TechKnowSurge
CompTIA Security+ 5.2 ISC2 CISSP 1.9 CompTIA SecurityX 1.3 NIST CSF GV.RM-06 NIST CSF ID.RA-04
VideoSecurityFree

Quantitative Risk Analysis

Quantitative risk analysis translates cybersecurity risks into measurable dollar amounts, giving organizations a clear, comparable basis for evaluating and prioritizing threats. This approach moves beyond subjective high-medium-low ratings by factoring in probability, full financial impact, and annualized loss expectations for recurring risks.

Complete this video to capture a CTF flag worth 1 point.

About this video

Quantitative risk analysis converts cybersecurity risk into concrete dollar amounts, enabling organizations to compare and prioritize threats on a common financial scale. The core calculation multiplies the probability of a risk event by its total impact, producing a figure that reflects the true cost of exposure rather than a subjective rating like high, medium, or low. This makes the stakes of individual risks immediately tangible to stakeholders and decision-makers. Determining impact accurately requires looking well beyond the purchase price or book value of affected assets. Using the example of stolen servers, the real financial damage extends to replacement and deployment costs, lost revenue during downtime, regulatory fines if data protection requirements were violated, mandatory customer notification, and long-term reputational harm that can drive customer attrition. A thorough impact assessment accounts for all of these consequences to produce a number that reflects what the organization would actually lose. For risks that are not one-time events but ongoing business realities — such as employees periodically falling for scams — quantitative analysis incorporates annualized loss expectancy. This metric estimates the average financial loss an organization can expect from a given threat over the course of a year, combining the frequency of incidents with the average cost of each. Together, single-event impact analysis and annualized loss expectancy give risk managers the tools to translate uncertainty into actionable financial intelligence.

What you'll learn

What's covered

Quantitative Risk Analysis

Aligned to

CompTIA Security+
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts
CompTIA SecurityX
1.3 Explain the importance of risk management for an enterprise.
NIST CSF
GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated.
ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded.

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Quantitative Risk Analysis
A risk analysis method that assigns numerical values — such as probability percentages and monetary loss estimates — to risks in order to prioritize them and justify the cost of controls. It produces metrics like Single Loss Expectancy and Annualized Loss Expectancy.
Annualized Loss Expectancy
ALE
Annualized Loss Expectancy is a risk metric representing the expected yearly monetary loss from a threat, calculated by multiplying the Single Loss Expectancy by the Annualized Rate of Occurrence.
Impact
The potential consequence or damage to an organization if a risk event occurs, expressed qualitatively or as a monetary value.

Topics

Quantitative Risk Analysis Risk Management Annualized Loss Expectancy Cybersecurity Risk Financial Impact Assessment

Transcript

A great way to compare the different risks that we have to a company is using quantitative risk analysis. It's a way that we can render down our information into some sort of quantity — in this case, into a dollar amount, a dollar amount associated with that risk.

In our example here we're taking a probability, a percent, times the impact, to create a dollar amount, versus something like a likelihood and impact where we're just selecting high, medium and low from a list. So we're getting to the actual dollar amount. What's great about this is it really drives home the point of what the risk is of our specific risks. It's a great way to do risk comparison.

Understanding impact

To be able to calculate our risk, we really have to understand what the impact is. Let's use the example of, let's say we have a few servers — there are three servers here — and those servers were stolen. In the scenario we have a 100% loss of these assets.

So now the question is, do we use the asset value, or do we use a total cost of ownership? Asset value being the assets that these servers have right there, either on the books or what we purchased them for; and the total cost of ownership would be, what is all that went into setting these up and getting them back up and running.

I'm going to say that the impact is neither of those, because the asset value is really just the purchase price or the depreciated value there, and those aren't really representative of what the impact is going to be. Because if we buy all new servers to replace them, we have deployment costs there. The operation cost really isn't a factor here, so we can ignore that one — it does play into total cost of ownership, but it's not really going to affect the new servers, we'd be paying for it whether we have the old servers or the new servers. Same thing with ongoing maintenance: we're going to have that ongoing maintenance whether they're new servers or old servers, so the impact doesn't change those. We don't need new training, new processes. So there's going to be some extra costs here for things like deployment, but total cost of ownership isn't representative of it either. So we have to kind of choose what is going to be actually impactful if these servers were to be stolen.

The impact goes beyond the asset

The impact goes beyond just the loss of those assets. We have the loss of asset, which is one consideration here, but there are other considerations as well. These are all of what could happen with a cyber security incident.

For instance, those servers are now gone, they were stolen, so they're not operating during that time. If we were an e-commerce business, we're losing revenue at that point in time. Or maybe we were caught, then we had to admit that we didn't encrypt the drives, and that was against laws and regulations, so now there's some judgment and fines. Not to mention now we have to notify the customers, so we have got to go out and notify the customers. Now we have a reputation loss, and because of that our brand is not as powerful as it used to be, and because of that maybe now we're going to actually lose some customers. So it could be very devastating beyond just the value of these servers that were stolen.

When we analyze impact we really have to look at all of the considerations that go into both the assets themselves and what the loss means to the company as a whole. What is the full impact?

Once we understand what the impact is going to be by understanding these, what we have to do is just figure out what the probability is that these servers are going to get stolen, and now that's going to equate to some sort of dollar amount associated with risk.

Recurring risks

There is one other consideration that I'm just going to throw out there, which is what happens to things that are reoccurring risks. There are some risks that are just associated with maybe a project that you have, and how are you going to deal with that risk. But there are some ongoing risks that need to be considered as well.

For instance, in this case right here, let's say we have scams that are actively being carried out on our employees, and we have employees now and then that fall for that. This is a reality of doing business today: we're going to probably lose some money to scams. If we've got a big enough workforce, it's probably just a matter of time until that's going to happen.

So what we need to figure out in this case is what our annualized loss expectancy is for this. What this essentially means is that on an annual basis there's going to be a certain amount of employees that are going to fall for this every single year, and there's an average expected loss for each one of those, and so then we'll find out what our annualized loss expectancy is.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →