Cyber Risk Quantification

The Probability of a Cyberattack: How to Estimate It?

Frequency of attempts, probability of success, scenario: how to estimate the probability of a cyberattack with a cyber risk quantification approach.

18 August 2026 · Citalid

Understanding the probability of a cyberattack has become a central issue for businesses. Yet the question is often poorly framed. In practice, you’re not just trying to know whether an attack is possible, but to estimate how often a given scenario might occur, and with what probability it could actually result in a loss.

Key idea

The probability of a cyberattack can't be reduced to a gut feeling or a score. In a Cyber Risk Quantification approach, it's built by combining two dimensions: the frequency of attempts and the probability that those attempts succeed.

Why this estimate is difficult

Estimating the probability of a cyberattack is more complex than it appears, for three main reasons. First, not all attacks are alike. Second, you never observe the full threat. Finally, probability depends as much on the attacker as on the target.

  1. 1

    Not all attacks are alike

    A ransomware attack, a data leak, a credential compromise, or a third-party attack don't share the same perpetrators, the same targets, or the same consequences.
  2. 2

    You never observe the full threat

    Some attacks are visible, documented, claimed, or detected, while another share remains invisible, incomplete, or hard to characterize.
  3. 3

    Probability depends as much on the attacker as on the target

    A highly exposed but well-defended organization doesn't carry the same risk level as a comparable organization that is less mature on the defensive side.

In other words, estimating a probability isn’t about predicting the future with certainty, but about modeling a plausible risk from data, scenarios, and structured assumptions. This logic is what distinguishes a quantification approach from a simple gut feeling about risk level.

The right question to ask

Behind the phrase “probability of a cyberattack” actually lie several distinct questions: the probability of being targeted by a type of attack, the probability that an attempt occurs over a given period, the probability that an attempt succeeds, or the probability that a cyber event actually results in a loss.

01

Being targeted

The probability of being targeted by a type of attack.

02

Facing an attempt

The probability that an attempt occurs over a given period.

03

Seeing an attempt succeed

The probability that an attempt breaches the defenses.

04

Suffering a loss

The probability that a cyber event actually results in a loss.

In a quantification logic, the most useful question isn’t therefore “will I be attacked?” but rather: what is the likely frequency of a given scenario, and what is the probability it results in a loss event? This distinction is what allows you to move from a vague discussion to a genuinely usable analysis.

Breaking probability down into two components

The FAIR approach, Factor Analysis of Information Risk, distinguishes two essential components.

The first is the frequency of attack attempts, or Threat Event Frequency (TEF): the number of attempts a given scenario can generate over a period, typically a year. This frequency doesn’t yet say whether the attack will succeed; it lets you estimate the intensity of the threat, how often a comparable organization can be targeted by this type of operation.

The second is the probability of success, or susceptibility. It measures the probability that an attempt actually succeeds, meaning it breaches the defenses and produces an event that results in losses.

The calculation, concretely

Combining these two dimensions gives the Loss Event Frequency (LEF), that is, the expected frequency of events that actually lead to a loss: LEF = TEF × Susceptibility. This logic is what turns a vague question about the probability of a cyberattack into an estimate useful for decision-making.

How to estimate the frequency of attempts

The first step is understanding who attacks whom, and in what context. At Citalid, frequency estimation relies on a threat-oriented approach rather than looking at the company alone: we observe known attacks, identify the associated groups or modes of operation, understand their usual targets, then link these behaviors to a victimology context that combines industry, geography, and company size. From there, we can start estimating the threat pressure on a given organization.

To approach this frequency, the model draws on five families of data.

01

Observed attacks

Attacks documented in open and specialized sources.

02

Attacker groups

Identified actors and their modes of operation.

03

Operational capacity

The estimated volume of operations on an annual basis.

04

Opportunism or targeting

The attacker's degree of selectivity in choosing victims.

05

Appetite

Their preference for certain sectors, countries, or types of organization.

Counting only observed attacks isn’t enough, though: not everything is visible, and a documented attack isn’t necessarily representative of everything that’s actually happening. That’s why the strongest models also try to reconstruct a share of the threat that isn’t directly observable, based on typical attacker profiles, behavior-based groupings, and calibration mechanisms designed to avoid overestimating the most visible threats at the expense of less visible ones. Frequency, then, isn’t a simple count, it’s a structured estimate of probable threat activity.

How to estimate the probability of success

Once frequency is estimated, a second question must be answered: if an attempt occurs, does it have a good chance of succeeding? This is where susceptibility comes in, resting on a simple idea: a scenario has more or less chance of succeeding depending on the level of offensive means deployed against the actual level of defensive means in place. You therefore need to compare the attacker’s capabilities, the techniques they’re likely to use, and the controls that are actually relevant on the organization’s side.

An overall cyber maturity level isn’t enough to estimate the probability of success for a specific scenario. An organization can have decent average maturity but be very weak on a few controls that are decisive for a given scenario, and conversely be globally imperfect but well protected on the mechanisms that matter against a specific attack. The challenge, then, is to assess the defense in the context of the scenario, not in the abstract.

Concretely, this means identifying the relevant attack techniques, linking them to the security controls meant to counter them, then measuring the level of defense actually available for the assets concerned. This produces a contextualized defensive score, which positions the organization against a given source of risk.

See how Citalid models frequency and susceptibility for your scenarios.

Discover the platform

Discover the platform

You can’t seriously estimate the probability of a cyberattack while staying at too general a level. You need to define a precise scenario: what type of attack, what type of actor, which assets are targeted, what business context, and what potential losses.

Les cinq paramètres d'un scénario

— What type of attack
— What type of actor
— Which assets are targeted
— What business context
— What potential losses

Without a scenario, probability stays too vague to be useful; with a scenario, you can link the threat to a concrete situation and a precise defensive mechanism, which also makes it possible to compare several risks against each other rather than talking about cyber as a single homogeneous block.

What this approach changes in practice

Estimating the probability of a cyberattack this way changes how risk is read. It first avoids confusing visibility with reality, then overly simplistic reasoning, and finally makes smarter risk steering possible.

  1. 1

    No longer confusing visibility with reality

    It's not because a type of attack gets more attention that it's mechanically the most likely in a given context.
  2. 2

    Avoiding overly simplistic reasoning

    Of the type "we have a lot of vulnerabilities so the risk is high" or "we haven't been attacked much recently so the risk is low," two intuitions that don't hold up under structured analysis.
  3. 3

    Steering more intelligently

    Once frequency and susceptibility are estimated, it becomes easier to prioritize investments, compare scenarios, objectify a budget, discuss it with an executive committee, or prepare a cyber insurance renewal.

Limits to keep in mind

Even with a good model, estimation shouldn’t be confused with certainty. A cyberattack probability remains a structured approximation, based on data, assumptions, behavior groupings, and modeling choices. It depends notably on the quality of threat data, the ability to properly define the scenario, the level of detail chosen for assets and controls, and how uncertainty is handled. The goal, then, isn’t to produce an absolute truth, but a base solid enough to support better decisions.

In summary

Estimating the probability of a cyberattack doesn’t mean handing over a single number pulled from a magic score. A robust approach consists of defining a precise scenario, estimating the frequency of attempts in that context, measuring the probability of those attempts succeeding based on the defensive posture, then combining the two to obtain an estimate of the frequency of loss-generating events.

A robust approach in four steps

— Define a precise scenario
— Estimate the frequency of attempts in that context
— Measure the probability of those attempts succeeding based on the defensive posture
— Combine the two to obtain an estimate of the frequency of loss-generating events

This breakdown is what allows a move from an intuitive question to a genuinely actionable answer. It turns a vague discussion about cyber risk into a quantified, debatable, and usable base for decision-making.

FAQ

Can you estimate the probability of a cyberattack without an internal incident history?

Yes. The estimate doesn't rely solely on incidents already suffered. It also draws on external threat data, attacker profiles, sector contexts, and modeling assumptions.

Why not just use technical vulnerabilities?

Because a vulnerability alone doesn't say how often the organization will be targeted, nor whether a given attacker will actually be capable of exploiting it in a specific scenario.

Does attack frequency correspond to the number of incidents suffered?

No. Attack frequency refers to the estimated number of attempts for a given scenario. Only once combined with susceptibility does it allow you to estimate the frequency of loss events.

Does susceptibility correspond to overall cyber maturity?

Not exactly. It depends on the defense relevant to a given scenario. Average, decent maturity doesn't guarantee low susceptibility across all scenarios.

Why is this approach more useful than a heatmap?

Because it allows reasoning from scenarios, frequency, probability of success, and impact, rather than from categories that are too general to arbitrate precisely.

Time to put this into practice

See quantification applied to your risk scenarios

Talk to an expert
Explore this topic further

La probabilité n'est qu'une des deux composantes du risque. Les autres articles du dossier traitent de l'impact financier, des scénarios et de la modélisation. The complete guide Cyber Risk Quantification: The Complete Guide covers the full subject.