Quantitative Risk Analysis Suite

Calculate SLE, ALE and safeguard value with the standard risk formulas. Build an asset inventory, model controls, export a PDF report. Free, browser-based.

Advertisement

Quantitative Risk Analysis: SLE, ALE and Safeguard Value

This quantitative risk analysis tool implements the standard asset-based risk arithmetic taught in CISSP, CISM, and NIST SP 800-30 training and used in real risk registers: single loss expectancy, annualised loss expectancy, and the net value of a proposed safeguard. You build an asset inventory, attach loss scenarios to each asset, then model controls against those scenarios and see whether each control is worth more than it costs.

It is built for risk analysts, vCISOs, GRC practitioners, and anyone studying for a security certification who wants to work real numbers rather than exam questions. Work is saved automatically in your browser, a bar chart compares annualised loss before and after safeguards, and the whole analysis exports to a PDF report with asset, scenario, and safeguard tables.

The Three Formulas

Quantitative risk analysis rests on a short chain of arithmetic. The tool applies it exactly as written, with no hidden adjustments.

SLE = AV × EF

Single loss expectancy is asset value multiplied by exposure factor. Asset value is the total value of the asset including replacement cost, revenue impact, and intangible value. Exposure factor is the proportion of that value destroyed by a single occurrence of the scenario, expressed as a percentage.

ALE = SLE × ARO

Annualised loss expectancy is single loss expectancy multiplied by the annual rate of occurrence. An ARO of 1.0 means once a year; 0.5 means once every two years; 4.0 means quarterly. ALE is the figure that belongs in a budget conversation, because it is already expressed per year and therefore directly comparable to an annual control cost.

Safeguard value = ALE₁ − ALE₂ − ACS

The value of a safeguard is the annualised loss before the control, minus the annualised loss after, minus the annual cost of the safeguard. A positive result means the control pays for itself in expected-loss terms. The tool labels this column ROI, but note precisely what it is: a net dollar figure per year, not a percentage ratio. If you want a ratio, divide the risk reduction by the annual cost yourself.

A worked example

Take a customer database valued at $2,000,000, covering replacement, revenue impact, and reputational value.

  • Scenario: ransomware encrypts the database. Exposure factor 60% — not total destruction, because some data is recoverable and the business continues in degraded form.
  • SLE = $2,000,000 × 0.60 = $1,200,000.
  • ARO = 0.5, meaning you judge this to be a once-in-two-years event given current controls.
  • ALE = $1,200,000 × 0.5 = $600,000 per year.

Now model a safeguard: immutable off-site backup plus endpoint detection and response, at $95,000 per year. It does not eliminate the scenario, but it reduces both terms. Exposure factor drops to 15%, because a clean restore limits the damage. ARO drops to 0.25, because EDR intercepts a share of attempts before encryption.

  • New SLE = $2,000,000 × 0.15 = $300,000.
  • New ALE = $300,000 × 0.25 = $75,000.
  • Safeguard value = $600,000 − $75,000 − $95,000 = $430,000 per year.

The control returns $430,000 of expected annual value against $95,000 of cost. Crucially, the model shows why: risk reduction of $525,000 came from cutting both exposure and frequency, and either alone would have delivered roughly half. That decomposition is what makes a quantitative model more useful than a red-amber-green rating — it tells you which lever to pull.

How to Use It

  1. Asset Valuation tab. Add each asset with a name, description, and total value. Value it fully: replacement cost plus revenue dependency plus intangible value such as customer trust. Undervaluing assets here quietly deflates every downstream figure.
  2. ALE Calculator tab. Attach one or more loss scenarios to each asset. Set the exposure factor as a percentage and the annual rate of occurrence as a decimal. SLE and ALE compute as you type.
  3. Safeguard Analysis tab. For each scenario, add candidate controls with an annual cost and the post-control exposure factor and ARO. The tool computes the new ALE and the net value.
  4. Summary tab. Total ALE before and after, total safeguard spend, net value, and a chart comparing each scenario before and after. Where a scenario has several candidate safeguards, the summary uses the one producing the lowest residual ALE.
  5. Export. The PDF carries an executive summary plus full asset, scenario, and safeguard tables.

Your work persists in browser local storage, so you can build an analysis across several sessions without an account.

Choosing Defensible Inputs

The arithmetic is trivial; the inputs are the hard part, and honest sourcing is what makes a quantitative analysis survive review.

Exposure factor should reflect what one occurrence actually destroys. Total loss of an asset is rare. A ransomware event against a system with working backups might have an exposure factor of 20–40%, dominated by downtime rather than data loss. A full database exfiltration of regulated records may exceed 100% of the database’s replacement cost once notification and fines are counted — in which case value the asset to include that exposure rather than pushing the exposure factor above 1.0.

Annual rate of occurrence is where most analyses become guesswork. Anchor it in published incidence data where you can. Verizon’s 2025 Data Breach Investigations Report, drawn from more than 22,000 incidents and 12,195 confirmed breaches, found ransomware present in 44% of breaches, rising to 88% of breaches at small and medium businesses, with third-party involvement doubling year on year to 30% and vulnerability exploitation now behind 20% of breaches. IBM’s Cost of a Data Breach Report 2026 found 39% of breached organisations had experienced at least one ransomware attack, up from 24% in 2023. Those are population frequencies, not your frequency — but they bound the plausible range, and citing them makes an ARO defensible in a way that “we thought once every three years” is not.

Asset value for data assets can be sized from breach cost research. IBM’s 2026 report put the global average breach cost at $4.99M and the US average at $11.5M across 602 organisations breached between March 2025 and February 2026, with healthcare highest at $6.64M. If you want a per-organisation figure built from your own record counts and industry, the data breach cost calculator produces one.

State your assumptions alongside your results. A quantitative model with documented inputs can be argued with productively; one presented as a black box invites rejection of the whole analysis.

Quantitative or Qualitative?

Quantitative analysis gives you dollars, which compare directly against control costs and insurance premiums. It demands numeric estimates you may not have. Qualitative analysis — likelihood and impact on ordinal scales — is faster and works when data is thin, but its scores cannot be added, averaged, or compared to a budget. Most mature programmes run both: a risk matrix to triage the register quickly, then quantitative analysis on the handful of risks that reach the top of it. Once you have an ALE, the cybersecurity ROI calculator extends the safeguard comparison to multi-year NPV and payback.

Frequently Asked Questions

What is the difference between SLE and ALE?

Single loss expectancy is the cost of one occurrence. Annualised loss expectancy is that cost multiplied by how often it is expected per year. ALE is the budgeting figure, because it is already annual and therefore comparable to an annual control cost.

How do I estimate the annual rate of occurrence?

Start with your own incident history, then bound it with published incidence rates for your sector and threat type. Express it as a decimal: 0.25 for once in four years, 2.0 for twice a year. If you can only give a range, run the analysis at both ends and report the spread rather than a false point estimate.

Can the exposure factor be over 100%?

The tool accepts up to 100%. If a single event would cost more than the asset’s stated value — likely once regulatory fines and notification are counted — raise the asset value to include that exposure rather than pushing the exposure factor higher. Keeping EF within 0–100% preserves the meaning of the formula.

Is the ROI column a percentage?

No. It is the net annual dollar value of the safeguard: risk reduction minus annual cost. A result of $430,000 means the control is expected to save that much per year net of its own cost. For a ratio, divide risk reduction by annual cost.

What if a safeguard covers several scenarios?

Model it against each scenario separately with its share of the annual cost, or model it once against the scenario it most affects and note the additional coverage. Counting the full cost against each scenario would understate its value; counting the full benefit in each would overstate it.

Does this replace a qualitative risk assessment?

No, it complements it. Qualitative scoring triages a large register quickly. Quantitative analysis is worth the effort on the small number of risks that matter enough to justify sourcing real numbers.

Is my data uploaded anywhere?

No. Everything runs in your browser and persists in local storage on your own device. Clearing site data removes it, so export the PDF before you rely on it.

Why does my ALE look implausibly large?

Usually an overstated exposure factor or an ARO above 1.0 applied to a rare event. Check that the exposure factor reflects partial rather than total loss, and that the rate of occurrence is expressed per year rather than per decade.

What Is Quantitative Risk Analysis

Quantitative risk analysis assigns numerical values — dollar amounts, probabilities, and expected losses — to security risks, enabling data-driven decisions about security investments. Unlike qualitative risk assessment (which uses subjective scales like High/Medium/Low), quantitative analysis calculates the expected monetary impact of threats, allowing direct comparison between the cost of security controls and the losses they prevent.

The FAIR (Factor Analysis of Information Risk) framework is the most widely adopted quantitative risk analysis model in cybersecurity. It decomposes risk into measurable factors: threat event frequency, vulnerability, and loss magnitude, producing dollar-denominated risk estimates that executives and boards can act on.

Key Formulas

MetricFormulaDescription
SLE (Single Loss Expectancy)Asset Value x Exposure FactorExpected loss from a single incident
ARO (Annualized Rate of Occurrence)Historical frequency or estimated probability per yearHow often the threat is expected to occur
ALE (Annualized Loss Expectancy)SLE x AROExpected yearly loss from a specific threat
Risk ReductionALE (before control) - ALE (after control)Annual savings from implementing a control
ROI(Risk Reduction - Control Cost) / Control CostReturn on security investment

Example Calculation

FactorValue
Asset value (customer database)$5,000,000
Exposure factor (data breach)40%
Single Loss Expectancy$2,000,000
Annualized Rate of Occurrence0.2 (once every 5 years)
Annualized Loss Expectancy$400,000/year
Proposed control cost (DLP system)$150,000/year
Risk reduction with control70%
Residual ALE$120,000/year
Annual savings$280,000/year
ROI87%

Common Use Cases

  • Security budget justification: Present quantified risk reduction to executives to justify security spending with concrete ROI calculations
  • Control prioritization: Compare the cost-effectiveness of different security controls by calculating risk reduction per dollar invested
  • Cyber insurance: Calculate expected losses to determine appropriate cyber insurance coverage levels and evaluate policy cost-effectiveness
  • Regulatory compliance: Frameworks like NIST CSF and ISO 27005 recommend quantitative risk assessment for mature security programs
  • Board reporting: Translate technical risks into financial terms that board members and executives can understand and act on

Best Practices

  1. Use ranges, not point estimates — Risk factors are uncertain. Use probability distributions (Monte Carlo simulation) rather than single values to produce realistic confidence intervals.
  2. Start with your highest risks — Apply quantitative analysis to your top 10-20 risks first. The precision of quantitative methods is most valuable for high-impact decisions.
  3. Base estimates on data — Use industry breach cost reports (Verizon DBIR, IBM Cost of a Data Breach), internal incident history, and threat intelligence to ground your estimates in evidence.
  4. Account for indirect costs — Direct costs (remediation, notification) are easy to estimate. Include indirect costs: reputation damage, customer churn, regulatory fines, and litigation.
  5. Update regularly — Risk factors change as your environment evolves. Recalculate quarterly or after significant changes to assets, threats, or controls.

Frequently Asked Questions

What is quantitative risk analysis?+

Quantitative risk analysis uses numerical values and formulas to measure risk in monetary terms. Key formulas include: Single Loss Expectancy (SLE) = Asset Value x Exposure Factor, and Annualized Loss Expectancy (ALE) = SLE x Annual Rate of Occurrence (ARO). This approach helps organizations make data-driven decisions about security investments.

How do I calculate safeguard ROI?+

Safeguard ROI is calculated as: (ALE before safeguard - ALE after safeguard) - Annual Cost of Safeguard (ACS). A positive result means the safeguard is cost-justified. This tool automatically computes ROI and shows the breakeven point where security investment pays for itself.

What is the difference between SLE and ALE?+

SLE (Single Loss Expectancy) represents the monetary loss from a single occurrence of a threat event. ALE (Annualized Loss Expectancy) accounts for how often that event occurs per year by multiplying SLE by the Annual Rate of Occurrence (ARO). ALE gives you the expected yearly cost of a specific risk.

What is Exposure Factor (EF)?+

Exposure Factor (EF) is the percentage of an asset that would be lost if a threat is realized, expressed as a value between 0% and 100%. For example, if a server worth $50,000 would be 60% damaged by a flood, the EF is 0.6 and the SLE would be $30,000.

How does this differ from qualitative risk analysis?+

Quantitative analysis uses specific dollar amounts and probabilities, producing concrete financial metrics like ALE. Qualitative analysis uses subjective ratings (High/Medium/Low) and risk matrices. Quantitative is more precise but requires more data; qualitative is faster but less precise. Both are covered in CISSP Domain 1.

Related tools

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.