What everyone else scores
Every diagnostic run leaves an anonymous row — four layer scores, sector, jurisdiction, action class and volume band, with nothing that identifies anyone. This is what those rows say.
3 runs so far — not enough to publish a median.
A sector median is published once it has at least 12 completed runs. Below that the number says more about who happened to take the assessment than about the sector, and publishing it would be exactly the kind of unsupported quantification this practice exists to challenge.
Currently held back: Banking & capital markets (1) · Healthcare & life sciences (1) · Other regulated industry (1)
How to read it
- Scores are 0–100 per layer, weighted into an overall. Below 30 is a critical gap, 30–54 weak, 55–79 developing, 80 and above defensible.
- Only runs at 60% completeness or better are counted, so a run abandoned after two questions cannot drag a sector down.
- Rows carry no identifier — no organisation, no email, no IP address — so nothing here can be traced to a respondent, including by me.
- The rubric is fixed and deterministic. The same answers always produce the same score, which is what makes comparison across respondents meaningful at all.
Method and data handling: data & privacy · run the assessment.
Your score is only useful next to the obligation
A median tells you where the field sits. What matters is the gap between your evidence and what your regime expects — that is a twenty-minute conversation, not a number.