The M&S and Co-op attacks were classified by UK analysts as a "Category 2 systemic event", explicitly borrowing the vocabulary used for hurricanes.
This desk grades severity on every file it publishes, so we have some sympathy with anyone attempting a scale. It is harder than it looks and worth doing anyway.
Why Cyber Has Lacked One
Natural catastrophe scales work because the phenomenon is physical and measurable independently of who it hits. Wind speed is wind speed.
A cyber incident has no equivalent intrinsic magnitude. The same technique produces a footnote at one organisation — as in the Google file in 26-0619 — and a national supply disruption at another. Severity is a property of the victim and the coupling around it, not of the attack.
What A Scale Buys
Insurers need to reserve against events rather than incidents. Regulators need to distinguish routine losses from systemic ones. Boards need to know whether what happened to a peer was a bad week or an existential quarter.
None of that is possible while every incident is described in the same adjectives. A scale forces the assessing body to commit to a number and to publish its reasoning, which is checkable in a way "sophisticated attack" never is.
The Obvious Failure Mode
Any scale becomes a target once it carries consequences. If a category determines regulatory attention or insurance treatment, the affected organisation acquires a strong interest in the number, and the assessment becomes a negotiation.
The protection is the same as for our own grading: publish the criteria, publish the reasoning, and let people argue with it. We would rather be told our Sev 4 was wrong than have nobody able to check.
This is a standards file. Compiled from public reporting on the classification, listed below. The comparison to our own grading is our commentary and is labelled as such. Corrections: corrections@forensicpost.com.