Loss Event Frequency
Loss Event Frequency is an estimate of how often, within a set time period, a threat is expected to succeed in causing actual harm to an organization. It focuses not just on how often attackers try, but on how often those attempts turn into a loss that has real impact. It is a forecasting concept used to help quantify risk, not a measure of an organization's recovery capability or an insurance coverage term.
In factor-based cyber risk quantification (as used in the FAIR methodology and platforms such as SAFE One), Loss Event Frequency (LEF) is the probable frequency, within a given timeframe (commonly a 12-month window), that a threat action results in loss. It is distinct from Threat Event Frequency (TEF), which is the expected frequency that a threat actor acts against an asset; a threat event becomes a loss event only when it produces material impact. LEF is one of the two top-level factors combined with loss magnitude to derive a quantified risk estimate. It is an analytical/estimation construct and should not be conflated with resilience metrics (such as RTO or RPO) or with insurance policy terms (such as coverage triggers, retentions, or waiting periods); those govern recovery objectives and coverage conditions rather than the modeled likelihood of a loss occurring.
Why it matters
Loss Event Frequency is central to moving cyber risk conversations away from vague qualitative labels like "high" or "medium" and toward defensible, comparable estimates. Because it isolates how often threat activity is expected to actually produce material harm, rather than simply how often attackers act, it helps organizations distinguish between noise (frequent but harmless probing) and genuine loss exposure. This distinction matters for prioritization: two scenarios can involve similar volumes of attacker activity yet carry very different loss event frequencies once the likelihood of material impact is factored in.
For decision-makers, LEF is one of the two building blocks (alongside loss magnitude) used to derive a quantified risk estimate, which in turn can inform where to invest in controls, how to frame risk-transfer decisions, and how to communicate exposure to executives and boards. It is important to keep LEF in its proper lane: it is a forward-looking estimate of likelihood, not a statement of what will happen, and not a measure of how well an organization can recover once a loss occurs. Recovery capability is governed by resilience concepts such as recovery time and recovery point objectives, which are separate from the modeled frequency of loss.
LEF also should not be confused with anything in an insurance policy. It does not describe a coverage trigger, a retention, or a waiting period, and a high or low LEF does not by itself determine whether a given loss would be covered, coverage always depends on the specific policy wording, endorsements, exclusions, and conditions. Rather, LEF is an analytical input that can help an organization reason about how much risk it may want to mitigate, accept, or transfer, while remembering that transferring risk through insurance does not reduce the likelihood captured by the LEF estimate itself.
Who it's relevant to
Inside LEF
Common questions
Answers to the questions practitioners most commonly ask about LEF.
