Single loss expectancy, rate of occurrence and the return on security spending, worked for a private equity manager's cyber register as an operational due diligence analyst would rebuild it.
Annualised loss expectancy is the single loss expectancy times the annual rate of occurrence: ALE = SLE × ARO, where SLE = asset value × exposure factor. For an illustrative private equity manager facing ransomware, an investor data breach and an administrator outage, the three risks expect $0.622m a year of loss. A $0.18m control package cuts that to $0.282m, a return on the spend of 88.9 per cent, but only if the controls are tested: half-working controls turn the return negative.
Worked in full in Operational Due Diligence in Private Equity by Julian R. Sterling, with every figure reproduced in a free workbook.See the book on Amazon →
Cyber security is one of the domains every operational due diligence review covers, and it is usually assessed by checklist: is there multi-factor authentication, an incident response plan, a penetration test. ALE turns the checklist into money, which is the only form in which an investment committee can weigh it against everything else in the report.
A mid-sized buyout manager has identified three scenarios. Asset value is what the scenario puts at stake: recovery, interruption, notification, legal and investor-relations costs. Exposure factor is the share of that value one event destroys. Every figure is illustrative and in $m.
| Scenario | Asset value | Exposure factor | SLE | ARO | ALE |
|---|---|---|---|---|---|
| Ransomware on the firm's systems | 4.0 | 35% | 1.40 | 0.20 | 0.280 |
| Breach of investor personal data | 6.0 | 40% | 2.40 | 0.08 | 0.192 |
| Outage at the fund administrator | 2.0 | 25% | 0.50 | 0.30 | 0.150 |
| Total | 0.622 |
Where do the inputs come from? Asset value is built from the manager's own figures: the cost of restoring systems, days of interruption times the daily cost of the team, notification and legal fees, and the time senior staff spend with investors afterwards. Rates of occurrence come from the manager's incident log, its insurer's assumptions and its penetration test findings. An analyst rarely gets all of it, and that absence is itself a finding: a manager that cannot estimate its own exposure has not managed it.
SLE = asset value (AV) × exposure factor (EF)
ALE = SLE × annual rate of occurrence (ARO)
In Excel, with AV in B2, EF in C2 and ARO in E2: =B2*C2 for SLE and =B2*C2*E2 for ALE.
Ransomware: 4.0 × 0.35 = $1.40m per event. An ARO of 0.20 means one event every five years on average, so ALE = 1.40 × 0.20 = $0.280m. The data breach is the largest single loss, $2.40m, but rarer; the administrator outage is small and frequent. Ransomware carries 45.0 per cent of the total expected loss.
The manager proposes immutable backups, endpoint detection and response, phishing-resistant authentication and a tested recovery plan, at $0.18m a year. Its effect has to be stated scenario by scenario.
| Scenario | EF | SLE | ARO | ALE |
|---|---|---|---|---|
| Ransomware: backups shrink the damage, detection cuts the frequency | 15% | 0.60 | 0.06 | 0.036 |
| Data breach: authentication halves the frequency | 40% | 2.40 | 0.04 | 0.096 |
| Administrator outage: outside the manager's controls | 25% | 0.50 | 0.30 | 0.150 |
| Total | 0.282 |
ROSI = (ALE before − ALE after − annual cost) ÷ annual cost
Here: (0.622 − 0.282 − 0.18) ÷ 0.18 = 88.9 per cent, a net benefit of $0.16m a year.
The package returns almost twice its cost, and most of the benefit, $0.244m of the $0.34m reduction or 71.8 per cent, comes from ransomware. The administrator outage is untouched: the manager cannot fix it, and the right ODD question there is about the administrator's own continuity testing and the contract, not the manager's spending.
ALE is an average, and averages hide the year the event happens. Treating each ARO as an independent annual probability, the chance of at least one ransomware event in ten years is 89.3 per cent before the controls; after them, 46.1 per cent. The data breach still has a 33.5 per cent ten-year chance, and its $2.40m loss against a $1.0m cyber insurance limit leaves $1.4m uninsured. That gap belongs in the report as a number.
| Ransomware ARO | ALE before | ALE after | Reduction | ROSI |
|---|---|---|---|---|
| 0.10 | 0.482 | 0.264 | 0.218 | 21.1% |
| 0.20 | 0.622 | 0.282 | 0.340 | 88.9% |
| 0.40 | 0.902 | 0.318 | 0.584 | 224.4% |
The second sensitivity is the one an ODD analyst controls. If the controls exist on paper but have never been tested, assume they deliver half the reduction: ALE after is $0.452m, the reduction $0.17m, and the return −5.6 per cent. The manager is paying for controls that do not pay for themselves. The same pattern, a control written and never tested, is priced for payment fraud in what an untested callback control costs.
Ask the manager for its risk register in ALE terms, recompute SLE and ALE for the main scenarios, and test the claimed control effect against evidence of testing. Report the expected loss, the worst single loss against the insurance limit, and whether the controls pay for themselves if they work only half as well as described. The rating logic that keeps a finding like this from being averaged away is in the free workbook for this case.
SLE is the loss from one event: asset value times exposure factor. ALE spreads it over time by multiplying by the expected number of events a year. In the worked case ransomware has an SLE of $1.40m and, at one event every five years, an ALE of $0.280m. Budget for the SLE, compare controls on the ALE.
Subtract the ALE after the controls and their annual cost from the ALE before, then divide by the annual cost. In the worked case (0.622 minus 0.282 minus 0.18) divided by 0.18 gives 88.9 per cent. If the controls deliver only half the claimed reduction, the return is minus 5.6 per cent.
Because it turns a checklist into a figure an investment committee can weigh. In the worked case it also shows what a checklist misses: a $2.40m data breach against a $1.0m insurance limit leaves $1.4m uninsured, and a quarter of the expected loss sits with the fund administrator, outside the manager's own controls.
This article is one calculation from Operational Due Diligence in Private Equity. The book takes the same case from first principles to the decision, chapter by chapter, and every figure it prints is a live formula in the free companion workbooks.
Get the book on Amazon →Free companion files
Also on Amazon UK · Amazon Germany · Amazon France · Amazon Canada
Reading guide: private equity and private markets → · All 453 articles →
If this book helped, or didn’t, a few lines on Amazon are worth more than they look: they are what the next reader goes on. Write a review. The workbook stays free either way.