Which of the following information security metrics is the MOST difficult to quantify?