Loss Exceedance Curve
A loss exceedance curve is a graph that shows the probability that a financial loss will be larger than a given amount, usually over a set period such as a year. Instead of predicting a single dollar figure, it presents a range of possible losses paired with the likelihood of each being exceeded. This helps decision-makers see, for example, how likely it is that losses will exceed a specific threshold within a year.
A loss exceedance curve (LEC) is a graphical representation that plots the probability that a given loss magnitude will be exceeded over a defined time horizon, typically annualized. The horizontal axis displays loss magnitude (commonly expressed in financial terms), while the vertical axis displays the exceedance probability, generally ranging from 0% to 100%; some representations also express the vertical axis as frequency and its inverse, the return period. In cyber risk quantification, LECs are frequently used to communicate the output of probabilistic risk models, such as those following FAIR methodology, by conveying the full distribution of potential loss outcomes rather than a single point estimate, supporting risk-tolerance and prioritization decisions. Interpretation requires reading a probability from the vertical axis against a corresponding loss threshold on the horizontal axis, and the curve's usefulness depends on the quality of the underlying loss and frequency estimates.
Why it matters
A loss exceedance curve matters because it replaces a single, often misleading, point estimate of cyber risk with a full picture of possible outcomes and their likelihoods. When security leaders present risk as one number, they obscure the reality that losses fall across a range, from modest and frequent to severe and rare. By plotting the probability that a loss will exceed a given amount over a defined period, typically a year, an LEC lets executives and boards see how likely it is that losses will cross a threshold that matters to them, such as a level that would trigger regulatory concern or strain the balance sheet.
For a virtual or fractional CISO, this framing is a core governance tool rather than a technical exercise. Security leadership is fundamentally about communicating business risk to decision-makers who allocate budget and set tolerance. An LEC supports risk-tolerance and prioritization decisions by translating the output of probabilistic models into a form that aligns with how officers already think about financial exposure. It helps move a conversation away from tool-by-tool debates and toward the question of whether the organization's exposure sits within its stated appetite.
The value of an LEC depends heavily on the quality of the underlying loss and frequency estimates that feed it. A curve built on poorly sourced or unexamined inputs can convey false precision, and readers may over-trust a smooth line. Because accountability for security decisions typically remains with the client organization and its officers, an LEC is best treated as a decision-support artifact that informs judgment, not a guarantee of any particular outcome.
Who it's relevant to
Inside LEC
Common questions
Answers to the questions practitioners most commonly ask about LEC.