US9781164B2, US8631488B2, US8789202B2, US9756079B2, and US9843595B2. The patents collectively cover endpoint behavioral security monitoring, network threat detection, security policy enforcement, and data encryption — spanning application filings from 2008 through 2016.
The plaintiffs filed an unopposed motion to transfer under 28 U.S.C. §1404(a), citing the District of Delaware as the appropriate venue. Symantec did not oppose the motion, and Judge William H. Orrick granted the transfer, directing the Clerk to close the E.D. Cal. file. The specific reasons motivating both parties to agree on Delaware are not disclosed in the public transfer order.
No. A §1404(a) transfer does not dismiss or resolve any claims. All nine asserted patents and all pending matters carry over to the District of Delaware. The E.D. Cal. file is administratively closed, but the litigation is ongoing in the new venue. No infringement, validity, or damages findings were made by the transferring court.
CUPP accused four Symantec product categories: Norton Security Products, Symantec Endpoint Security Products, Symantec Network Security Products, and Symantec’s Endpoint Encryption products. These represent core enterprise and consumer security offerings in Symantec’s portfolio, indicating a broad product-level assertion strategy rather than a targeted single-product claim.
Track the CUPP v. Symantec cybersecurity IP dispute as it continues in Delaware
With nine patents now active in the District of Delaware, monitoring claim construction and IPR activity is critical for any cybersecurity vendor. PatSnap Eureka delivers real-time docket alerts and FTO analysis across the full CUPP portfolio.
PatSnap Eureka searches patents and litigation data to answer instantly.