Skip to main content
← Blog·7 min read·August 3, 2026

Risk management for beginners: SLE, ALE, ARO math made simple

Risk math on CompTIA Security+ comes down to two short formulas. SLE equals Asset Value times Exposure Factor. ALE equals SLE times ARO. Memorize those two lines, learn what each variable means, and Domain 5 calculation questions stop being the ones you dread. This post walks through the math the way a beginner needs to see it, with a worked dollar example you can copy onto scratch paper the moment your exam timer starts.

N
IT Service Center Manager, former CTE teacher, founder of Revtek

Why risk math matters on Security+

Domain 5 (Security Program Management and Oversight) is roughly 20 percent of the SY0-701 exam, and risk management is the load-bearing objective inside it. Every other Domain 5 topic (governance, third party, compliance, audits, awareness) eventually points back at the risk register, and the risk register only works if someone has done the math. That means the calculation questions are not optional knowledge. They are the spine of the domain.

CompTIA publishes a maximum of 90 questions and the domain weightings. It does not publish how many items sit behind any single objective, so nobody can honestly tell you how much risk math you will see. What you can control is speed. Calculation items and control-proposal items both reduce to the same two formulas, and if you can run them on paper in under a minute, they cost you almost none of your clock.

The three formulas you need to memorize

Honestly, two formulas. The third is a definition.

  • SLE = AV × EF. Single Loss Expectancy is what one incident costs.
  • ALE = SLE × ARO. Annualized Loss Expectancy is what that risk costs you per year on average.
  • ARO is a count, not a formula. It is how many times per year the event is expected to happen. One event every four years is an ARO of 0.25.

That is the whole toolkit. Every Security+ risk-math question reduces to plugging numbers into those two lines. The second the exam starts, write them on your scratch paper before you read the first question. Future-you will thank you.

What each term actually means in plain English

Variables are where beginners trip. The acronyms sound like finance jargon, but the underlying ideas are not complicated.

  • AV (Asset Value). What the asset is worth to the business in dollars. Not what you paid for it. What it is worth right now if it disappeared.
  • EF (Exposure Factor). The percentage of that value lost in one incident, written as a decimal between 0.0 and 1.0. A 75 percent loss is 0.75. A total wipeout is 1.0.
  • SLE (Single Loss Expectancy). The dollar cost of one event. AV times EF.
  • ARO (Annualized Rate of Occurrence). How often the event happens per year, expressed as a decimal. Once every four years is 0.25. Five times a year is 5.
  • ALE (Annualized Loss Expectancy). The expected dollar cost per year. SLE times ARO. This is the number finance and the board care about.

Worked example: ransomware risk to a 50-person company

Picture a fictional 50-person logistics firm, Pinehurst Logistics. Their operational server stack (file servers, application servers, the dispatch database) is worth $200,000 to the business. A ransomware-grade incident, if it lands, would wipe out roughly 75 percent of operational capacity during the recovery window. Their threat-intel feed and industry data say a company their size sees that kind of incident about once every four years.

Plugging in the numbers:

AV  = $200,000
EF  = 0.75
SLE = AV × EF = $200,000 × 0.75 = $150,000

ARO = 0.25  (one event every four years)
ALE = SLE × ARO = $150,000 × 0.25 = $37,500 per year

Now the business decision becomes legible, and the first honest answer is no. Say a vendor pitches a $40,000 per year EDR-plus-immutable-backup stack that would cut the ARO from 0.25 to 0.05. Run it out: ALE before is $37,500 per year, ALE after is $7,500 per year, so the control removes $30,000 of annual exposure and costs $40,000. That is $10,000 per year underwater on this risk alone.

ALE before = $150,000 × 0.25 = $37,500 / yr
ALE after  = $150,000 × 0.05 = $7,500 / yr
Risk reduced   = $37,500 - $7,500 = $30,000 / yr
Control cost   = $40,000 / yr
Net            = $30,000 - $40,000 = -$10,000 / yr

This is the case the exam wants you to catch. The numbers look close enough to feel like a yes until you subtract them. To clear the bar on this risk, a control that produces the same ARO drop would have to cost under $30,000 per year. A $200,000 per year managed-XDR platform is further underwater still. That does not end the conversation (more on that below), but it gives leadership a defensible starting number instead of a vendor's.

When quantitative beats qualitative

Quantitative analysis (the kind we just did) wins when you have three things: real numbers for asset value, defensible frequency data, and a methodology you can show an auditor. When all three are present, finance can compare risk against control cost the same way they compare any other budget line.

Qualitative analysis (low, medium, high on a heat map) wins when one of those three is missing. Novel threats with no frequency history. Intangible assets like brand reputation where the dollar value is genuinely contested. Or rooms where leadership simply trusts a narrative more than a spreadsheet. Most real programs run both: qualitative across the long tail of risks, quantitative on the top few where the control spend justifies the analytical work.

Risk treatment: accept, avoid, transfer, mitigate

Once you have a quantified risk, there are exactly four things you can do with it. The exam tests every one.

  • Mitigate. Add or change controls to lower likelihood, impact, or both. MFA, segmentation, immutable backups.
  • Transfer. Push the financial impact to someone else. Cyber insurance, a contracted SOC, a vendor SLA with penalties.
  • Avoid. Stop doing the activity that produces the risk. Cancel the third-party integration that requires sharing customer data.
  • Accept. Decide, on paper, to carry the risk. This is the right move when the control costs more than the exposure it would remove, meaning the ALE reduction is smaller than the price tag, and leadership signs off. Accept does not mean ignore. Unwritten acceptance is just an unmanaged risk.

How Security+ tests this

The formulas show up in a few recognizable shapes. Some items are pure calculation: here are AV, EF, and ARO, what is ALE. Some are control comparisons: control A costs $25,000 per year and drops ARO from 0.4 to 0.1, control B costs $60,000 per year and drops ARO from 0.4 to 0.0, which one wins on dollars. A performance-based item may hand you a half-filled risk register row and ask which treatment the residual score justifies. How many of each you get is not something CompTIA publishes.

The pattern is the same every time. Compute the ALE. Compute the ALE delta the control would create. If the control costs less than the delta, mitigate. If it costs more, accept (with documentation), transfer (with insurance), or avoid (stop the activity).

The deep walk-through lives in lesson SP-5.2, including the full risk register layout, the four risk assessment cadences, and the difference between risk tolerance and risk appetite. Once the math is reflex, sit a full-length Practice Exam and watch how the Domain 5 calculation items feel under a clock. If you can run them without stalling, the math is not the thing slowing you down.

Where to go next

If you are studying for Security+ specifically, the Security+ track page has the full objective map and how Domain 5 sits next to the other four domains. If you are already in the platform, head to the dashboard and review your Security+ Mastery Index with its evidence-quality label.

Questions about your specific path? Email the team. We reply personally, usually within a day.

Sources

  1. NIST. SP 800-30 Rev. 1, Guide for Conducting Risk Assessments. Federal reference for the risk identification, analysis, and reporting steps the SY0-701 objective is built on, including the risk register template in Appendix D.
  2. NIST. SP 800-37 Rev. 2, Risk Management Framework for Information Systems and Organizations. The seven-step RMF that anchors the broader risk management vocabulary on the Security+ exam.
  3. ISO. ISO 31000 Risk Management. International standard for risk management principles, framework, and process. Source for the four treatment strategies (transfer, accept, avoid, mitigate) referenced in this post.

About the authors

Nicholas Miller
Founder and Lead Author

IT Service Center Manager and former CTE / IT teacher. Owner of Revtek in Chicago's south suburbs. Writes everything that ships under his name and reviews every line of Revy-assisted drafting before publish.

LinkedIn ↗
R
Revy
Study buddy · AI co-author

Revy helps draft and structure these posts. Every piece is reviewed, edited, and fact-checked by Nick before publish. We disclose this here because it is the right thing to do. See the AI Policy for the full stance.

Who writes this, and who checks it

Nicholas Miller
IT Service Center Manager · former high school CTE and IT teacher · founder of Revtek IT Solutions

Nick writes and edits these posts. AI helps with research, outlines, and first drafts. Nick reviews the draft before it goes live, and he is the only reviewer, so this is one person checking his own work. That catches a lot and it misses some.

When a post turns out to be wrong, the fix and the date it happened go on the corrections log, in public, including the ones nobody outside noticed. We do not use confidential, recalled, or leaked exam content. These posts are written from CompTIA's published objectives and authoritative technical sources. The AI policy has the longer version.

LinkedIn ↗