Tools
Annual Loss Expectancy Calculator: Is the Control Worth It?
A cyber risk assessment only becomes a spending decision once you put a yearly price on each risk. The standard method is annual loss expectancy: what one incident would cost, multiplied by how often you expect it to happen. Enter your own figures below to see the ALE before and after a control, what the control saves each year, and its return on security investment (ROSI). A control is worth buying when the yearly loss it removes is bigger than what it costs you each year.
1. The risk
2. The control you are considering
How the calculation works
The formulas are the classic quantitative risk ones used in information security courses and risk registers:
- Single loss expectancy (SLE) = asset value × exposure factor. It is the cost of one incident.
- Annual rate of occurrence (ARO) is how many times a year you expect it. Something you expect once every four years has an ARO of 0.25.
- Annual loss expectancy (ALE) = SLE × ARO. It is the average yearly cost of carrying the risk.
- ROSI = (ALE before − ALE after − annual control cost) ÷ annual control cost.
A control can work on either side of the sum. Multi-factor authentication or email filtering mostly cuts how often an incident happens. Tested offline backups mostly cut how much each incident costs, because you restore rather than rebuild or pay. Enter both percentages if a control does both.
Where the inputs come from
The weak point of any ALE figure is the guesswork in the inputs, so be honest about it. For the incident cost, our downtime cost calculator and ransomware cost calculator will give you a defensible SLE built from your own turnover and staffing. For likelihood, use your own incident history, what your IT provider sees across its clients, and published government survey data on how often UK businesses report breaches. Then run the tool again with a pessimistic set of numbers: if the control still pays for itself, the decision is safe.
ALE is an average, not a forecast. A risk with an ARO of 0.1 will not cost you a tenth of the incident each year; it will cost nothing for years and then the full amount. That is why the residual ALE left after your controls is often the part you transfer to a cyber insurance policy, and why you should list each risk separately in your cyber security risk assessment rather than adding them into one number.