Cybersecurity Risk Assessment Calculator
Calculate annualized loss expectancy (ALE) using FAIR-based risk analysis with threat frequency, vulnerability, and control effectiveness.
About this calculator
This calculator applies a simplified version of FAIR (Factor Analysis of Information Risk), the risk-quantification model published by The Open Group as the Risk Analysis (O-RA) Standard (the Open FAIR body of knowledge) for putting a dollar figure on cybersecurity risk instead of leaving it as a qualitative "high/medium/low" label. It works in two stages: first, it derives how often a loss event actually happens per year (loss event frequency) by combining how often threats attempt to strike, how likely an attempt would succeed against an undefended system, and how much your existing controls cut that success rate down. Second, it multiplies that frequency by the single loss expectancy — the dollar cost of one incident, calculated as the asset's total value times the percentage a breach would actually destroy or expose — to arrive at the annualized loss expectancy, a genuinely useful figure because it's expressed in the same units (dollars per year) as a security budget, making direct comparison possible.
The risk score and level translate the same underlying numbers into a traditional 5x5 likelihood-by-impact risk matrix, a format many security teams and auditors already use for reporting and prioritization. Recommended security spend applies a common industry rule of thumb — roughly 10% of the annualized loss — as a starting reference point for how much investment a specific risk might justify, not a rigid target; real budgeting should also weigh diminishing returns on additional controls and the cost of controls that address multiple risks simultaneously. Every input here is necessarily an estimate, since true threat frequencies and control effectiveness percentages are rarely known with precision — the output is only as reliable as the judgment behind these inputs.
Inputs
Results
Annualized Loss Expectancy
$60,000.00
Figures current as of 2025. Source: The Open Group, "Risk Analysis (O-RA) Standard", Version 2.1 (the Open FAIR body of knowledge)
How to Use This Calculator
- Enter the asset value — the total worth of the data or system this risk analysis covers.
- Set threat frequency (expected attack attempts per year), vulnerability (odds a threat succeeds unopposed), and control effectiveness (how much your existing defenses reduce that success rate).
- Enter impact severity — the percentage of the asset's value a successful incident would actually destroy or expose.
- Review the Annualized Loss Expectancy, the expected dollar cost of this risk per year averaged over time.
- Use the Risk Level and Recommended Security Spend to gauge urgency and a reasonable starting security budget for this specific risk.
How the result changes with Control Effectiveness
| Control Effectiveness | Annualized Loss Expectancy |
|---|---|
| 30 | $105,000.00 |
| 45 | $82,500.00 |
| 90 | $15,000.00 |
| 100 | $0.00 |
What each input means
- Asset Value
- Total value of the asset or data at risk.
- Threat Frequency
- Expected threat events per year (e.g., attack attempts).
- Vulnerability
- Likelihood that a threat exploits the vulnerability (0-100%).
- Control Effectiveness
- Effectiveness of existing security controls (0-100%).
- Impact Severity
- Percentage of asset value lost per incident.
What each result means
- Annualized Loss Expectancy
- Expected annual loss from this risk (ALE = LEF × SLE).
- Single Loss Expectancy
- Expected loss per incident.
- Loss Event Frequency
- Expected successful attacks per year.
- Risk Score
- Risk matrix score (1-25).
- Risk Level
- 1=low, 2=medium, 3=high, 4=critical.
- Recommended Security Spend
- Suggested annual security investment (~10% of ALE).
How this is calculated
Worked example, using the default values
- Identify Input Parameters4 parametersAsset Value = 1000000, Threat Frequency = 1, Vulnerability = 50, Control Effectiveness = 60 = 5 input(s) provided
- Calculate Annualized Loss ExpectancyAnnualized Loss Expectancy = lossEventFrequency * singleLoss60000 = $60,000
- Calculate Single Loss ExpectancySingle Loss Expectancy = assetValue * (impactPct / 100)300000 = $300,000
- Calculate Loss Event FrequencyLoss Event Frequency = threatFrequency * effectiveVulnerability0.2 = 0.2
Figures and sources
- FAIR risk-quantification model (Loss Event Frequency × Loss Magnitude) (2025) — The Open Group, "Risk Analysis (O-RA) Standard", Version 2.1 (the Open FAIR body of knowledge)
Engine last updated . Checked against 1 independently-derived test — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
What does 'vulnerability' mean here, separately from control effectiveness?
Vulnerability represents how likely a threat would succeed if it hit your systems with no defenses at all — an inherent weakness in the asset or process itself. Control effectiveness then represents how much your actual security measures reduce that raw likelihood, so the two combine to give effective vulnerability: the real-world chance a threat event turns into an actual loss after your existing defenses are accounted for.
Why is annualized loss expectancy more useful than just knowing the cost of one incident?
A single incident's cost tells you what one bad event would hurt, but it says nothing about how often that event is likely to happen — a rare but catastrophic risk and a frequent but minor one can have wildly different single-incident costs while representing similar overall exposure. Annualizing the loss by multiplying by expected frequency puts every risk in the same per-year dollar terms, which is what actually needs comparing when allocating a limited security budget.
Is the 10% recommended security spend a hard rule I should follow exactly?
No — it's a commonly cited industry rule of thumb (often stated as a 5-15% range) meant as a starting reference point, not a precise optimal figure for every situation. The right investment level also depends on factors this simplified model doesn't capture, like whether a control also mitigates other risks simultaneously, and the point of diminishing returns as spending increases.
Is FAIR an actual published standard, or just an informal industry framework?
FAIR is a real, published standard: The Open Group maintains it as the Risk Analysis (O-RA) Standard, the risk-quantification half of the Open FAIR body of knowledge (paired with the Risk Taxonomy, O-RT, Standard that defines FAIR's risk factors). This calculator implements FAIR's core mechanic — Loss Event Frequency multiplied by Loss Magnitude (here, Single Loss Expectancy) to produce an Annualized Loss Expectancy — in simplified form, without the full taxonomy's more granular threat-capability and control-strength breakdowns.
How reliable are the risk numbers if my threat frequency or vulnerability estimates are rough guesses?
The math itself is exact, but its output quality depends entirely on the accuracy of the inputs you supply, and threat frequency and vulnerability in particular are often genuinely difficult to estimate precisely in the real world. Treat the annualized loss figure as a structured, defensible estimate for comparing and prioritizing risks relative to each other, rather than a guaranteed prediction of actual future losses.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Security Budget Calculator
Calculate recommended cybersecurity budget based on industry benchmarks, company size, and risk profile with spending allocation.
CybersecurityIncident Response Cost Calculator
Estimate total cybersecurity incident response costs including forensics, legal, notification, and recovery based on IBM breach report data.
Actuarial ScienceRisk Assessment Calculator
Calculate Value at Risk (VaR), Conditional VaR, and risk metrics for actuarial risk assessment.
CybersecurityPassword Generator
Generate secure random passwords with customizable length and character sets. See password strength and entropy.
More in Technology & Computing.