Quantitative risk analysis
Also known as: quantitative risk assessment
Putting numbers on risks - how often a loss may happen and how much it would cost - to compare them in money.
Draft - this entry has not been reviewed yet.
Formal
A risk assessment method that estimates likelihood as a rate or probability and impact as a money amount, giving an expected yearly loss that can be weighed directly against the cost of a control or of insurance.
In plain English
Like deciding on an extended warranty for a washing machine - if a repair costs 2,000 and is needed once in five years, paying 800 a year for the warranty is a bad deal.
In practice
The finance team at a trucking company works out that a day without its planning system costs 400,000 kroner and happens about once every four years - an expected 100,000 a year - so a 60,000-a-year backup service that cuts such a day to an hour is worth buying.
Why it matters
Leaders understand money, and figures make it possible to compare security spending with other investments, though good data is often hard to find.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Pick the few risks where a money figure changes a decision, such as a large control investment, an insurance limit or a risk above appetite, rather than quantifying the whole register.
- Write each risk as a precise scenario with one asset, one threat and one type of loss, for example ransomware stopping the planning system for several days.
- Gather data on how often such events happen and what they cost, from your own incident history, industry loss studies, insurers and the finance team's figures for downtime and recovery.
- Have calibrated experts give a minimum, most likely and maximum value (a 90 % range) for event frequency and for each type of loss, including secondary losses such as fines and lost customers.
- Run a Monte Carlo simulation, in a spreadsheet or a FAIR tool, to produce a loss exceedance curve and the expected annual loss.
- Model the risk again with the proposed control or insurance in place, and compare the drop in expected loss and in the tail with the control's yearly cost.
- Present the results to management as ranges with the key assumptions, and compare the curve with the risk appetite agreed with them.
- Update the inputs after incidents, control changes or new loss data, and check earlier estimates against what actually happened to improve calibration.
Common pitfalls
- Presenting a single ALE figure, which hides a rare loss large enough to threaten the organisation.
- Letting precise-looking numbers rest on guesses that nobody documented or challenged.
- Modelling losses as independent when one supplier or cloud outage can hit many processes at once.
- Trying to quantify every risk in the register and running out of time and data.
Good guides
- NIST IR 8286A Rev. 1 - Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management(opens in a new tab) · NIST
- The Open FAIR Body of Knowledge(opens in a new tab) · The Open Group
- Vejledning i risikostyring inden for informationssikkerhed (2025)(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
Technical deep dive
The classic textbook model, familiar from CISSP material, uses point estimates. Single loss expectancy is asset value times exposure factor (SLE = AV × EF), the share of the value lost in one event; annualised loss expectancy is SLE times the annualised rate of occurrence (ALE = SLE × ARO). A control is justified when ALE before minus ALE after, minus the control's annual cost, is positive. The arithmetic is simple, but a single ALE figure hides the shape of the loss: an event expected once in a hundred years that costs 50 million has an ALE of 500,000, the same as a frequent 50,000 nuisance occurring ten times a year, yet only the first can threaten the organisation's survival.
Modern practice replaces points with distributions. FAIR (Factor Analysis of Information Risk), published by The Open Group as the Open FAIR standards O-RT (risk taxonomy) and O-RA (risk analysis), decomposes risk into loss event frequency and loss magnitude. Loss event frequency is threat event frequency times vulnerability, meaning the probability that a threat event becomes a loss event; loss magnitude is split into primary loss, borne directly, and secondary loss arising from stakeholder reactions such as fines, lawsuits and customer churn. Each factor is estimated as a range, typically minimum, most likely and maximum fed into a PERT or lognormal distribution, and Monte Carlo simulation produces a loss exceedance curve showing the probability that annual loss exceeds any given amount.
The loss exceedance curve is what makes the method useful for decisions: it can be compared with a risk appetite curve set by leadership, used to compare controls by how much they shift the curve, and read at the tail to choose insurance limits and retentions. Hubbard and Seiersen's How to Measure Anything in Cybersecurity Risk argues that calibrated expert estimates, expressed as 90% confidence intervals by people trained to be neither over- nor underconfident, outperform ordinal scoring even with sparse data.
Weaknesses are practical rather than theoretical. Good frequency data is scarce, so estimates lean on incident history, industry loss studies and insurance claims data that may not fit the organisation; results can look authoritative while resting on weak inputs; correlated losses, such as a single cloud provider outage hitting many processes at once, are easy to model as independent by mistake; and the effort means most organisations quantify only a few top risks. The output is a model of uncertainty, not a forecast, and should be reported with its ranges and key assumptions.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Quantitative risk analysis
Relationships
- A kind of
- Risk assessment
- Requires
- RiskLikelihoodImpact
- Don't confuse with
- Qualitative risk analysis
- Used with
- Risk transfer
Sources & further reading
Standards & official texts
- NIST SP 800-30 Rev. 1 - Guide for Conducting Risk Assessments
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 5
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…