1. Estimate annual attack frequency
Enter the number of meaningful DDoS attempts expected during a typical year.
2. Set disruption probability
Estimate the share of attempts likely to cause material service degradation or outage.
3. Value one disruptive event
Include downtime, response, lost transactions, service credits, and other nonduplicated losses.
4. Adjust for threat trend
Use a positive or negative percentage when you expect frequency to change from the baseline.
5. Review expected annual loss
Compare the result with mitigation cost and tolerance for severe events.