A classified document does not stop being classified because the technology changed.

The public sector holds information whose classification term is measured in decades and whose technology replacement depends on procurement cycles that are equally long. Both ends push the same way: the data stays sensitive for a long time, and the ability to replace its protection arrives slowly.

01Sector profile on the ruler

The comparison available

Cohort

23,330

companies · Government

Sector median

75.3

High

Half the cohort between

70.883.8

p25 – p75

Standard deviation

9.86

σ

Distribution by band

  • Critical32.3%
  • High64.8%
  • Moderate3.0%

H · time horizon

0.9559

E · observable exposure

0.5492

Cohort medians at the cutoff date. H accounts for the shelf life of the data the cryptography protects; E, for the surface reachable from outside. Both describe the cohort, not your organization.

Nearly the entire government cohort falls into the two highest bands on the ruler, and the sector median is the highest among the five sectors with a page of their own. Dispersion, however, is wide: there is meaningful distance between the best and worst positioned organizations, which means position is not destiny — part of it responds to configuration and vendor decisions.

The aggregates describe the cohort at the cutoff date, with an anonymity floor. No agency is identifiable in them.

What this comparison is measured against

Cutoff date
July 12, 2026
Run
producao_324k_20260712
Population
316,911 companies
Sectors
15 sectors in the engine taxonomy
Anonymity floor
K = 30

Limits of the comparison

  • The ruler is a static reference base, not a continuous measurement: there is no automatic update between one run and the next.
  • Comparison is always against anonymous aggregates, never against another organization's individual result.
  • A public-mode result does not compare to a complete-mode result, because the two readings start from different kinds of evidence.
02What distinguishes the sector

Government combines the longest secrecy term on the ruler with the least replacement flexibility: formal procurement, multi-year contracts, approved vendor lists, and infrastructure serving essential services that cannot stop.

  • Classification terms defined in law.
  • Procurement by formal process, on its own cycle.
  • Approved vendors and slow substitution.
  • Essential services with low tolerance for interruption.
03Data shelf life

This sector has the highest median time horizon among all sectors on the operational ruler: what it protects must stay secret for terms no other sector faces. When the secrecy term outlasts the technology guaranteeing it, the difference becomes accumulated exposure.

  • Classified information with a legal secrecy term.
  • Citizen data that follows a person for life.
  • Diplomatic and security communication.
  • Critical infrastructure and planning records.

Typical dependencies

  • Approved infrastructure and software vendors.
  • Hosting and connectivity providers for digital services.
  • Certification chains used on service portals.
  • Integrations across agencies and levels of government.
04The sector's HNDL context

When the secrecy term is measured in decades, the question stops being whether break capability will exist within it — it becomes what has already been captured. This sector is where the structure of HNDL risk shows most clearly: long-lived data, slow replacement, and a wide public surface, because public services must be reachable.

05What applies

In a sector with formal procurement, a readout must be documentable and citable before it is useful.

Exposure Report

In production

A readout from public signals, with no access to the environment.

Published methodology

In production

A documented criterion under an open license, with a citable DOI.

Appliance

Internal use

Execution inside the perimeter, when data cannot travel. Internal use, licensed by contract.

The limits of this readout

  • IEQ does not attest compliance with any standard, normative instruction, or certification requirement.
  • Collection observes only the public surface; systems on restricted networks are not in the readout.
  • The absence of a public post-quantum readiness signal does not prove the absence of an internal initiative.
  • Time scenarios are scenarios, not predictions of the cryptographic break date.

Boundary

Where measurement ends

Adequacy programNot implemented

Measurement ends at: the technical change in the environment. Measuring exposure does not reduce it: reduction requires changing configuration, replacing certificates, switching negotiation policy, or migrating libraries — work carried out by the organization's own teams and suppliers.

This readout delivers

  • Measured exposure with a documented, citable criterion.
  • Position against the sector cohort, with an anonymity floor.
  • A record of what the readout does not conclude.

After the change, GWK

  • Re-collects public signals and recalculates IEQ on the same ruler, when contracted to do so.
  • States scope, mode, coverage, and run for both measurements, so the difference is interpretable.
  • Attributes the observed effect only to the scope actually changed and verified.

Not included

  • Executing the change: GWK does not alter the client's configuration, certificates, or infrastructure.
  • Deployment, assisted operation, or change management.
  • An adequacy program: it exists as a GWK engineering project, not as a contractable capability.

Start from the method

The methodology is published under an open license and can be reviewed before any commercial conversation — including by whoever must justify the choice of criterion.