Why the IEQ multiplies, not adds.

The structural justification, with proof, for why vulnerability and exposure are complements — and why no additive score reproduces that interaction.

The problem with adding things up

The natural instinct when building a risk score is to add things up: weight vulnerability, weight exposure, maybe add a governance factor. That's the full compensability assumption in the composite-indicator literature (OECD, 2008) — a deficit in one dimension is perfectly offset by a surplus in another.

Under the HNDL model, vulnerability (V) and exposure (E) are not substitutes — they're complements. An organization with high vulnerability but zero external exposure cannot be harvested. An organization with high exposure but no quantum-vulnerable cryptography has nothing of value for an adversary to capture. Both conditions must hold simultaneously for the attack to work. No choice of weights in an additive formula recovers this interaction.

Three structural hypotheses

We model attacker and defender as two races of constant-rate (exponential) processes. The adversary tries to exploit captured data before the defender renders it strategically worthless — through natural data expiry, operational key rotation, or cryptographic remediation. The attack rate takes the form λ_A = λ₀ · Vᵃ · Eᵇ: multiplicative, because a compromise requires the simultaneous occurrence of two approximately independent conditions — the adversary being able to reach the asset (E), and that asset using vulnerable cryptography (V).

This multiplicative form is supported by three axioms established for contest success functions (Skaperdas, 1996): anonymity (the attack rate depends only on V and E, not on who the organization is), independence of irrelevant alternatives (the ratio of attack rates between two organizations depends only on their own V, E pair), and homogeneity (the attack rate is homogeneous of positive degree in V and E jointly).

The third hypothesis assumes that, given a cryptographically relevant quantum computer has arrived, the probability that the attacker exploits the data before the defender neutralizes it follows the proportional Tullock (1980) contest form — the attacker wins in proportion to their relative attack rate.

The formal result

Under these three hypotheses, we prove that the HNDL compromise probability factors as P_HNDL = H · (VᵃEᵇ)/(VᵃEᵇ + θ), where H is the probability that a relevant quantum computer arrives within the data's adversarial horizon, and θ is the ratio between defense and attack intensity.

A direct consequence: the cross-partial of ln(P_HNDL) with respect to ln(V) and ln(E) is strictly negative for any finite, positive V, E, θ. This means the elasticities of V and E — how much the score moves, in percentage terms, for a 1% change in V or E — are endogenous: they depend on where the organization sits in the vulnerability–exposure plane, not on fixed global constants.

Why additive scoring doesn't work — the proof

For any additive separable score S = Σ wᵢxᵢ, the cross-partial in natural coordinates ∂²S/∂V∂E = 0 by construction: the marginal contribution of V is independent of E. But for P_HNDL, direct computation shows this cross-partial is nonzero across nearly the entire (V, E) domain. Therefore no additive score can simultaneously match ∂P/∂V and ∂P/∂E across the full domain. An ordinal transformation (ranking) preserves the sign of first derivatives but cannot recover the interaction structure.

We tested this multiplicative form against alternatives (CES — constant elasticity of substitution —, log-additive, and threshold forms) using the Vuong test for non-nested model comparison. The CES form yielded a positive log-log cross-partial, inconsistent with the expected theoretical structure — empirically confirming the structural distinction between the two model families.

Two readings of risk: level and time

P_HNDL describes the compromise probability itself. The operational IEQ applies three implementation-specific transformations on top of it: floors to prevent score collapse at boundary values, local log-linearization via the endogenous elasticities, and a governance multiplier M ≥ 1 for qualitative risk factors (absence of a cryptographic inventory, regulatory non-compliance) not directly captured by V and E.

The published IEQ should be read as an operational prioritization index, with ordering locally consistent with P_HNDL within a fixed regime of H, θ, and M — not as a globally calibrated probability across heterogeneous sectors.

Acknowledged limitations

The model assumes that cryptographic posture (V) and external exposure (E) are approximately independent in the cross-sectional distribution of the population — an approximation that holds in large, heterogeneous populations but can fail in sectors with tightly integrated supply chains, where an organization's internal posture correlates with that of its providers. There is currently no dataset of confirmed HNDL exploitations: absolute calibration is infeasible in the pre-quantum-computer regime, and signal influence is assessed against the internal variance structure of observable data, not against confirmed outcomes.