1. Define event frequency
Enter the expected number of relevant security events in one year, including fractional values for less frequent scenarios.
2. Estimate loss per event
Use an average loss that reflects response, downtime, recovery, and other measurable impacts.
3. Set zero trust coverage
Estimate the share of users, devices, applications, and data paths actually governed by the modeled controls.
4. Rate effectiveness
Enter how much loss the controls are expected to prevent within the covered scope.
5. Compare baseline and residual loss
Use both values to understand the modeled benefit and remaining exposure.