Threat Event Frequency
Threat Event Frequency is an estimate of how often, within a given period of time, someone or something is likely to act in a way that could cause a loss. It focuses on the number of attempts or actions directed against an asset, not on whether those attempts actually succeed. It is one input used in quantitative approaches to estimating cyber risk.
Within the FAIR (Factor Analysis of Information Risk) model, Threat Event Frequency (TEF) is defined as the probable frequency, within a given timeframe, that a threat agent will act against an asset in a manner that may result in loss. TEF measures the occurrence of threat events, the adversary's actions or attempts, independent of whether those events result in a loss, which is a separate factor (loss event frequency depends additionally on vulnerability). TEF is expressed as a frequency (occurrences per unit time) rather than a probability, and serves as an input into quantitative cyber risk estimation rather than as an insurance coverage term or resilience metric.
Why it matters
Threat Event Frequency matters because it isolates one of the most misunderstood variables in cyber risk: how often adversaries actually act against an asset, as distinct from how often those actions succeed. In quantitative approaches such as the FAIR model, TEF is deliberately separated from vulnerability so that analysts do not collapse two very different questions, how often you are attacked versus how likely an attack is to cause a loss, into a single vague judgment. Keeping these distinct helps risk managers and CISOs reason about where investment actually changes outcomes: some controls reduce the frequency of threat events (for example, by reducing exposure or attack surface), while others reduce the probability that an event becomes a loss.
For cyber risk quantification programs, TEF provides a defensible input into loss estimates that can inform capital allocation, control prioritization, and decisions about how much risk to transfer through insurance versus retain or mitigate. Because TEF is expressed as a frequency over a timeframe rather than as a single probability, it forces explicit assumptions about the relevant period and the relevant threat community, which makes the resulting analysis easier to challenge and refine.
It is important not to overstate what TEF represents. It is an estimate, typically expressed as a range reflecting uncertainty, and it is not an insurance coverage term or a resilience metric. TEF does not tell you whether a resulting loss would be covered by a policy, nor does it substitute for recovery objectives such as RTO or RPO. It is one factor among several in estimating cyber risk, and its usefulness depends entirely on the quality of the assumptions and data behind it.
Who it's relevant to
Inside TEF
Common questions
Answers to the questions practitioners most commonly ask about TEF.
