Risk & Scoring
The exposure range
An indicative magnitude derived from the count and severity of failed controls. Not actuarial, not a loss estimate, and not a prediction.
What it is
A severity band is assigned once per distinct failed control, using GovIntel's own published severity banding. The bands are summed, and the total is rounded outward onto a ladder of round numbers.
What it is not
This is the most important part of the page, and the pack carries the same disclosure.
- Not actuarial. No actuarial method is applied.
- Not derived from external loss data. No breach-loss statistics, industry claims data or third-party loss dataset is used.
- Not a likelihood. It contains no probability term whatsoever.
- Not a prediction of loss to your organisation.
- Not a costing. It does not model remediation or incident-handling cost.
Severity describes the relative governance priority of a control failure. It is not financial exposure.
Why the exact sum is never printed
Summing per-control bands produces a figure with far more apparent precision than the inputs carry. Printing seven significant figures on a board page invites the reader to treat it as a measurement, when the underlying bands are order-of-magnitude judgements applied to a control count.
The summed range is therefore rounded outward onto a ladder before it is shown, and the exact sum is never printed. Below the floor it reads as a below-threshold label; above the ceiling, as an above-threshold label.
What is excluded
Cloud cost recovery. That is a real, recoverable operating cost and is reported separately, so a recoverable saving is never presented alongside a governance exposure as though the two were the same kind of number.
Provenance is printed
The basis, the source of the banding, and explicit statements that it is neither actuarial nor derived from external loss data are printed in the pack alongside the figure.
