Intelligence
Cryptographic risk measurement

Quantum exposure.
Clear decision.

IEQ, the Quantum Exposure Index, shows how much your organization depends on cryptography that may become vulnerable to quantum computing and where to act first. An executive readout that turns technical risk into migration priority.

Defines riskCompares sectorsPrioritizes action
No guessworkNo access to your systemsOpen method for review
Market snapshot
2026-S1

Median market exposure

76.3

High level

Critical34.3%
High42.1%
Moderate8.8%
Low9.9%
Minimal4.9%

Organizations measured

39.903

across 17 sectors

Vulnerability

69.9

Exposure

60.9

Horizon

79.0

Executive readout

Score, ranking, and priority in a single view for technical and executive teams.

01Why it matters

Quantum risk is already part of security planning.

Some data protected today must remain confidential for years. If that traffic is captured now, it can be stored and decrypted later, once quantum computers can break algorithms that are widely used today. This is the harvest-now, decrypt-later scenario.

The transition to post-quantum cryptography has already begun: NIST has finalized PQC standards, and the Brazilian ITI norm is in force. The challenge is not just knowing that risk exists. It is knowing where to start.

01

What is IEQ?

IEQ means Quantum Exposure Index. It is a way to measure, compare, and explain how exposed an organization is to cryptographic migration risk.

02

What problem does it solve?

It makes the discussion concrete. Instead of saying only “we need PQC”, IEQ shows which domains, sectors, and signals point to higher priority.

03

How is exposure read?

The methodology combines time urgency, cryptographic fragility, exposed surface, and governance maturity into one comparable readout.

04

What decision does it support?

Migration priority. The result helps define where to act now, where to monitor, and how to explain investment to leadership and the board.

39.903

organizations analyzed

76.4%

in high or critical exposure

90%

statistical confidence

10

recurring technical archetypes

02How it works

First the diagnosis. Then the technical conversation.

The first scan requires no agent, credential, or integration. It reads public signals your organization already exposes on the internet and turns them into a comparable score, with an explanation of the factors that most influence the result.

Collects public signals

DNS, TLS, PQC readiness, HTTP headers, and exposed technologies

Translates signals into risk

Vulnerability and exposure enter the same readout

Calculates the IEQ score

A 0 to 100 ruler for comparison and prioritization

Sector context

Data horizon and governance maturity

Σ

Delivers priority

Comparable diagnosis to guide migration, without exposing organizations

Then, an optional declarative layer can refine the diagnosis with internal information that does not appear in public signals.

03Comparability

Move beyond an isolated score. See priority.

A number alone is only partly useful. When the readout is comparable across organizations and sectors, it becomes a decision map. IEQ puts each organization on the same ruler and shows who should move first.

The sector snapshot shows where the market is most exposed today. Your organization follows the same method, domain by domain.

Risk composition by sector

The larger the critical/high share, the more urgent sector migration tends to be

Government / Unclassified
71
21
Hospitals and healthcare
75
25
Pharmaceuticals and biotech
66
34
Supplementary healthcare
54
46
Materials and chemicals
20
80
Agroindustry
14
83
Industrial manufacturing
14
84
Defense and aerospace
86
Utilities (energy)
38
62
Oil, gas, and energy
35
65
Traditional finance
21
79
Payment processing
15
85
Cloud
49
51
Telecom
33
67
SaaS
100
Retail and brands
17
83
E-commerce and marketplace
94
CriticalHighModerateLowMinimal

Exposure window by sector

The longer data must remain confidential, the earlier migration should begin

Government / Unclassified
20y
Hospitals and healthcare
20y
Pharmaceuticals and biotech
20y
Supplementary healthcare
20y
Materials and chemicals
15y
Agroindustry
15y
Industrial manufacturing
15y
Defense and aerospace
15y
Utilities (energy)
10y
Oil, gas, and energy
10y
Traditional finance
10y
Payment processing
10y
Cloud
7y
Telecom
6y
SaaS
6y
Retail and brands
5y
E-commerce and marketplace
5y

Health and government keep data for ~20 years; retail and e-commerce, around 5. The color follows sector exposure level. The decision is not only technical: it is a race against data lifetime.

04Risk is also time

It is not enough to measure level. Measure the window.

Risk changes as time passes. Data that must remain secret for twenty years carries more exposure than short-lived data, even when both use the same cryptography.

IEQ brings that clock into the readout. The question shifts from “how much risk exists” to “where do we act now to reduce accumulated exposure”.

05How IEQ earns trust

Public method, verifiable signals.

IEQ is designed to support executive decisions without becoming a black box. Measurement uses observable cryptographic signals, published methodology, and privacy-preserving statistical aggregation.

100%

integration independent

First readout from public signals, with no agent, credential, or access to systems.

100%

reviewable statistical model

Monte Carlo, Sobol analysis, and technical clustering support the score readout.

DOI

public report

Methodology and aggregated data are published for reading, citation, and external verification.

CC-BY

open license

The report can be reused and reviewed with attribution, reinforcing transparency.

2026-S1 technical report published on Zenodo under a CC-BY license.

Read the report
06Who is GWK

Deep research, direct product.

GWK Security is a Campinas deep-tech focused on post-quantum cryptography and quantitative cryptographic risk measurement. The work combines scientific research, data engineering, and product to support security decisions.

IEQ is the main engine behind that vision: academic rigor in the back, a simple readout in the front, and a focus on prioritizing migration before exposure accumulates.

MRMatheus Rufino

Matheus Rufino

Founder & CEO

PhD in Physics

Leads the scientific and strategic direction. Principal author of the IEQ formal framework.

RMRafael Duarte Marcelino

Rafael Duarte Marcelino

Founder & CTO

Mechanical Engineering · MBA in Data Science

Data architecture, analytics, and platform engineering for IEQ. Experience in regulated sectors.

JGJulio Smanioto Garcia

Julio Smanioto Garcia

Founder & CSO

Physics · MSc student

Scientific front for QKD, post-quantum cryptography, and the interface with experimental research.

07Publications

The methodology can be read, tested, and reviewed.

GWK’s technical work is documented in scientific output by the founders and in an open technical report.

01

A Formal Basis for Quantum Cryptographic Exposure Measurement under HNDL Threat

Rufino, Marcelino & Garcia (2026) · submitted to Elsevier

The formal basis of IEQ. It defines cryptographic exposure under the harvest-now, decrypt-later threat and supports the structure of the index.

arXiv:2605.22569
02

Detectability Limits for Intra-Block Temporal Drift in Finite-Key Entanglement-Based QKD

Marcelino, Garcia & Rufino (2026) · Springer Nature (under review)

Statistical limits for detecting temporal drift in finite-key entanglement-based quantum key distribution.

arXiv:2605.24230
03

Quantum Exposure Index Technical Report 2026-S1: Sector-Level HNDL Exposure

Garcia, Marcelino & Rufino (2026) · Zenodo · CC-BY

Applies IEQ to 39,903 organizations and consolidates HNDL exposure by sector, with migration priorities for post-quantum cryptography.

DOI 10.5281/zenodo.20767648

Start with your organization’s diagnosis.

Apply the IEQ method to your domains and see which public signals increase your organization’s cryptographic exposure.

Score, risk factors, and migration priority in a decision-ready readout.