Method · From the series on measurement and adequacy
A diagnosis does not change the environment it describes.
A thermometer does not lower a fever. The statement is obvious out of context and stops being obvious inside a risk report: whoever receives an exposure score usually expects the next reading to come out better because the reading happened. It does not. Understanding why changes how a transition program gets built.
What measurement does
IEQ takes a data envelope made of the collected public signals and, when it exists, a layer declared by the organization. It returns a score, four dimensions, the contributors that weighed most, the coverage achieved, and the calculation mode used. What it does with that is order things: it says which, among a large set of cryptographic dependencies, accumulates the most structural exposure to the risk of capture today and decryption later.
That ordering is the scarce part. No organization replaces all of its cryptography at once, and the constraint is rarely technical. It is budget, change windows, supplier contracts, and team capacity. A measure that is comparable across units, against the sector, and over time lets that limited capacity go where it returns most.
What measurement never touches
Collection observes from outside, with no credentials, no installed agent, and no changes to anything. That is an architectural choice rather than a temporary limitation. It makes it possible to assess a supplier that has never heard of GWK, and to assess your own organization without opening a change window. The price is exact: whoever only observes does not modify.
Reducing exposure requires changing the environment: switching a load balancer's negotiation policy, replacing a certificate, updating a library, migrating a service that depends on a vulnerable algorithm, renegotiating a contract with a supplier that has no post-quantum plan. Each of those actions has an owner, a deadline, operational risk, and a rollback path. None of them happens because a score was computed.
Why keep the two apart
A vendor that promises to measure and to fix with the same tool almost always does only one of the two well. Measurement has to be conservative, declare its coverage, and admit what it did not reach. Execution has to be assertive and hold opinions about the environment. The two postures compete inside the same product.
Keeping them apart also has a practical consequence in audits: whoever measures has no stake in the result. A number produced by the same party that sells the fix carries a conflict, the auditor will ask about it, and the answer needs to exist before the question does.
The objection
If measurement changes nothing, why pay for it?
For the same reason you commission a structural survey before renovating. The order in which the work happens determines the total cost, and once the work is done it is the survey that shows what changed. Without an initial measurement there is no recorded prior state, and a program that cannot show where it started cannot show progress later, however well it executed.
What this supports
- Requiring measurement before the program starts, not after, so a comparable prior state exists.
- Separating diagnosis from execution in the budget, since they are contracts of different natures.
- Telling the board what the assessment delivers, without creating the expectation that it runs the transition.
Outside the scope of this text
- This text does not claim GWK performs remediation. Execution belongs to the organization's own teams and suppliers.
- Measuring does not prevent, either. The risk addressed here is capture today and decryption later, and what has already been captured is not undone by any later action.
From the series on measurement and adequacy
What has to happen between diagnosis and verification
Five steps separate a score from a demonstrated reduction. Who owns each one, and why skipping any of them invalidates the final comparison.
Configurable, structural, and organizational signals
Not every exposure is resolved the same way. Three classes of signal, three different timelines, and why classifying before prioritizing saves quarters.
Discuss an assessment
If this text described a problem you have, the conversation starts from the scope you need to measure, with the limits written down before any proposal.