An information security manager is quantifying the annual loss expectancy for a customer database exposed to ransomware. The asset is valued at 4,000,000 pounds, the exposure factor for a successful ransomware event is estimated at 25 per cent, and historical and threat-intelligence data suggest such an event is likely twice per year. What is the annual loss expectancy that should be reported to support the business case for additional controls?
- A1,000,000 pounds, calculated as the asset value multiplied by the exposure factor for a single occurrence.
- B2,000,000 pounds, calculated as the single loss expectancy multiplied by the annualised rate of occurrence. Correct
- C8,000,000 pounds, calculated as the asset value multiplied by the annualised rate of occurrence.
- D500,000 pounds, calculated as the single loss expectancy divided by the annualised rate of occurrence.
Why A is wrong: This is the single loss expectancy, not the annual loss expectancy; it ignores the annualised rate of occurrence of two events per year, so it understates the expected yearly loss.
Why B is correct: Single loss expectancy is 4,000,000 multiplied by 0.25, giving 1,000,000, and annual loss expectancy is the single loss expectancy multiplied by the annualised rate of occurrence of two, giving 2,000,000, which is the correct expected annual loss.
Why C is wrong: This multiplies the full asset value by the rate of occurrence and omits the exposure factor, which treats every event as a total loss of the asset and badly overstates the annual loss expectancy.
Why D is wrong: Dividing rather than multiplying by the rate of occurrence inverts the relationship; a higher event frequency must raise, not lower, the annual loss expectancy, so this is wrong.