The research assistant spent seven and a half million years computing the Answer to the Ultimate Question of Risk, the Threat Landscape, and Everything. The answer was 42. The trouble, it turned out, was that nobody knew what the question had been. — with apologies to Douglas Adams
In case you missed them: here’s the assistant announcement, and Office Hours #1, where we made the case for “I don’t know”-as-a-Service.
Last time, we argued that an assistant willing to say “I can’t answer that” is more trustworthy than one that always produces… something. That post was about the refusal itself; this one is about what you do next.
Because “I can’t ground that” isn’t the end of a session—it’s usually the middle of one. The research often can speak to the question you’re really asking; it just won’t answer it the way you phrased it. Let me show you what I mean by asking the same thing two ways.
Here’s a question shaped the way risk questions tend to arrive in the real world—a specific firm, a specific threat, a specific number on the line:

No number, and correctly so. Three independent specifics are stacked into one question: the attacker is a state actor, the loss clears $100M, the victim is a large manufacturer. Our research doesn’t slice ransomware that finely so the assistant says as much, and points you toward the kind of source that would. A tool that answered this would be making up at least two of the three.
That’s the same restraint we covered last time, but what happens when we stop trying to get the whole answer in one shot? The question above isn’t unanswerable—it’s over-specified. It bundles four separate things the research might measure into one bespoke scenario it almost certainly doesn’t. So let’s take it apart.

An 11% chance in the next twelve months, up from roughly 2% fifteen years ago. That’s a real, sourced base rate—the foundation everything else sits on.

Ransomware is the leading incident type in the sector, accounting for 51% of incidents. Note: this is a share of incidents, not a second probability—it tells you how much of that 11% is ransomware-flavored.

A typical ransomware event runs to seven figures, with a long tail—the 95th percentile reaches roughly $50M. This is where our “$100M” gets its context: not a probability, but a sense of where $100M sits on the loss curve (out past the 95th percentile, which tells you something on its own).

Financially motivated, professionalizing, adaptable—and, the report is careful to say, not attributed to named states. Which is the honest answer to the part of the original question that asked about state actors: the research deliberately doesn’t make that call.
Put the four together and you haven’t reconstructed the original number: you’ve built something better than a number you couldn’t trust. You know the sector’s base rate, ransomware’s share of it, the shape of the loss distribution, and the limits of what’s known about attribution. That’s enough to reason about the original scenario yourself, with every piece traceable to a source. The assistant won’t do the final synthesis for you; the last step is judgment, and judgment is yours.
A single confident number with no question behind it is worth exactly 42. Four grounded numbers and a clear sense of what you were asking is worth considerably more. So when a question doesn’t ground, don’t rephrase it until it does. Decompose it into the dimensions the research actually measures, and triangulate.
One caution, since this is us. Triangulation gives you context, not a hidden answer—four real figures don’t multiply into the bespoke probability the research declined to provide, and a tool that claimed otherwise would just be hiding the guesswork one layer down.