Evidence & Findings

Materiality, not severity

Why the reach of a control failure in your own account is a different measure from the severity a scanner assigns it in the abstract.

Currentengine 9.0.0Verified 2026-08-30

Severity is not materiality

Severity is the scanner's judgement of a control in the abstract. It is identical for every customer in the world, and it cannot distinguish a medium control failing on forty resources across five regions from a critical failing on one.

Materiality is how far that failure reaches in this account.

The bands

BandCondition
Estate-wideGoverns the account as a whole, or failed on 10 or more distinct resources, or failed in every region it was evaluated in
BroadFailed on 2 or more distinct resources, or failures span more than one region
ContainedExactly one distinct resource failed
Not determinableThe evidence carried no resource identifier. Reach is not guessed at

The two adjustments

A critical control whose concern is externally reachable and whose class is preventive is escalated one band, capped at estate-wide. An open door anyone can reach carries further than its resource count suggests.

A detective control is never escalated by severity. A missing alarm is a visibility gap, not an open door, and inflating it would make the band meaningless where it matters.

Every band shows its working

Each band carries the identifiers of the rules that produced it, and the pack prints them. A band a reader cannot check is an opinion.

What it does not model

Nothing about your business. Not revenue, not data value, not workload criticality, not customer impact, not regulatory position, and not the probability of compromise. The assessment observes none of those and must not imply them.