You already know what you have. What is missing is the ruler that orders what comes first.

Cryptographic inventory, scanning, and environment knowledge answer what exists and where. None of them alone produces a measure that is comparable across units, against the sector, and over time. That measure is what is missing when the board asks for an execution order.

01The decision

Choosing, among hundreds of known cryptographic dependencies, which enter the next cycle — and defending that choice before a committee that does not read handshakes. The constraint is not technical knowledge: it is a comparable, communicable criterion.

What is at stake

  • Without a common ruler, prioritization follows what was discovered most recently, not what accumulates the most exposure.
  • Being at the sector median is often read as being fine, and the median is not a security target.
  • Third-party environments enter scope without any access to inventory them.
  • Real technical progress stays invisible to the committee when there is no comparable prior measurement.
02Evidence

In finance, the operational ruler's median is 51.3 with a standard deviation of 7.57: half of the sector's 25,826 organizations sit between 48.3 and 58.6. The distribution is narrow — the gap between median and third quartile is 7.3 points, which means moving off the median requires structural change, not a one-off configuration tweak.

In finance, the operational ruler's median is 51.3 with a standard deviation of 7.57: half of the sector's 25,826 organizations sit between 48.3 and 58.6. The distribution is narrow — the gap between median and third quartile is 7.3 points, which means moving off the median requires structural change, not a one-off configuration tweak.

Source
GWK operational base, finance cohort
Date
July 12, 2026
Run
producao_324k_20260712
Population
25,826 organizations in the finance sector
Coverage
Public layer only: DNS, TLS, PQC readiness, headers, infrastructure, and observable subdomains.

Limitation: Quartiles describe the cohort at the cutoff date. A specific organization may sit outside the range, and an individual readout requires its own assessment — the cohort does not substitute for it.

03What applies to your work

This is the persona that pushes hardest against the boundary of what GWK does. That is why each item's maturity is stated: two are on the roadmap and should not enter planning as though they existed.

Public-signal assessment

In production

A readout with no credentials, agent, or integration — including environments you have no access to.

Cohort benchmark

In production

Percentile and band distribution against the sector, on the same ruler and cutoff date.

Governance roadmap

In production

Projection of the effect of declared actions, with current and projected state on the same complete ruler.

Regression alerts

On the roadmap

Difference between collections, TLS downgrade, expiring certificates. Product direction, not contractable scope.

Third-party management

On the roadmap

Exposure arriving through the supplier chain. Product direction, not contractable scope.

04What comes out

Technical output with provenance preserved: every number carries origin, run, and coverage, so the readout can be checked rather than accepted.

  • Score, level, and the four dimensions, with the calculation mode stated.
  • Ranked contributors, with the evidence origin for each.
  • Coverage per module and the fallbacks the model applied.
  • Comparison against the sector cohort and the corresponding percentile.
  • A PDF report for internal circulation.
  • Governance projection in complete mode, when a declaration exists.

What it depends on

  • The organization's domains, or express authorization from the owner.
  • For complete mode: a declaration covering sensitive data, critical systems, cryptographic agility, and governance.
  • A defined owner for validating what is declared — the engine consumes the data, it does not audit it.
05The method's boundary

IEQ does not replace cryptographic inventory, security architecture, or internal assessment. It measures one specific thing, and the separation below is what makes the readout usable in a technical discussion.

Observed

Public collection saw

  • TLS versions, suites, and publicly negotiated parameters.
  • Certificates, chains, and issuance policies declared in DNS.
  • Security headers and announced PQC readiness.
  • Subdomains reachable through public sources.

Calculated

The IEQ engine derived

  • Structural HNDL exposure on a common scale.
  • Relative weight of each signal in the result.
  • Risk band and position in the sector distribution.

Declared

The organization reported

  • Secrecy shelf life by data category.
  • Critical systems and dependency on Shor-vulnerable cryptography.
  • Cryptographic agility and governance posture.

Inferred

The model estimated

  • Sector prior for shelf life, when no declaration exists.
  • Model-defined fallbacks when a module fails.

Out of scope

Other evidence decides

  • A cryptographic inventory of the internal environment.
  • Conventional vulnerabilities: a low IEQ does not mean their absence.
  • Comparison between a public and a complete result — they are different rulers.
  • A supplier's internal posture from its public surface.

What this comparison is measured against

Cutoff date
July 12, 2026
Run
producao_324k_20260712
Population
316,911 companies
Sectors
15 sectors in the engine taxonomy
Anonymity floor
K = 30

Limits of the comparison

  • The ruler is a static reference base, not a continuous measurement: there is no automatic update between one run and the next.
  • Comparison is always against anonymous aggregates, never against another organization's individual result.
  • A public-mode result does not compare to a complete-mode result, because the two readings start from different kinds of evidence.

Boundary

Where measurement ends

Adequacy programNot implemented

Measurement ends at: the technical change in the environment. Measuring exposure does not reduce it: reduction requires changing configuration, replacing certificates, switching negotiation policy, or migrating libraries — work carried out by the organization's own teams and suppliers.

This readout delivers

  • A comparable measure of HNDL exposure, with provenance.
  • A defensible priority order to present to the committee.
  • Projection of declared actions' effect, in complete mode.

After the change, GWK

  • Re-collects public signals and recalculates IEQ on the same ruler, when contracted to do so.
  • States scope, mode, coverage, and run for both measurements, so the difference is interpretable.
  • Attributes the observed effect only to the scope actually changed and verified.

Not included

  • Executing the change: GWK does not alter the client's configuration, certificates, or infrastructure.
  • Deployment, assisted operation, or change management.
  • An adequacy program: it exists as a GWK engineering project, not as a contractable capability.

Bring a scope, not an RFP

Tell us which domains are in scope, whether the readout needs to be public or complete, and which decision it will support. If what you need is on the roadmap, we say so in the first conversation.