← Argus · Sources & licensing · Glossary · Track record · Live demo

Scoring methodology

Argus produces structured evidence, not analysis: every score below is a deterministic computation over cited events, and every constant on this page is rendered from the module that computes with it — the page cannot drift from the code. The same engine runs twice, in TypeScript and Python, held identical by a cross-language parity suite.

Likelihood (1–5)

Likelihood is tempo (since methodology 2026.10): a theater’s last 7 days of weighted activity against its own previous 8 weeks, z = (now − norm mean) / max(norm spread, 10% of the norm mean), banded at ≥ -1 → 2 · ≥ 0.5 → 3 · ≥ 1.5 → 4 · ≥ 2.5 → 5 (below -1 → 1). So 2 is normal for that theater, 1 is quieter than usual and 4–5 is well above its usual level — a theater that is always busy reads 2, and a genuine surge stands out whatever the theater’s volume.

Daily activity comes from two places. The volume series measures each theater’s machine-coded (GDELT) activity over every complete UTC day before the feed’s per-theater cap, so a busy theater’s surge is not hidden by how many rows the feed keeps; it is rebuilt from GDELT’s public archive with the same filters. To that we add the theater’s other same-day sources (official maritime warnings, Taiwan’s defence ministry, advisories, your own private events, and an exercise’s injected events). Lagged bulk conflict data and sanctions decisions never count toward tempo. A theater with fewer than 28 days of norm, or a series more than 3 days old, keeps the intensity band below as its level, and says so.

Intensity is the second number, shown beside it: how loud the theater is on one scale shared by every theater. Per theater, over a 120-day event window: activity = Σ confidence_weight × severity_weight × 0.5^(age / 14 d) across the theater’s events, then likelihood = 1 + (bands cleared). Age is whole days from the event to the computation date, so an event from this morning counts in full and one 14 days old counts half (recency decay, since methodology 2026.09). Both weight tables and the intensity bands are below, in full. Every score cites its driving events by id — the score is an index into evidence, not a judgment.

provisional The tempo edges, the norm length and the intensity bands are our provisional judgement: what “4 of 5” should mean to a continuity planner is a doctrinal call, labeled as such on every surface that renders the number and open to analyst review. A change moves the constants, never the shape.

Counted, never scored: events from decision-class sources (ofac-sdn, federal-register-bis) — a sanctions designation is a decision, not an incident — appear in a theater’s event count and in the feed, and contribute nothing to its activity.

Confidence weights

One column of this table used to say “meaning”. It had one meaning for the reporting sources and a different one for the four hazard adapters, which is a defect, so both are now printed side by side.

ConfidenceWeightReporting sources (OFAC · Taiwan MND · NCSC · IC3 · UCDP · GDELT)Hazard adapters (USGS · GDACS · NHC · NWS)
high1primary source — an official publication or instrument recordintensity, not evidence: magnitude ≥ 6 · sustained wind ≥ 64 kt (hurricane strength) · GDACS Red · NWS Extreme
medium0.6reputable secondary source, or a curated dataset coded after the factmagnitude 4.5–6 · wind 34–64 kt (tropical storm) · GDACS Orange · NWS Severe
low0.3uncorroborated — news-derived candidates enter here. Two rules can promote one to medium, never higher: a primary source reporting the same thing, or enough distinct outlets carrying it (see Limitations)anything weaker than the bands above

For hazards, “confidence” is intensity, not evidential quality — so severity is counted twice. All four hazard adapters grade confidence by how strong the phenomenon is: USGS by magnitude, NHC by sustained wind, NWS by the alert’s own severity field, GDACS by alert colour. Nothing in that grading is about whether the event happened. An M4.5 earthquake is instrument-measured and published by the USGS — as certain as anything in this feed — and it is graded medium and discounted to 0.6. The consequence is structural: on a hazard row the two factors of confidence × severity are not independent, both are reading intensity, and no hazard row’s weight can be read as “how sure are we that this occurred”. Separating an evidential axis from an intensity axis is an engine change in both engines with a parity regeneration behind it; it is recorded and not yet done. Until it is, read hazard confidence as a second severity column.

Severity weights (by event type)

Event typeWeightInstrument (DIME)
armed-clash1Military
missile-activity1Military
attack-on-shipping1Military
tropical-cyclone0.9—
earthquake0.8—
volcanic0.8—
adiz-incursion0.7Military
maritime-incursion0.7Military
military-exercise0.7Military
flood0.7—
wildfire0.7—
cable-pipeline-incident0.6Military
cyber-operation0.6Informational
naval-transit0.5Military
gps-interference0.5Informational
severe-weather0.5—
labor-action0.5—
disinformation-campaign0.4Informational
sanctions-action0.4Economic
export-control-action0.4Economic
economic-coercion0.4Economic
diplomatic-incident0.3Diplomatic
protest-unrest0.3Diplomatic
other0.3—
political-statement0.2Diplomatic

Intensity bands

Decayed activity ≥ 2 → 2 · ≥ 8 → 3 · ≥ 32 → 4 · ≥ 96 → 5 — geometric, each band four times the last, so one more band means four times the recent weighted activity. These are provisional expert-judgment constants, not derivations — see Limitations, which is not a footnote. The hazard path below does not use them.

Natural hazards: the strongest active hazard sets the level

A hazard is a point-and-radius phenomenon, not a theater one, so a radius-bearing event is removed from theater activity entirely and scored per asset, on its own rule (provisional, like the bands above):

HazardSeverityLevel at high / medium / low confidenceActive for
earthquake0.85 / 3 / 27 days
flood0.74 / 3 / 25 days
tropical-cyclone0.95 / 4 / 23 days
wildfire0.74 / 3 / 27 days
severe-weather0.54 / 3 / 23 days
volcanic0.85 / 3 / 214 days

Why it changed (2026.09.2). The previous rule summed every in-radius hazard of any age, undecayed, against absolute thresholds (≥ 1 → 2 · ≥ 3 → 3 · ≥ 6.5 → 4 · ≥ 11 → 5) set for whole regions. It failed in both directions: the heaviest single hazard weighed less than the first threshold, so one hazard of any severity scored 1 of 5 — a live hurricane over a site read 1 — while a site inside many old, minor warnings saturated at 5. On the live snapshot, 76% of hazard rows were more than a week old. The level still reads the hazard’s reported strength and whether the site is inside its footprint, not conditions at the site; see Limitations.

Impact (1–5), risk, and propagation

Impact is the owner-assigned asset criticality (1–5) — a Business Impact Analysis input, not a computed value. A susceptibility tag raises impact by one (capped at 5) while a matching acute hazard is active — the chronic condition (a flood zone) is always true; the storm is now. Tags and the hazards that trigger them: seismic_zone ← earthquake · flood_zone ← flood · coastal_surge ← tropical-cyclone, severe-weather · wildfire_interface ← wildfire.

Risk = likelihood × impact on a 5×5 matrix: low <5 · medium <10 · high <15 · critical ≥15. Supply-chain propagation is one labeled hop: a downstream asset inherits 0.8 of an upstream’s likelihood when that exceeds its own direct exposure, always labeled inherited via <id> — one honest hop, not a multi-hop digital twin. Natural hazards match by proximity instead of theater: great-circle distance (haversine) against the event’s published radius.

Presentation rules — where honesty is enforced

Three rules govern how scores are shown, because a scale’s floor and ceiling are not measurements:

Limitations — stated by us, not discovered by you

Review us — candor, not encouragement

This instrument is young and we would rather hear its weaknesses from a reviewer than from a customer. If you teach or research international security, business continuity, or risk measurement, we invite a red-pen read of four things, in whatever depth you have time for:

What we commit to in return: substantive critiques are answered in writing, and changes they cause are recorded against the methodology version below with attribution if you want it. We keep a public corrections record rather than a quiet edit history. Send reviews to bhyde@engsecsolutions.com.

Citing this

This methodology is versioned: argus-methodology-2026.10. The constants on this page are imported live from the engine, which makes the page self-updating and therefore a moving target — a number quoted from it in March is not necessarily the number it renders in June. Cite the version alongside the claim so the two can be told apart:

Argus geopolitical risk register, methodology argus-methodology-2026.10, retrieved <date>.

The version is bumped whenever weights, thresholds or the taxonomy change, and a posture comparison across a bump compares two different rulers — the product says so out loud rather than letting the line move silently. Version history, the calibration plan and the corrections record are on the track record page. What is not yet available is a dated, immutable snapshot of the feed itself: exposure is recomputed over a rolling 120-day window, so a register value is reproducible only for as long as the window still holds its evidence. Until snapshots ship, treat a cited score as an observation made on a date, not a re-runnable query. Source-level terms — including the ones that require attribution when you republish — are on sources & licensing.

Frameworks & references

The register follows TARA-style threat-asset-risk assessment; the asset/dependency model maps to an ISO 22301 Business Impact Analysis (§8.2.2) and risk assessment (§8.2.3); treatments follow ISO 31000 §6.5 decisions (accept · mitigate · transfer · avoid) with residual scoring. The DIME instrument dimension (Diplomatic · Informational · Military · Economic) follows the instruments-of-national-power framing in U.S. joint doctrine (JP 1). Framework mappings in the product are worded as evidence for — never “makes you compliant”.