Skip to main content
Category: Loss Modeling & Aggregation

Loss Event Frequency

Also known as:
Simply put

Loss Event Frequency is an estimate of how often, within a set time period, a threat is expected to succeed in causing actual harm to an organization. It focuses not just on how often attackers try, but on how often those attempts turn into a loss that has real impact. It is a forecasting concept used to help quantify risk, not a measure of an organization's recovery capability or an insurance coverage term.

Formal definition

In factor-based cyber risk quantification (as used in the FAIR methodology and platforms such as SAFE One), Loss Event Frequency (LEF) is the probable frequency, within a given timeframe (commonly a 12-month window), that a threat action results in loss. It is distinct from Threat Event Frequency (TEF), which is the expected frequency that a threat actor acts against an asset; a threat event becomes a loss event only when it produces material impact. LEF is one of the two top-level factors combined with loss magnitude to derive a quantified risk estimate. It is an analytical/estimation construct and should not be conflated with resilience metrics (such as RTO or RPO) or with insurance policy terms (such as coverage triggers, retentions, or waiting periods); those govern recovery objectives and coverage conditions rather than the modeled likelihood of a loss occurring.

Why it matters

Loss Event Frequency is central to moving cyber risk conversations away from vague qualitative labels like "high" or "medium" and toward defensible, comparable estimates. Because it isolates how often threat activity is expected to actually produce material harm, rather than simply how often attackers act, it helps organizations distinguish between noise (frequent but harmless probing) and genuine loss exposure. This distinction matters for prioritization: two scenarios can involve similar volumes of attacker activity yet carry very different loss event frequencies once the likelihood of material impact is factored in.

For decision-makers, LEF is one of the two building blocks (alongside loss magnitude) used to derive a quantified risk estimate, which in turn can inform where to invest in controls, how to frame risk-transfer decisions, and how to communicate exposure to executives and boards. It is important to keep LEF in its proper lane: it is a forward-looking estimate of likelihood, not a statement of what will happen, and not a measure of how well an organization can recover once a loss occurs. Recovery capability is governed by resilience concepts such as recovery time and recovery point objectives, which are separate from the modeled frequency of loss.

LEF also should not be confused with anything in an insurance policy. It does not describe a coverage trigger, a retention, or a waiting period, and a high or low LEF does not by itself determine whether a given loss would be covered, coverage always depends on the specific policy wording, endorsements, exclusions, and conditions. Rather, LEF is an analytical input that can help an organization reason about how much risk it may want to mitigate, accept, or transfer, while remembering that transferring risk through insurance does not reduce the likelihood captured by the LEF estimate itself.

Who it's relevant to

Chief Information Security Officers and Risk Quantification Teams
CISOs and analysts use LEF to prioritize control investments by focusing on scenarios most likely to produce material loss, rather than on raw volumes of attacker activity. Precise scenario scoping is essential so that threat event frequency is not mistaken for loss event frequency.
Risk Managers and Insurance Buyers
Risk managers can use LEF as an analytical input when weighing mitigation, acceptance, and transfer. It helps frame how much exposure exists, but it does not by itself determine coverage, and buying insurance does not lower the modeled frequency of loss, coverage outcomes still depend on the specific policy terms.
Underwriters and Brokers
Underwriters and brokers may encounter LEF in a client's risk quantification outputs. It can inform discussions about an insured's exposure, but it should be treated as the insured's estimate rather than a policy term or a coverage determinant, and it says nothing about recovery capability.
Board Members and Executives
For senior leaders, LEF supports risk communication in financial and probabilistic terms. Leaders should understand it as a forward-looking estimate carrying uncertainty, distinct from resilience metrics that describe recovery, and separate from any insurance coverage that may respond after a loss.

Inside LEF

Threat Event Frequency (TEF)
The estimated number of times within a defined period that a threat actor or source is expected to act against an asset in a way that could result in loss. It reflects how often an attempt or triggering action occurs, independent of whether that action succeeds.
Vulnerability (Susceptibility)
The probability that a given threat event will overcome existing controls and become a loss event. Loss Event Frequency is a function of how often threats act combined with how likely those actions are to succeed, so control strength directly influences the frequency component.
Defined Time Horizon
Loss Event Frequency is always expressed relative to a period (for example, per year). Without a stated time frame the figure is ambiguous, and the horizon must be consistent when the frequency is combined with loss magnitude for risk estimation.
Scope: Frequency Only, Not Severity
This concept addresses only how often loss events are expected to occur. It does not describe the financial or operational size of any single event; magnitude is a separate dimension that is combined with frequency to estimate overall risk.
Relationship to Insurance and Resilience
As an estimate of how often incidents occur, Loss Event Frequency informs underwriting judgments and risk-mitigation priorities. It is a measure of likelihood, not a coverage term; whether any resulting loss is insured depends on policy wording, exclusions, and conditions rather than on the frequency estimate itself.

Common questions

Answers to the questions practitioners most commonly ask about LEF.

Is loss event frequency the same as the frequency of all threat events or attempted attacks against an organization?
No. Loss event frequency refers specifically to the rate at which events that actually result in loss are expected to occur, not the rate of all threat events or attempts. Many threat events are stopped by controls or otherwise fail to produce loss, so counting attempts or contact events overstates loss event frequency. The distinction matters because conflating the two inflates modeled risk and can distort decisions about controls and coverage.
Does a low loss event frequency mean an organization has low overall risk?
Not necessarily. Frequency is only one dimension of risk; the magnitude of loss per event is the other. A rare event can still carry catastrophic loss magnitude, and a frequent event may produce only minor losses each time. Assessing risk requires considering frequency together with the probable range of loss magnitude rather than treating a low frequency estimate as evidence of low risk on its own.
How can loss event frequency be estimated when historical loss data is sparse?
When internal loss history is limited, practitioners commonly supplement it with external data sources, industry loss information, expert judgment, and structured estimation techniques that express frequency as a range with stated confidence rather than a single point value. The key is to document assumptions and the basis for estimates, and to treat the result as an uncertain range subject to revision as more data becomes available, rather than as a precise figure.
How does loss event frequency relate to underwriting and coverage decisions?
Underwriters may use frequency estimates as one input when assessing the likelihood of claims within a policy period, which can inform pricing, retentions, sublimits, and terms. However, whether a given loss event is actually covered depends on the specific policy wording, exclusions, conditions, and endorsements rather than on frequency modeling. Frequency estimates inform expectations about how often losses may occur; they do not determine whether any particular loss falls within coverage.
Can improving security controls change the loss event frequency used in risk analysis?
Yes, in principle. Controls that reduce the likelihood that a threat event succeeds in producing loss can lower the estimated loss event frequency, which is a form of risk mitigation. This is distinct from risk transfer through insurance, which does not reduce the likelihood of an event occurring. When updating frequency estimates to reflect new controls, it is important to base the revision on evidence of control effectiveness rather than assumed reductions.
Over what time period should loss event frequency be expressed?
Loss event frequency is expressed relative to a defined time interval, commonly an annual basis, so that estimates are comparable and can align with analysis or policy periods. The chosen interval should be stated explicitly, because a frequency figure is meaningless without knowing the period it references. Consistency in the time basis across scenarios and inputs is necessary to avoid errors when aggregating or comparing frequency estimates.

Common misconceptions

Loss Event Frequency measures how bad an incident will be.
It measures how often loss events are expected to occur within a defined period, not their magnitude. Severity is a distinct dimension, and the two are combined separately to estimate risk. Treating frequency as a proxy for size can materially distort risk prioritization.
Every threat action counts as a loss event, so threat frequency and loss event frequency are the same.
Threat Event Frequency counts attempts or triggering actions, while Loss Event Frequency counts only those that overcome controls and produce loss. The difference is governed by susceptibility, so stronger controls can lower Loss Event Frequency even when threat activity is unchanged.
Purchasing insurance lowers an organization's Loss Event Frequency.
Insurance is a mechanism for transferring the financial consequences of loss; it does not reduce the likelihood that a loss event will occur. Reducing frequency requires risk mitigation such as strengthening controls, whereas insurance addresses funding of losses after they happen.

Best practices

State the time horizon explicitly whenever expressing Loss Event Frequency, and keep that horizon consistent when combining frequency with loss magnitude to estimate overall risk.
Decompose the estimate into its underlying components, distinguishing how often threats act (Threat Event Frequency) from how likely those actions are to succeed (susceptibility), rather than estimating a single blended figure.
Keep frequency estimates separate from severity estimates so that likelihood and magnitude can be analyzed and reported as distinct dimensions.
Use frequency estimates to inform risk-mitigation priorities, and recognize that lowering frequency depends on strengthening controls rather than on transferring loss through insurance.
Document the assumptions, data sources, and uncertainty behind each estimate, using ranges or qualified language where precise data is unavailable instead of presenting a single deterministic number.
Do not treat Loss Event Frequency as a coverage indicator; assess separately whether any resulting loss would be insured, since that depends on policy wording, exclusions, and conditions.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps