{
  "slug": "annualized-loss-expectancy",
  "title": "Annualized Loss Expectancy (ALE) Calculator",
  "heading": "Annualized Loss Expectancy Calculator",
  "category": "financial",
  "url": "https://www.revenuelab.fyi/toolbox/annualized-loss-expectancy",
  "summary": "Turn asset value, exposure, and threat frequency into a yearly risk dollar figure.",
  "description": "ALE is the backbone of quantitative risk assessment in FAIR and classic NIST risk models. It multiplies single loss expectancy (SLE) by the annualized rate of occurrence (ARO) to produce a dollar figure you can compare against control costs. SLE itself is asset value multiplied by exposure factor, the percentage of the asset's value destroyed in one incident. A $2M database with a 30% exposure factor from a single ransomware event has an SLE of $600,000. If that event realistically happens once every four years, ARO is 0.25 and ALE is $150,000 a year. This number is what justifies a security budget line: if a control costs $80,000 a year and cuts ARO in half, it saves $75,000 in expected loss, a straightforward return. The method breaks down when frequency estimates are guesses dressed up as precision, so pair it with a range (best/worst case ARO) rather than a single point estimate, and revisit it after every real incident or near miss.",
  "formula": "SLE = Asset Value × Exposure Factor. ALE = SLE × Annualized Rate of Occurrence (ARO).",
  "dateModified": "2026-09-30",
  "run_url": "https://www.revenuelab.fyi/api/public/calc?tool=annualized-loss-expectancy",
  "inputs": [
    {
      "id": "assetValue",
      "label": "Asset value",
      "kind": "number",
      "hint": null,
      "default": 2000000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "exposureFactor",
      "label": "Exposure factor (% of asset lost per incident)",
      "kind": "number",
      "hint": null,
      "default": 30,
      "unit": null,
      "min": 0,
      "max": 100
    },
    {
      "id": "aro",
      "label": "Annualized rate of occurrence (events/year)",
      "kind": "number",
      "hint": null,
      "default": 0.25,
      "unit": null,
      "min": 0,
      "max": 20
    },
    {
      "id": "controlCost",
      "label": "Proposed control cost per year",
      "kind": "number",
      "hint": null,
      "default": 80000,
      "unit": null,
      "min": 0,
      "max": null
    },
    {
      "id": "aroReduction",
      "label": "ARO reduction from control",
      "kind": "number",
      "hint": null,
      "default": 50,
      "unit": null,
      "min": 0,
      "max": 100
    }
  ],
  "outputs": [
    {
      "id": "ale",
      "label": "Annualized loss expectancy (before control)",
      "format": "currency",
      "hint": null,
      "primary": true
    },
    {
      "id": "sle",
      "label": "Single loss expectancy",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "newAle",
      "label": "ALE after control",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "savings",
      "label": "Annual expected loss avoided",
      "format": "currency",
      "hint": null,
      "primary": false
    },
    {
      "id": "netBenefit",
      "label": "Net benefit of control (savings − cost)",
      "format": "currency",
      "hint": null,
      "primary": false
    }
  ],
  "worked_example": {
    "inputs": [
      "Asset value: 2000000",
      "Exposure factor (% of asset lost per incident): 30",
      "Annualized rate of occurrence (events/year): 0.25",
      "Proposed control cost per year: 80000",
      "ARO reduction from control: 50"
    ],
    "outputs": [
      "Annualized loss expectancy (before control): $150,000",
      "Single loss expectancy: $600,000",
      "ALE after control: $75,000",
      "Annual expected loss avoided: $75,000",
      "Net benefit of control (savings − cost): -$5,000"
    ]
  },
  "how_to": {
    "title": "How to use this",
    "steps": [
      "Enter asset value.",
      "Enter exposure factor (% of asset lost per incident).",
      "Enter annualized rate of occurrence (events/year).",
      "Enter proposed control cost per year.",
      "Enter aro reduction from control.",
      "Read your annualized loss expectancy (before control) on the right — it updates as you type.",
      "Hit Share to keep the scenario or send it to someone."
    ]
  },
  "scenarios": [
    {
      "name": "Conservative",
      "description": "Lower-end numbers — what if things land soft?",
      "values": {
        "assetValue": 1200000,
        "exposureFactor": 18,
        "aro": 0.15,
        "controlCost": 48000,
        "aroReduction": 30
      }
    },
    {
      "name": "Typical",
      "description": "Defaults — the most common real-world setup.",
      "values": {
        "assetValue": 2000000,
        "exposureFactor": 30,
        "aro": 0.25,
        "controlCost": 80000,
        "aroReduction": 50
      }
    },
    {
      "name": "Ambitious",
      "description": "Higher-end numbers — what if things really pop?",
      "values": {
        "assetValue": 3200000,
        "exposureFactor": 48,
        "aro": 0.4,
        "controlCost": 128000,
        "aroReduction": 80
      }
    }
  ],
  "limitations": [
    "Results are estimates before tax, fees, and inflation unless an input explicitly covers them.",
    "Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.",
    "This is educational maths, not financial advice. Check anything contractual with the lender or your accountant."
  ],
  "faq": [
    {
      "q": "Where do I get an ARO number that isn't a guess?",
      "a": "Use your own incident history first, then industry breach reports (Verizon DBIR, IBM Cost of a Data Breach) for base rates by sector and size, and threat intel feeds for frequency of specific attack types against similar organizations. Blend all three and document your assumption so it can be challenged and updated later."
    },
    {
      "q": "What exposure factor should I assume for ransomware?",
      "a": "Most ransomware incidents destroy or encrypt 20-60% of an asset's effective value once you count downtime, recovery labor, and data that can't be restored from backup. Use the higher end if you lack tested offline backups, and the lower end if you have verified immutable backups with a known RTO."
    },
    {
      "q": "Is ALE useful if my numbers are rough?",
      "a": "Yes, because the value is in ranking and comparing options, not decimal precision. Running the calculation with pessimistic and optimistic ARO gives you a range that still tells you whether a control is worth funding."
    },
    {
      "q": "How does this differ from a qualitative risk matrix (high/medium/low)?",
      "a": "A matrix tells you priority order, ALE tells you a dollar figure you can put next to a budget request. Both have a place, but finance and executives respond better to a defensible dollar number than a color code."
    }
  ],
  "related": [
    "https://www.revenuelab.fyi/toolbox/breach-cost-per-record",
    "https://www.revenuelab.fyi/toolbox/vendor-risk-exposure",
    "https://www.revenuelab.fyi/toolbox/ransomware-downtime-cost"
  ],
  "license": "CC-BY-4.0",
  "citation": "RevenueLab — Annualized Loss Expectancy (ALE) Calculator (https://www.revenuelab.fyi/toolbox/annualized-loss-expectancy)"
}