Free Security Risk Score calculator with clear step-by-step results.
Risk is the product of how often something is likely to be attempted, how exposed you are when it is, and how much it costs when it lands. This calculator reports that two ways. The monetary view follows the classic quantitative model: single loss expectancy is asset value times exposure factor, annualised loss expectancy multiplies that by the yearly event rate, and residual ALE applies the fraction of loss your controls actually prevent. The 0-100 composite blends normalised likelihood, vulnerability and impact scores at a 35/30/35 weighting, then damps the total by up to 70 percent for control effectiveness — controls reduce risk substantially but never to zero, which is why a perfectly controlled high-value asset still carries a non-zero score.
Single loss expectancy
SLE = asset value x exposure factor%
Residual annual loss
Residual ALE = SLE x events per year x (1 - control effectiveness%)
Composite score
Score = (0.35 x likelihood + 0.30 x vulnerability + 0.35 x impact) x (1 - 0.7 x control effectiveness%)
This is a planning and prioritisation model, not an actuarial or regulatory assessment. Outputs depend entirely on the estimates you supply and should not be used on their own to set insurance limits, satisfy a compliance obligation, or accept a risk formally. Have quantitative risk figures reviewed by a qualified security or risk professional.
They answer different questions. The currency figure (residual ALE) is what you take to a budget conversation — it is directly comparable to the cost of a control. The 0-100 score is for ranking a register of assets against each other when their values are not all known to the same precision.
Control effectiveness is capped at damping 70 percent of inherent risk. No control set is perfect: patches lag, staff make mistakes, and novel techniques appear. A model that let risk hit zero would encourage treating a controlled asset as one you can stop monitoring.
Estimate the share of the asset's value you would lose in a single realistic incident, not a worst case. Ransomware on a well-backed-up file server might be 20 to 30 percent (recovery time and response cost); theft of a customer database that triggers regulatory penalties could exceed 80 percent.