A risk practitioner has calculated the single loss expectancy for a customer database breach as 800,000 and judges that such a breach occurs roughly once every four years. Which annualised loss expectancy should be reported to support the comparison of this risk against the cost of a proposed control?
- A3,200,000, because the single loss expectancy is multiplied by the four-year exposure window to show full lifetime loss.
- B200,000, because the single loss expectancy is multiplied by an annualised rate of occurrence of 0.25 events per year. Correct
- C800,000, because the single loss expectancy is itself the annualised figure once a credible breach scenario has been defined.
- D400,000, because the single loss expectancy is halved to reflect the average position across the four-year recurrence cycle.
Why A is wrong: This multiplies single loss expectancy by the number of years rather than the annual rate of occurrence, inflating the figure and misrepresenting the metric the formula produces.
Why B is correct: Annualised loss expectancy equals single loss expectancy times annualised rate of occurrence, and one event every four years gives a rate of 0.25, so 800,000 times 0.25 is 200,000.
Why C is wrong: This treats single loss expectancy as already annualised, which is tempting but ignores that frequency below once per year must scale the value down.
Why D is wrong: Halving the loss has no basis in the annualised loss expectancy formula and confuses an averaging heuristic with the rate of occurrence multiplier.