Industry: Defense Product: ModelRisk Application: Quantifying Cybersecurity Risk and Optimizing Defense Strategies
A defense agency holds a $40M annual cyber-resilience budget — the line above which a loss year forces an emergency supplemental and a hearing. The legacy risk register reported an annual loss expectancy of $18M and called the budget comfortable. Rebuilt in ModelRisk as a compound-frequency-severity model over 120,000 simulated years, the picture inverts: the mean annual loss is $46M (already over budget), the 99% Value-at-Risk is $498M, and there is a 26% chance — better than one year in four — that losses breach the $40M line. The point estimate was not just wrong; it was reassuring about the wrong thing.
This article is about money: the annual aggregate loss the agency must be capitalised and insured against. The mechanism that produces a breach is covered separately; here the question is the shape of the loss distribution and where control investment moves it.
A single expected-loss number is the average of a distribution whose mass sits in two utterly different regimes: most years are quiet (the median loss is $14M, comfortably under budget), but a thin band of years carry catastrophic classified-data exfiltration or weapons-platform OT events. Averaging those regimes produces a figure ($18M, or even the truer $46M mean) that describes no actual year. The budget is not sized against the mean — it is sized against the tail, and the tail is exactly what a deterministic ALE cannot show. The loss-exceedance (EP) curve above answers the only question that matters for capitalisation: for any dollar figure, what is the chance the year exceeds it?
Five threat families each contribute a compound-Poisson loss stream: a Poisson count of breaches per year, each carrying a severity draw.
Severity is LogNormal in the body (the standard cyber-loss choice — Verizon DBIR and Advisen loss data both fit log-skew) plus a Generalized Pareto tail above a threshold on the four severe families. Peaks-over-threshold (GPD, shape ξ ≈ 0.38–0.40) is what separates a "bad year" from a catastrophic one; a single LogNormal undersells the extreme regime.
Crucially, the families are not independent. A single per-year threat-climate factor (Gamma, mean 1) scales both every family's Poisson rate and its GPD-tail trigger probability. In an elevated-threat year — a state-sponsored campaign wave — the agency sees more breaches that are also individually nastier. That common factor couples frequency and severity and is what fattens the aggregate tail.
The coupling is imposed, not asserted, and the model verifies it:
The mean sits far out in the right shoulder of the distribution because the GPD-tailed catastrophic years drag it there — the classic signature of a loss curve that a point estimate cannot describe.
Sensitivity is run on VaR99, not the mean, because the budget question is a tail question.
Each control package shifts frequency and/or the catastrophic-tail probability; the agency compared them on the same axis the budget lives on.
The full programme spends an extra $10M/yr over the MFA+EDR level but more than halves VaR99 again — the explicit trade between expected-cost reduction and tail protection that a single ALE figure can never frame.
Cyber risk for a defense agency is not the average year — it is the exceedance curve, the conditional loss above the budget line, and the dependence that makes bad years cluster, and Monte Carlo is what turns those three into a single chart a comptroller and a CISO can argue over with the same numbers.