Cybersecurity Patents: Top Companies & Filing Trends 2026
- Filings grew 46% from 2021 to 2024, rising from 767 to 1,121 records a year, with 2022 the peak year so far at 1,214.
- The field is not concentrated at the top: the leading assignee holds 362 records, and the top 10 combined account for only 17.0% of all 9,882 records in scope.
- H04L and G06F dominate the classification mix, covering 57.2% and 53.3% of records respectively, while AI-linked G06N sits at 13.9% and is still climbing.
Filing growth compares 2021 (767 records) with 2024 (1,121) — a three-year span. 2024 is the most recent year we treat as complete: publication lags filing by roughly 18 months, so 2025 onwards are still filling in and any growth rate that ends there would understate the field. Top-5 share is the combined record count of the five largest assignees divided by all 9,882 records in scope (CR5), not by the ranked leaders only.
What this landscape covers
This landscape draws on 9,882 patent records published between 2015 and mid-2026 that combine cybersecurity, information security or digital trust language with a named technical route — biometrics, software supply chain security, zero trust architecture, cloud security, application security, operational technology security, cyber threat intelligence or digital credentials. The scope is deliberately cross-cutting: it captures how established network-security vendors, financial institutions and cloud platform owners are all filing against overlapping claim territory rather than isolating any single vendor category.
Because publication lags filing by roughly 18 months, the most recent one to two years in any trend line will understate real filing activity — 2024 is the last year that can be read as a complete picture.
Let an AI agent run this analysis on your own technology
Pick a task. Every answer cites the patents behind it.
Filing trend and technology composition
Two views of the same 9,882 records: how filing volume has moved year over year, and which IPC subclasses the claims actually sit in.
Filings climbed through 2022, then eased off the peak
Annual filings rose from 400 in 2017 to a peak of 1,214 in 2022. The 2021-to-2024 span shows sustained growth of 46%, from 767 to 1,121 records; 2025 and 2026 figures are still filling in as later publications land.
H04L and G06F carry most of the claim volume
57.2% of records sit in H04L (digital information transmission) and 53.3% in G06F (electric digital data processing), reflecting how much of this field is claimed as network-layer and general-purpose data-processing art rather than a narrower category. G06Q (16.7%), G06N (13.9%) and G06K (5.1%) mark where commerce logic, AI models and recognition techniques intersect with security claims; G16H and A61B, each under 4%, show the field's smaller healthcare-adjacent edge.
Shares are the percentage of the 9,882 records in scope. A patent can carry several IPC classes, so the shares add up to more than 100%.
Go deeper on Cybersecurity, Privacy & Digital Trust Patent Landscape with Eureka
This page is one run against one query. Ask Eureka your own question about cybersecurity, privacy & digital trust patent landscape and every answer comes back with the patent numbers behind it.
Try EurekaA representative early filing
System and method for generating and refining cyber threat intelligence data (US9118702B2, BCE Inc., filed 2015)
The claim describes a feedback loop for threat intelligence: a threat list is sent to two separate intelligence sources, their original responses are used to build a revised second version of the list, and that revised list is sent back to both sources to obtain updated data. The mechanism is iterative cross-validation between independent sources rather than single-source ingestion.Filed in 2015, this is an early articulation of multi-source threat-intelligence refinement — a pattern that later cyber threat intelligence platforms have had to design around or license.


| # | Publication no. | Patent title | Citations |
|---|---|---|---|
| 1 | US6850252B1 | Intelligent electronic appliance system and method | 4,059 |
| 2 | US20090254572A1 | Digital information infrastructure and method | 2,826 |
| 3 | US6601233B1 | Business components framework | 1,860 |
| 4 | US20100250497A1 | Electromagnetic pulse (EMP) hardened information infrastructure with extractor, cloud dispersal, secure stora… | 1,775 |
| 5 | US7100195B1 | Managing user information on an e-commerce system | 1,649 |
| 6 | US20020010679A1 | Information record infrastructure, system and method | 1,634 |
| 7 | US8316237B1 | System and method for secure three-party communications | 1,622 |
| 8 | US20070053513A1 | Intelligent electronic appliance system and method | 1,452 |
| 9 | US20170041296A1 | Systems and methods of secure data exchange | 1,323 |
| 10 | US7181017B1 | System and method for secure three-party communications | 1,316 |
Citation counts favour older filings that have had more time to accumulate citations inside this corpus — read them as a signal of influence, not of current technical importance.
Each row carries its publication number; clicking a row searches Eureka by that number.
Put your own technology through the same analysis
Eureka on the web
When you want the answer in the next five minutes.
The agent works the prompt against patents and technical literature, citing every source.
Run your analysis now →MCP server & REST API
When it has to run inside your own pipeline.
Patent search, landscape analysis and assignee resolution as MCP tools. Drop them into any agent framework, or call REST directly.
Browse MCP servers →What the numbers mean for filing strategy
Read together, the concentration figures, the trend line and the classification mix point to a field that is still open at the edges despite dense claim coverage at the core.
No single owner controls the core claim space
The leading assignee holds 362 records and the top five combined reach 1,063 records, 10.8% of all records in scope. That leaves the large majority of filings spread across a long tail of single- and few-filing entrants, which means freedom-to-operate analysis has to look well past the household names.
Growth is real, but 2025–2026 will look artificially soft
Filings rose steadily through the peak year of 2022 at 1,214 records. Because publication lags filing by about 18 months, the 2025 and 2026 counts shown in any trend chart are still incomplete and should not be read as a slowdown.
Network-layer claims dominate, AI-linked claims are rising fast
H04L and G06F together cover most records, but G06N (AI models) already reaches 13.9% of the 9,882 records in scope — a share that keeps expanding as threat-detection and identity systems incorporate model-based claims.
Eureka can read the same corpus for gaps instead of for coverage: under-claimed branches adjacent to cybersecurity, privacy & digital trust patent landscape, with the prior art for and against each one.
Who is filing, and where the pace is cooling
The ranked list spans 100 companies from network-security specialists to banks and cloud platform owners. Recent-year momentum figures show pace slowing across several of the largest filers — consistent with the trend line's incomplete latest years rather than a genuine retreat from the field.
A network-security specialist tops the list
The leading assignee's 362 records outpace the fifth-place holder's 156 and the tenth-place holder's 106, but even at the top the gap to the rest of the ranked field is not so wide that newer entrants are locked out of adjacent claim territory.
Latest-year counts look low across the board
Every assignee tracked for recent-year momentum shows a steep year-over-year drop in the latest year, from a single-digit filer down 62% to a filer at zero. Given the 18-month publication lag, this pattern is expected for the newest year of data and should not be read as firms exiting the field.
Filing is concentrated in a handful of offices
The United States receives by far the largest share of filings, followed by India, the EPO and the WIPO PCT route; Australia and Canada trail well behind. That pattern reflects where enforcement and market access matter most to filers in this space, not necessarily where R&D originates.
| Assignee | Recent year | YoY |
|---|---|---|
| LUCOMM TECHNOLOGIES INC | 8 | -62% |
| Zscaler Inc | 3 | -92% |
| Microsoft Technology Licensing, LLC | 3 | -73% |
| Palo Alto Networks Inc | 2 | -90% |
| Bank of America Corp | 1 | -89% |
| Strong Force VCN Portfolio 2019 LLC | 0 | -100% |
| Centripetal Networks Inc | 0 | -100% |
| ADVANCED NEUROMODULATION SYSTEMS INC | 0 | -100% |
Where to take this next
The dataset points to specific questions worth running deeper — on claim scope, on which branches are still open, and on which filers are actually accelerating rather than just publishing.
Map freedom-to-operate against the long tail
With the top 10 assignees holding only 17.0% of records, a freedom-to-operate check has to reach well past the named leaders into the single- and few-filing entrants that make up most of the field.
Run a freedom-to-operate scan in EurekaTrack AI-linked claim growth inside G06N
G06N already covers 13.9% of the 9,882 records in scope and is the fastest-composing class outside the H04L/G06F core, worth watching as threat-detection and identity systems add model-based claims.
Monitor G06N filings in EurekaRevisit under-claimed branches before filing
OT-specific detection, credential revocation and supply-chain attestation sit outside the densest claim clusters today, which is where a well-drafted first claim has the most room to stand.
Explore white space in EurekaCommon questions about this landscape
The ranked list covers 100 companies, led by a network-security specialist with 362 records, ahead of the fifth-place holder at 156 and the tenth-place holder at 106. The top 10 assignees combined account for 17.0% of all 9,882 records in scope, which means most of the field's activity comes from companies outside that ranked top tier. Financial institutions and cloud platform owners appear alongside network-security vendors, reflecting how broadly the search terms cut across industries rather than isolating one vendor category.
Yes, based on the last complete years of data: filings rose 46% from 767 in 2021 to 1,121 in 2024, with a peak of 1,214 in 2022. Figures for 2025 and 2026 appear lower in any trend chart, but that reflects the roughly 18-month lag between filing and publication rather than an actual slowdown. Treat the most recent one to two years as still filling in, not as a decline.
H04L (digital information transmission) and G06F (electric digital data processing) are the two dominant classes, covering 57.2% and 53.3% of the 9,882 records in scope respectively — since records can carry multiple classes, these figures overlap heavily. G06Q (business and admin data processing) and G06N (AI models) follow at 16.7% and 13.9%, marking where commerce logic and machine-learning methods intersect with security claims. Smaller shares in G16H and A61B show a modest healthcare-adjacent edge to the field.
The dense claim territory sits in network-transmission and general data-processing art under H04L and G06F, so a new entrant competing head-on there faces the most crowded prior art. Branches like operational-technology-specific threat detection, digital credential revocation protocols, and supply-chain provenance attestation carry comparatively thin claim density relative to the core and are worth a closer freedom-to-operate look before drafting. The long tail of single- and few-filing assignees in the ranking also suggests that narrow, well-defined technical claims can still find room even in a heavily filed field.
US9118702B2, assigned to BCE Inc. and filed in 2015, claims a method of refining threat intelligence by sending a threat list to two independent sources, using their original responses to build a revised list, and sending that revision back to both sources for updated data. Any threat-intelligence platform that iterates a shared list across multiple independent feeds in this specific request-revise-resend pattern sits close to this claim's scope. Alternatives that avoid the two-source resend loop — for example single-source ingestion with internal correlation, or asynchronous aggregation without sending a revised list back to the original sources — are more likely to sit outside it, though a full claim chart is needed before relying on that distinction.
Research Cybersecurity, Privacy & Digital Trust Patent Landscape in depth with Eureka
Go past this page: query the whole cybersecurity, privacy & digital trust patent landscape corpus yourself, in your own scope.
Every answer comes back with patent numbers you can open.
Disclaimer. This page is generated from Patsnap Eureka data drawn from a limited snapshot of global patent and scientific-literature records, and is provided for general information and reference only.
Patent data carries inherent limitations: recent filings (typically the most recent 18–24 months) are under-counted due to standard publication lag; counts may be reported at either a patent-family or a patent-record basis and are not always directly comparable; classification, applicant-name, and citation data may contain errors, duplicates, or omissions; and the underlying search query defines and constrains the scope shown. As a result, the analysis may be incomplete or inaccurate and may not reflect the full technology landscape.
Nothing on this page constitutes an exhaustive prior-art, novelty, freedom-to-operate, or validity search, nor does it constitute legal, financial, investment, or professional advice, and it should not be relied upon as such. Any patent, commercial, or strategic decision should be verified independently and reviewed with qualified patent, legal, and domain professionals. Patsnap makes no warranties, express or implied, as to the accuracy, completeness, or fitness for any particular purpose of the information presented.
Machine translation. Assignee and organisation names originally recorded in Chinese, Japanese or Korean have been rendered into English by an AI translation step so that the tables stay readable. These renderings are best-effort and may not match a company’s registered English name; the original name is what the underlying patent record carries, and it is what any Eureka query launched from this page uses.