How the model works

The formula expresses total business exposure as two terms added together:

Total Exposure = V·A + ∫0tr C(t) dt

  • V·A — the value of your data (V) times a composite threat factor (A). A is the weighted sum of the five risk components below — concentration, reconstruction, jurisdiction, recovery, and integrity. When A = 1 every threat lands; when A = 0 none do.
  • 0tr C(t) dt — the accumulated cost of being offline (C, $/hr) over your recovery time (tr). Assuming a constant hourly cost this simplifies to C·tr.

How SkyeConnex moves the needle

Erasure coding (Reed–Solomon RS 5,2) and multi-vendor distribution shrink A; parallel reconstruction across providers shrinks tr; independent SHA-256 + AES-GCM verification shrinks the integrity component of A. The before/after comparison above quantifies each reduction.

The approach is borrowed from operational risk modelling — value-at-risk plus duration-of-disruption. The provider-concentration component of A is grounded in an HHI-style measure of how few vendors hold your data.

What this is and isn't

This is a directional model for framing exposure and comparing architectures — not an actuarial loss estimate. The component weights are calibrated illustratively; your own figures for data value, downtime cost, and acceptable recovery time make the output specific to you. For a posture score against the sovereign-cloud bar, use the Sovereignty Score Calculator.

Want this run on your real numbers?

The 45-minute briefing models your actual data value, downtime cost, and recovery target — and walks the architecture that shrinks each exposure component, live. We'll bring the relevant compliance preset packs pre-configured.