Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 889

Quantitative Risk Analysis

What is Quantitative Risk Analysis?

Quantitative Risk AnalysisA risk analysis approach that expresses likelihood and impact in numbers, typically as probabilities and monetary loss distributions, to support data-driven decisions.


Quantitative risk analysis uses statistical and financial techniques to express risk in figures that the business can compare to budgets, insurance limits, or capital. Typical metrics include Annualized Loss Expectancy (ALE), Loss Exceedance Curves, and Value at Risk. Practitioners model loss event frequencies and magnitudes using historical incident data, industry datasets, and expert calibration, often via FAIR or Monte Carlo simulation. Compared to qualitative methods, quantitative analysis demands more data and discipline but produces defensible numbers for board reporting, ROSI (return on security investment) decisions, and prioritization of large programs. Hybrid approaches mix qualitative triage with quantitative depth for top risks.

Examples

  1. 01

    Loss exceedance curve for ransomware modelled with FAIR and Monte Carlo.

  2. 02

    ALE-based business case for replacing a legacy VPN with a Zero Trust platform.

Frequently asked questions

What is Quantitative Risk Analysis?

A risk analysis approach that expresses likelihood and impact in numbers, typically as probabilities and monetary loss distributions, to support data-driven decisions. It belongs to the Compliance & Frameworks category of cybersecurity.

What does Quantitative Risk Analysis mean?

A risk analysis approach that expresses likelihood and impact in numbers, typically as probabilities and monetary loss distributions, to support data-driven decisions.

How does Quantitative Risk Analysis work?

Quantitative risk analysis uses statistical and financial techniques to express risk in figures that the business can compare to budgets, insurance limits, or capital. Typical metrics include Annualized Loss Expectancy (ALE), Loss Exceedance Curves, and Value at Risk. Practitioners model loss event frequencies and magnitudes using historical incident data, industry datasets, and expert calibration, often via FAIR or Monte Carlo simulation. Compared to qualitative methods, quantitative analysis demands more data and discipline but produces defensible numbers for board reporting, ROSI (return on security investment) decisions, and prioritization of large programs. Hybrid approaches mix qualitative triage with quantitative depth for top risks.

How do you defend against Quantitative Risk Analysis?

Defences for Quantitative Risk Analysis typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for Quantitative Risk Analysis?

Common alternative names include: Quantitative risk assessment, Cyber risk quantification.

Related terms

See also