Does this make sense?
I understand the need of the human mind to reduce complexity.
However, unlike hurricanes, where damages usually are in fact mostly proportional to wind speed, damages and consequences for any one affected by a cyber attack depend completely on the internal setup of the affected component and all other components around it.
A Cat1 cyber event might just have completely owned your company, while a Cat5 event was barely noticable in your enviroment, because the affected component did not use a specific configration that was needed by the exploit to work or because it was fully shielded against other components.
A simple number is IMHO too simple to retain any usefulness for responders to cyber events.
At least one handy number 1-5 to describe a complex series of events will help the tabloids to sell more headlines .