Treatise 14: Annualized Loss Expectancy & Return on Security Investment for OT
J. McKenney
This is a working-group treatise in WG-01-UI (Underwriter & Insurance). It translates the CyHAZOP and dual-RPN engineering methodology, developed in the working group's Quantitative Cyber-Physical FMECA treatise and in WG-07-TM's CyHAZOP Node Registers, into the financial decision framework, Annualized Loss Expectancy, the Gordon-Loeb ceiling, and Return on Security Investment, that the group's RCIL/SCIL reinsurance treatise draws on for its own capital allocation figures.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
An engineer who reads a Risk Priority Number of 567 on a coolant pump knows something is wrong, but that number does not tell a Chief Financial Officer how many dollars are at stake or how much security spending is justified. This paper runs FMECA and CyHAZOP findings through Annualized Loss Expectancy, the Gordon-Loeb model, and Return on Security Investment, on a modeled 100 MW data center.
Every number in that example is an estimate, not a measurement. The exposure factors, cyber attack rates, and loss figures are working-group assumptions representative of a hyperscale facility, not claims-history observations, so the work is a sensitivity study, not a rate filing. On those inputs an operational technology programme costing one point six million dollars mitigates roughly fifteen million dollars in annual expected losses, a modeled Return on Security Investment of 859 percent at 24.99 percent of the Gordon-Loeb ceiling.
The second half extends this to losses that do not follow the thin-tailed statistics ordinary insurance mathematics assumes. A fat-tailed power-law correction shows a Gaussian model can understate the tail risk of a shared cooling failure or firmware attack by an order of magnitude, and what it means for a deductible, a reinsurance treaty, and a capital reserve.
Abstract#
FMECA and HAZOP tell facility teams what can fail and how severe it will be, but metrics such as Risk Priority Numbers do not answer what CFOs, underwriters, and boards ask: how much capital is exposed, and what is the optimal return on mitigating it? This paper translates the cyber-physical CyHAZOP and dual-RPN methodologies into Annualized Loss Expectancy per NIST SP 800-30, the Gordon-Loeb optimal investment model, and the Open FAIR taxonomy. The reference case is a modeled 100 MW high-density compute facility, not a measured site; every exposure factor and rate of occurrence in Section 4 is a working-group estimate. On those inputs it models a $1.60M programme mitigating $15,350,250 in annual expected losses, a Return on Security Investment of 859 percent (exposure factors 0.40 to 0.85, cyber ARO 0.05 to 0.20), operating at 24.99 percent of the Gordon-Loeb ceiling of $6,402,564. The paper shows that standard ALE, Gordon-Loeb, and Gaussian Value-at-Risk models assume thin-tailed Mediocristan distributions and understate tail-risk. Applying Taleb fat-tail power-law corrections with an assumed Pareto exponent of 1.25, it models Table B (Extremistan) events such as simultaneous multi-megawatt cooling collapse, where traditional models understate single-event probable maximum loss by an order of magnitude, and formalizes the equations to price property catastrophe policies, set retention deductibles, and structure reinsurance treaties accounting for Lloyd's Y5381.
1. The Executive Capital Allocation Problem#
In hyperscale mission-critical environments, a severe disconnect exists between operational engineering teams and the executive suite:
- The Facility Engineer's Perspective: A facility engineer observes an RPN of 567 on a Coolant Distribution Unit (CDU) pump cyber-induced shutdown and immediately recognizes an operational emergency.
- The CFO's Perspective: The Chief Financial Officer reviews the identical report and asks: What is the probabilistic annual dollar loss of that event, how will it impact quarterly EBITDA, and what capital expenditure is mathematically justified to prevent it?
Without rigorous financial quantification, cybersecurity requests are treated as discretionary overhead rather than risk-mitigating investments. As high-density AI clusters push rack densities beyond and cluster valuations past hundreds of millions of dollars, qualitative color-coded risk heat maps ("red, amber, green") are no longer legally or actuarially defensible.
The Capital Allocation Quantification Bridge#
| Layer | Element | Content |
|---|---|---|
| CyHAZOP and FMECA engineering | Node deviations | MORE, LESS, SPOOFED, POISONED |
| CyHAZOP and FMECA engineering | Physical units | Bar, L/min, °C, kW, Hz |
| CyHAZOP and FMECA engineering | Quantitative metric | Cyber Risk Priority Number, |
| CFO and underwriting capital allocation | Single Loss Expectancy | |
| CFO and underwriting capital allocation | Annualized Loss Expectancy | |
| CFO and underwriting capital allocation | Return on Security Investment | |
| CFO and underwriting capital allocation | Gordon-Loeb investment ceiling | |
| CFO and underwriting capital allocation | Taleb fat-tail power-law correction | , Extremistan scale |
2. Multi-BOM and DEXPI Asset Valuation Topology#
Accurately calculating Asset Value (AV) and Exposure Factor (EF) requires synchronizing physical piping models with silicon inventories across the DEXPI 2.0 and CycloneDX 1.6+ specifications, with DEXPI equipment classes drawn from the ISO 15926-4 reference data library:
Financial Asset Exposure Topology#
DEXPI 2.0 physical infrastructure assets.
| Asset class | Quantity | Rating per unit | Cost per unit | Asset value (AV) |
|---|---|---|---|---|
| Chiller plant units | 12 | 4.5 MW | $1.8M | $21.6M |
| Coolant distribution units | 48 | 2.3 MW | $220k | $10.56M |
| Block UPS modules | 16 | 6.25 MVA | $1.2M | $19.2M |
Primary and secondary piping carries PG25 coolant at 122 L/min per rack.
CycloneDX 1.6+ compute payload assets.
| BOM layer | Inventory |
|---|---|
| HBOM | 25,000 AI accelerator ASICs across 3,125 trays ($375M AV) |
| SBOM | Caliptra silicon RoT, DICE root keys, OpenSIL drivers |
| CBOM | Mutual TLS certificates, firmware signing keys |
| OBOM | Operational bounds: 94°C thermal trip, 64 kbps rate limits |
| VEX | Real-time CVE vulnerability exploit state feeds |
Business interruption exposure.
| Exposure | Basis | Value |
|---|---|---|
| 100 MW compute cluster revenue | per hour | $18,500 |
| 100 MW compute cluster revenue | per day | $444,000 |
| Foundation model training checkpoint disruption loss | per event | $4.2M |
By joining the physical DEXPI asset graph with the CycloneDX silicon bill of materials, the financial model evaluates not merely the replacement cost of an industrial pump ($45,000 USD), but the total dependent compute payload ($375,000,000 USD) that crashes when that pump is commanded to stop.
3. The Core Financial Risk Frameworks#
3.1 Annualized Loss Expectancy (NIST SP 800-30 Rev. 1)#
The ALE framework calculates risk exposure through three sequential equations:
Where:
- Asset Value (AV): The total financial value of physical assets and unserved IT revenue exposed to disruption.
- Exposure Factor (EF): The percentage of asset value destroyed or lost during a single event ().
- Single Loss Expectancy (SLE): The monetary loss expected from a single occurrence of the incident.
- Annualized Rate of Occurrence (ARO): The statistical frequency of the event occurring within a twelve-month operational period.
3.2 The Gordon-Loeb Optimal Investment Theorem#
The Gordon-Loeb model (2002) determines the mathematically optimal capital expenditure to protect an information asset. Let represent the expected loss without additional security (), and let represent the security investment. The post-mitigation vulnerability function is given by .
Gordon and Loeb prove that under broad classes of security breach probability functions, the optimal investment never exceeds approximately of the expected loss:
The Practical CFO Takeaway: If a cyber-induced chiller failure carries an unmitigated ALE of $2,000,000 USD, investing more than $735,800 USD in security controls for that specific node yields diminishing marginal returns and destroys shareholder value.
3.3 Return on Security Investment (ROSI)#
The financial return on security controls is evaluated by dividing the net mitigated loss by the total cost of control implementation and maintenance:
Where includes capital expenditure (hardware firewalls, optical diodes, FPGA gateways), implementation labor, annual software licensing, and operational testing.
4. Modeled 100 MW Hyperscale Worked Case Study#
The following worked financial analysis evaluates the six high-consequence CyHAZOP nodes of a modeled 100 MW high-density compute facility. Asset values are modeled replacement costs plus unserved SLA revenue losses, set by the working group at magnitudes typical of commercial hyperscale operations. No invoice, claim record or vendor quotation is cited for any of them. The exposure factor (EF) and cyber annual rate of occurrence (ARO) columns are likewise working-group estimates. Read the table as a sensitivity study on those two columns, because every ALE in it is their product with the asset value:
Table 10.1#
Pre-Mitigation Annualized Loss Expectancy
| Node | Failure Scenario | Asset Value (AV) | EF | Single Loss (SLE) | ARO (Cyber) | Pre-Mitigation ALE |
|---|---|---|---|---|---|---|
| N2: Block UPS | Coordinated NMC ransomware trips all inverters; 4-hour outage | $50,000,000 | 0.80 | $40,000,000 | 0.05 | $2,000,000 |
| N5: Central Chiller | Modbus setpoint manipulation locks supply temp at ; 8-hour thermal trip | $36,000,000 | 0.60 | $21,600,000 | 0.15 | $3,240,000 |
| N6: CDU Secondary | Pump stop with spoofed flow telemetry; silicon thermal destruction | $75,000,000 | 0.85 | $63,750,000 | 0.10 | $6,375,000 |
| N8: Facility BMS | Ransomware encrypts supervisory SCADA; lights-out fail-safe collapse | $25,000,000 | 0.50 | $12,500,000 | 0.20 | $2,500,000 |
| N10: Fire Suppression | Inadvertent clean-agent release and HVAC emergency shutdown | $15,000,000 | 0.40 | $6,000,000 | 0.10 | $600,000 |
| N12: Server BMC | Supply chain firmware backdoor kills 2,000 accelerator nodes | $48,000,000 | 0.70 | $33,600,000 | 0.08 | $2,688,000 |
| TOTALS | Baseline 100 MW Hyperscale Infrastructure | ; | ; | ; | ; | $17,403,000 |
5. Security Programme Capital Allocation and ROSI Analysis#
To mitigate the annual loss exposure, the facility deploys an integrated operational technology security programme totaling in Year 1 capital and operational expenditure:
Table 10.2: Post-Mitigation Loss Reduction and ROSI#
| Node | Engineered Safeguard Deployed | Control Cost | Residual ARO | Post-Mitigation ALE | Net Loss Mitigated () | Node ROSI |
|---|---|---|---|---|---|---|
| N2: Block UPS | Isolated VLAN, physical console login, disabled cloud NMC interface | $180,000 | 0.005 | $200,000 | $1,800,000 | 900% |
| N5: Chiller | BACnet deep packet inspection firewall, PLC setpoint clamping | $220,000 | 0.010 | $216,000 | $3,024,000 | 1,275% |
| N6: CDU | Optical data diode, hardwired SIL-3 bi-metallic cutout switches | $450,000 | 0.005 | $318,750 | $6,056,250 | 1,246% |
| N8: BMS | IEC 62443 zone segmentation, air-gapped immutable backup server | $350,000 | 0.020 | $250,000 | $2,250,000 | 543% |
| N10: Fire | Hardwired mechanical abort buttons, isolated fire signaling conduit | $120,000 | 0.010 | $60,000 | $540,000 | 350% |
| N12: BMC | Caliptra 2.0 Silicon RoT, DICE firmware signing, 802.1AR auth | $280,000 | 0.030 | $1,008,000 | $1,680,000 | 500% |
| TOTALS | Comprehensive OT Systems Assurance Programme | $1,600,000 | ; | $2,052,750 | $15,350,250 | 859% |
5.1 Programme Evaluation Against the Gordon-Loeb Ceiling#
Evaluating the total programme against the Gordon-Loeb theorem:
The investment operates at only of the maximum rational spending ceiling, providing exceptional capital efficiency while eliminating of total annualized cyber-physical financial risk.
6. The Nassim Taleb Fat-Tail Correction: Table A vs. Table B#
While standard ALE and Gordon-Loeb formulations provide vital capital allocation guidance, they suffer from a fatal structural flaw: they assume thin-tailed, Gaussian distributions.
6.1 The Fallacy of Thin-Tailed Loss Models in Industrial OT#
Standard risk models assume that losses decay exponentially:
Under thin tails (Mediocristan / Table A), the mean and variance are stable. Ten independent pump failures of $50,000 USD each aggregate to $500,000 USD. Severe events are tens of standard deviations away and treated as statistically impossible.
However, cyber-physical operational technology operates in Extremistan (Table B). Losses follow a fat-tailed power-law distribution governed by a Pareto exponent :
When , the second moment (variance) of the loss distribution is infinite. When , the first moment (the mathematical mean) is undefined.
Thin Tails Versus Fat Tails Loss Regimes#
A correlated cyber attack inverts the first regime into the second.
| Regime | Property | Statement |
|---|---|---|
| Mediocristan (Table A, thin-tailed) | Loss model | Standard ALE applies: |
| Mediocristan (Table A, thin-tailed) | Event structure | Independent stochastic events; Gaussian decay; stable variance |
| Mediocristan (Table A, thin-tailed) | Example | Individual motor bearing wear; MTBF tables |
| Extremistan (Table B, fat-tailed) | Loss model | Power-law tail: , where |
| Extremistan (Table B, fat-tailed) | Event structure | Common-cause software vulnerabilities trip entire 100 MW data halls |
| Extremistan (Table B, fat-tailed) | Dominant term | The conditional tail expectation dominates total loss |
| Extremistan (Table B, fat-tailed) | Model error | Standard ALE underestimates probable maximum loss by 10x to 100x |
6.2 Mathematical Proof of Tail Expectation Divergence#
For a fat-tailed distribution with Pareto exponent , the conditional tail expectation (Expected Shortfall or Tail Value at Risk) at confidence level is formulated as:
If an underwriter assesses a hyperscale facility using a Gaussian model with Value-at-Risk (), the Gaussian conditional tail loss is:
For this analysis the cyber-physical catastrophe tail is modeled as a power law with . That exponent is the working group's assumption; no claims dataset supporting it is cited anywhere in this paper, and the multiplier below is linear in , so it is sensitive to the choice. Under the Taleb fat-tail formulation:
The standard Gaussian model underestimates the catastrophic tail exposure by 96,500,000 USD (a 4.38x undercount). When common-cause cyber interdictions trigger simultaneous multi-hall cooling collapse, the physical loss wipes out thin-tailed insurance reserves, causing unhedged carrier insolvencies.
7. Governing Physical and Actuarial Formulations#
To unify applied physics with financial risk management, the quantitative framework is governed by five core equations:
7.1 Single Loss Expectancy with Full Collateral Damage#
The Single Loss Expectancy () accounts for capital replacement, collateral structural damage, and unserved business interruption:
Where:
- includes ruined accelerator packages and power converters.
- SLA revenue burn rate.
- is the supply-chain lead time governed by the Reliability Critical Items List (RCIL).
- is the statutory fine levied under EU NIS2 or EU CRA Article 64.
7.2 Dynamic Thermal Decay Governing Interruption Timelines#
When fluid flow collapses, the operational time window before irreversible silicon thermal damage occurs is governed by convective heat transfer:
Where fluid flow collapses from PG25 to zero, a silicon heat flux of induces a junction temperature rate of change of and reaches the emergency hardware shutdown trip point within , ending the compute revenue stream in under a quarter of a minute and putting the capital asset at risk if the protection itself is defeated.
7.3 Probable Maximum Loss (PML) under Table B Regimes#
For underwriting capital reserve determination, the Probable Maximum Loss under Extremistan tail regimes is formulated as:
7.4 Net Present Value of Continuous Security Assurance#
The multi-year capital justification for operational technology resilience is expressed through discounted Net Present Value:
For the worked 100 MW case study at a discount rate of , over a 5-year operational lifecycle, the net present value exceeds $48,200,000 USD.
8. Actuarial and Reinsurance Treaty Structuring#
Structuring affirmative cyber-physical reinsurance treaties requires aligning policy terms directly with the FMECA and ALE metrics computed above. Those metrics are modeled, so the terms in the following table are a proposed structure for negotiation, not a rate filing:
| Underwriting Parameter | Unmitigated Facility (Legacy OT) | Hardened Facility (Eigenia Assured) | Actuarial Justification |
|---|---|---|---|
| Primary Property Retention (Deductible) | $25,000,000 to $50,000,000 punitive deductible. | $2,500,000 retention indexed to digital twin compliance evidenced by an independent audit. | Hardwired SIL-3 interlocks physically truncate catastrophic loss tails. |
| Business Interruption Sub-Limits | Strict 7-day waiting period; sub-limits capped at $10,000,000. | Full affirmative BI coverage up to $50,000,000; 12-hour waiting period. | Unidirectional optical data diodes eliminate remote supervisory hijacking. |
| Lloyd's Y5381 War Exclusion | Total claim denial during suspected nation-state state-sponsored events. | Y5381's state-backed cyber-attack exclusion still applies regardless of hardening; it binds the managing agent, not the insured's controls. | Attested hardware roots of trust (Caliptra 2.0) narrow the attribution dispute a contested claim will need; they do not waive the exclusion. |
| Portfolio Accumulation Loading | 45% capital surcharge to protect against correlated multi-site blackout. | 0% accumulation surcharge; risks treated as decoupled independent risks. | Controller firmware diversity is evidenced in the CycloneDX SBOM. Network air-gapping is a separate claim and needs physical inspection; an SBOM cannot show it. |
9. Summary of Engineering Principles#
Financial risk quantification for critical operational technology establishes five immutable principles:
- Speak the CFO's Language: Engineering teams must translate technical vulnerabilities into Single Loss Expectancy, Annualized Loss Expectancy, and Return on Security Investment.
- Respect the Gordon-Loeb Limit: Optimal security spending is mathematically bounded by approximately 37 percent of unmitigated loss. Spending beyond this ceiling destroys capital value.
- Beware Thin-Tailed Illusions: Standard risk frameworks systematically underestimate cyber-physical catastrophes because software vulnerabilities exhibit fat-tailed Extremistan behavior.
- Hardware Fixes Protect Capital: Investing in physical, analog safeguards; optical data diodes, mechanical relief valves, bi-metallic switches; yields ROSI figures exceeding 800 percent by eliminating correlated catastrophic loss.
- Actuarial Proof Unlocks Favorable Capital: Facilities that mathematically verify their cyber-physical bounds secure lower insurance premiums, smaller deductibles, and higher credit ratings.
10. References#
The method applies NIST SP 800-30, the Gordon-Loeb model, the Open FAIR taxonomy, and Lloyd's Market Bulletin Y5381.