Skip to main content
Calcimator

Cybersecurity Risk Assessment Calculator

Calculate annualized loss expectancy (ALE) using FAIR-based risk analysis with threat frequency, vulnerability, and control effectiveness.

About this calculator

This calculator applies a simplified version of FAIR (Factor Analysis of Information Risk), the risk-quantification model published by The Open Group as the Risk Analysis (O-RA) Standard (the Open FAIR body of knowledge) for putting a dollar figure on cybersecurity risk instead of leaving it as a qualitative "high/medium/low" label. It works in two stages: first, it derives how often a loss event actually happens per year (loss event frequency) by combining how often threats attempt to strike, how likely an attempt would succeed against an undefended system, and how much your existing controls cut that success rate down. Second, it multiplies that frequency by the single loss expectancy — the dollar cost of one incident, calculated as the asset's total value times the percentage a breach would actually destroy or expose — to arrive at the annualized loss expectancy, a genuinely useful figure because it's expressed in the same units (dollars per year) as a security budget, making direct comparison possible.

The risk score and level translate the same underlying numbers into a traditional 5x5 likelihood-by-impact risk matrix, a format many security teams and auditors already use for reporting and prioritization. Recommended security spend applies a common industry rule of thumb — roughly 10% of the annualized loss — as a starting reference point for how much investment a specific risk might justify, not a rigid target; real budgeting should also weigh diminishing returns on additional controls and the cost of controls that address multiple risks simultaneously. Every input here is necessarily an estimate, since true threat frequencies and control effectiveness percentages are rarely known with precision — the output is only as reliable as the judgment behind these inputs.

Inputs

$
/year
%
%
%

Results

Annualized Loss Expectancy

$60,000.00

Single Loss Expectancy$300,000.00
Loss Event Frequency0.2/year
Risk Score4
Risk Level1
Residual Vulnerability20%
Recommended Security Spend$6,000.00

Figures current as of 2025. Source: The Open Group, "Risk Analysis (O-RA) Standard", Version 2.1 (the Open FAIR body of knowledge)

How to Use This Calculator
  1. Enter the asset value — the total worth of the data or system this risk analysis covers.
  2. Set threat frequency (expected attack attempts per year), vulnerability (odds a threat succeeds unopposed), and control effectiveness (how much your existing defenses reduce that success rate).
  3. Enter impact severity — the percentage of the asset's value a successful incident would actually destroy or expose.
  4. Review the Annualized Loss Expectancy, the expected dollar cost of this risk per year averaged over time.
  5. Use the Risk Level and Recommended Security Spend to gauge urgency and a reasonable starting security budget for this specific risk.

How the result changes with Control Effectiveness

Control EffectivenessAnnualized Loss Expectancy
30$105,000.00
45$82,500.00
90$15,000.00
100$0.00

What each input means

Asset Value
Total value of the asset or data at risk.
Threat Frequency
Expected threat events per year (e.g., attack attempts).
Vulnerability
Likelihood that a threat exploits the vulnerability (0-100%).
Control Effectiveness
Effectiveness of existing security controls (0-100%).
Impact Severity
Percentage of asset value lost per incident.

What each result means

Annualized Loss Expectancy
Expected annual loss from this risk (ALE = LEF × SLE).
Single Loss Expectancy
Expected loss per incident.
Loss Event Frequency
Expected successful attacks per year.
Risk Score
Risk matrix score (1-25).
Risk Level
1=low, 2=medium, 3=high, 4=critical.
Recommended Security Spend
Suggested annual security investment (~10% of ALE).

How this is calculated

Worked example, using the default values

  1. Identify Input Parameters
    4 parameters
    Asset Value = 1000000, Threat Frequency = 1, Vulnerability = 50, Control Effectiveness = 60 = 5 input(s) provided
  2. Calculate Annualized Loss Expectancy
    Annualized Loss Expectancy = lossEventFrequency * singleLoss
    60000 = $60,000
  3. Calculate Single Loss Expectancy
    Single Loss Expectancy = assetValue * (impactPct / 100)
    300000 = $300,000
  4. Calculate Loss Event Frequency
    Loss Event Frequency = threatFrequency * effectiveVulnerability
    0.2 = 0.2

Figures and sources

Engine last updated . Checked against 1 independently-derived test — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.

Frequently Asked Questions

What does 'vulnerability' mean here, separately from control effectiveness?

Vulnerability represents how likely a threat would succeed if it hit your systems with no defenses at all — an inherent weakness in the asset or process itself. Control effectiveness then represents how much your actual security measures reduce that raw likelihood, so the two combine to give effective vulnerability: the real-world chance a threat event turns into an actual loss after your existing defenses are accounted for.

Why is annualized loss expectancy more useful than just knowing the cost of one incident?

A single incident's cost tells you what one bad event would hurt, but it says nothing about how often that event is likely to happen — a rare but catastrophic risk and a frequent but minor one can have wildly different single-incident costs while representing similar overall exposure. Annualizing the loss by multiplying by expected frequency puts every risk in the same per-year dollar terms, which is what actually needs comparing when allocating a limited security budget.

Is the 10% recommended security spend a hard rule I should follow exactly?

No — it's a commonly cited industry rule of thumb (often stated as a 5-15% range) meant as a starting reference point, not a precise optimal figure for every situation. The right investment level also depends on factors this simplified model doesn't capture, like whether a control also mitigates other risks simultaneously, and the point of diminishing returns as spending increases.

Is FAIR an actual published standard, or just an informal industry framework?

FAIR is a real, published standard: The Open Group maintains it as the Risk Analysis (O-RA) Standard, the risk-quantification half of the Open FAIR body of knowledge (paired with the Risk Taxonomy, O-RT, Standard that defines FAIR's risk factors). This calculator implements FAIR's core mechanic — Loss Event Frequency multiplied by Loss Magnitude (here, Single Loss Expectancy) to produce an Annualized Loss Expectancy — in simplified form, without the full taxonomy's more granular threat-capability and control-strength breakdowns.

How reliable are the risk numbers if my threat frequency or vulnerability estimates are rough guesses?

The math itself is exact, but its output quality depends entirely on the accuracy of the inputs you supply, and threat frequency and vulnerability in particular are often genuinely difficult to estimate precisely in the real world. Treat the annualized loss figure as a structured, defensible estimate for comparing and prioritizing risks relative to each other, rather than a guaranteed prediction of actual future losses.

The questions that sit next to this one — chosen by subject, including calculators filed under a different category.

More in Technology & Computing.