← Argus · Methodology · Sources & licensing · Track record · Live demo

Glossary

55 terms the register, board pack and methodology page use, each with what it means and why it changes what you do. Where a definition depends on a constant, it points at the methodology, which renders the number from the code that runs it.

Scoring

Theater

A named region of geopolitical activity with a fixed polygon (Taiwan Strait, Red Sea & Horn of Africa, …). Events are routed to a theater; assets fall inside one by coordinates or country.

Why it matters: Likelihood is scored per theater, so the theater an asset lands in decides which evidence it inherits. Methodology →

Event

One observed occurrence from a named source — a naval transit, a sanctions designation, an earthquake — with a type, a theater or footprint, a date, a confidence and a source link.

Why it matters: Events are the only input to likelihood. Nothing in a score is an opinion; every score can be unrolled to its events. Sources & licensing →

Event type

The controlled vocabulary an event is classified into (adiz-incursion, sanctions-action, tropical-cyclone, …). Each type carries a fixed severity weight.

Why it matters: The taxonomy is what makes events from different publishers comparable; it is versioned and identical across both engine implementations. Methodology →

Confidence

How well an event is evidenced: high (primary source), medium (reputable secondary), low (uncorroborated). It is a weight on the event, not on the score.

Why it matters: News-derived events start at low confidence. Two rules can raise one to medium, never to high: a primary source reporting the same thing, or enough separate outlets carrying it. Only an official or primary source reaches high. Many low-confidence reports can still add up, so a region covered mainly by machine-coded news can reach a high level on volume alone; recent events count most. Methodology →

Likelihood (1–5)

Per-theater tempo: the last seven days of weighted activity against the theater's own previous eight weeks, in spreads, cut into five bands (methodology 2026.10). A theater without an eight-week norm keeps its intensity band.

Why it matters: It is an activity index, not a forecast probability. Read 4/5 as “well above this region's usual pressure, recently and on evidence”, never as “80%”. A region that is always busy reads 2 — its loudness is the intensity number beside it. The cut-offs are provisional. Methodology →

Intensity (1–5)

The absolute band of a theater's decayed activity — how loud the theater is on one scale shared by every theater, regardless of what is normal there.

Why it matters: It is the second of two numbers: likelihood (tempo) says whether a region is moving against its own norm; intensity says how loud it is on a scale shared by every region. Methodology →

Tempo

A theater's last seven days of weighted activity against its previous eight weeks (mean and spread), from the uncapped daily volume series plus its other same-day sources. It is the likelihood number since methodology 2026.10.

Why it matters: A permanently busy region reads “normal for here” instead of pinning the scale forever, and a genuine surge stands out — which is what makes a likelihood-change alert mean something. Methodology →

Provisional (doctrine)

A scoring constant that is an analyst's judgement call — what “4 of 5” should mean to a continuity planner — shipped before the analyst has reviewed it, and labeled as such wherever it renders.

Why it matters: The same discipline as a draft scenario pack: the label travels with the number until a reviewer signs it. Confirmation changes constants, never shapes, so nothing built on the API moves. Methodology →

Driver (driving event)

One of the top-weighted events behind a likelihood score, cited by id and title on the row it drives.

Why it matters: Drivers are the audit trail. If a board member asks “why is this red?”, the answer is the driver list, not a narrative.

Impact (1–5)

The owner-assigned criticality of an asset — a Business Impact Analysis input. Raised by one while a hazard the asset is susceptible to is active.

Why it matters: Impact is yours to set. It is the one number in the register that reflects your business, not the world.

Risk (L × I)

Likelihood multiplied by impact on a 5×5 matrix, banded low / medium / high / critical.

Why it matters: The matrix is the shared language of ISO 31000 / TARA audits. Its known weaknesses are disclosed on the methodology page rather than hidden. Methodology →

Inherent vs residual risk

Inherent is the computed risk before any treatment; residual is the risk after the best active treatment on that row, using the residual L and I recorded on the treatment.

Why it matters: Boards fund the gap between the two. The API serves inherent only; residual is a console-layer join over your treatment records.

Insufficient data

Shown instead of a low score when a theater has too few contributing events to rate.

Why it matters: “We barely looked” must never read as “we looked and risk is low”. Methodology →

Saturated

A likelihood pegged far past the top band — the scale has stopped discriminating there.

Why it matters: A saturated 5 is a ceiling, not a ranking; two saturated theaters cannot be compared against each other. Methodology →

Stale / freshness

Every score shows the age of its newest contributing event; beyond the fresh window it is marked stale.

Why it matters: Sources publish with lags from minutes to months. A score is only as current as its freshest evidence. Sources & licensing →

DIME

Diplomatic · Informational · Military · Economic — the instruments of national power (U.S. joint doctrine). Each event type maps to one; a theater’s DIME mix is its pressure profile.

Why it matters: Tells a continuity planner what KIND of disruption to plan for — a 90%-military theater and a 90%-economic theater call for different controls. Methodology →

Elevated cyber posture

A flag on theaters at likelihood 4 or above: state-attributed cyber activity historically rises with geopolitical tension.

Why it matters: It is a posture warning for your security team, not an indicator feed — Argus never stores IOCs.

Register & assets

Asset

Anything you want exposure computed for: a plant, office, supplier, port, route or hub — with a location (coordinates, country or theater), a type and a criticality.

Why it matters: The register is asset-scoped by design. The same world event matters differently to a fab in Hsinchu and a sales office in Taipei.

Exposure register

The table of asset × theater rows with likelihood, impact, risk, cited drivers and (if recorded) treatment and residual — the TARA-style risk register.

Why it matters: This is the product. The feed exists to compute it; the board pack exists to export it.

Exposure basis: direct · in-country · proximity · inherited

How a row was matched: coordinates inside a theater polygon (direct), ISO country in the theater (in-country), inside a hazard’s radius (proximity), or carried over from an upstream dependency (inherited).

Why it matters: The basis tells you how much to trust the match. An in-country match on a large country is coarser than a direct one.

Inherited exposure

A downstream asset takes a damped share of an upstream’s likelihood when that exceeds its own — one labeled hop, always cited as “inherited via <id>”.

Why it matters: It is how a plant nowhere near the strait shows Taiwan-Strait risk: through the supplier it depends on. Methodology →

Susceptibility tag

A chronic condition on an asset (seismic zone, flood zone, coastal surge, wildfire interface) that raises impact while a matching acute hazard is active.

Why it matters: Chronic × acute: the flood zone is always true; the storm is now. Only the combination moves the score.

Register hygiene

The share of assets reviewed within their review interval. Assets past due are flagged stale.

Why it matters: A register that silently rots fails its audit purpose. Hygiene is the KPI that proves the register is alive.

Dependencies (BIA)

BIA (Business Impact Analysis)

ISO 22301’s exercise of identifying critical business services, what they depend on, and how long they can be down. In Argus: the asset & dependency register.

Why it matters: It is the door BC programmes already have budget for. “Your BIA, connected to live data” is the pitch. Methodology →

Business service

The thing that actually fails for a customer — a revenue line, a product, an operation — with a tier (1 = revenue-critical), an RTO, an MTPD and optionally revenue per day.

Why it matters: Assets don’t lose money; services do. Modeling services is what turns L×I scores into dollars.

Dependency edge

A typed link: asset → asset (“depends on”) or asset → service (“supports”), with a type (material-supply, logistics, utility, digital, people) and an impact (fail or degrade).

Why it matters: Typed edges make failure modes computable: a typhoon threatens logistics edges, an export control threatens material-supply edges.

Redundancy group

Edges sharing a group name are interchangeable (either fab). The service fails only when ALL members are down; one down = degraded.

Why it matters: It is how the model shows the redundancy you paid for actually working — degraded, not dead.

SPOF (single point of failure)

An asset whose loss alone stops a tier-1 or tier-2 service — a size-1 minimal cut set.

Why it matters: Every SPOF is a Redundancy treatment waiting to be recorded, and the board pack prices it in revenue per day.

Minimal cut set

The smallest set of assets whose joint loss stops a service. Size-1 sets are SPOFs; size-2 sets are the pairs that would need to fail together.

Why it matters: Read adversarially, the cheapest cut set is where a coercive actor would apply pressure first.

Blast radius

Everything downstream that fails or degrades if a given asset is lost, simulated over the dependency graph with its redundancy gates.

Why it matters: Answers the board question “what breaks if X fails?” with a computed set, not a hand-drawn diagram.

Critical path (lineage)

The chain from an asset through its dependents to the tier-1 service it ultimately supports, shown as a breadcrumb on the register row.

Why it matters: It connects a supplier in Odesa to the EU revenue line in one line of text.

RTO · MTPD · RPO

Recovery Time Objective (how fast you plan to restore), Maximum Tolerable Period of Disruption (how long before harm is unacceptable), Recovery Point Objective (how much data loss is tolerable).

Why it matters: MTPD × revenue per day is the loss figure in the board pack. These are ISO 22301 terms your auditor already uses.

Revenue at risk

Revenue per day of the services that ride on a single point of failure, plus loss-at-MTPD per service. Customer-entered, labeled directional.

Why it matters: Boards fund dollars, not L×I scores.

Treatments & posture

Analyst brief (BLUF)

A printable one-page regional brief in a fixed doctrinal order: bottom line up front, what changed, key events by instrument, hazards, advisories, watch items, sources.

Why it matters: It is the analyst's deliverable for a room that did not read the feed. Every line cites an event id, a snapshot or a treatment; the only prose is the analyst's own comment, printed under their name. Methodology →

Risk treatment

A recorded decision on a register row — accept, mitigate, transfer or avoid (ISO 31000) — with a control type, owner, status, due date, optional cost and the residual L and I it achieves.

Why it matters: It turns an assessment into a management system: decision → residual → review. Auditors and boards want to see the loop closed.

The 5Rs

Control types for a treatment: Robustness (prevent damage), Redundancy (remove single points of failure), Resilience (operate through), Response (detect and contain), Recovery (restore within RTO).

Why it matters: A shared vocabulary for what a control does. An Argus alert can itself be the Response control.

Treatment coverage

The share of critical and high register rows that carry at least one active treatment.

Why it matters: The headline retention KPI: it is what justifies the programme to the board every quarter.

Posture (snapshot & trend)

A dated aggregate of the register — critical and high counts, treatment coverage, hygiene, SPOFs, revenue on SPOFs — taken after each publish and plotted over time.

Why it matters: Answers the one question a snapshot cannot: are we getting better?

Baseline (compare)

A struck posture point the current register is diffed against, row by row, with each change attributed to the world (new events), your profile (assets, treatments), or a methodology change.

Why it matters: Separates “the world got worse” from “we got worse” — the honest mixed story a board actually gets.

Methodology version

A version stamp bumped whenever weights, thresholds or the taxonomy change. Carried on every snapshot and exercise run.

Why it matters: A posture comparison across a bump compares two rulers; the product says so out loud. Methodology →

Exercises & demo

Exercise (wargame)

A continuity exercise computed rather than written: hypothetical events are added to the feed in memory, the register is recomputed with the same engine, and the diff shows which rows move and by how much.

Why it matters: ISO 22301 §8.5 requires an exercise programme. Here the tabletop and the register are the same object.

Inject

One hypothetical event in an exercise, in its own sim-- id namespace with an EXERCISE marker in its title.

Why it matters: The marker rides every citation, so a simulated event can never be mistaken for intelligence or reach alerts or the feed.

Scenario pack

An ordered, authored set of injects — an escalation ladder, a shipping campaign, a typhoon — reusable across exercises.

Why it matters: Packs are analyst intellectual property: doctrine encoded as a re-runnable, citable object.

Sandbox (demo)

In the public demo, assets you add for your own session. The register recomputes in your browser; nothing is sent to a server, and a reload resets it.

Why it matters: You can type real plant locations into the demo. They never leave your browser — that is a structural guarantee, not a policy. Live demo →

Synthetic data

The demo’s fictional organization (Meridian Dynamics): its assets, treatments and dependency graph are invented and labeled on every surface. Its FEED is not synthetic — since 2026-09-05 the demo scores those invented assets against a daily snapshot of the real global feed.

Why it matters: The organization is not real, so its register is not intelligence about anyone — but the events it is scored against are real and carry their source links. Both halves are stated on every demo banner. Live demo →

Data & integration

Global feed

The normalized, confidence-scored event stream Argus publishes daily from public and licensed sources, available as JSON and STIX 2.1.

Why it matters: Shared across all customers, read-only. Your private events merge into your register only. Sources & licensing →

STIX 2.1

Structured Threat Information Expression — the OASIS standard cyber-threat-intel platforms already ingest. Argus exports events as STIX bundles.

Why it matters: It is how geopolitical context lands in the SIEM/TIP your security team already runs, with no new console to learn.

Content-addressed event id

An event’s id is a hash of its source, type, theater, date, location and title (evt--…), so the same real-world event ingested twice dedupes to one.

Why it matters: Ids are stable and citable; two publishers reporting the same hazard are, deliberately, two events until cross-source dedup ships. Methodology →

Provenance

Every event carries its source id and a source URL; every source carries its licence, cadence and typical lag on the sources page.

Why it matters: Auditable beats authoritative. A reviewer can follow any score to a primary document. Sources & licensing →

Scoped API key

A machine credential shown once at creation, stored only as a hash, limited to named scopes (feed:read, exposure:read, events:write, …) and revocable.

Why it matters: Integrations get exactly the access they need and nothing more; a lost key is re-minted, never recovered. Security →

Customer ingest

Pushing your own private events and assets into your tenant over the API; private events sharpen your register and no one else’s.

Why it matters: Your incident data becomes evidence in your own likelihood scores without ever entering the shared feed.

Frameworks

TARA

Threat, Asset and Risk Assessment — the structure of scoring each asset against each threat and recording risk and treatment.

Why it matters: The register follows this shape so it drops into existing enterprise-risk processes unchanged.

ISO 22301

The business-continuity management standard: BIA (§8.2.2), risk assessment (§8.2.3), strategies (§8.3), exercising (§8.5), monitoring and review (§9).

Why it matters: Argus is worded as evidence FOR these clauses, never as compliance with them.

ISO 31000

The risk-management standard supplying the treatment decisions (accept, mitigate, transfer, avoid) and the assessment → treatment → review loop.

Why it matters: The treatment record is structured to match §6.4–6.5 so auditors recognise it.

NIS2 Art. 21 · SEC Reg S-K Item 106

EU NIS2 requires supply-chain and business-continuity risk measures (Art. 21(2)(c)(d)); the SEC rule requires disclosing processes for assessing material risks and board oversight.

Why it matters: The board pack and the register’s audit history are the artifacts these disclosures point to.