Articles

How do you calculate annualised loss expectancy (ALE) for cyber risk?

Single loss expectancy, rate of occurrence and the return on security spending, worked for a private equity manager's cyber register as an operational due diligence analyst would rebuild it.

Annualised loss expectancy is the single loss expectancy times the annual rate of occurrence: ALE = SLE × ARO, where SLE = asset value × exposure factor. For an illustrative private equity manager facing ransomware, an investor data breach and an administrator outage, the three risks expect $0.622m a year of loss. A $0.18m control package cuts that to $0.282m, a return on the spend of 88.9 per cent, but only if the controls are tested: half-working controls turn the return negative.

Worked in full in Operational Due Diligence in Private Equity by Julian R. Sterling, with every figure reproduced in a free workbook.See the book on Amazon →

Cyber security is one of the domains every operational due diligence review covers, and it is usually assessed by checklist: is there multi-factor authentication, an incident response plan, a penetration test. ALE turns the checklist into money, which is the only form in which an investment committee can weigh it against everything else in the report.

The case

A mid-sized buyout manager has identified three scenarios. Asset value is what the scenario puts at stake: recovery, interruption, notification, legal and investor-relations costs. Exposure factor is the share of that value one event destroys. Every figure is illustrative and in $m.

Risk register before the control package.
ScenarioAsset valueExposure factorSLEAROALE
Ransomware on the firm's systems4.035%1.400.200.280
Breach of investor personal data6.040%2.400.080.192
Outage at the fund administrator2.025%0.500.300.150
Total0.622

Where do the inputs come from? Asset value is built from the manager's own figures: the cost of restoring systems, days of interruption times the daily cost of the team, notification and legal fees, and the time senior staff spend with investors afterwards. Rates of occurrence come from the manager's incident log, its insurer's assumptions and its penetration test findings. An analyst rarely gets all of it, and that absence is itself a finding: a manager that cannot estimate its own exposure has not managed it.

Step 1: single loss expectancy

Formulas

SLE = asset value (AV) × exposure factor (EF)
ALE = SLE × annual rate of occurrence (ARO)

In Excel, with AV in B2, EF in C2 and ARO in E2: =B2*C2 for SLE and =B2*C2*E2 for ALE.

Ransomware: 4.0 × 0.35 = $1.40m per event. An ARO of 0.20 means one event every five years on average, so ALE = 1.40 × 0.20 = $0.280m. The data breach is the largest single loss, $2.40m, but rarer; the administrator outage is small and frequent. Ransomware carries 45.0 per cent of the total expected loss.

Step 2: price the control package

The manager proposes immutable backups, endpoint detection and response, phishing-resistant authentication and a tested recovery plan, at $0.18m a year. Its effect has to be stated scenario by scenario.

After the control package.
ScenarioEFSLEAROALE
Ransomware: backups shrink the damage, detection cuts the frequency15%0.600.060.036
Data breach: authentication halves the frequency40%2.400.040.096
Administrator outage: outside the manager's controls25%0.500.300.150
Total0.282

Return on security investment

ROSI = (ALE before − ALE after − annual cost) ÷ annual cost

Here: (0.622 − 0.282 − 0.18) ÷ 0.18 = 88.9 per cent, a net benefit of $0.16m a year.

The result

The package returns almost twice its cost, and most of the benefit, $0.244m of the $0.34m reduction or 71.8 per cent, comes from ransomware. The administrator outage is untouched: the manager cannot fix it, and the right ODD question there is about the administrator's own continuity testing and the contract, not the manager's spending.

ALE is an average, and averages hide the year the event happens. Treating each ARO as an independent annual probability, the chance of at least one ransomware event in ten years is 89.3 per cent before the controls; after them, 46.1 per cent. The data breach still has a 33.5 per cent ten-year chance, and its $2.40m loss against a $1.0m cyber insurance limit leaves $1.4m uninsured. That gap belongs in the report as a number.

What if the inputs move?

Return on the package by the ransomware rate of occurrence before controls. Controls cut it to 0.3 times that rate.
Ransomware AROALE beforeALE afterReductionROSI
0.100.4820.2640.21821.1%
0.200.6220.2820.34088.9%
0.400.9020.3180.584224.4%

The second sensitivity is the one an ODD analyst controls. If the controls exist on paper but have never been tested, assume they deliver half the reduction: ALE after is $0.452m, the reduction $0.17m, and the return −5.6 per cent. The manager is paying for controls that do not pay for themselves. The same pattern, a control written and never tested, is priced for payment fraud in what an untested callback control costs.

The common mistakes

Takeaway

Ask the manager for its risk register in ALE terms, recompute SLE and ALE for the main scenarios, and test the claimed control effect against evidence of testing. Report the expected loss, the worst single loss against the insurance limit, and whether the controls pay for themselves if they work only half as well as described. The rating logic that keeps a finding like this from being averaged away is in the free workbook for this case.

Questions readers ask

What is the difference between SLE and ALE?

SLE is the loss from one event: asset value times exposure factor. ALE spreads it over time by multiplying by the expected number of events a year. In the worked case ransomware has an SLE of $1.40m and, at one event every five years, an ALE of $0.280m. Budget for the SLE, compare controls on the ALE.

How do you calculate return on security investment?

Subtract the ALE after the controls and their annual cost from the ALE before, then divide by the annual cost. In the worked case (0.622 minus 0.282 minus 0.18) divided by 0.18 gives 88.9 per cent. If the controls deliver only half the claimed reduction, the return is minus 5.6 per cent.

Why does operational due diligence care about cyber ALE?

Because it turns a checklist into a figure an investment committee can weigh. In the worked case it also shows what a checklist misses: a $2.40m data breach against a $1.0m insurance limit leaves $1.4m uninsured, and a quarter of the expected loss sits with the fund administrator, outside the manager's own controls.

Read the whole case

This article is one calculation from Operational Due Diligence in Private Equity. The book takes the same case from first principles to the decision, chapter by chapter, and every figure it prints is a live formula in the free companion workbooks.

Get the book on Amazon →Free companion files

Also on Amazon UK · Amazon Germany · Amazon France · Amazon Canada

Also on this site

Reading guide: private equity and private markets → · All 453 articles →

If this book helped, or didn’t, a few lines on Amazon are worth more than they look: they are what the next reader goes on. Write a review. The workbook stays free either way.