Put a dollar figure on a risk
Quantify a risk as Annualized Loss Expectancy (ALE) using a simplified Open FAIR model โ so you can express risk in dollars for the board and compare controls by risk-reduced-per-dollar.
Simplified Open FAIR model (The Open Group / FAIR Institute). This is an estimation model for decision support โ the ยฑ50% range reflects the uncertainty inherent in any risk estimate. It is not a prediction; use ranges and your own calibrated inputs, and treat the output as an input to judgement, not a result.

What is ALE in cyber security?
ALE (Annualized Loss Expectancy) is the average amount of money you should expect to lose from a particular risk over one year. It converts a fuzzy โhigh / medium / lowโ risk rating into a dollar figure that a board or budget owner can actually act on, which is why it sits at the heart of quantitative risk methods like FAIR and appears in certifications such as CISSP.
It is built from two ideas:
- SLE (Single Loss Expectancy) โ the dollar loss from one occurrence of the event: SLE = Asset Value ร Exposure Factor.
- ARO (Annual Rate of Occurrence) โ how many times per year you expect it to happen.
- ALE = SLE ร ARO โ the annualized figure the calculator above returns in dollars.
Comparing the ALE before and after a control is the cleanest way to justify security spend: if a $40,000 control cuts a $250,000 ALE to $50,000, that is a $200,000/yr risk reduction for $40,000. Use the calculator's control-ROI mode to rank mitigations, and pair it with the Breach Cost Calculatorand the NIST CSF 2.0 assessment to turn the numbers into a plan.