Annualized Loss Expectancy
Annualized Loss Expectancy (ALE) is a way to estimate how much money an organization can expect to lose from a specific risk or threat over the course of a year. It combines how much a single incident would cost with how often that incident is likely to happen in a year, producing a single dollar figure. This figure helps leaders compare risks and decide where to focus attention and spending.
Annualized Loss Expectancy (ALE) is a quantitative risk analysis metric expressing the expected monetary loss associated with a specific threat to an asset over a one-year period. It is calculated as the product of the Single Loss Expectancy (SLE), the expected loss from one occurrence of the event, and the Annual Rate of Occurrence (ARO), the estimated frequency of that event per year: ALE = SLE × ARO. Because ALE normalizes loss to an annualized rate, it supports prioritization and comparison across distinct risks and informs decisions such as control investment and risk treatment. Its accuracy depends heavily on the quality of the SLE and ARO estimates, which are often uncertain and should be treated as informed approximations rather than precise predictions.
Why it matters
Annualized Loss Expectancy gives security leaders a way to translate abstract threats into a financial figure that business executives and boards can weigh against other priorities. Because it expresses risk as an annualized dollar amount, ALE allows an organization to prioritize and compare distinct risks on a common scale, which is often more persuasive to budget holders than qualitative descriptions such as high, medium, or low. For a virtual or fractional CISO whose core value lies in framing security as a business risk function rather than a purely technical one, ALE is a useful instrument for justifying control investments and structuring risk treatment decisions.
The metric also disciplines the conversation about where to spend. By combining the cost of a single incident with how frequently that incident is expected to occur, ALE helps leaders avoid over-investing in low-frequency, low-impact risks or under-investing in frequent, costly ones. It can support a rational comparison between the annualized cost of a risk and the cost of a control intended to reduce it, which is central to defensible risk treatment recommendations.
Its value, however, depends entirely on the quality of the inputs. ALE is built from estimates of Single Loss Expectancy and Annual Rate of Occurrence, both of which are frequently uncertain. Presenting an ALE figure as a precise prediction rather than an informed approximation can mislead decision-makers and erode trust when actual outcomes diverge. A virtual CISO should present ALE with its assumptions stated, and should treat it as one input into risk decisions rather than a guarantee of future loss or breach prevention.
Who it's relevant to
Inside ALE
Common questions
Answers to the questions practitioners most commonly ask about ALE.