Methodology
The method, in four layers.
From the formal model to the protection of the implementation: what supports IEQ, where the data comes from, how calibration is done, and what stays proprietary.
Layer 01
Model
The formal structure of the index: horizon, vulnerability, exposure, governance, and the interaction between them.
The problem with adding things up
The natural instinct when building a risk score is to add things up: weight vulnerability, weight exposure, maybe add a governance factor. Adding assumes a deficit in one dimension is offset by a surplus in another — and that is where the arithmetic parts ways with the phenomenon it is meant to describe.
Under the harvest-now-decrypt-later model, vulnerability and exposure work as complements, not as substitutes. An organization with fragile cryptography but no external surface cannot be harvested. A widely exposed organization with no vulnerable cryptography has nothing worth storing for later. The attack requires both conditions at once.
The interaction between the dimensions
IEQ handles that dependency by multiplying the dimensions rather than adding them. The choice is not a modeling preference: there is a formal, published, reviewable proof that no additive score reproduces the interaction between vulnerability and exposure, whatever the choice of weights. The form was tested against the usual alternative families, and the distinction holds empirically as well.
The practical consequence is what sets the readout apart: the weight of each dimension is endogenous. The same technical finding is not worth the same in two organizations — it is worth what their position in the vulnerability/exposure plane makes it worth. A fixed-weight score cannot express that, which is why two scanners with the same list of findings reach different priorities without being able to justify either.
From the formal model to the operational index
Between the formal result and the number delivered sits an implementation layer: transformations that stabilize the scale, the local reading of the elasticities, and a governance factor for qualitative risk that leaves no technical signal — a missing cryptographic inventory, pending regulatory compliance. That layer is proprietary, for the reasons in layer 04.
IEQ should be read as a prioritization index: it ranks, compares, and supports the decision of where to start, within a declared ruler and cutoff date. The full formal treatment — hypotheses, derivation, and proofs — is published under a DOI and can be consulted, cited, and challenged by any reviewer.
Layer 02
Data
Where the evidence comes from: the public layer, the declaratory layer, the coverage achieved, and what happens when a signal does not appear.
Two layers of evidence
The public layer gathers what the organization already exposes on the internet: algorithms, key sizes, protocol versions, and certificates of services reachable from outside. It operates with no agent, credential, or access to internal systems, and it is the only layer needed to produce a first reading.
The declaratory layer exists because part of the risk has no external signal. Cryptographic inventory, internal controls, governance milestones already delivered, and the required lifetime of the data are known only to the organization itself. When it declares those fields, they enter the envelope with their origin marked, so the engine always knows what was observed and what was reported.
Coverage, and what it means
Every assessment comes with the signal coverage achieved: how much of the expected evidence the collection actually observed. Low coverage does not invalidate the result, but it widens the uncertainty of the estimate, which is why it is published alongside the score rather than buried in a technical annex.
Where the public signal does not appear, the index takes a conservative stance: absence of evidence is never treated as evidence of absence. Organizations with little observable surface are read at worst case until the declaratory layer fills in what collection could not reach.
GWK's two populations
GWK maintains two collections with different roles. Technical report 2026-S1 publishes a cut under an open licence, so the method can be reviewed by third parties. The operational base is larger and more recent, and it is the source of the sector ruler that comparisons are made against.
These are distinct collections with distinct cutoffs. Neither is a sample of the other, and results from one do not add to the other. Every published comparison declares which base and which cutoff date support it.
Layer 03
Calibration
How each signal's contribution is set, what keeps assessments comparable, and where calibration meets its limit.
The reach of calibration
Calibration is statistical and happens once, over the reference base: it sets how much each observable signal contributes to the dimensions of the index. The calculation for a specific organization is deterministic. Given the same evidence envelope, the engine returns the same result, and that is what makes an assessment reproducible and auditable.
Calibration scores no one. It is not redone per client, not adjusted to produce a desired result, and does not look at the organization being assessed. Recalibrating per client would destroy the only property that makes sector comparison possible: a single ruler.
Each signal counts once
Observable cryptographic signals are strongly correlated with one another. A server that accepts an old protocol usually accepts the corresponding old ciphers too. Counted naively, those signals would record the same fact several times, and the vulnerability dimension would start measuring redundancy instead of risk.
Handling that coupling is part of what calibration resolves: a signal's contribution reflects the new information it brings, not a repetition of what another signal already said. It is what keeps an isolated configuration from dominating an entire organization's result.
What the ranking supports
IEQ is an index of relative exposure, and that is how it should be used: it says who acts first, how far an organization sits from its own sector's reference, and which move removes the most exposure per unit of effort. That ordering is reproducible and defensible in committee, in audit, and in front of a supplier.
It is also what the decision requires. Prioritizing a multi-year programme does not depend on an absolute probability of compromise; it depends on knowing, under a declared criterion and one ruler for everyone, what enters the first cycle and what waits for the second.
Layer 04
Protection
What is published for external review, what stays proprietary, and how the engine runs outside GWK without exposing the implementation.
What is published
The structure of the model is public: the axioms, the proof that the multiplicative form follows from them, the demonstration that no additive score reproduces it, the conceptual transformations applied to the result, and the acknowledged limitations. The sector report and the aggregated data are released under an open licence, with a DOI, so they can be cited and contested.
Publishing this is deliberate. A risk index nobody can review will rarely support an investment decision, however many decimal places it carries.
What is not published
The weight table, the per-sector parameters, the full set of implementation transformations, the fallback rules, and the internal operation of the collection remain proprietary. The boundary is this: we publish enough for the method to be audited, not enough for the product to be rebuilt.
That separation is what keeps a single ruler. If the parameters circulated, any assessment could be reproduced with weights tuned to whoever is computing, and comparability across organizations would cease to exist. That comparability is what gives the sector percentile its meaning.
Execution outside GWK
When the calculation needs to run on a partner's infrastructure, it runs through the appliance: a binary that packages collection and engine with protected weights, produces the raw output and the computed output, and keeps an auditable usage ledger. Licensing is defined per contract.
The appliance serves one specific case: integrating the engine into a third-party product without the intellectual property travelling with it. Access goes through a contract rather than self-service.
What the index measures
IEQ is an index of relative exposure: it ranks and compares organizations under a single ruler, with declared provenance and an explicit cutoff date. That is what supports the prioritization decision — where to start, what comes first, how far an organization sits from its own sector's reference.
The scope of each reading is declared alongside the result: the collection mode, the coverage achieved, and the comparison base. The full formal treatment, with the axioms and the proofs, is published for external review and can be consulted in full.