Integration Integration: combine prior outputs into a full risk curve.
Loss Exceedance Curve

Build a Loss Exceedance CurveA curve that shows the chance losses exceed a given dollar amount.

Use a simple Monte Carlo simulationRunning thousands of random scenarios to estimate a distribution. to visualize loss exceedance probabilities.

This web tool mirrors the spreadsheet workflow used in the workshop.

Learning Objectives

By the end, you will be able to:

  1. Run a Monte Carlo simulation from your input ranges.
  2. Read a loss exceedance curve and explain what it shows.
  3. Use percentiles to describe expected loss ranges.
  4. Identify the probability of exceeding a material threshold.

Recall from Applied Forecasting: Run 1 feeds Outside-In, and Run 2 feeds Inside-Out reduction.

Loss Exceedance Curve

Interactive Monte Carlo simulator (lognormalA distribution where the log of values is normally distributed, common for loss sizes., 90% bounds).

Threshold probabilities Material threshold
Ready.
Download Excel template
Running simulation...

Chart summary updates after you run the simulation.

How to use
  • Enter assumptions on the right. Use formats like 9%, 0.09, 3M, or 3 million.
  • The curve updates live. Blue dots mark exceedance thresholds; the amber dot marks your materiality threshold.
  • Probability of material impact = Outside-In minus Inside-Out, clamped to 0-1.
  • Lognormal parameters: mu = (ln(UB) + ln(LB)) / 2, sigma = (ln(UB) - ln(LB)) / 3.29.
Learning Debrief

What You Just Learned

  • Translate probability and loss ranges into a curve you can explain.
  • Use percentiles to communicate expected loss ranges.
  • Identify the probability of crossing a material loss threshold.
  • Compare scenarios by changing inputs and watching the curve shift.

Applying This to Cyber Risk

Loss exceedance curves help connect controls to dollars and decisions.

Control Investment Tradeoffs

Model how an added control shifts the curve and lowers the chance of exceeding a board-defined loss threshold.

Scenario Comparison

Compare ransomware, third-party outage, and insider scenarios using the same materiality threshold.

Workshop Home