Quantitative risk analysis
Also known as: quantitative risk assessment
Putting numbers on risks - how often a loss may happen and how much it would cost - to compare them in money.
Draft - this entry has not been reviewed yet.
Formal
A risk assessment method that estimates likelihood as a rate or probability and impact as a money amount, giving an expected yearly loss that can be weighed directly against the cost of a control or of insurance.
In plain English
Like deciding on an extended warranty for a washing machine - if a repair costs 2,000 and is needed once in five years, paying 800 a year for the warranty is a bad deal.
In practice
The finance team at a trucking company works out that a day without its planning system costs 400,000 kroner and happens about once every four years - an expected 100,000 a year - so a 60,000-a-year backup service that cuts such a day to an hour is worth buying.
Why it matters
Leaders understand money, and figures make it possible to compare security spending with other investments, though good data is often hard to find.
Technical deep dive
The classic textbook model, familiar from CISSP material, uses point estimates. Single loss expectancy is asset value times exposure factor (SLE = AV × EF), the share of the value lost in one event; annualised loss expectancy is SLE times the annualised rate of occurrence (ALE = SLE × ARO). A control is justified when ALE before minus ALE after, minus the control's annual cost, is positive. The arithmetic is simple, but a single ALE figure hides the shape of the loss: an event expected once in a hundred years that costs 50 million has an ALE of 500,000, the same as a frequent 50,000 nuisance occurring ten times a year, yet only the first can threaten the organisation's survival.
Modern practice replaces points with distributions. FAIR (Factor Analysis of Information Risk), published by The Open Group as the Open FAIR standards O-RT (risk taxonomy) and O-RA (risk analysis), decomposes risk into loss event frequency and loss magnitude. Loss event frequency is threat event frequency times vulnerability, meaning the probability that a threat event becomes a loss event; loss magnitude is split into primary loss, borne directly, and secondary loss arising from stakeholder reactions such as fines, lawsuits and customer churn. Each factor is estimated as a range, typically minimum, most likely and maximum fed into a PERT or lognormal distribution, and Monte Carlo simulation produces a loss exceedance curve showing the probability that annual loss exceeds any given amount.
The loss exceedance curve is what makes the method useful for decisions: it can be compared with a risk appetite curve set by leadership, used to compare controls by how much they shift the curve, and read at the tail to choose insurance limits and retentions. Hubbard and Seiersen's How to Measure Anything in Cybersecurity Risk argues that calibrated expert estimates, expressed as 90% confidence intervals by people trained to be neither over- nor underconfident, outperform ordinal scoring even with sparse data.
Weaknesses are practical rather than theoretical. Good frequency data is scarce, so estimates lean on incident history, industry loss studies and insurance claims data that may not fit the organisation; results can look authoritative while resting on weak inputs; correlated losses, such as a single cloud provider outage hitting many processes at once, are easy to model as independent by mistake; and the effort means most organisations quantify only a few top risks. The output is a model of uncertainty, not a forecast, and should be reported with its ranges and key assumptions.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Quantitative risk analysis
Relationships
- A kind of
- Risk assessment
- Requires
- RiskLikelihoodImpact
- Don't confuse with
- Qualitative risk analysis
- Used with
- Risk transfer
Sources & further reading
Standards & official texts
- NIST SP 800-30 Rev. 1 - Guide for Conducting Risk Assessments
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 5
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…