Methodology
Risk signals count curated public developments. They do not measure any organisation's security posture, they do not draw on Govern360 customer data, and they are not a market benchmark.
What is counted
Items published or updated in the previous 24 hours, drawn from the source registry, after editorial review. Duplicates across outlets are clustered and counted once.
How severity is set
Severity is assigned by a human editor against a written rubric, never by headline urgency and never by a model without review. Critical requires a confirmed primary advisory or an exploited condition affecting enterprise deployments. Items in Emerging signals are Unrated unless a primary source confirms them.
What the counts are not
They are not an index. We will not publish a composite score until we have a public scoring model, a defined source universe, historical backtesting, and independent review.