
Rex says
Money math without the spreadsheet headache. Plug in your numbers and I'll show you exactly where the dollars land.
Try a scenario
Click to load — tweak from there.Inputs
Result
Annualized loss expectancy (before control)
$150,000
Single loss expectancy
$600,000
ALE after control
$75,000
Annual expected loss avoided
$75,000
Net benefit of control (savings − cost)
-$5,000

Psst — share this and help Rex grow
One click, a permanent link with your numbers baked in.
How to use this
- 1Enter asset value.
- 2Enter exposure factor (% of asset lost per incident).
- 3Enter annualized rate of occurrence (events/year).
- 4Enter proposed control cost per year.
- 5Enter aro reduction from control.
- 6Read your annualized loss expectancy (before control) on the right — it updates as you type.
- 7Hit Share to keep the scenario or send it to someone.
About this calculator
ALE is the backbone of quantitative risk assessment in FAIR and classic NIST risk models. It multiplies single loss expectancy (SLE) by the annualized rate of occurrence (ARO) to produce a dollar figure you can compare against control costs. SLE itself is asset value multiplied by exposure factor, the percentage of the asset's value destroyed in one incident. A $2M database with a 30% exposure factor from a single ransomware event has an SLE of $600,000. If that event realistically happens once every four years, ARO is 0.25 and ALE is $150,000 a year. This number is what justifies a security budget line: if a control costs $80,000 a year and cuts ARO in half, it saves $75,000 in expected loss, a straightforward return. The method breaks down when frequency estimates are guesses dressed up as precision, so pair it with a range (best/worst case ARO) rather than a single point estimate, and revisit it after every real incident or near miss.
Worked example
Using the values the calculator loads with:
Inputs
- Asset value: 2000000
- Exposure factor (% of asset lost per incident): 30
- Annualized rate of occurrence (events/year): 0.25
- Proposed control cost per year: 80000
- ARO reduction from control: 50
Results
- Annualized loss expectancy (before control): $150,000
- Single loss expectancy: $600,000
- ALE after control: $75,000
- Annual expected loss avoided: $75,000
- Net benefit of control (savings − cost): -$5,000
What each field means
Inputs
- Asset value
- The asset value used in the calculation. Starts at 2000000 so you have a working example on load.
- Exposure factor (% of asset lost per incident)
- The exposure factor (% of asset lost per incident) used in the calculation. Starts at 30 so you have a working example on load. Accepted range: 0–100.
- Annualized rate of occurrence (events/year)
- The annualized rate of occurrence (events/year) used in the calculation. Starts at 0.25 so you have a working example on load. Accepted range: 0–20.
- Proposed control cost per year
- The proposed control cost per year used in the calculation. Starts at 80000 so you have a working example on load.
- ARO reduction from control
- The aro reduction from control used in the calculation. Starts at 50 so you have a working example on load. Accepted range: 0–100.
Results
- Annualized loss expectancy (before control)
- Returned as a money amount in US dollars and shown as the headline result. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Single loss expectancy
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- ALE after control
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Annual expected loss avoided
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Net benefit of control (savings − cost)
- Returned as a money amount in US dollars. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
FAQ
Where do I get an ARO number that isn't a guess?
Use your own incident history first, then industry breach reports (Verizon DBIR, IBM Cost of a Data Breach) for base rates by sector and size, and threat intel feeds for frequency of specific attack types against similar organizations. Blend all three and document your assumption so it can be challenged and updated later.
What exposure factor should I assume for ransomware?
Most ransomware incidents destroy or encrypt 20-60% of an asset's effective value once you count downtime, recovery labor, and data that can't be restored from backup. Use the higher end if you lack tested offline backups, and the lower end if you have verified immutable backups with a known RTO.
Is ALE useful if my numbers are rough?
Yes, because the value is in ranking and comparing options, not decimal precision. Running the calculation with pessimistic and optimistic ARO gives you a range that still tells you whether a control is worth funding.
How does this differ from a qualitative risk matrix (high/medium/low)?
A matrix tells you priority order, ALE tells you a dollar figure you can put next to a budget request. Both have a place, but finance and executives respond better to a defensible dollar number than a color code.
Accuracy and limitations
- Results are estimates before tax, fees, and inflation unless an input explicitly covers them.
- Rates are treated as fixed for the whole period — variable-rate products will drift from this projection.
- This is educational maths, not financial advice. Check anything contractual with the lender or your accountant.
Related tools
Data Breach Cost Calculator
Estimate total breach cost from records exposed, industry, and detection speed.
Vendor Risk Exposure Calculator
Score and dollar-weight vendor risk from data access, criticality, and control maturity.
Ransomware Downtime Cost Calculator
Model lost revenue, labor, and recovery cost for each day systems are down.
Cite this calculator
Writing about this topic? Grab a citation — every link helps keep these tools free.
RevenueLab. (2026). Annualized Loss Expectancy (ALE) Calculator. Retrieved from https://www.revenuelab.fyi/toolbox/annualized-loss-expectancy
<p>Source: <a href="https://www.revenuelab.fyi/toolbox/annualized-loss-expectancy" target="_blank" rel="noopener">Annualized Loss Expectancy (ALE) Calculator — RevenueLab</a> (2026).</p>
Source: [Annualized Loss Expectancy (ALE) Calculator — RevenueLab](https://www.revenuelab.fyi/toolbox/annualized-loss-expectancy) (2026).
