S.I.N.S.-tagged audit findings from 1,554 Kenya OAG public reports, the empirical backbone of RETACH's Cyber Risk Quantification Engine.
# Kenya Digital Risk Index
**The empirical backbone of RETACH's Cyber Risk Quantification (CRQ) Engine.**
Audit findings extracted from all 1,554 public Office of the Auditor-General (Kenya) reports, tagged to RETACH's S.I.N.S. Framework™ (Systems, Infrastructure, Network, Security) and aligned to ISO 27005 and NIST CSF.
Live site: **kdri.retach.ke**
Company: **retach.tech**
## Headline numbers
| Metric | Value |
|---|---|
| Published register rows | 4,675 |
| Entities covered | 562 |
| Source reports | 1,361 |
| Financial years | FY2015/16 – FY2023/24 (9 years) |
| Real findings | 4,406 (269 rows are clean/no-findings) |
| Scanned/unextractable files excluded | 178 (11.6% of corpus, excluded as noise, not zeros) |
| Content-matched recurrence rate | **25.6%** (1,126 of 4,406 real findings recur) |
| Self-reported prior-year reference rate | 19.8% |
| Recurring issue-threads identified | 458 (243 entities, 341 with an unbroken consecutive-year run) |
## S.I.N.S. pillar distribution (real findings, multi-label so >100%)
| Pillar | Share | Count |
|---|---|---|
| Other | 95.2% | 4,194 |
| Systems | 3.0% | 134 |
| Infrastructure | 1.3% | 59 |
| Security | 0.8% | 36 |
| Network | 0.5% | 22 |
Only 18 of the 458 recurring issue-threads tag to an actual S.I.N.S. pillar — that subset (disaster-recovery, IT-governance, e-procurement, and ICT-procurement findings recurring across two audit cycles) is explicitly labeled small-by-design / proof-of-concept, not a validated prevalence rate.
## What's in this repo
- `kenya-digital-risk-index.html` — the standalone public site (also live at retach.ke / retach.tech)
- `Kenya_Digital_Risk_Index_Methodology.docx` — full methodology: extraction approach, patch history, ISO 27005 / NIST CSF alignment, and an actuarial honesty banner
- `register_public_v38_stats.json` — the aggregate statistics behind every number above and on the site
## What's *not* in this repo, and why
The row-level register (4,675 individually tagged fin …