Skip to main content
Category: Loss Modeling & Aggregation

Threat Event Frequency

Also known as:
Simply put

Threat Event Frequency is an estimate of how often, within a given period of time, someone or something is likely to act in a way that could cause a loss. It focuses on the number of attempts or actions directed against an asset, not on whether those attempts actually succeed. It is one input used in quantitative approaches to estimating cyber risk.

Formal definition

Within the FAIR (Factor Analysis of Information Risk) model, Threat Event Frequency (TEF) is defined as the probable frequency, within a given timeframe, that a threat agent will act against an asset in a manner that may result in loss. TEF measures the occurrence of threat events, the adversary's actions or attempts, independent of whether those events result in a loss, which is a separate factor (loss event frequency depends additionally on vulnerability). TEF is expressed as a frequency (occurrences per unit time) rather than a probability, and serves as an input into quantitative cyber risk estimation rather than as an insurance coverage term or resilience metric.

Why it matters

Threat Event Frequency matters because it isolates one of the most misunderstood variables in cyber risk: how often adversaries actually act against an asset, as distinct from how often those actions succeed. In quantitative approaches such as the FAIR model, TEF is deliberately separated from vulnerability so that analysts do not collapse two very different questions, how often you are attacked versus how likely an attack is to cause a loss, into a single vague judgment. Keeping these distinct helps risk managers and CISOs reason about where investment actually changes outcomes: some controls reduce the frequency of threat events (for example, by reducing exposure or attack surface), while others reduce the probability that an event becomes a loss.

For cyber risk quantification programs, TEF provides a defensible input into loss estimates that can inform capital allocation, control prioritization, and decisions about how much risk to transfer through insurance versus retain or mitigate. Because TEF is expressed as a frequency over a timeframe rather than as a single probability, it forces explicit assumptions about the relevant period and the relevant threat community, which makes the resulting analysis easier to challenge and refine.

It is important not to overstate what TEF represents. It is an estimate, typically expressed as a range reflecting uncertainty, and it is not an insurance coverage term or a resilience metric. TEF does not tell you whether a resulting loss would be covered by a policy, nor does it substitute for recovery objectives such as RTO or RPO. It is one factor among several in estimating cyber risk, and its usefulness depends entirely on the quality of the assumptions and data behind it.

Who it's relevant to

Cyber risk quantification analysts
Analysts using FAIR or similar quantitative methods rely on TEF as a foundational input, and must keep it distinct from vulnerability and loss event frequency. Precise scoping of the threat community, asset, and timeframe is what makes a TEF estimate defensible and repeatable.
CISOs and security leaders
Security leaders can use TEF to reason about which controls change the frequency of adversary actions versus which reduce the chance those actions succeed. This distinction helps prioritize investment, though TEF alone does not quantify loss and should not be read as a resilience metric.
Risk managers and insurance buyers
Risk managers can use TEF as one input when weighing risk transfer against mitigation, acceptance, or avoidance. TEF informs how often exposure may materialize but does not determine whether any resulting loss is covered, coverage depends on policy wording, endorsements, exclusions, and conditions.
Underwriters and brokers
For underwriters and brokers, TEF-based analysis submitted by an insured can inform discussions about exposure, but it is a risk-estimation input rather than a coverage term. Its assumptions and data quality should be scrutinized, and it does not by itself establish sublimits, retentions, or triggers.

Inside TEF

Contact Frequency
The rate at which a threat actor comes into contact with an asset within a defined time period. In quantitative risk models such as those in the FAIR methodology, threat event frequency is often decomposed into contact frequency and the probability that contact results in an action against the asset.
Probability of Action
The likelihood that, given contact, a threat actor will act against the asset. Multiplying contact frequency by probability of action helps estimate how often threat events are expected to occur, distinct from how often they succeed.
Time Interval
Threat event frequency is expressed over a stated period (for example, events per year). The chosen interval must be consistent across a risk analysis to allow meaningful comparison and aggregation.
Threat Event versus Loss Event
A threat event is an attempt or occurrence in which a threat actor acts against an asset; it does not by itself imply that a loss occurred. A loss event requires the threat event to overcome controls and produce harm. Threat event frequency measures attempts, not realized losses.
Relationship to Vulnerability
Threat event frequency, combined with the susceptibility of the asset to the threat, contributes to loss event frequency. The frequency of attempts is a separate input from the likelihood that an attempt succeeds.

Common questions

Answers to the questions practitioners most commonly ask about TEF.

Is threat event frequency the same as how often a loss actually occurs?
No. Threat event frequency estimates how often a threat actor acts against an asset in a way that could cause harm, not how often that action succeeds or produces a loss. Whether a threat event results in a loss depends on additional factors, such as the strength of controls and the vulnerability of the asset. Conflating the two overstates expected losses, because many threat events are stopped or absorbed before they cause damage.
Does a higher threat event frequency mean my organization needs more cyber insurance?
Not directly. Threat event frequency is a risk analysis input, not an insurance metric, and it describes likelihood of attempts rather than the size or coverage of any resulting loss. Insurance is a risk transfer mechanism that responds to losses subject to policy wording, retentions, sublimits, and exclusions; it does not reduce how often threat events occur. Frequency estimates may inform how you weigh mitigation, acceptance, and transfer, but they do not by themselves determine an appropriate limit or coverage structure.
How do I actually estimate threat event frequency for a given scenario?
Estimation typically combines available data sources with structured judgment: internal logs and historical incident records, industry or sector reporting, threat intelligence, and calibrated expert input. Because precise historical counts are often unavailable, many analysts express frequency as a range or distribution rather than a single number and document the assumptions behind it. Be explicit about the scope, that is, the specific asset and threat actor community the estimate applies to, so the figure is not misread as an organization-wide rate.
Should threat event frequency be measured per asset, per threat actor, or across the whole organization?
It is usually most useful when scoped narrowly, to a defined asset (or asset class) and a defined threat community, because different actors act at very different rates against different targets. Aggregating to an organization-wide number can obscure where the meaningful exposure sits. If you need an enterprise view, build it up from scoped estimates rather than starting with a single global figure, and keep the scope boundaries of each component documented.
How does threat event frequency relate to the resilience metrics my continuity team already tracks?
They address different questions and should not be treated as interchangeable. Threat event frequency concerns how often an adverse action may occur, while recovery-oriented metrics such as RTO and RPO concern how quickly systems must be restored and how much data loss is tolerable after an event occurs. Frequency is a likelihood input to risk analysis; RTO and RPO are recovery targets that shape disaster recovery and business continuity planning. Used together they inform prioritization, but neither substitutes for the other.
How often should threat event frequency estimates be reviewed or updated?
Because the threat landscape, the asset environment, and available data all change, estimates are best treated as time-bound rather than fixed. Common practice is to revisit them on a regular cadence and also after material changes, such as a shift in the threat environment, a significant new exposure, or a relevant incident. Recording the date, data sources, and assumptions with each estimate makes it clear when a figure has become stale and supports consistent comparison over time.

Common misconceptions

Threat event frequency is the same as the frequency of losses or claims.
Threat event frequency measures how often a threat actor acts against an asset, not how often those actions succeed or produce a loss. Many threat events are stopped by controls and never become loss events. Treating the two as interchangeable overstates expected loss and confuses a resilience/security input with an insurance loss metric.
A higher threat event frequency automatically means a proportionally higher insurance premium or covered loss.
Threat event frequency is one qualitative or quantitative input into a risk analysis, not a coverage term. Whether resulting losses are covered depends on policy wording, exclusions, retentions, and conditions, and insurers weigh frequency alongside control maturity, susceptibility, and potential loss magnitude rather than treating it in isolation.
Reducing threat event frequency is something insurance can accomplish.
Insurance is a form of risk transfer and does not reduce the likelihood that a threat actor will act against an asset. Lowering threat event frequency is a matter of risk mitigation and avoidance, such as reducing exposure or attack surface, not risk transfer.

Best practices

Define the time interval explicitly (for example, events per year) and apply it consistently across the analysis so frequencies can be compared and aggregated meaningfully.
Keep threat event frequency separate from loss event frequency in your models, and document the susceptibility or control-strength assumptions that translate attempts into realized losses.
Where possible, decompose threat event frequency into contact frequency and probability of action to make assumptions explicit and reviewable rather than relying on a single opaque estimate.
Treat threat event frequency as a security and resilience input, not a coverage trigger or premium determinant; coordinate with brokers and underwriters on how it informs, but does not dictate, coverage decisions.
Use threat event frequency to prioritize mitigation measures that reduce exposure or attack surface, recognizing that insurance transfers financial consequences but does not lower the frequency of threat events.
State the uncertainty in frequency estimates using ranges or qualified language, and revisit them as threat intelligence, asset exposure, and the control environment change.
Application Security Isn’t Optional Anymore.