Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
ALE & ROSICyber Risk Underwriting

Treatise 14: Annualized Loss Expectancy & Return on Security Investment for OT

100% Complete & Untruncated 15 min read
Return to Research Tracks

J. McKenney

This is a working-group treatise in WG-01-UI (Underwriter & Insurance). It translates the CyHAZOP and dual-RPN engineering methodology, developed in the working group's Quantitative Cyber-Physical FMECA treatise and in WG-07-TM's CyHAZOP Node Registers, into the financial decision framework, Annualized Loss Expectancy, the Gordon-Loeb ceiling, and Return on Security Investment, that the group's RCIL/SCIL reinsurance treatise draws on for its own capital allocation figures.

Licence: CC BY 4.0. 17 September 2026.

Executive Abstract#

An engineer who reads a Risk Priority Number of 567 on a coolant pump knows something is wrong, but that number does not tell a Chief Financial Officer how many dollars are at stake or how much security spending is justified. This paper runs FMECA and CyHAZOP findings through Annualized Loss Expectancy, the Gordon-Loeb model, and Return on Security Investment, on a modeled 100 MW data center.

Every number in that example is an estimate, not a measurement. The exposure factors, cyber attack rates, and loss figures are working-group assumptions representative of a hyperscale facility, not claims-history observations, so the work is a sensitivity study, not a rate filing. On those inputs an operational technology programme costing one point six million dollars mitigates roughly fifteen million dollars in annual expected losses, a modeled Return on Security Investment of 859 percent at 24.99 percent of the Gordon-Loeb ceiling.

The second half extends this to losses that do not follow the thin-tailed statistics ordinary insurance mathematics assumes. A fat-tailed power-law correction shows a Gaussian model can understate the tail risk of a shared cooling failure or firmware attack by an order of magnitude, and what it means for a deductible, a reinsurance treaty, and a capital reserve.

Abstract#

FMECA and HAZOP tell facility teams what can fail and how severe it will be, but metrics such as Risk Priority Numbers do not answer what CFOs, underwriters, and boards ask: how much capital is exposed, and what is the optimal return on mitigating it? This paper translates the cyber-physical CyHAZOP and dual-RPN methodologies into Annualized Loss Expectancy per NIST SP 800-30, the Gordon-Loeb optimal investment model, and the Open FAIR taxonomy. The reference case is a modeled 100 MW high-density compute facility, not a measured site; every exposure factor and rate of occurrence in Section 4 is a working-group estimate. On those inputs it models a $1.60M programme mitigating $15,350,250 in annual expected losses, a Return on Security Investment of 859 percent (exposure factors 0.40 to 0.85, cyber ARO 0.05 to 0.20), operating at 24.99 percent of the Gordon-Loeb ceiling of $6,402,564. The paper shows that standard ALE, Gordon-Loeb, and Gaussian Value-at-Risk models assume thin-tailed Mediocristan distributions and understate tail-risk. Applying Taleb fat-tail power-law corrections with an assumed Pareto exponent of 1.25, it models Table B (Extremistan) events such as simultaneous multi-megawatt cooling collapse, where traditional models understate single-event probable maximum loss by an order of magnitude, and formalizes the equations to price property catastrophe policies, set retention deductibles, and structure reinsurance treaties accounting for Lloyd's Y5381.


1. The Executive Capital Allocation Problem#

In hyperscale mission-critical environments, a severe disconnect exists between operational engineering teams and the executive suite:

  • The Facility Engineer's Perspective: A facility engineer observes an RPN of 567 on a Coolant Distribution Unit (CDU) pump cyber-induced shutdown and immediately recognizes an operational emergency.
  • The CFO's Perspective: The Chief Financial Officer reviews the identical report and asks: What is the probabilistic annual dollar loss of that event, how will it impact quarterly EBITDA, and what capital expenditure is mathematically justified to prevent it?

Without rigorous financial quantification, cybersecurity requests are treated as discretionary overhead rather than risk-mitigating investments. As high-density AI clusters push rack densities beyond 100 kW100\text{ kW} and cluster valuations past hundreds of millions of dollars, qualitative color-coded risk heat maps ("red, amber, green") are no longer legally or actuarially defensible.

The Capital Allocation Quantification Bridge#

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram
LayerElementContent
CyHAZOP and FMECA engineeringNode deviationsMORE, LESS, SPOOFED, POISONED
CyHAZOP and FMECA engineeringPhysical unitsBar, L/min, °C, kW, Hz
CyHAZOP and FMECA engineeringQuantitative metricCyber Risk Priority Number, RPNc=567\text{RPN}_c = 567
CFO and underwriting capital allocationSingle Loss ExpectancySLE=AV×EF\text{SLE} = \text{AV} \times \text{EF}
CFO and underwriting capital allocationAnnualized Loss ExpectancyALE=SLE×ARO\text{ALE} = \text{SLE} \times \text{ARO}
CFO and underwriting capital allocationReturn on Security InvestmentROSI=[ΔALE−Cost]/Cost\text{ROSI} = [\Delta\text{ALE} - \text{Cost}] / \text{Cost}
CFO and underwriting capital allocationGordon-Loeb investment ceilingS∗≤0.368×ALES^* \le 0.368 \times \text{ALE}
CFO and underwriting capital allocationTaleb fat-tail power-law correctionα<2.0\alpha < 2.0, Extremistan scale

2. Multi-BOM and DEXPI Asset Valuation Topology#

Accurately calculating Asset Value (AV) and Exposure Factor (EF) requires synchronizing physical piping models with silicon inventories across the DEXPI 2.0 and CycloneDX 1.6+ specifications, with DEXPI equipment classes drawn from the ISO 15926-4 reference data library:

Financial Asset Exposure Topology#

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

DEXPI 2.0 physical infrastructure assets.

Asset classQuantityRating per unitCost per unitAsset value (AV)
Chiller plant units124.5 MW$1.8M$21.6M
Coolant distribution units482.3 MW$220k$10.56M
Block UPS modules166.25 MVA$1.2M$19.2M

Primary and secondary piping carries PG25 coolant at 122 L/min per rack.

CycloneDX 1.6+ compute payload assets.

BOM layerInventory
HBOM25,000 AI accelerator ASICs across 3,125 trays ($375M AV)
SBOMCaliptra silicon RoT, DICE root keys, OpenSIL drivers
CBOMMutual TLS certificates, firmware signing keys
OBOMOperational bounds: 94°C thermal trip, 64 kbps rate limits
VEXReal-time CVE vulnerability exploit state feeds

Business interruption exposure.

ExposureBasisValue
100 MW compute cluster revenueper hour$18,500
100 MW compute cluster revenueper day$444,000
Foundation model training checkpoint disruption lossper event$4.2M

By joining the physical DEXPI asset graph with the CycloneDX silicon bill of materials, the financial model evaluates not merely the replacement cost of an industrial pump ($45,000 USD), but the total dependent compute payload ($375,000,000 USD) that crashes when that pump is commanded to stop.


3. The Core Financial Risk Frameworks#

3.1 Annualized Loss Expectancy (NIST SP 800-30 Rev. 1)#

The ALE framework calculates risk exposure through three sequential equations:

SLE=AV×EF\text{SLE} = \text{AV} \times \text{EF}
ALE=SLE×ARO\text{ALE} = \text{SLE} \times \text{ARO}
ΔALE=ALEunmitigated−ALEhardened\Delta \text{ALE} = \text{ALE}_{\text{unmitigated}} - \text{ALE}_{\text{hardened}}

Where:

  • Asset Value (AV): The total financial value of physical assets and unserved IT revenue exposed to disruption.
  • Exposure Factor (EF): The percentage of asset value destroyed or lost during a single event (0.0≤EF≤1.00.0 \le \text{EF} \le 1.0).
  • Single Loss Expectancy (SLE): The monetary loss expected from a single occurrence of the incident.
  • Annualized Rate of Occurrence (ARO): The statistical frequency of the event occurring within a twelve-month operational period.

3.2 The Gordon-Loeb Optimal Investment Theorem#

The Gordon-Loeb model (2002) determines the mathematically optimal capital expenditure S∗S^* to protect an information asset. Let vv represent the expected loss without additional security (v=ALEv = \text{ALE}), and let SS represent the security investment. The post-mitigation vulnerability function is given by S(v)S(v).

Gordon and Loeb prove that under broad classes of security breach probability functions, the optimal investment S∗S^* never exceeds approximately 37%37\% of the expected loss:

S∗(z,v)≤1e⋅v≈0.3679⋅ALES^*(z, v) \le \frac{1}{e} \cdot v \approx 0.3679 \cdot \text{ALE}

The Practical CFO Takeaway: If a cyber-induced chiller failure carries an unmitigated ALE of $2,000,000 USD, investing more than $735,800 USD in security controls for that specific node yields diminishing marginal returns and destroys shareholder value.

3.3 Return on Security Investment (ROSI)#

The financial return on security controls is evaluated by dividing the net mitigated loss by the total cost of control implementation and maintenance:

ROSI=ΔALE−CcontrolCcontrol×100%=(ALEunmitigated−ALEhardened)−CcontrolCcontrol×100%\text{ROSI} = \frac{\Delta \text{ALE} - C_{\text{control}}}{C_{\text{control}}} \times 100\% = \frac{(\text{ALE}_{\text{unmitigated}} - \text{ALE}_{\text{hardened}}) - C_{\text{control}}}{C_{\text{control}}} \times 100\%

Where CcontrolC_{\text{control}} includes capital expenditure (hardware firewalls, optical diodes, FPGA gateways), implementation labor, annual software licensing, and operational testing.


4. Modeled 100 MW Hyperscale Worked Case Study#

The following worked financial analysis evaluates the six high-consequence CyHAZOP nodes of a modeled 100 MW high-density compute facility. Asset values are modeled replacement costs plus unserved SLA revenue losses, set by the working group at magnitudes typical of commercial hyperscale operations. No invoice, claim record or vendor quotation is cited for any of them. The exposure factor (EF) and cyber annual rate of occurrence (ARO) columns are likewise working-group estimates. Read the table as a sensitivity study on those two columns, because every ALE in it is their product with the asset value:

Table 10.1#

Pre-Mitigation Annualized Loss Expectancy

NodeFailure ScenarioAsset Value (AV)EFSingle Loss (SLE)ARO (Cyber)Pre-Mitigation ALE
N2: Block UPSCoordinated NMC ransomware trips all inverters; 4-hour outage$50,000,0000.80$40,000,0000.05$2,000,000
N5: Central ChillerModbus setpoint manipulation locks supply temp at 22∘C22^\circ\text{C}; 8-hour thermal trip$36,000,0000.60$21,600,0000.15$3,240,000
N6: CDU SecondaryPump stop with spoofed flow telemetry; silicon thermal destruction$75,000,0000.85$63,750,0000.10$6,375,000
N8: Facility BMSRansomware encrypts supervisory SCADA; lights-out fail-safe collapse$25,000,0000.50$12,500,0000.20$2,500,000
N10: Fire SuppressionInadvertent clean-agent release and HVAC emergency shutdown$15,000,0000.40$6,000,0000.10$600,000
N12: Server BMCSupply chain firmware backdoor kills 2,000 accelerator nodes$48,000,0000.70$33,600,0000.08$2,688,000
TOTALSBaseline 100 MW Hyperscale Infrastructure; ; ; ; $17,403,000

5. Security Programme Capital Allocation and ROSI Analysis#

To mitigate the 17.40M USD17.40\text{M USD} annual loss exposure, the facility deploys an integrated operational technology security programme totaling 1.60M USD1.60\text{M USD} in Year 1 capital and operational expenditure:

Table 10.2: Post-Mitigation Loss Reduction and ROSI#

NodeEngineered Safeguard DeployedControl CostResidual AROPost-Mitigation ALENet Loss Mitigated (ΔALE\Delta\text{ALE})Node ROSI
N2: Block UPSIsolated VLAN, physical console login, disabled cloud NMC interface$180,0000.005$200,000$1,800,000900%
N5: ChillerBACnet deep packet inspection firewall, PLC setpoint clamping$220,0000.010$216,000$3,024,0001,275%
N6: CDUOptical data diode, hardwired SIL-3 bi-metallic cutout switches$450,0000.005$318,750$6,056,2501,246%
N8: BMSIEC 62443 zone segmentation, air-gapped immutable backup server$350,0000.020$250,000$2,250,000543%
N10: FireHardwired mechanical abort buttons, isolated fire signaling conduit$120,0000.010$60,000$540,000350%
N12: BMCCaliptra 2.0 Silicon RoT, DICE firmware signing, 802.1AR auth$280,0000.030$1,008,000$1,680,000500%
TOTALSComprehensive OT Systems Assurance Programme$1,600,000; $2,052,750$15,350,250859%

5.1 Programme Evaluation Against the Gordon-Loeb Ceiling#

Evaluating the total programme against the Gordon-Loeb theorem:

Gordon-Loeb Investment Ceiling=0.3679×ALEunmitigated=0.3679×$17,403,000=$6,402,564\text{Gordon-Loeb Investment Ceiling} = 0.3679 \times \text{ALE}_{\text{unmitigated}} = 0.3679 \times \$17{,}403{,}000 = \$6{,}402{,}564
Budget Utilization Ratio=Programme CostGordon-Loeb Ceiling=$1,600,000$6,402,564=24.99%\text{Budget Utilization Ratio} = \frac{\text{Programme Cost}}{\text{Gordon-Loeb Ceiling}} = \frac{\$1{,}600{,}000}{\$6{,}402{,}564} = 24.99\%

The 1.60M USD1.60\text{M USD} investment operates at only 25%25\% of the maximum rational spending ceiling, providing exceptional capital efficiency while eliminating 88.2%88.2\% of total annualized cyber-physical financial risk.


6. The Nassim Taleb Fat-Tail Correction: Table A vs. Table B#

While standard ALE and Gordon-Loeb formulations provide vital capital allocation guidance, they suffer from a fatal structural flaw: they assume thin-tailed, Gaussian distributions.

6.1 The Fallacy of Thin-Tailed Loss Models in Industrial OT#

Standard risk models assume that losses decay exponentially:

P(L>x)∼exp⁡(−λx)P(L > x) \sim \exp(-\lambda x)

Under thin tails (Mediocristan / Table A), the mean and variance are stable. Ten independent pump failures of $50,000 USD each aggregate to $500,000 USD. Severe events are tens of standard deviations away and treated as statistically impossible.

However, cyber-physical operational technology operates in Extremistan (Table B). Losses follow a fat-tailed power-law distribution governed by a Pareto exponent α\alpha:

P(L>x)=Lmin⁡α⋅x−α(1<α<2)P(L > x) = L_{\min}^\alpha \cdot x^{-\alpha} \quad (1 < \alpha < 2)

When α<2\alpha < 2, the second moment (variance) of the loss distribution is infinite. When α≤1\alpha \le 1, the first moment (the mathematical mean) is undefined.

Thin Tails Versus Fat Tails Loss Regimes#

A correlated cyber attack inverts the first regime into the second.

RegimePropertyStatement
Mediocristan (Table A, thin-tailed)Loss modelStandard ALE applies: ALE=SLE×ARO\text{ALE} = \text{SLE} \times \text{ARO}
Mediocristan (Table A, thin-tailed)Event structureIndependent stochastic events; Gaussian decay; stable variance
Mediocristan (Table A, thin-tailed)ExampleIndividual motor bearing wear; MTBF tables
Extremistan (Table B, fat-tailed)Loss modelPower-law tail: P(L>x)=x−αP(L > x) = x^{-\alpha}, where 1<α<21 < \alpha < 2
Extremistan (Table B, fat-tailed)Event structureCommon-cause software vulnerabilities trip entire 100 MW data halls
Extremistan (Table B, fat-tailed)Dominant termThe conditional tail expectation E[L∣L>VaR]E[L \mid L > \text{VaR}] dominates total loss
Extremistan (Table B, fat-tailed)Model errorStandard ALE underestimates probable maximum loss by 10x to 100x

6.2 Mathematical Proof of Tail Expectation Divergence#

For a fat-tailed distribution with Pareto exponent α\alpha, the conditional tail expectation (Expected Shortfall or Tail Value at Risk) at confidence level 1−p1 - p is formulated as:

ESp=E[L∣L>VaRp]=αα−1⋅VaRp\text{ES}_p = E[L \mid L > \text{VaR}_p] = \frac{\alpha}{\alpha - 1} \cdot \text{VaR}_p

If an underwriter assesses a hyperscale facility using a Gaussian model with 99%99\% Value-at-Risk (VaR0.99=25,000,000 USD\text{VaR}_{0.99} = 25{,}000{,}000\text{ USD}), the Gaussian conditional tail loss is:

ES0.99Gaussian≈VaR0.99+σ2π≈$28,500,000\text{ES}_{0.99}^{\text{Gaussian}} \approx \text{VaR}_{0.99} + \frac{\sigma}{\sqrt{2\pi}} \approx \$28{,}500{,}000

For this analysis the cyber-physical catastrophe tail is modeled as a power law with α≈1.25\alpha \approx 1.25. That exponent is the working group's assumption; no claims dataset supporting it is cited anywhere in this paper, and the multiplier below is linear in α/(α−1)\alpha/(\alpha - 1), so it is sensitive to the choice. Under the Taleb fat-tail formulation:

ES0.99Fat-Tail=1.251.25−1⋅$25,000,000=5.0×$25,000,000=$125,000,000\text{ES}_{0.99}^{\text{Fat-Tail}} = \frac{1.25}{1.25 - 1} \cdot \$25{,}000{,}000 = 5.0 \times \$25{,}000{,}000 = \$125{,}000{,}000

The standard Gaussian model underestimates the catastrophic tail exposure by 96,500,000 USD (a 4.38x undercount). When common-cause cyber interdictions trigger simultaneous multi-hall cooling collapse, the physical loss wipes out thin-tailed insurance reserves, causing unhedged carrier insolvencies.


7. Governing Physical and Actuarial Formulations#

To unify applied physics with financial risk management, the quantitative framework is governed by five core equations:

7.1 Single Loss Expectancy with Full Collateral Damage#

The Single Loss Expectancy (SLE\text{SLE}) accounts for capital replacement, collateral structural damage, and unserved business interruption:

SLE(k)=Chardware(k)+Crecovery(k)+∫0Trestore(k)L˙BI(t) dt+Φregulatory\text{SLE}(k) = C_{\text{hardware}}(k) + C_{\text{recovery}}(k) + \int_0^{T_{\text{restore}}(k)} \dot{L}_{\text{BI}}(t) \, dt + \Phi_{\text{regulatory}}

Where:

  • ChardwareC_{\text{hardware}} includes ruined accelerator packages and power converters.
  • L˙BI(t)=18,500 USD/hour\dot{L}_{\text{BI}}(t) = 18{,}500\text{ USD/hour} SLA revenue burn rate.
  • TrestoreT_{\text{restore}} is the supply-chain lead time governed by the Reliability Critical Items List (RCIL).
  • Φregulatory\Phi_{\text{regulatory}} is the statutory fine levied under EU NIS2 or EU CRA Article 64.

7.2 Dynamic Thermal Decay Governing Interruption Timelines#

When fluid flow collapses, the operational time window before irreversible silicon thermal damage occurs is governed by convective heat transfer:

dTj(t)dt=Pdie−hconv(Q˙(t))⋅Adie⋅(Tj(t)−Tcoolant)Cthermal\frac{dT_j(t)}{dt} = \frac{P_{\text{die}} - h_{\text{conv}}(\dot{Q}(t)) \cdot A_{\text{die}} \cdot (T_j(t) - T_{\text{coolant}})}{C_{\text{thermal}}}

Where fluid flow collapses from 122 L/min122\text{ L/min} PG25 to zero, a silicon heat flux of 75 W/cm275\text{ W/cm}^2 induces a junction temperature rate of change of 1.46∘C/s1.46^\circ\text{C/s} and reaches the 94.0∘C94.0^\circ\text{C} emergency hardware shutdown trip point within 14.8 seconds14.8\text{ seconds}, ending the compute revenue stream in under a quarter of a minute and putting the capital asset at risk if the protection itself is defeated.

7.3 Probable Maximum Loss (PML) under Table B Regimes#

For underwriting capital reserve determination, the Probable Maximum Loss under Extremistan tail regimes is formulated as:

PMLExtremistan=(αα−1)⋅[∑j=1NhallsSLE(j)⋅1{shared_SCADA}]\text{PML}_{\text{Extremistan}} = \left( \frac{\alpha}{\alpha - 1} \right) \cdot \left[ \sum_{j=1}^{N_{\text{halls}}} \text{SLE}(j) \cdot \mathbf{1}_{\{\text{shared\_SCADA}\}} \right]

7.4 Net Present Value of Continuous Security Assurance#

The multi-year capital justification for operational technology resilience is expressed through discounted Net Present Value:

NPVsecurity=∑t=1NΔALEt−OPEXt(1+r)t−CAPEX0\text{NPV}_{\text{security}} = \sum_{t=1}^N \frac{\Delta \text{ALE}_t - \text{OPEX}_t}{(1 + r)^t} - \text{CAPEX}_0

For the worked 100 MW case study at a discount rate of r=8.5%r = 8.5\%, over a 5-year operational lifecycle, the net present value exceeds $48,200,000 USD.


8. Actuarial and Reinsurance Treaty Structuring#

Structuring affirmative cyber-physical reinsurance treaties requires aligning policy terms directly with the FMECA and ALE metrics computed above. Those metrics are modeled, so the terms in the following table are a proposed structure for negotiation, not a rate filing:

Underwriting ParameterUnmitigated Facility (Legacy OT)Hardened Facility (Eigenia Assured)Actuarial Justification
Primary Property Retention (Deductible)$25,000,000 to $50,000,000 punitive deductible.$2,500,000 retention indexed to digital twin compliance evidenced by an independent audit.Hardwired SIL-3 interlocks physically truncate catastrophic loss tails.
Business Interruption Sub-LimitsStrict 7-day waiting period; sub-limits capped at $10,000,000.Full affirmative BI coverage up to $50,000,000; 12-hour waiting period.Unidirectional optical data diodes eliminate remote supervisory hijacking.
Lloyd's Y5381 War ExclusionTotal claim denial during suspected nation-state state-sponsored events.Y5381's state-backed cyber-attack exclusion still applies regardless of hardening; it binds the managing agent, not the insured's controls.Attested hardware roots of trust (Caliptra 2.0) narrow the attribution dispute a contested claim will need; they do not waive the exclusion.
Portfolio Accumulation Loading45% capital surcharge to protect against correlated multi-site blackout.0% accumulation surcharge; risks treated as decoupled independent risks.Controller firmware diversity is evidenced in the CycloneDX SBOM. Network air-gapping is a separate claim and needs physical inspection; an SBOM cannot show it.

9. Summary of Engineering Principles#

Financial risk quantification for critical operational technology establishes five immutable principles:

  1. Speak the CFO's Language: Engineering teams must translate technical vulnerabilities into Single Loss Expectancy, Annualized Loss Expectancy, and Return on Security Investment.
  2. Respect the Gordon-Loeb Limit: Optimal security spending is mathematically bounded by approximately 37 percent of unmitigated loss. Spending beyond this ceiling destroys capital value.
  3. Beware Thin-Tailed Illusions: Standard risk frameworks systematically underestimate cyber-physical catastrophes because software vulnerabilities exhibit fat-tailed Extremistan behavior.
  4. Hardware Fixes Protect Capital: Investing in physical, analog safeguards; optical data diodes, mechanical relief valves, bi-metallic switches; yields ROSI figures exceeding 800 percent by eliminating correlated catastrophic loss.
  5. Actuarial Proof Unlocks Favorable Capital: Facilities that mathematically verify their cyber-physical bounds secure lower insurance premiums, smaller deductibles, and higher credit ratings.

10. References#

The method applies NIST SP 800-30, the Gordon-Loeb model, the Open FAIR taxonomy, and Lloyd's Market Bulletin Y5381.

Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 24,333 chars