1:100 Annual Loss
The 1:100 annual loss is the loss magnitude at the 99th percentile of the annual loss distribution, meaning the level a cyber portfolio is statistically expected to exceed roughly once every hundred years.
What the 1:100 Actually Represents
The 1:100 annual loss is a return period metric. It reads a specific point off the annual loss distribution: the loss level exceeded 1% of the time in any given year. It does not mean a loss of that size happens on a fixed 100-year schedule. It means the annual probability of exceeding it is 1%.
The measure is most commonly derived from the Loss Exceedance Curve (LEC) produced by cyber risk quantification.
Why the 1:100 Matters
Cyber exposure is not distributed evenly. Most years carry moderate loss activity. A small fraction of years produce catastrophic tail losses that dominate long-run averages. The 1:100 is the point that captures that tail without being so extreme that it disappears into statistical noise.
Boards and CFOs use the 1:100 as a stress test benchmark. It answers a specific business question: what is the size of loss the organization should be prepared to withstand in a bad-but-plausible year.
1:100 vs. Other Return Periods
The 1:100 sits alongside other return period markers commonly reported in CRQ: the 1:20 (5% annual exceedance probability, moderate tail), the 1:250 (0.4% exceedance, deeper tail), and the Average Annual Loss (expected value). Each answers a different question about the shape of exposure.
How Kovrr Approaches the 1:100
Kovrr's CRQ Platform produces the full loss exceedance curve for each modeled portfolio, with 1:100 and other return period figures reported alongside AAL as standard outputs. See what is cyber risk quantification (CRQ) for the broader framing.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


