1. Estimate annual attempt volume
Count or forecast phishing attempts serious enough to enter the risk model.
2. Set success probability
Use the chance that one attempt produces a material incident under current conditions.
3. Estimate loss severity
Include the financial consequences represented by your risk scope, such as fraud, response, downtime, and recovery.
4. Apply control effectiveness
Enter the modeled percentage reduction from training, filtering, authentication, monitoring, and response controls.
5. Review net and gross exposure
Compare the controlled estimate with gross expected loss to understand modeled risk reduction.