Loss Exceedance Curve (LEC)

A Loss Exceedance Curve (LEC) plots the probability that annual losses will exceed each dollar amount, providing a view of the full shape of an organization's cyber exposure including expected losses and tail risk.

What the LEC Actually Shows

The LEC is a curve with loss magnitude on one axis and exceedance probability on the other. For any point on the curve, you can read either "how likely is it that annual losses exceed X" or "what is the loss level associated with an X% exceedance probability."

The curve compresses a full loss distribution into a single visualization. Point figures like the 1:100 annual loss (99th percentile) and the Average Annual Loss (mean of the distribution) can be read directly from the curve.

Why the LEC Matters

Boards and CFOs care about both the expected loss and the tail. The LEC shows both simultaneously. A program with low AAL but a heavy tail behaves very differently from one with the same AAL but a thin tail, and the LEC makes that visible.

The LEC is also the standard way to compare pre- and post-mitigation exposure. Investing in a specific control reshapes the curve, typically pulling the tail in. The magnitude of that reshaping is the quantified value of the investment.

The LEC in Board Reporting

Modern CRQ-driven board reporting often includes the LEC as a primary visual, alongside point figures for AAL, 1:100, and other return periods. See deciphering the Loss Exceedance Curve in cyber risk quantification for a fuller treatment.

How Kovrr Approaches the LEC

Kovrr's CRQ Platform produces LECs as standard output, calibrated against one of the largest cyber loss datasets in the industry. See what is cyber risk quantification (CRQ).

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.