Value at Risk (VaR)
Value at Risk (VaR) is a financial risk metric expressing the maximum loss expected at a given confidence level over a defined time horizon, originally developed in financial risk management and increasingly applied to cyber through CRQ.
What VaR Actually Says
A 99% one-year cyber VaR of $50M means the organization is 99% confident that annual cyber losses will not exceed $50M in any given year. Equivalently, there is a 1% chance losses will exceed that amount. The same information appears elsewhere as the 1:100 annual loss.
The two vocabularies come from different traditions. Return period language (1:100, 1:250) comes from actuarial and insurance modeling. VaR language comes from banking and financial risk. Both express the same underlying tail information.
Why VaR Vocabulary Matters
Financial services organizations already use VaR extensively for market, credit, and operational risk. Reporting cyber risk in VaR terms lets cyber exposure sit alongside other risk categories on the same terms, which is exactly what boards and CFOs increasingly ask for.
See how to translate cyber risk into financial terms the CFO understands.
VaR and Enterprise Risk Integration
Quantified cyber programs increasingly report both VaR and return period figures depending on audience. Financial risk teams prefer VaR. Insurance and actuarial teams prefer return period. The underlying data is the same, drawn from the Loss Exceedance Curve.
Beyond VaR
VaR has known limits, particularly around tail behavior beyond the confidence threshold. Complementary metrics like Conditional VaR (expected loss given that VaR is exceeded) address some of these limits. Mature CRQ outputs typically include multiple views of the tail rather than a single VaR number.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


