Method · From the series on measurement and adequacy
You fixed one domain. You did not fix the organization.
The temptation is arithmetic: if forty domains were measured and five were fixed, exposure fell by an eighth. The math is simple, intuitive, and wrong. The problem is not the imprecision, but the fact that it produces a number that does not survive an auditor's first question.
Why the arithmetic fails
Exposure is not a quantity that spreads evenly across assets. The model is multiplicative: time horizon, vulnerability, observable exposure, and governance interact, and no single dimension determines the total. Two domains with identical cryptographic configuration can carry very different exposures if they protect data with different shelf lives.
There is also the problem of what was not measured. Fixing five domains of the public surface says nothing about internal systems that never entered the readout, about supplier dependencies that remain unchanged, or about traffic already captured before the fix. A consolidated figure hides all three gaps behind a decimal point.
The missing rule
Carrying an effect measured on one asset up to the organizational level requires a formal aggregation rule: how to weight assets, what to do with what fell outside scope, how to treat dependencies shared across units. That rule is not defined in GWK's methodology, and it is one of the open questions of the adequacy project, not a documentation gap.
Until it exists, GWK does not publish organizational reduction derived from a partial scope, not in a case study, not in an example, not in illustrative material. Inventing the rule so it fits on a slide would produce exactly the kind of number this site exists not to produce.
What to report instead
A group does not have a score, it has a distribution. The defensible readout describes where each entity sits, how far the extremes are from the internal median, which contributors repeat across entities and, after an intervention, what changed within the scope that was actually altered and verified.
That readout is less comfortable to present and harder to contest. A board that receives distribution and scope learns more about its own program than one receiving a single number sliding down across quarters.
The objection
I have to report a single consolidated number to the board. What do I take?
Take three things instead of one: the distribution of assessed entities with the cutoff date, the exact scope changed in the period, and what moved inside it on the same ruler. That is more information, not less, and it answers the question the board actually has, which is whether the program is reaching where it needs to reach, instead of answering one the methodology cannot support.
What this supports
- Rejecting organizational reduction metrics that do not declare the scope they came from.
- Structuring the program report around distribution and scope, which is what withstands audit.
- Evaluating vendor proposals by the aggregation rule they use, and asking for it when it is not written down.
Outside the scope of this text
- The absence of an aggregation rule is a declared limitation of the methodology, not a property of the risk. It can be solved, and until then silence is the correct posture.
From the series on measurement and adequacy
How to verify risk reduction without changing rulers
Five conditions make two measurements comparable. Break any one and the delta measures method instead of risk, and the error never shows up in the final figure.
Why measuring does not reduce exposure
A diagnosis does not alter the environment it describes. What measurement solves, what it never touches, and why the separation between the two matters to whoever is buying.
Discuss an assessment
If this text described a problem you have, the conversation starts from the scope you need to measure, with the limits written down before any proposal.