A group does not have a score. It has a distribution.

The natural question from anyone who controls several entities is what the group's number is. There isn't one: exposure does not add up, nor can it be computed as a revenue-weighted average. What does exist — and is more useful — is the distribution across entities, who sits at the extremes, and where dispersion shows governance has not reached evenly.

01The problem

Allocating attention and capital across entities of the same group, or assessing a portfolio of holdings, without a metric that can be compared across them.

What is at stake

  • Each entity reports on its own criterion, and the consolidated view becomes a sum of different things.
  • The smaller, more exposed entity disappears behind the weight of the largest.
  • Recent acquisitions join the group with unknown posture and no baseline.
  • Without measured dispersion, there is no way to know whether the group program reached the extremes.
02Evidence

The operational ruler positions each entity against its own sector cohort, which matters in diversified groups: a technology subsidiary and a healthcare one should not be compared to each other by absolute score, because the data shelf-life priors entering the calculation differ by construction.

The operational ruler positions each entity against its own sector cohort, which matters in diversified groups: a technology subsidiary and a healthcare one should not be compared to each other by absolute score, because the data shelf-life priors entering the calculation differ by construction.

Source
GWK operational base, sector aggregates
Date
July 12, 2026
Run
producao_324k_20260712
Population
316,911 companies in the operational base
Coverage
Public layer only: DNS, TLS, PQC readiness, headers, infrastructure, and observable subdomains.

Limitation: Sector percentiles make entities from different sectors comparable in relative position, not in absolute score. The group's consolidated view remains a distribution, not a single number.

03What applies

The same ruler as the benchmark application, with the readout organized by corporate structure instead of by sector.

Per-entity assessment

In production

Score, dimensions, and contributors for each entity, in the same collection window.

Percentile by home sector

In production

Each entity positioned against its own sector cohort, not against its siblings.

Distribution and dispersion

In production

How the group distributes across bands, and how far the extremes sit from the internal median.

Portfolio analytical report

In production

A consolidated PDF readout, with the distribution and comparability caveats.

04What comes out

A distribution readout, not a consolidated figure. The difference is methodological and is stated in every piece of the deliverable.

  • Score and band for each entity, with the shared cutoff date.
  • Each entity's percentile against its own sector.
  • The group's distribution across risk bands.
  • Internal dispersion and identification of the extremes.
  • Recurring contributors: what shows up across several entities.
  • A consolidated analytical report, with comparability caveats.

What it depends on

  • A list of entities with each one's domains.
  • A declared sector per entity, when the detected one is not sufficient.
  • Collection in the same window for the entire portfolio.
05Why there is no single group number

Consolidating exposure into a single value would require an aggregation rule the methodology does not define — and inventing one to fit a slide would be exactly the kind of number that does not survive a question.

Observed

Public collection saw

  • Each entity's public surface, collected identically.
  • Signals shared across entities of the same group.

Calculated

The IEQ engine derived

  • Score and dimensions per entity.
  • Sector percentile and band for each.
  • Dispersion across the set.

Inferred

The model estimated

  • Each entity's sector, when not declared.
  • Shared infrastructure relationships between entities.

Out of scope

Other evidence decides

  • A consolidated group score.
  • That a subsidiary's exposure transfers to the parent.
  • Direct comparison of absolute scores across different sectors.
  • Valuation, credit risk, or estimated financial impact.

What this comparison is measured against

Cutoff date
July 12, 2026
Run
producao_324k_20260712
Population
316,911 companies
Sectors
15 sectors in the engine taxonomy
Anonymity floor
K = 30

Limits of the comparison

  • The ruler is a static reference base, not a continuous measurement: there is no automatic update between one run and the next.
  • Comparison is always against anonymous aggregates, never against another organization's individual result.
  • A public-mode result does not compare to a complete-mode result, because the two readings start from different kinds of evidence.

Boundary

Where measurement ends

Adequacy programNot implemented

Measurement ends at: the technical change in the environment. Measuring exposure does not reduce it: reduction requires changing configuration, replacing certificates, switching negotiation policy, or migrating libraries — work carried out by the organization's own teams and suppliers.

This readout delivers

  • The group's distribution, with the extremes identified.
  • Each entity's position against its own sector.
  • A common criterion, applied in the same collection window.

After the change, GWK

  • Re-collects public signals and recalculates IEQ on the same ruler, when contracted to do so.
  • States scope, mode, coverage, and run for both measurements, so the difference is interpretable.
  • Attributes the observed effect only to the scope actually changed and verified.

Not included

  • Executing the change: GWK does not alter the client's configuration, certificates, or infrastructure.
  • Deployment, assisted operation, or change management.
  • An adequacy program: it exists as a GWK engineering project, not as a contractable capability.

Bring the structure

Entities, domains, and sectors. With that, the readout comes out in the same window for the whole portfolio, which is the condition for the distribution to mean anything.