Cryptographic risk measurement

Quantum risk,now measurable.

IEQ measures your organization's cryptographic exposure and places it on the same ruler as its sector. Security, risk, and board teams get to know where migration starts, and how urgently.

Verifiable public dataTransparent proprietary methodComparable across organizationsFocused on real migration risk

Where the number comes from

Vulnerability
69.9
Exposure
60.9
Horizon
79.0
IEQ — Quantum Exposure Index2026-S1
76.3IEQ · 0 to 100High
Critical
12%
High
64%
Medium
18%
Low
6%

Data captured today still counts in 2046

Access report

Measured base

39.903organizations17sectors
01What you contract first

IEQ Exposure Report

The first thing you contract is the IEQ Exposure Report: a dated assessment of the organization, with a score from 0 to 100, sector comparison, risk factors, and priorities for the cryptographic migration.

GWK Security · IEQ01

IEQ Exposure Report

From 0 to 100, explainable and reproducible.

76.3IEQ · 0 to 100High
GWK Security · IEQ03

Executive Summary

The dimensions that weigh most in the reading, with the evidence behind each one.

01
02
03
04
05
GWK Security · IEQ04

Sector comparison

69.9V

60.9E

79.0H

02How it works

From public signal to comparable score.

No agent, no credentials, no access to internal systems. The engine computes over what is already exposed and returns a result on the sector's ruler.

  1. 01

    Public sources

    DNS, TLS, and exposed technologies

  2. 02

    Collection and normalization

    Public signals in one structure

  3. 03

    Analysis and correlation

    Vulnerability, exposure, and horizon

  4. 04

    GWK methodology (IEQ)

    Sector context and governance

  5. 05

    Comparable score

    A 0-to-100 ruler for prioritization

Collection observes what the organization keeps lit on the internet: DNS, TLS, headers, and published technologies. An optional declarative layer refines the result with internal information no public signal reveals.

See the layers and the maturity of each
03Report preview

What you get, in miniature.

The panel below uses the same component and the same sample data as the demonstration page — not a mockup.

Product sample

exemplo.com.br

63.4IEQ · 0 to 100High

IEQ score

12.1 points above the sector median.

Suggested priority: review the protocol and certificate signals identified in the full report.

Signal coverage

71%

Breakdown

68%
Horizon
71%
Vulnerability
55%
Exposure
1.06×
Governance

Fictional domain, for demonstration

See the full sample report
04Decisions it supports

The question changes by audience. The evidence doesn't.

Board, security, risk and compliance, migration program, research: every card leads to the reading that answers whoever is deciding.

05Evidence

Three in four organizations sit in high or critical exposure.

Traffic captured today can be decrypted later: the harvest-now, decrypt-later scenario, and the risk IEQ measures. NIST has finalized the PQC standards and the Brazilian ITI norm 35/2026 is in force.

What the index measures is not abstract: it is the cipher a load balancer negotiates, a certificate's validity, a protocol version.

39.903

organizations analyzed

76.4%

in high or critical exposure

90%

confidence interval of the study

10

recurring technical archetypes

IEQ Technical Report 2026-S1, June 2026. It covers 39,903 organizations across 17 sectors, aggregated under k-anonymity (K = 30) and published on Zenodo under a CC-BY licence.

Read the 2026-S1 sector report

Comparability

A number alone is only partly useful. On a shared ruler, it becomes an order of priority.

Market snapshot

There are 67 points between the most and the least exposed sector

The ordering sets the market's migration sequence, not the outcome of any single organization.

SectorSector median · 0 to 100IEQ
sector median 58.2
Government / Unclassified
85.0
Hospitals and healthcare
84.8
Pharmaceuticals and biotech
82.0
Supplementary healthcare
81.3
Materials and chemicals
76.2
Agroindustry
75.9
Industrial manufacturing
75.0
Defense and aerospace
72.8
Utilities (energy)
58.2
0255075100
SectorSector median · 0 to 100IEQ
sector median 58.2
Oil, gas, and energy
56.8
Traditional finance
55.3
Payment processing
54.7
Cloud
39.7
Telecom
38.4
SaaS
30.7
Retail and brands
18.4
E-commerce and marketplace
18.1
0255075100
ScaleCritical80–100High60–80Moderate40–60Low20–40Minimal0–20

4 of 17

sectors in the critical band

8 of 17

above the sector median

14.6 vs 2.9

exposure and vulnerability spread across sectors

Risk is also time

Level is not enough. Urgency comes from how long data captured today still counts: 20 years in health and government, 5 in retail.

See the exposure window by sector

Questions about the risk

The objections that come up in the first conversation, answered before it.

Understand the HNDL scenario
06IEQ line

The complete line of IEQ deliverables.

The Exposure Report, above, is the first thing you contract. The other four deliverables extend the same measurement: sector comparison, regression alerts, post-quantum migration, and third-party exposure.

  1. 01

    Exposure Report

    IEQ score with the contributors that weigh most

    In productionSee a sample report
  2. 02

    Sector Benchmark

    Sector percentile, against anonymous aggregates

  3. 03

    Regression Alerts

    Difference between successive collections

  4. 04

    PQC Readiness Track

    Current score against projected score, on the same ruler

  5. 05

    Third-Party Management

    Reach of exposure per supplier

See the full line of deliverables
07What IEQ is

The engine takes evidence and returns a score.

The Quantum Exposure Index takes an evidence envelope, computes, and returns an explainable result on the same ruler for any organization.

Takes

An evidence envelope: signals observed by public collection and, where it exists, what the organization declared.

Returns

A score from 0 to 100, the four dimensions, the contributors that weigh most, and the signal coverage achieved.

Used for

Prioritizing migration: where to act first, how urgently, and why.

How to read the result

  • Minimal020
  • Low2040
  • Moderate4060
  • High6080
  • Critical80100

Where the engine's job ends

The engine computes. Collection is what observes.

It does not monitor between collections, does not certify, and does not estimate when the quantum computer arrives.

What goes into the index

Four factors, one comparable readout.

Three come from public signal and have a market median. The fourth exists only if the organization reports it.

How long the data still needs to stay secret. This is the time factor of risk: data requiring twenty years of secrecy carries more exposure than short-lived data, even under the same cryptography.

Market median · 79.0

08Differentiators and limits

What GWK's measurement does that a scanner does not.

More context, more depth, and more value for decision-making.

Traditional scanner

  • ×Surface view of assets
  • ×Focus on known vulnerabilities
  • ×No business context
  • ×Isolated results
  • ×No sector comparison
  • ×Technical readout without an executive ruler

GWK measurement (IEQ)

  • The dimensions multiply
  • The same ruler for everyone
  • Our own benchmark
  • Explainable result
  • Scale without integration
  • Intellectual property preserved

Scope

Every readout declares its own scope.

Public collection has an exact reach, and it is written here. A number only holds up in a committee when you know what went into it.

See the formal basis and the method's declared scope

After the measurement

Whoever runs the environment is who reduces the exposure.

Infrastructure engineer holding a laptop beside server racks

Lowering exposure means changing concrete things: a load balancer, a certificate, a library, a supplier contract. That work belongs to the organization's own teams and suppliers, who hold the access and the responsibility for the environment. GWK measures before and after, always on the same ruler.

GWK is building EVA, for Exposure, Vulnerability and Adequacy, to cover that step. It is an ongoing project, with no closed scope and no date.

EVA solutionOn the roadmap
Read the series on measuring, changing, and verifying
09Methodology and credibility

Public method, verifiable signals, numbers with an origin.

Executive decisions without a black box: observable signals, published methodology, and privacy-preserving aggregation.

See the formal basis of IEQ

100%

integration independent

First readout from public signals, with no access to systems.

100%

reviewable statistical model

Monte Carlo and Sobol calibrate the model once. Each organization's calculation is deterministic.

DOI

public report

Methodology and aggregated data published for citation and external verification.

CC-BY

open license

The report can be reused and reviewed with attribution.

DOI

2026-S1 technical report published on Zenodo under a CC-BY license.

Read the report

Two collections, two roles

The public report and the operational ruler are distinct collections, with distinct cutoffs. Results from one do not add up with the other.

Who is GWK

Deep research, direct product.

GWK Security is a Campinas deep-tech focused on post-quantum cryptography and quantitative cryptographic risk measurement. The work combines scientific research, data engineering, and product to support security decisions.

GWK GitHub
MRMatheus Rufino

Matheus Rufino

Founder & CEO

PhD in Physics

Leads the scientific and strategic direction. Principal author of the IEQ formal framework.

RMRafael Duarte Marcelino

Rafael Duarte Marcelino

Founder & CTO

Mechanical Engineering · MBA in Data Science

Data architecture, analytics, and platform engineering for IEQ. Experience in regulated sectors.

JGJulio Smanioto Garcia

Julio Smanioto Garcia

Founder & CSO

Physics · MSc student

Scientific front for QKD, post-quantum cryptography, and the interface with experimental research.

Publications

The methodology can be read, tested, and reviewed.

Peer-reviewed output by the founders, plus an open technical report.

arXiv:2605.22569

A Formal Basis for Quantum Cryptographic Exposure Measurement under HNDL Threat

Defines cryptographic exposure under the HNDL threat and supports the structure of the index.

Rufino, Marcelino & Garcia (2026) · submitted to Elsevier

Open publication

arXiv:2605.24230

Detectability Limits for Intra-Block Temporal Drift in Finite-Key Entanglement-Based QKD

Statistical limits for detecting temporal drift in finite-key entanglement-based QKD.

Marcelino, Garcia & Rufino (2026) · Springer Nature (under review)

Open publication

DOI 10.5281/zenodo.20767648

Quantum Exposure Index Technical Report 2026-S1: Sector-Level HNDL Exposure

Applies IEQ to 39,903 organizations and consolidates HNDL exposure by sector, with migration priorities.

Garcia, Marcelino & Rufino (2026) · Zenodo · CC-BY

Open publication

Start from a real scope.

Tell us how many organizations need to be assessed and which decision the result will support.

Score, risk factors, and migration priority in a decision-ready readout.