Annual loss expectancy vs. a loss distribution: what one number hides
Two illustrative cyber risks share an annual loss expectancy of USD 239,000. One costs about that every year; the other is quiet for years, then costs far more.
Iván Lendner, CEO
Published · Updated · 5 min read
Key takeaways
- Annual loss expectancy multiplies frequency by cost into one average, so two risks with the same average can still need opposite decisions.
- In an illustrative ransomware scenario, seven years in ten have no loss, yet one year in ten costs more than USD 850,000.
- Report the chance of a zero-loss year, the median, and the one-in-ten and one-in-a-hundred years, with the assumptions beside them.
Annual loss expectancy multiplies how often a loss happens by what it costs and gives you one number: the average year. A loss distribution keeps every year: how often nothing happens, what a typical bad year costs, and how far the tail runs. Two risks can share the same annual loss expectancy and still need opposite decisions. The average cannot tell them apart; the distribution can.
What annual loss expectancy calculates
Annual loss expectancy is cost per event times events per year. NIST set it out in 1979 in FIPS PUB 65, the Guideline for Automatic Data Processing Risk Analysis, building on Robert Courtney's work at IBM. The guideline called it annual loss exposure: estimated impact in dollars multiplied by estimated frequency of occurrence per year. Security courses still teach the same product under the names single loss expectancy and annualized rate of occurrence.
Annual loss expectancy = cost per event × events per year
FIPS 65 meant it as an order-of-magnitude device. Frequencies came from a ladder running from once in 300 years to 100 times a day, and costs from powers of ten. NIST's own history of its risk management work records that people kept reading the results as having "more precision than was justified". That is the whole problem in one line. A rough product became a precise-looking number, and the number lost the range it came from.
Open FAIR keeps the same two factors and drops the single point. The Open Group's Open FAIR Risk Analysis standard (O-RA) works with calibrated ranges for Loss Event Frequency and Loss Magnitude. The inputs look familiar. The output is a different kind of object.
Two scenarios with the same average
The same average does not mean the same risk. Take two illustrative scenarios. The first is ransomware encrypting the billing servers, with the ranges from our methodology page: 0.2 to 0.6 loss events a year and USD 300,000 to 1,200,000 per event. The second is business email compromise that diverts supplier payments out of accounts payable: 3 to 6 events a year, USD 20,000 to 115,000 each.
We simulated 100,000 years of each, drawing frequency and cost per event from lognormal ranges in which each low and high value is a 90% interval. These figures are illustrative, not customer data.
| Reading | Ransomware on the billing servers | Payment fraud through email compromise |
|---|---|---|
| Loss events per year | 0.2 to 0.6 | 3 to 6 |
| Cost per event | USD 300,000 to 1,200,000 | USD 20,000 to 115,000 |
| Expected annual loss | USD 239,000 | USD 239,000 |
| Chance of a zero-loss year | 70% | 2% |
| Median year (P50) | USD 0 | USD 220,000 |
| Median of years with a loss | USD 675,000 | USD 223,000 |
| One year in ten (P90) | USD 850,000 | USD 430,000 |
| One year in a hundred (P99) | USD 1,850,000 | USD 651,000 |
A report built on annual loss expectancy would list both at USD 239,000 and rank them as equal. They are not equal. The fraud scenario costs roughly its average in most years, so the average is a fair budget line. The ransomware scenario costs nothing in most years and, one year in ten, more than three and a half times its average.

Why no year looks like the average
For the ransomware scenario, the average describes a year that almost never happens. Seven years in ten have no loss at all, so the median year is zero. When a loss does happen, the median of those years is USD 675,000, nearly three times the average. The USD 239,000 figure sits in the gap between the two outcomes, where very few simulated years land.
This is where the budget conversation goes wrong. A CFO who sets aside USD 239,000 a year for this risk watches the reserve sit unused for several years, then sees one year run through three and a half times the amount. The number was never wrong as an average. It answered the wrong question for a risk that arrives rarely and expensively.

The curve reads left to right: for each amount, the chance that a year's loss is larger. It starts at 30%, not 100%, because most years never leave zero. It is still at 1% at USD 1,850,000, which is the part of the risk that an insurer, a treasurer and a board all care about and that the average leaves out.
Which questions each one answers
Annual loss expectancy answers one question well: what does this risk cost on average over many years? Most of what a board decides about cyber risk turns on something else.
| Question | Annual loss expectancy | Loss distribution |
|---|---|---|
| What does this cost on average? | Yes | Yes, as its mean |
| How often does a year pass with no loss? | No | The chance of a zero-loss year |
| How bad is a bad year? | No | The one-in-ten year (P90) |
| Where does the tail an insurer would cover begin? | No | P90 to P99 |
| Is this within our risk appetite? | Only if appetite is an average | Yes, against any stated threshold |
| Which of two risks is worse? | A tie when averages match | Separated by their tails |
A risk appetite written as "no more than a one-in-ten chance of losing over USD 1 million in a year" can be tested against a distribution. The ransomware scenario passes, narrowly: its one-in-ten year is USD 850,000. The same statement cannot be tested against an average at all, which is reason enough to stop reporting the average on its own.
When annual loss expectancy is still useful
The mean is an incomplete number, not a wrong one. For frequent, small, fairly independent losses like the payment fraud scenario, the median and the mean sit close together, at USD 220,000 and USD 239,000, and budgeting to the average works. Means also add: the expected loss of a portfolio is the sum of the expected losses of its scenarios. Percentiles do not add that way.
So keep the mean, as one reading of the distribution, next to the chance of a zero-loss year and the tail percentiles. Just do not let it stand in for them. A single expected value hides how wide the uncertainty is and how often a year passes with no loss. For a rare, costly risk, those two facts are the decision.
How to move from one number to a distribution
You do not need new data to start; you need your existing estimates written as ranges. If your annual loss expectancy came from "about once every three years, about USD 600,000", the honest version is a range for each factor: how rarely and how often, how cheap and how costly, with a note on where each end came from.
Then simulate. Draw a frequency and a cost for each of many thousands of years and count what happens; the methodology shows how Sentrio reads the result for one scenario. Report four readings: the chance of a zero-loss year, the median, the one-in-ten year and the one-in-a-hundred year. Put the assumptions in one sentence beside them.
Missing data is not a reason to fall back to a point estimate. Lack of data widens the range; it never hides a number, and it is never zero. A wide range on day one is honest, and it tells you which input to work on next. In the ransomware example, frequency is a declared estimate while the cost per event is documented, so better evidence on how often the billing servers are attacked is what would narrow the tail.
Frequently asked questions
Does the answer depend on how the ranges are modelled?
Yes, and the tail moves more than the average. Running the ransomware scenario with uniform ranges instead of lognormal ones gives an expected annual loss of USD 300,000 instead of USD 239,000, and a one-in-ten year of USD 1,050,000 instead of USD 850,000. The chance of a zero-loss year barely moves: about 68% against 70%. That is why every distribution should carry its assumptions in one sentence next to the numbers.
Is annual loss expectancy the same as the mean of the loss distribution?
It is when both come from the same inputs and the ALE uses the average frequency and the average cost per event, because the mean annual loss is average events per year times average cost. In practice ALE is often built from a most-likely frequency and a most-likely cost. That usually understates the mean, since cyber loss costs are skewed: a few expensive events pull the average above the typical one.