Sentrio
Methodology

Annual loss expectancy vs. a loss distribution: what one number hides

Two illustrative cyber risks share an annual loss expectancy of USD 239,000. One costs about that every year; the other is quiet for years, then costs far more.

Iván Lendner, CEO

Published · Updated · 5 min read

Key takeaways

  • Annual loss expectancy multiplies frequency by cost into one average, so two risks with the same average can still need opposite decisions.
  • In an illustrative ransomware scenario, seven years in ten have no loss, yet one year in ten costs more than USD 850,000.
  • Report the chance of a zero-loss year, the median, and the one-in-ten and one-in-a-hundred years, with the assumptions beside them.

Annual loss expectancy multiplies how often a loss happens by what it costs and gives you one number: the average year. A loss distribution keeps every year: how often nothing happens, what a typical bad year costs, and how far the tail runs. Two risks can share the same annual loss expectancy and still need opposite decisions. The average cannot tell them apart; the distribution can.

What annual loss expectancy calculates

Annual loss expectancy is cost per event times events per year. NIST set it out in 1979 in FIPS PUB 65, the Guideline for Automatic Data Processing Risk Analysis, building on Robert Courtney's work at IBM. The guideline called it annual loss exposure: estimated impact in dollars multiplied by estimated frequency of occurrence per year. Security courses still teach the same product under the names single loss expectancy and annualized rate of occurrence.

Annual loss expectancy = cost per event × events per year

FIPS 65 meant it as an order-of-magnitude device. Frequencies came from a ladder running from once in 300 years to 100 times a day, and costs from powers of ten. NIST's own history of its risk management work records that people kept reading the results as having "more precision than was justified". That is the whole problem in one line. A rough product became a precise-looking number, and the number lost the range it came from.

Open FAIR keeps the same two factors and drops the single point. The Open Group's Open FAIR Risk Analysis standard (O-RA) works with calibrated ranges for Loss Event Frequency and Loss Magnitude. The inputs look familiar. The output is a different kind of object.

Two scenarios with the same average

The same average does not mean the same risk. Take two illustrative scenarios. The first is ransomware encrypting the billing servers, with the ranges from our methodology page: 0.2 to 0.6 loss events a year and USD 300,000 to 1,200,000 per event. The second is business email compromise that diverts supplier payments out of accounts payable: 3 to 6 events a year, USD 20,000 to 115,000 each.

We simulated 100,000 years of each, drawing frequency and cost per event from lognormal ranges in which each low and high value is a 90% interval. These figures are illustrative, not customer data.

Illustrative figures, not customer data. 100,000 simulated years per scenario.
ReadingRansomware on the billing serversPayment fraud through email compromise
Loss events per year0.2 to 0.63 to 6
Cost per eventUSD 300,000 to 1,200,000USD 20,000 to 115,000
Expected annual lossUSD 239,000USD 239,000
Chance of a zero-loss year70%2%
Median year (P50)USD 0USD 220,000
Median of years with a lossUSD 675,000USD 223,000
One year in ten (P90)USD 850,000USD 430,000
One year in a hundred (P99)USD 1,850,000USD 651,000

A report built on annual loss expectancy would list both at USD 239,000 and rank them as equal. They are not equal. The fraud scenario costs roughly its average in most years, so the average is a fair budget line. The ransomware scenario costs nothing in most years and, one year in ten, more than three and a half times its average.

Bar chart: both scenarios average USD 239k, but the ransomware one-in-ten year is USD 850k against USD 430k for payment fraud
Identical expected annual loss, yet the ransomware scenario's one-in-ten year is about twice the payment fraud scenario's.

Why no year looks like the average

For the ransomware scenario, the average describes a year that almost never happens. Seven years in ten have no loss at all, so the median year is zero. When a loss does happen, the median of those years is USD 675,000, nearly three times the average. The USD 239,000 figure sits in the gap between the two outcomes, where very few simulated years land.

This is where the budget conversation goes wrong. A CFO who sets aside USD 239,000 a year for this risk watches the reserve sit unused for several years, then sees one year run through three and a half times the amount. The number was never wrong as an average. It answered the wrong question for a risk that arrives rarely and expensively.

Loss exceedance curve for the ransomware scenario starting at 30% and falling to 10% at USD 850k and 1% at USD 1.85M
The curve starts at 30% because seven years in ten never leave zero, and it still has a 1% chance at USD 1.85 million.

The curve reads left to right: for each amount, the chance that a year's loss is larger. It starts at 30%, not 100%, because most years never leave zero. It is still at 1% at USD 1,850,000, which is the part of the risk that an insurer, a treasurer and a board all care about and that the average leaves out.

Which questions each one answers

Annual loss expectancy answers one question well: what does this risk cost on average over many years? Most of what a board decides about cyber risk turns on something else.

QuestionAnnual loss expectancyLoss distribution
What does this cost on average?YesYes, as its mean
How often does a year pass with no loss?NoThe chance of a zero-loss year
How bad is a bad year?NoThe one-in-ten year (P90)
Where does the tail an insurer would cover begin?NoP90 to P99
Is this within our risk appetite?Only if appetite is an averageYes, against any stated threshold
Which of two risks is worse?A tie when averages matchSeparated by their tails

A risk appetite written as "no more than a one-in-ten chance of losing over USD 1 million in a year" can be tested against a distribution. The ransomware scenario passes, narrowly: its one-in-ten year is USD 850,000. The same statement cannot be tested against an average at all, which is reason enough to stop reporting the average on its own.

When annual loss expectancy is still useful

The mean is an incomplete number, not a wrong one. For frequent, small, fairly independent losses like the payment fraud scenario, the median and the mean sit close together, at USD 220,000 and USD 239,000, and budgeting to the average works. Means also add: the expected loss of a portfolio is the sum of the expected losses of its scenarios. Percentiles do not add that way.

So keep the mean, as one reading of the distribution, next to the chance of a zero-loss year and the tail percentiles. Just do not let it stand in for them. A single expected value hides how wide the uncertainty is and how often a year passes with no loss. For a rare, costly risk, those two facts are the decision.

How to move from one number to a distribution

You do not need new data to start; you need your existing estimates written as ranges. If your annual loss expectancy came from "about once every three years, about USD 600,000", the honest version is a range for each factor: how rarely and how often, how cheap and how costly, with a note on where each end came from.

Then simulate. Draw a frequency and a cost for each of many thousands of years and count what happens; the methodology shows how Sentrio reads the result for one scenario. Report four readings: the chance of a zero-loss year, the median, the one-in-ten year and the one-in-a-hundred year. Put the assumptions in one sentence beside them.

Missing data is not a reason to fall back to a point estimate. Lack of data widens the range; it never hides a number, and it is never zero. A wide range on day one is honest, and it tells you which input to work on next. In the ransomware example, frequency is a declared estimate while the cost per event is documented, so better evidence on how often the billing servers are attacked is what would narrow the tail.

Frequently asked questions

Does the answer depend on how the ranges are modelled?

Yes, and the tail moves more than the average. Running the ransomware scenario with uniform ranges instead of lognormal ones gives an expected annual loss of USD 300,000 instead of USD 239,000, and a one-in-ten year of USD 1,050,000 instead of USD 850,000. The chance of a zero-loss year barely moves: about 68% against 70%. That is why every distribution should carry its assumptions in one sentence next to the numbers.

Is annual loss expectancy the same as the mean of the loss distribution?

It is when both come from the same inputs and the ALE uses the average frequency and the average cost per event, because the mean annual loss is average events per year times average cost. In practice ALE is often built from a most-likely frequency and a most-likely cost. That usually understates the mean, since cyber loss costs are skewed: a few expensive events pull the average above the typical one.

Written by

Iván Lendner

CEO

LinkedIn

See your estate as a map before the next budget cycle.

Thirty minutes with the team is enough to walk one route end to end.

Talk to the team