Annualized Loss Expectancy (ALE)

Annualized Loss Expectancy (ALE) is a classical quantitative risk metric equal to the expected annual loss from a specific risk event, calculated as Single Loss Expectancy multiplied by Annual Rate of Occurrence.

What ALE Actually Calculates

ALE has a deliberately simple formula: Single Loss Expectancy (SLE) multiplied by the annual rate of occurrence. A single ransomware event might carry a $2M SLE, with an expected 0.25 occurrences per year, producing an ALE of $500K.

The metric predates modern CRQ by decades and appears throughout classical information security risk literature, including early NIST publications.

Why ALE Has Limits

ALE produces a point estimate, a single expected value per risk. That works for simple, well-characterized risks. It struggles with the reality of cyber, where losses are heavily skewed, event frequencies are uncertain, and correlated events matter more than isolated ones.

Modern CRQ approaches, particularly Monte Carlo-based methods, produce full loss distributions rather than point estimates. Those distributions can be summarized as ALE (mean of the distribution equals AAL), but they carry additional information about variance and tail risk that ALE alone cannot represent.

When ALE Is Still Useful

ALE remains useful for back-of-the-envelope comparisons, for teaching the basics of quantified risk, and for regulatory contexts that specifically reference it (some older standards and audit frameworks still cite ALE by name). Most mature CRQ programs report AAL rather than ALE while acknowledging the direct lineage.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.