* Annualized loss expectancy explained
endif; ?>As I’ve mentioned in the four-part textbook review in recent issues, one of the most important tools of quantitative risk management is the annualized loss expectancy. The ALE is calculated by using probabilities of events (as the name implied, calculated over a period of a year) and the expected costs associated with those events.
To get a simple illustration of how ALE works, one can apply it to an insurance or any other loss-management computation.
Suppose an insurance-company statistician, called an actuary, determines that the likelihood that a particular customer will die in the coming year is about 0.005 (0.5%). For a million-dollar insurance policy, the insurance company is betting the customer that he won’t die this year; the customer is betting that he will die this year. If the customer dies, the company will pay his beneficiary $1 million; if he does not die, they get to keep all of his premium. Although in reality the loss to the insurer is the payout minus the premium, for simplicity’s sake, we can ignore this minor difference in our illustration.
Readers will easily be able to see that with the 0.005/year probability of death, the actuary will be able to calculate a premium of $5,025.13 as the break-even point for the company (because 0.005*-$1,000,000 + 0.995*$5,025.13 = $0). Any premium above $5,025.13 will make a profit for the company on average for this class of customer and any premium below that amount will, on average, result in losses.
Back to our insurance-company actuary. She knows that the 0.005 probability happens to have been based on, say, 1,000 observations of men of this particular age, health status, occupational status, and other demographic attributes associated with differential mortality. Using standard statistical methods, she can easily compute (as I just did in less than one minute using the well-known Minitab statistical software package) that the probability of death for this class of customer might be as low as 0.001625 or as high as 0.011629 with a confidence of 95%; i.e., that the calculated interval – what statisticians call the “95% confidence limits” – would include the real (the “parametric”) population’s proportion in 95% of the random samples of 1,000 from the population in question.
Using those numbers, we discover that the break-even points would go down to $1,627.64 or up to $11,765.82. So the actuary would turn the figures over to the financial and marketing experts in the company, who would then evaluate how high they could reasonably put the premium while maintaining their market share – and how low they would be willing to push down the premium given the increasing risks of losses.
What the actuary has done for her company is a sensitivity analysis. I recommend that IA practitioners learn to use sensitivity analysis on all quantitative risk-management techniques that use estimated costs and estimated probabilities.
My worry about naïve applications of ALE calculations is that neither the costs nor the probabilities associated with security breaches are known precisely in any given organization or situation. Given the often-large uncertainty (sometimes orders of magnitude) in the numerical values used in these computations, practitioners should apply sensitivity analysis to evaluate the results of such models.
As we saw in the insurance example, sensitivity analysis examines the consequences of varying assumptions on the results of numerical models. Rather than assuming that a fixed result of a single calculation should be taken on faith as the basis for making a decision about expenditures, practitioners can make a number of computations using reasonable ranges of probabilities and reasonable ranges of costs. The set of results is typically evaluated using graphical representation and can provide a much more convincing basis for discussion with colleagues than a single estimate with no sense of possible variability or error.
An extension of this manual process is called Monte Carlo simulation and can involve thousands of stochastic computations based on underlying probabilistic models for some or all of the parameters of a numerical model. Typically we show the results of such aleatory (random) processing as graphs.
Incidentally, I recently priced the cost of a new 20-year term $250,000 life-insurance policy; it is about $2,000 a year – pretty close to the figures used in the illustration in today’s column.




