Banking secrecy does not expire when the contract ends.

A financial institution holds data that must remain secret for terms longer than the useful life of any technology protecting it today. That distance between the secrecy term and the cryptography term is what defines the sector's HNDL exposure — not the quality of its current configuration.

01Sector profile on the ruler

The comparison available

Cohort

25,826

companies · Finance

Sector median

51.3

Moderate

Half the cohort between

48.358.6

p25 – p75

Standard deviation

7.57

σ

Distribution by band

  • High22.3%
  • Moderate74.6%
  • Low3.1%

H · time horizon

0.6591

E · observable exposure

0.5871

Cohort medians at the cutoff date. H accounts for the shelf life of the data the cryptography protects; E, for the surface reachable from outside. Both describe the cohort, not your organization.

The finance cohort is one of the most concentrated on the ruler: most organizations fall in the same risk band, and the distance between median and third quartile is small. That carries an uncomfortable practical consequence — sitting at the sector median distinguishes no one, and moving off it requires structural change, not a configuration tweak.

The aggregates describe the cohort at the cutoff date, with an anonymity floor. No organization is identifiable in them, and individual position requires its own assessment.

What this comparison is measured against

Cutoff date
July 12, 2026
Run
producao_324k_20260712
Population
316,911 companies
Sectors
15 sectors in the engine taxonomy
Anonymity floor
K = 30

Limits of the comparison

  • The ruler is a static reference base, not a continuous measurement: there is no automatic update between one run and the next.
  • Comparison is always against anonymous aggregates, never against another organization's individual result.
  • A public-mode result does not compare to a complete-mode result, because the two readings start from different kinds of evidence.
02What distinguishes the sector

Finance combines long retention obligations, hard-to-replace core systems, and a dense third-party chain — processors, bureaus, correspondents, and integrations all running on the same cryptography.

  • Regulatory retention measured in years, not product cycles.
  • Core systems with cryptography embedded in old layers.
  • A volume of external integrations that widen the negotiated surface.
  • Continuity requirements that restrict change windows.
03Data shelf life

Credit records, contracts, customer data, and transaction history retain value for long periods. Traffic captured today and decrypted later would still reveal sensitive information — which is the operational definition of HNDL risk.

  • Customer and relationship data, with persistent value.
  • Contracts and collateral with multi-year terms.
  • Transaction history used in models and disputes.
  • Internal communication about structured deals.

Typical dependencies

  • Processors and acquirers in the payment mesh.
  • Infrastructure and hosting providers for digital channels.
  • Certificate authorities used on exposed channels.
  • Core banking and regulatory module vendors.
04The sector's HNDL context

The relevant threat here does not require a quantum computer today: it requires someone to store traffic today and decrypt it when the capability exists. In a sector whose data stays sensitive for many years, the window between capture and break fits comfortably inside the period where secrecy still matters.

05What applies

In a sector with a dense chain and meaningful peer comparison, the three capabilities below are the ones that produce decisions.

Exposure Report

In production

Individual readout from public signals, no integration.

Sector Benchmark

In production

Position against the finance cohort, with percentile and band.

Third-party assessment

In production

Ranking the supplier portfolio by observable exposure.

The limits of this readout

  • IEQ does not assert compliance with any sector standard or regulatory requirement.
  • Public collection does not reach core systems with no external face, which is where part of the legacy lives.
  • Sector medians authorize no conclusion about a specific institution.
  • The ruler is a static reference base, with no automatic update between runs.

Boundary

Where measurement ends

Adequacy programNot implemented

Measurement ends at: the technical change in the environment. Measuring exposure does not reduce it: reduction requires changing configuration, replacing certificates, switching negotiation policy, or migrating libraries — work carried out by the organization's own teams and suppliers.

This readout delivers

  • Measured exposure and position against the sector cohort.
  • Ranked contributors, with evidence origin.
  • A readout of the third-party chain in the same window.

After the change, GWK

  • Re-collects public signals and recalculates IEQ on the same ruler, when contracted to do so.
  • States scope, mode, coverage, and run for both measurements, so the difference is interpretable.
  • Attributes the observed effect only to the scope actually changed and verified.

Not included

  • Executing the change: GWK does not alter the client's configuration, certificates, or infrastructure.
  • Deployment, assisted operation, or change management.
  • An adequacy program: it exists as a GWK engineering project, not as a contractable capability.

Start from your position

A public-signal readout requires no integration or change window, and already shows where the institution sits within the sector cohort.