TrustDyne maps technical findings to the regulatory articles they breach and the statutory maximum penalty for each, so you can brief the board and executives.
Board members and executives struggle with technical risk metrics like CVSS. To win budget and set security priorities, technical teams need to describe risk in business terms: which regulations are involved and what the law sets as the ceiling.
TrustDyne maps vulnerabilities to the regulatory articles they violate (for example UK GDPR Art. 32, EU CRA and PSTI) and cites the statutory maximum penalty for each regime. The figures come from the legal text and are shown as a ceiling, not an estimate. The regulator sets any actual penalty case by case. TrustDyne does not estimate breach cost, downtime, customer loss or ROI. Those depend on user numbers, data volume, revenue and contract terms that a scan cannot see, so we do not guess.