| Vose Software

Industry: Defense
Product: ModelRisk
Application: Quantifying Cybersecurity Risk and Optimizing Defense Strategies


The Budget Was Sized for $18M of Cyber Loss. The 99th-Percentile Year Costs $498M

A defense agency holds a $40M annual cyber-resilience budget — the line above which a loss year forces an emergency supplemental and a hearing. The legacy risk register reported an annual loss expectancy of $18M and called the budget comfortable. Rebuilt in ModelRisk as a compound-frequency-severity model over 120,000 simulated years, the picture inverts: the mean annual loss is $46M (already over budget), the 99% Value-at-Risk is $498M, and there is a 26% chance — better than one year in four — that losses breach the $40M line. The point estimate was not just wrong; it was reassuring about the wrong thing.

This article is about money: the annual aggregate loss the agency must be capitalised and insured against. The mechanism that produces a breach is covered separately; here the question is the shape of the loss distribution and where control investment moves it.

Cyber loss exceedance curve showing probability annual loss exceeds a dollar threshold

Why a point estimate fails here

A single expected-loss number is the average of a distribution whose mass sits in two utterly different regimes: most years are quiet (the median loss is $14M, comfortably under budget), but a thin band of years carry catastrophic classified-data exfiltration or weapons-platform OT events. Averaging those regimes produces a figure ($18M, or even the truer $46M mean) that describes no actual year. The budget is not sized against the mean — it is sized against the tail, and the tail is exactly what a deterministic ALE cannot show. The loss-exceedance (EP) curve above answers the only question that matters for capitalisation: for any dollar figure, what is the chance the year exceeds it?

Modelling annual loss as compound frequency × severity

Five threat families each contribute a compound-Poisson loss stream: a Poisson count of breaches per year, each carrying a severity draw.

  • Phishing / credential theft: λ ≈ 6/yr, LogNormal severity (median $0.15M) — high frequency, low severity.
  • Ransomware on mission systems: λ ≈ 1.1/yr, LogNormal median $3M, with a heavy-tail spike.
  • Supply-chain / firmware compromise: λ ≈ 0.6/yr, median $5M.
  • Classified-data exfiltration: λ ≈ 0.4/yr, median $8M — rare but severe.
  • OT / weapons-platform sabotage: λ ≈ 0.25/yr, median $12M — rarest, worst.

Severity is LogNormal in the body (the standard cyber-loss choice — Verizon DBIR and Advisen loss data both fit log-skew) plus a Generalized Pareto tail above a threshold on the four severe families. Peaks-over-threshold (GPD, shape ξ ≈ 0.38–0.40) is what separates a "bad year" from a catastrophic one; a single LogNormal undersells the extreme regime.

Crucially, the families are not independent. A single per-year threat-climate factor (Gamma, mean 1) scales both every family's Poisson rate and its GPD-tail trigger probability. In an elevated-threat year — a state-sponsored campaign wave — the agency sees more breaches that are also individually nastier. That common factor couples frequency and severity and is what fattens the aggregate tail.

The coupling is imposed, not asserted, and the model verifies it:

  • VaR99 is $498M with the climate factor, versus $349M in an otherwise-identical independent model — a 43% heavier tail.
  • The highest-tempo decile of years averages $156M in losses; the lowest-tempo decile averages $5M — a 31× ratio.
  • The correlation between the climate factor and annual loss is 0.36, confirming the shared-driver linkage.

What the loss distribution actually looks like

Annual aggregate cyber loss distribution with VaR and budget threshold

  • Mean annual loss: $46M (vs the register's $18M).
  • VaR95: $189M. VaR99: $498M. TVaR99 (mean loss in the worst 1% of years): $909M.
  • P(annual loss > $40M budget) = 26%.

The mean sits far out in the right shoulder of the distribution because the GPD-tailed catastrophic years drag it there — the classic signature of a loss curve that a point estimate cannot describe.

What drives the 99% Value-at-Risk

Sensitivity is run on VaR99, not the mean, because the budget question is a tail question.

Tornado of drivers of the 99 percent Value-at-Risk of annual cyber loss

  • Threat-climate dispersion is the top driver — widening the Gamma factor (shape 3.5 → 1.5, i.e. more year-to-year clustering) swings VaR99 by ±$112M. The dependence structure itself is the largest single lever, which an independent model would never surface.
  • Ransomware frequency (λ 0.7 → 1.6/yr): ±$71M.
  • Classified-exfil GPD tail shape ξ (0.30 → 0.55): ±$68M.
  • Supply-chain tail trigger probability (3% → 8%): ±$54M.
  • OT-sabotage severity median ($8M → $18M): ±$10M; phishing frequency barely registers at ±$3M — the high-volume, low-severity family that the legacy register treated as the headline number is almost irrelevant to the tail.

Three investment levels, three exceedance curves

Each control package shifts frequency and/or the catastrophic-tail probability; the agency compared them on the same axis the budget lives on.

Loss exceedance curves for three cyber control investment levels

  • Status quo: VaR99 $514M, P(>$40M budget) 26%.
  • +$8M (MFA + EDR + email gateway): cuts breach frequency ~35%. VaR99 falls to $374M, budget-breach probability to 16%.
  • +$18M (zero-trust + immutable backups + OT segmentation): cuts frequency further and clips the GPD-tail trigger probability ~60% (segmentation contains catastrophic spread). VaR99 drops to $196M, budget-breach probability to 11%.

The full programme spends an extra $10M/yr over the MFA+EDR level but more than halves VaR99 again — the explicit trade between expected-cost reduction and tail protection that a single ALE figure can never frame.

What the model changed

  • The board metric switched from ALE ($18M) to VaR99 ($498M) and P(loss > budget) (26%) — the register's mean was understating the central estimate and hiding the tail the budget actually has to absorb.
  • Cyber capital reserve raised to sit between VaR99 and TVaR99, sized against the exceedance curve rather than the mean.
  • Investment reprioritised toward tail-clipping controls (OT segmentation, immutable backups) after the tornado showed the dependence structure and the GPD tail — not phishing volume — drive VaR99.

ModelRisk Functionality Used

  • Compound-Poisson frequency-severity construction across five threat families, producing a full annual-loss distribution rather than a single ALE.
  • LogNormal body + Generalized Pareto tail (peaks-over-threshold, ξ ≈ 0.38) on the four severe families — capturing the catastrophic regime a single LogNormal underprices.
  • A shared threat-climate factor (Gamma) scaling both frequency and tail probability — verified to fatten VaR99 by 43% versus an independent model, with a 31× loss ratio between high- and low-tempo years.
  • VaR/TVaR and a loss-exceedance curve read directly off the simulated distribution: VaR95 $189M, VaR99 $498M, TVaR99 $909M.
  • Tornado on VaR99 ranking the dependence dispersion (±$112M) above any single severity parameter.
  • Three-scenario exceedance comparison quantifying that the +$18M programme more than halves VaR99 versus the +$8M baseline.

Cyber risk for a defense agency is not the average year — it is the exceedance curve, the conditional loss above the budget line, and the dependence that makes bad years cluster, and Monte Carlo is what turns those three into a single chart a comptroller and a CISO can argue over with the same numbers.