In my first four posts, I looked at markets - equity, debt and collectibles - in the aggregate performed in 2025. In this post, I turn my attention to divergences in risk across companies, looking at alternative measures of risk, some based on prices and others at earnings, and how these differences play out in hurdle rates, a necessary ingredient for businesses trying to determine whether and how much to invest in individual projects and for investors making that same judgment, when looking at companies.
Risk: Definition and Measures
For a concept tas central to investing and corporate finance as risk is, it is astonishing how much divergence there is across even finance experts and academics on what it is, and consequently on how to measure it. I have heard some describe risk as uncertainty, essentially substituting one fuzzy word for another, others as the threat of grevious loss and still and still others as the possibility of negative outcomes. If you have taken a finance class, and I confess to having a part in this, you may define risk as volatility or standard deviation, or even bring Greek alphabets into play. My favorite definition of risk and one that I start my corporate finance class with is that Chinese symbol for crisis or big risk (and I am sure that I have mangled the symbols, since I have been corrected a dozen times in the past):
As someone who can neither read nor speak Chinese, I am reliant on friends who know the language, and I have been told that the first of the two symbols is the one for danger and the second is a symbol for opportunity. In effect, by bunding together danger and opportunity, the risk measure captures how risk both attracts (to get to opportunity) and repels (with the threat of danger). That duality explains why an investment or business strategy generally cannot be built around the objective of just minimizing risk, since that effectively will remove access to opportunities or recklessly chasing after opportunities, ignoring dangers
With that definition of risk in place, I will start the discussion of risk measures by examining the choices that we face in making the measurement:
Upside versus Downside: If you start with a generic definition of risk as receiving an outcome that is different from what your expectation, it is worth recognizing that some of these outcomes will be positive (better than expected) and some will be negative (worse than expected), and that it is the latter than investors and businesses dislike. Thus, there are some who argue that risk measures should focus on just downside outcomes, not all unexpected outcome.
Price-based versus accounting-based: Risk measures that are based upon data can be built on market prices, for publicly traded firms, or on accounting data, especially earnings. Price-based measures have the advantage of constant updating, giving you more data, but are sometimes contaminated by the noise and volatility that come from trading. Accounting measures yield more stability, but since they are updated infrequently, and accounting smooths changes over time, they can offer stale or distorted values.
Total versus Non-diversifiable: The risk in an investment, whether a project or a business, can come from many different sources, but some of the risks are more investment-specific whereas others are market-wide:
To the question of why we should care, the presence of many investments in a portfolio implies that risks that are investment-specific will average out, decreasing or even disappearing as portfolios get larger, whereas market risks remain intact. This insight, which earned Harry Markowitz a Nobel prize, gave birth to modern portfolio theory and is at the heart of most risk and return models in finance.
I have my preferences on how best to measure risk, I would like to keep an open mind and start by laying out the choices we face on risk-measures:
As you can see, the risk measure you choose will be a function of whether you (as an investor or business) believe that the marginal investors, i.e., the investors who own the most shares in your business and trade those share, are diversified or not, and what you believe about financial markets and accounting data.
Risk across Companies in 2025
My sample includes 48,156 publicly traded firms and given that these companies trade across different geographies and are in different businesses, it should come as no surprise that there are wide variations in risk across these companies. In this section, I will start with accounting-based measures, with the caveat that accounting standards vary across the world, though IFRS and GAAP have created significant convergence.
Accounting Measures
While there are a variety of accounting metrics that you can use to measure risk, the most logical one to focus on is earnings, but you have many choices. You could use net income or earnings per share, which will reflect not only the riskiness of the business operate in, but also the amount of debt you have chosen to take on, or you can used operating income, more reflective of just market risk. Within each of these metrics, you can measure risk as volatility (in earnings) or in more simplistic terms, on whether you have positive or negative income. For those investors and businesses to whom, it is debt that is the risk trigger, you can look at measures of that debt burden:
Let’s start with volatility in earnings, where we have two estimation choices that we must make, before we get started. The first is history, and I compute the standard deviations in operating and net income using ten years of earnings data, for each firm, a compromise between a number too high (where I lose too many firms in my sample) and too low (where I lack enough data). The second is that earnings standard deviations in earnings will reflect the level of earnings, with higher earnings companies having higher standard deviations. To control for this, I divide the standard deviation of earnings by the average earnings over the ten years, yielding coefficients of variation in earnings. The following table summarizes the distributional values for this metric, across sectors:
It should come as no surprise that utilities have the least volatile operating earnings and have the lowest coefficient of variation on that metric, and that energy and technology haver the most volatile operating income. On a net income basis, financials and utilities have the lowest volatility in earnings, , and energy and communication services have the highest net income volatility.
If you use the frequency of loss-making, as a risk proxy, the table below captures differences on that metric across sectors on this dimension:
Utilities are again the least risky sector, with a lower percentage of money losers than any other sector, and health care and technology firms have a higher percent of money losers than other sectors.
While there are some who use debt loads as proxies for company risk, and we will come back and look at differences across sectors and industries in a later post, it is a narrow measure, since a young, risky, high growth company with no debt would be classified as low-risk, if it is not debt-laden.
Price-based Measures
All of the stocks in our sample are publicly traded, and consequently, you can use market prices to measure risk. That said, liquidity is a wild card, high in some markets and low in others, and that can cause distortions in the comparison.
1. High and Low Prices: One of the simplest measures of price volatility is the range of prices, with wider divergences between high and low prices at more risky companies and smaller ones at safer companies:
I computed this statistic for each company in my sample, and then the averages across companies in each industry, and it should be lower (higher) for safer (riskier) stocks. Using my global data, this is what this statistic looks like, across sectors:
Utilities again come in as safest, using this risk metric, tied with real estate, and health care has the widest price ranges of the companies in my sample.
2. Standard deviation in price changes: This is a standard statistical construct, and measures volatility in a stock, though it does not distinguish between upside and downside volatility. Based upon the company-specific standard deviations, again averaged out across sectors, here is what the numbers looked like in 2025:
Financials and utilities are the two safest sectors, and technology and health care are the riskiest, if you measure risk with standard deviation.
3. Betas: If you buy into the notion that the investors setting prices are diversified, and thus care only about risk that cannot be diversified away, you will focus only on the portion of the standard deviation in a stock that comes from the market, and betas, notwithstanding the misinterpretations and misreading, are trying to measure that non-diversifiable portion of standard deviation and scale around one. Again, looking across industries, I look at the distribution of betas, by sector:
If you are interested in a less broad categorization, you can check out betas by industry at the end of this post.
As you review the sector rankings using the varied risk measures, you can see why the heated debates about which risk measure to use is often overdone, since they, for the most part, rank the sectors similarly, with the sectors having less earnings volatility and fewer money-losers also having less volatility in stock price, smaller price ranges and lower betas.
Hurdle Rates Even as we wrestle with choosing between price and accounting-based measures, it is worth remembering that the end game here is not the risk measure itself, and that risk measures are a means to an end, which is estimating hurdle rates. Hurdle rates come into play for both businesses and investors, setting thresholds that they can use to determine whether to invest or not:
There are some investors and businesses who believe that hurdle rates come from their guts, numbers that reflect personal risk aversion and past experiences, but hurdle rates are opportunity costs, reflecting returns that investors (businesses) can earn in the market on investments of equivalent risk.
In the context of a business, which raises money from debt and equity, you can look at hurdle rates through the eyes of the capital providers – a cost of equity, capturing what equity investor believers expect to make on other equity investments of equivalent risk, and a cost of debt, looking at what lenders can earn on lending to others with similar default risk:
That is what all risk and return models try to do, albeit with different degrees of fidelity to the principle. In fact, my use of an implied equity risk premium in the estimation of the cost of equity is designed to advance this cause, since it is model-agnostic and reflects what investors are pricing stocks to earn, on an annual basis. Thus, when you use the beta in the capital asset pricing model to derive the cost of equity, you should be computing the return you can earn elsewhere in the market on other investments with the same beta, making the cost of equity the hurdle rate for equity investments in a project or company. The cost of capital, which incorporate the cost of borrowing into its construct, is also a hurdle rate, albeit to both debt and equity providers:
As to the question of which of these hurdle rates you should use as a business, the answer lies in consistence. If you are looking at equity returns (return on equity or an internal rate of return based on equity cash flows alone), you should be measuring up against just the cost of equity. Alternatively, with returns on invested capital or an internal rate of return based upon cashflows to the business (pre-debt), it is the cost of capital that comes into play.
I compute the costs of equity and capital for all 48,156 firms in my sample, and in doing so, and in the interests of consistency and ease, I make some simplifying assumptions:
Once I have the costs of equity and capital for each firm, I compute industry averages, both for global firms, and by region (US, Japan, Europe, Emerging Markets, with India and China as sub-categories). You can find the links to the data at the end of this post, but there is another perspective that you can bring to the cost of capital discussion, based upon where a company falls in the company life cycle:
Intuitively, you would expect more uncertainty about business prospects with younger firms, than older ones, especially on the estimation front. That said, it is an open question of whether this uncertainty will translate into higher costs of equity and capital, since it depends on who the marginal investors in these firms are, and whether the risk is diversifiable (and not affect cost of equity) or non-diversifiable. To answer these questions, I classify firms into ten deciles, based on their corporate age, and compute costs of capital:
As you can see, there is no discernible pattern on costs of equity, as you go across the age classes. However, as firms age, they do borrow more, partly because their capacity to generate earnings increase, and that does have some impact on the cost of capital, especially with the oldest firms in the market. In corporate finance and valuation, an undervalued skill is having perspective, a sense of what comprises typical, and what is a high or a low value. It is for that reason that I also compute a histogram of costs of capital of all publicly traded firms at the start of 2026:
This table is one on my most-used, for many reasons. First, when doing my own valuations, especially for young firms or for firms where the cost of capital is in flux, it gives me the input to us. Thus, if I am valuing a small, AI firm that has just gone public and has global operations, in US dollars, I will start the valuation with a cost of capital of 11.66% and move that cost of capital over time towards 8.65%, as its gets larger and more established. Second, I do see (and must review or grade) other people’s valuations more than I do my own, and this table operates as a plausibility check; a valuation of a publicly traded US company that has a dollar cost of capital of 14% goes on my suspect list, since that is well above the 90th percentile for US firms. Third, the table operates as a reminder that any analysts where the bulk of the time is spent estimating and finessing the cost of capital is time ill-spent, since the 80% of all US (global) companies have costs of capital between 5.26% (6.28%) and 9.88% (11.66%).
For those working in different currencies, the inflation differential approach that I described and used in the last post can be used to convert the entire table. Thus, if you use the expected inflation rates of 2.24% and 4.00% for the United States and India, from the IMF forecasts, you can 1.76% to each of the numbers to each dollar cost of capital that you see in the table or as an industry average.
Conclusion
To run a business or invest in one, you need hurdle rates, and that is what costs of equi6y and debt measure. While models and equations may be how you get these numbers, it is always worth going back to first principles, whenever you face questions on what to do. Thus, recognizing that the cost of capital is an opportunity cost, i.e., the rate of return you can earn elsewhere in the market, on investments of equivalent risk, should be a prompt to use betas that reflect the risk in investments, rather than the entities making the investment, and updated costs of borrowing for the cost of debt. As we enter 2026, we are now in our fourth year with US dollar riskfree rates around 4%, and companies and investors seem to have become acclimatized to the resulting costs of capital, and the shock of seeing dollar riskfree rates surge in 2022, pushing up costs of capital across the board seem to have faded.
In the context of valuing companies, and sharing those valuations, I do get suggestions from readers on companies that I should value next. While I don't have the time or the bandwidth to value all of the suggested companies, a reader from Iceland, a couple of weeks ago, made a suggestion on a company to value that I found intriguing. He suggested Blue Lagoon, a well-regarded Icelandic Spa with a history of profitability, that was finding its existence under threat, as a result of volcanic activity in Southwest Iceland. In another story that made the rounds in recent weeks, 23andMe, a genetics testing company that offers its customers genetic and health information, based upon saliva sample, found itself facing the brink, after a hacker claimed to have hacked the site and accessed the genetic information of millions of its customers. Stepping back a bit, one claim that climate change advocates have made not just about fossil fuel companies, but about all businesses, is that investors are underestimating the effects that climate change will have on economic systems and on value. These are three very different stories, but what they share in common is a fear, imminent or expected, of a catastrophic event that may put a company's business at risk.
Deconstructing Risk
While we may use statistical measures like volatility or correlation to measure risk in practice, risk is not a statistical abstraction. Its impact is not just financial, but emotional and physical, and it predates markets. The risks that our ancestors faced, in the early stages of humanity, were physical, coming from natural disasters and predators, and physical risks remained the dominant form of risk that humans were exposed to, almost until the Middle Ages. In fact, the separation of risk into physical and financial risk took form just a few hundred years ago, when trade between Europe and Asia required ships to survive storms, disease and pirates to make it to their destinations; shipowners, ensconced in London and Lisbon, bore the financial risk, but the sailors bore the physical risk. It is no coincidence that the insurance business, as we know it, traces its history back to those days as well.
I have no particular insights to offer on physical risk, other than to note that while taking on physical risks for some has become a leisure activity, I have no desire to climb Mount Everest or jump out of an aircraft. Much of the risk that I think about is related to risks that businesses face, how that risk affects their decision-making and how much it affects their value. If you start enumerating every risk a business is exposed to, you will find yourself being overwhelmed by that list, and it is for that reason that I categorize risk into the groupings that I described in an earlier post on risk. I want to focus in this post on the third distinction I drew on risk, where I grouped risk into discrete risk and continuous risk, with the later affecting businesses all the time and the former showing up infrequently, but often having much larger impact. Another, albeit closely related, distinction is between incremental risk, i.e., risk that can change earnings, growth, and thus value, by material amounts, and catastrophic risk, which is risk that can put a company's survival at risk, or alter its trajectory dramatically.
There are a multitude of factors that can give rise to catastrophic risk, and it is worth highlighting them, and examining the variations that you will observe across different catastrophic risk. Put simply, a volcanic eruption, a global pandemic, a hack of a company's database and the death of a key CEO are all catastrophic events, but they differ on three dimensions:
Source: I started this post with a mention of a volcano eruption in Iceland put an Icelandic business at risk, and natural disasters can still be a major factor determining the success or failure of businesses. It is true that there are insurance products available to protect against some of these risks, at least in some parts of the world, and that may allow companies in Florida (California) to live through the risks from hurricanes (earthquakes), albeit at a cost. Human beings add to nature's catastrophes with wars and terrorism wreaking havoc not just on human lives, but also on businesses that are in their crosshairs. As I noted in my post on country risk, it is difficult, and sometimes impossible, to build and preserve a business, when you operate in a part of the world where violence surrounds you. In some cases, a change in regulatory or tax law can put the business model for a company or many company at risk. I confess that the line between whether nature or man is to blame for some catastrophes is a gray one and to illustrate, consider the COVID crisis in 2020. Even if you believe you know the origins of COVID (a lab leak or a natural zoonotic spillover), it is undeniable that the choices made by governments and people exacerbated its consequences.
Locus of Damage: Some catastrophes created limited damage, perhaps isolated to a single business, but others can create damage that extends across a sector geographies or the entire economy. The reason that the volcano eruptions in Iceland are not creating market tremors is because the damage is likely to be isolated to the businesses, like Blue Lagoon, in the path of the lava, and more generally to Iceland, an astonishingly beautiful country, but one with a small economic footprint. An earthquake in California will affect a far bigger swath of companies, partly because the state is home to the fifth largest economy in the world, and the pandemic in 2020 caused an economic shutdown that had consequences across all business, and was catastrophic for the hospitality and travel businesses.
Likelihood: There is a third dimension on which catastrophic risks can vary, and that is in terms of likelihood of occurrence. Most catastrophic risks are low-probability events, but those low probabilities can become high likelihood events, with the passage of time. Going back to the stories that I started this post with, Iceland has always had volcanos, as have other parts of the world, and until recently, the likelihood that those volcanos would become active was low. In a similar vein, pandemics have always been with us, with a history of wreaking havoc, but in the last few decades, with the advance of medical science, we assumed that they would stay contained. In both cases, the probabilities shifted dramatically, and with it, the expected consequences.
Business owners can try to insulate themselves from catastrophic risk, but as we will see in the next sections those protections may not exist, and even if they do, they may not be complete. In fact, as the probabilities of catastrophic risk increase, it will become more and more difficult to protect yourself against the risk.
Dealing with catastrophic risk
It is undeniable that catastrophic risk affects the values of businesses, and their market pricing, and it is worth examining how it plays out in each domain. I will start this section with what, at least for me, I is familiar ground, and look at how to incorporate the presence of catastrophic risk, when valuing businesses and markets. I will close the section by looking at the equally interesting question of how markets price catastrophic risk, and why pricing and value can diverge (again).
Catastrophic Risk and Intrinsic Value
Much as we like to dress up intrinsic value with models and inputs, the truth is that intrinsic valuation at its core is built around a simple proposition: the value of an asset or business is the present value of the expected cash flows on it:
That equation gives rise to what I term the "It Proposition", which is that for "it" to have value, "it" has to affect either the expected cashflows or the risk of an asset or business. This simplistic proposition has served me well when looking at everything from the value of intangibles, as you can see in this post that I had on Birkenstock, to the emptiness at the heart of the claim that ESG is good for value, in this post. Using that framework to analyze catastrophic risk, in all of its forms, its effects can show in almost every input into intrinsic value:
Looking at this picture, your first reaction might be confusion, since the practical question you will face when you value Blue Lagoon, in the face of a volcanic eruption, and 23andMe, after a data hack, is which of the different paths to incorporating catastrophic risks into value you should adopt. To address this, I created a flowchart that looks at catastrophic risk on two dimensions, with the first built around whether you can buy insurance or protection that insulates the company against its impact and the other around whether it is risk that is specific to a business or one that can spill over and affect many businesses.
As you can see from this flowchart, your adjustments to intrinsic value, to reflect catastrophic risk will vary, depending upon the risk in question, whether it is insurable and whether it will affect one/few companies or many/all companies.
A. Insurable Risk: Some catastrophic risks can be insured against, and even if firms choose not to avail themselves of that insurance, the presence of the insurance option can ease the intrinsic valuation process.
Intrinsic Value Effect: If the catastrophic risk is fully insurable, as is sometimes the case, your intrinsic valuation became simpler, since all you have to do is bring in the insurance cost into your expenses, lowering income and cash flows, leave discount rates untouched, and let the valuation play out. Note that you can do this, even if the company does not actually buy the insurance, but you will need to find out the cost of that foregone insurance and incorporate it yourself.
Pluses: Simplicity and specificity, because all this approach needs is a line item in the income statement (which will either exist already, if the company is buying insurance, or can be estimated).
Minuses: You may not be able to insure against some risks, either because they are uncommon (and actuaries are unable to estimate probabilities well enough, to set premiums) or imminent (the likelihood of the event happening is so high, that the premiums become unaffordable). Thus, Blue Lagoon (the Icelandic spa that is threatened by a volcanic eruption) might have been able to buy insurance against volcanic eruption a few years ago, but will not be able to do so now, because the risk is imminent. Even when risks are insurable, there is a second potential problem. The insurance may pay off, in the event of the catastrophic event, but it may not offer complete protection. Thus, using Blue Lagoon again as an example, and assuming that the company had the foresight to buy insurance against volcanic eruptions a few years ago, all the insurance may do is rebuild the spa, but it will not compensate the company for lost revenues, as customers are scared away by the fear of volcanic eruptions. In short, while there are exceptions, much of insurance insures assets rather than cash flow streams.
Applications: When valuing businesses in developed markets, we tend to assume that these businesses have insured themselves against most catastrophic risks and ignore them in valuation consequently. Thus, you see many small Florida-based resorts valued, with no consideration given to hurricanes that they will be exposed to, because you assume that they are fully insured. In the spirit of the “trust, but verity” proposition, you should probably check if that is true, and then follow up by examining how complete the insurance coverage is.
2. Uninsurable Risk, Going-concern, Company-specific: When a catastrophic risk is uninsurable, the follow up questions may lead us to decide that while the risk will do substantial damage, the injured firms will continue in existence. In addition, if the risk affects only one or a few firms, rather than wide swathes of the market, there are intrinsic value implications.
Intrinsic Value Effect: If the catastrophic risk is not insurable, but the business will survive its occurrence even in a vastly diminished state, you should consider doing two going-concern valuations, one with the assumption that there is no catastrophe and one without, and then attaching a probability to the catastrophic event occurring.
Expected Value with Catastrophe = Value without Catastrophe (1 – Probability of Catastrophe) + Value with Catastrophe (Probability of Catastrophe)
In these intrinsic valuations, much of the change created by the catastrophe will be in the cash flows, with little or no change to costs of capital, at least in companies where investors are well diversified.
Pluses: By separating the catastrophic risk scenario from the more benign outcomes, you make the problem more tractable, since trying to adjust expected cash flows and discount rates for widely divergent outcomes is difficult to do.
Minuses: Estimating the probability of the catastrophe may require specific skills that you do not have, but consulting those who do have those skills can help, drawing on meteorologists for hurricane prediction and on seismologists for earthquakes. In addition, working through the effect on value of the business, if the catastrophe occurs, will stretch your estimation skills, but what options do you have?
Applications: This approach comes into play for many different catastrophic risks that businesses face, including the loss of a key employee, in a personal-service business, and I used it in my post on valuing key persons in businesses. You can also use it to assess the effect on value of a loss of a big contract for a small company, where that contract accounts for a significant portion of total revenues. It can also be used to value a company whose business models is built upon the presence or absence of a regulation or law, in which case a change in that regulation or law can change value.
3. Uninsurable Risk. Failure Risk, Company-specific: When a risk is uninsurable and its manifestation can cause a company to fail, it poses a challenge for intrinsic value, which is, at its core, designed to value going concerns. Attempts to increase the discount rate, to bring in catastrophic risk, or applying an arbitrary discount on value almost never work.
Intrinsic Value Effect: If the catastrophic risk is not insurable, and the business will not survive, if the risk unfolds, the approach parallels the previous one, with the difference being that that the failure value of the business, i.e, what you will generate in cash flows, if it fails, replaces the intrinsic valuation, with catastrophic risk built in:
Expected Value with Catastrophe = Value without Catastrophe (1 – Probability of Catastrophe) + Failure Value (Probability of Catastrophe)
The failure value will come from liquidation the assets, or what is left of them, after the catastrophe.
Pluses: As with the previous approach, separating the going concern from the failure values can help in the estimation process. Trying to estimate cash flows, growth rates and cost of capital for a company across both scenarios (going concern and failure) is difficult to do, and it is easy to double count risk or miscount it. It is fanciful to assume that you can leave the expected cash flows as is, and then adjust the cost of capital upwards to reflect the default risk, because discount rates are blunt instruments, designed more to capture going-concern risk than failure risk.
Minuses: As in the last approach, you still have to estimate a probability that a catastrophe will occur, and in addition, and there can be challenges in estimating the value of a business, if the company fails in the face of catastrophic risk.
Applications: This is the approach that I use to value highly levered., cyclical or commodity companies, that can deliver solid operating and equity values in periods where they operate as going concerns, but face distress or bankruptcy, in the face of a severe recession. And for a business like the Blue Lagoon, it may be the only pathway left to estimate the value, with the volcano active, and erupting, and it may very well be true that the failure value can be zero.
4 & 5 Uninsurable Risk. Going Concern or Failure, Market or Sector wide:If a risk can affect many or most firms, it does have a secondary impact on the returns investors expect to make, pushing up costs of capital.
Intrinsic Value Effect: The calculations for cashflows are identical to those done when the risks are company-specific, with cash flows estimated with and without the catastrophic risk, but since these risks are sector-wide or market-wide, there will also be an effect on discount rates. Investors will either see more relative risk (or beta) in these companies, if the risks affect an entire sector, or in equity risk premiums, if they are market-wide. Note that these higher discount rates apply in both scenarios.
Pluses: The risk that is being built into costs of equity is the risk that cannot be diversified away and there are pathways to estimating changes in relative risk or equity risk premiums.
Minuses: The conventional approaches to estimating betas, where you run a regression of past stock returns against the market, and equity risk premiums, where you trust in historical risk premiums and history, will not work at delivering the adjustments that you need to make.
Applications: My argument for using implied equity risk premiums is that they are dynamic and forward-looking. Thus, during COVID, when the entire market was exposed to the economic effects of the pandemic, the implied ERP for the market jumped in the first six weeks of the pandemic, when the concerns about the after effects were greatest, and then subsided in the months after, as the fear waned:
In a different vein, one reason that I compute betas by industry grouping, and update them every year, is in the hope that risks that cut across a sector show up as changes in the industry averages. In 2009, for instance, when banks were faced with significant regulatory changes brought about in response to the 2008 crisis, the average beta for banks jumped from 0.71 at the end of 2007 to 0.85 two years later.
Catastrophic Risk and Pricing The intrinsic value approach assumes that we, as business owners and investors, look at catastrophic risk rationally, and make our assessments based upon how it will play out in cashflows, growth and risk. In truth, is worth remembering key insights from psychology, on how we, as human beings, deal with threats (financial and physical) that we view as existential.
The first response is denial, an unwillingness to think about catastrophic risks. As someone who lives in a home close to one of California's big earthquake faults, and two blocks from the Pacific Ocean, I can attest to this response, and offer the defense that in its absence, I would wither away from anxiety and fear.
The second is panic, when the catastrophic risk becomes imminent, where the response is to flee, leaving much of what you have behind.
When looking at how the market prices in the expectation of a catstrophe occurring and its consequences, both these human emotions play out, as the overpricing of businesses that face catastrophic risk, when it is low probability and distant, and the underpricing of these same businesses when catastrophic risk looms large.
To see this process at work, consider again how the market initially reacted to the COVID crisis in terms of repricing companies that were at the heart of the crisis. Between February 14, 2020 and March 23, 2020, when fear peaked, the sectors most exposed to the pandemic (hospitality, airlines) saw a decimation in their market prices, during that period:
With catastrophic risk that are company-specific, you see the same phenomenon play out. The market capitalization of many young pharmaceutical company have been wiped out by the failure of blockbuster drug, in trials. PG&E, the utility company that provides power to large portions of California saw its stock price halved after wildfires swept through California, and investors worried about the culpability of the company in starting them.
The most fascinating twist on how markets deal with risks that are existential is their pricing of fossil fuel companies over the last two decades, as concerns about climate change have taken center stage, with fossil fuels becoming the arch villain. The expectation that many impact investors had, at least early in this game, was that relentless pressure from regulators and backlash from consumers and investors would reduce the demand for oil, reducing the profitability and expected lives of fossil fuel companies. To examine whether markets reflect this view, I looked at the pricing of fossil fuel stocks in the aggregate, starting in 2000 and going through 2023:
In the graph to the left, I chart out the total market value for all fossil fuel companies, and note a not unsurprising link to oil prices. In fact, the one surprise is that fossil fuel stocks did not see surges in market capitalization between 2011 and 2014, even as oil prices surged. While fossil fuel pricing multiples have gone up and down, I have computed the average on both in the 2000-2010 period and again in the 2011-2023 period. If the latter period is the one of enlightenment, at least on climate change, with warnings of climate change accompanied by trillions of dollars invested in combating it, it is striking how little impact it has had on how markets, and investors in the aggregate, view fossil fuel companies. In fact, there is evidence that the business pressure on fossil fuel companies has become less over time, with fossil fuel stocks rebounding in the last three years, and fossil fuel companies increasing investments and acquisitions in the fossil fuel space.
Impact investors would point to this as evidence of the market being in denial, and they may be right, but market participants may point back at impact investing, and argue that the markets may be reflecting an unpleasant reality which is that despite all of the talk of climate change being an existential problem, we are just as dependent on fossil fuels today, as we were a decade or two decades ago:
Don’t get me wrong! It is possible, perhaps even likely, that investors are not pricing in climate change not just in fossil fuel stocks, and that there is pain awaiting them down the road. It is also possible that at least in this case, that the market's assessment that doomsday is not imminent and that humanity will survive climate change, as it has other existential crises in the past.
Mr. Market versus Mad Max Thunderdome
The question posed about fossil fuel investors and whether they are pricing in the risks of gclimated change can be generalized to a whole host of other questions about investor behavior. Should buyers be paying hundreds of millions of dollars for a Manhattan office building, when all of New York may be underwater in a few decades? Lest I be accused of pointing fingers, what will happen to the value of my house that is currently two blocks from the beach, given the prediction of rising oceans. The painful truth is that if doomsday events (nuclear war, mega asteroid hitting the earth, the earth getting too hot for human existence) manifest, it is survival that becomes front and center, not how much money you have in your portfolio. Thus, ignoring Armageddon scenarios when valuing businesses and assets may be completely rational, and taking investors to task for not pricing assets correctly will do little to alter their trajectory! There is a lesson here for policy makers and advocates, which is that preaching that the planet is headed for the apocalypse, even if you believe it is true, will induce behavior that will make it more likely to happen, not less.
On a different note, you probably know that I am deeply skeptical about sustainability, at least as preached from the Harvard Business School pulpit. It remains ill-defined, morphing into whatever its proponents want it to mean. The catastrophic risk discussion presents perhaps a version of sustainability that is defensible. To the extent that all businesses are exposed to catastrophic risks, some company-level and some having broader effects, there are actions that businesses can take to, if not protect to themselves, at least cushion the impact of these risks. A personal-service business, headed by an aging key person, will be well served designing a succession plan for someone to step in when the key person leaves (by his or her choice or an act of God). No global company was ready for COVID in 2020, but some were able to adapt much faster than others because they were built to be adaptable. Embedded in this discussion are also the limits to sustainability, since the notion of sustaining a business at any cost is absurd. Building in adaptability and safeguards against catastrophic risk makes sense only if the costs of doing so are less than the potential benefits, a simple but powerful lesson that many sustainability advocates seem to ignore, when they make grandiose prescriptions for what businesses should and should not do to avoid the apocalypse.
In my last data updates for this year, I looked first at how equity markets rebounded in 2023, driven by a stronger-than-expected economy and inflation coming down, and then at how interest rates mirrored this rebound. In this post, I look at risk, a central theme in finance and investing, but one that is surprisingly misunderstood and misconstrued. In particular, there are wide variations in how risk is measured, and once measured, across companies and countries, and those variations can lead to differences in expected returns and hurdle rates, central to both corporate finance and investing judgments.
Risk Measures
There is almost no conversation or discussion that you can have about business or investing, where risk is not a part of that discussion. That said, and notwithstanding decades of research and debate on the topic, there are still wide differences in how risk is defined and measured.
What is risk?
I do believe that, in finance, we have significant advances in understanding what risk, I also think that as a discipline, finance has missed the mark on risk, in three ways. First, it has put too much emphasis on market-price driven measures of risk, where price volatility has become the default measure of risk, in spite of evidence indicating that a great deal of this volatility has nothing to do with fundamentals. Second, in our zeal to measure risk with numbers, we have lost sight of the reality that the effects of risk are as much on human psyche, as they are on economics. Third, by making investing a choice between good (higher returns) and bad (higher risk), a message is sent, perhaps unwittingly, that risk is something to be avoided or hedged. It is perhaps to counter all of these that I start my session on risk with the Chinese symbol for crisis:
Chinese symbol for crisis = 危機 = Danger + Opportunity
I have been taken to task for using this symbol by native Chinese speakers pointing out mistakes in my symbols (and I have corrected them multiple times in response), but thinking of risk as a combination of danger and opportunity is, in my view, a perfect pairing, and this perspective offers two benefits. First, by linking the two at the hip, it sends the clear and very important signal that you cannot have one (opportunity), without exposing yourself to the other (danger), and that understanding alone would immunize individuals from financial scams that offer the best of both worlds - high returns with no risk. Second, it removes the negativity associated to risk, and brings home the truth that you build a great business, not by avoiding danger (risk), but by seeking out the right risks (where you have an advantage), and getting more than your share of opportunities.
Breaking down risk
One reason that we have trouble wrapping our heads around risk is that it has so many sources, and our capacity to deal with varies, as a consequence. When assessing risk in a project or a company, I find it useful to make a list of every risk that I see in the investment, big and small, but I then classify these risks into buckets, based upon type, with very different ways of dealing with and incorporating that risk into investment analysis. The table below provides a breakdown of those buckets, with economic uncertainty contrasted with estimation uncertainty, micro risk separated from macro risks and discrete risks distinguished from continuous risks:
While risk breakdowns may seem like an abstraction, they do open the door to healthier practices in risk analysis, including the following:
Know when to stop: In a world, where data is plentiful and analytical tools are accessible, it is easy to put off a decision or a final analysis, with the excuse that you need to collect more information. That is understandable, but digger deeper into the data and doing more analysis will lead to better estimates, only if the risk that you are looking at is estimation risk. In my experience, much of the risk that we face when valuing companies or analyzing investments is economic uncertainty, impervious to more data and analysis. It is therefore healthy to know when to stop researching, accepting that your analysis is always a work-in-progress and that decisions have to be made in the face of uncertainty.
Don't overthink the discount rate: One of my contentions of discount rates is that they cannot become receptacles for all your hopes and fears. Analysts often try to bring company-specific components, i.e, micro uncertainties, into discount rates, and in the process, they end up incorporating risk that investors can eliminate, often at no cost. Separating the risks that do affect discount rates from the risks that do not, make the discount rate estimation simpler and more precise.
Use more probabilistic & statistical tools: The best tools for bringing in discrete risk are probabilistic, i.e., decision trees and scenario analysis, and using them in that context may open the door to other statistical tools, many of which are tailor-made for the problems that we face routinely in finance, and are underutilized.
Measuring risk
The financial thinking on risk, at least in its current form, had its origins in the 1950s, when Harry Markowitz uncovered the simple truth that the risk of an investment is not the risk of it standing alone, but the risk it adds to an investor's portfolio. He followed up by showing that holding diversified portfolios can deliver much higher returns, for given levels of risk, for all investors. That insight gave rise not only to modern portfolio theory, but it also laid the foundations for how we measure and deal with risk in finance. In fact, almost every risk and return model in finance is built on pairing two assumptions, the first being that the marginal investors in a company or business are diversified and the second being that investors convey their risk concerns through market prices:
By building on the assumptions that the investors pricing a business are diversified, and make prices capture that risk, modern portfolio theory has exposed itself to criticism from those who disagree with one or both of these assumptions. Thus, there are value investors, whose primary disagreement is on the use of pricing measures for risk, arguing that risk has to come from numbers that drive intrinsic value - earnings and cash flows. There are other investors who are at peace with price-based risk measures , but disagree with the "diversified marginal investor" assumption, and they are more intent on finding risk measures that incorporate total risk, not just risk that cannot be diversified away. I do believe that the critiques of both groups have legitimate basis, and while I don't feel as strongly as they do, I can offer modifications of risk measures to counter the critiques;
For investors who do not trust market prices, you can create risk analogs that look at accounting earnings or cash flows, and for those who believe that the diversified investor assumption is an overreach, you can adapt risk measures to capture all risk, not just market risk. In short, if you don't like betas and have disdain for modern portfolio theory, your choice should not be to abandon risk measurement all together, but to come up with an alternative risk measure that is more in sync with your view of the world.
Risk Differences across Companies
With that long lead-in on risk, we are positioned to take a look at how risk played out, at the company level, in 2024. Using the construct from the last section, I will start by looking at price-based risk measures and then move on to intrinsic risk measures in the second section.
a. Price-based Risk Measures
My data universe includes all publicly traded companies, and since they are publicly traded, computing price-based risk measures is straight forward. That said, it should be noted that liquidity varies widely across these companies, with some located in markets where trading is rare and others in markets, with huge trading volumes. With that caveat in mind, I computed three risk-based measures - a simplistic measure of range, where I look at the distance between the high and low prices, and scale it to the mid-point, the standard deviation in stock prices, a conventional measure of volatility and beta, a measure of that portion of a company's risk that is market-driven.
I use the data through the end of 2023 to compute all three measures for every company, and in my first breakdown, I look at these risk measures, by sector (globally):
Utilities are the safest or close to the safest , on all three price-based measures, but there are divergences on the other risk measures. Technology companies have the highest betas, but health care has the riskiest companies, on standard deviation and the price range measure. Looking across geographies, you can see the variations in price-based risk measures across the world:
There are two effects at play here. The first is liquidity, with markets with less trading and liquidity exhibiting low price-based risk scores across the board. The second is that some geographies have sector concentrations that affect their pricing risk scores; the preponderance of natural resource and mining companies in Australia and Canada, for instance, explain the high standard deviations in 2023.
Finally, I brought in my corporate life cycle perspective to the risk question, and looked at price-based risk measures by corporate age, with the youngest companies in the first decile and the oldest ones in the top decile (with a separate grouping for companies that don't have a founding year in the database):
On both the price range and standard deviation measures, not surprisingly, younger firms are riskier than older ones, but on the beta measure, there is no relationship. That may sound like a contradiction, but it does reflect the divide between measures of total risk (like the price range and standard deviation) and measures of just market risk (like the beta). Much of the risk in young companies is company-specific, and for those investors who hold concentrated portfolios of these companies, that risk will translate into higher risk-adjusted required returns, but for investors who hold broader and more diversified portfolios, younger companies are similar to older companies, in terms of risk.
b. Intrinsic Risk Measures
As you can see in the last section, price-based risk measures have their advantages, including being constantly updated, but they do have their limits, especially when liquidity is low or when market prices are not trustworthy. In this section, I will look at three measures of intrinsic risk - whether a company is making or losing money, with the latter being riskier, the variability in earnings, with less stable earnings translating to higher risk, and the debt load of companies, with more debt and debt charges conferring more risk on companies.
I begin by computing these intrinsic risk measures across sectors, with the coefficient of variation on both net income and operating income standing in for earnings variability; the coefficient of variation is computed by dividing the standard deviation in earnings over the last ten years, divided by the average earnings over those ten years.
Globally, health care has the highest percentage of money-losing companies and utilities have the lowest. In 2023, energy companies have the most volatile earnings (net income and operating income) and real estate companies have the most onerous debt loads. Looking at the intrinsic risk measures for sub-regions across the world, here is what I see:
Again, Australia and Canada have the highest percentage of money losing companies in the world and Japan has the lowest, Indian companies have the highest earnings variability and Chinese companies carry the largest debt load, in terms of debt as a multiple of EBITDA. In the last table, I look at the intrinsic risk measures, broken down by company age:
Not surprisingly, there are more money losing young companies than older ones, and these young companies also have more volatile earnings. On debt load, though, there is no discernible pattern in debt load across age deciles, though the youngest companies do have the lowest interest coverage ratios (and thus are exposed to the most danger, if earnings drop).
Risk Differences across Countries
In this final section, I will look risk differences across countries, both in terms of why risk varies across, as well as how these variations play out as equity risk premiums. There are many reasons why risk exposures vary across countries, but I have tried to capture them all in the picture below (which I have used before in my country risk posts and in my paper on country risk):
Put simply, there are four broad groups of risks that lead to divergent country risk exposures; political structure, which can cause public policy volatility, corruption, which operates as an unofficial tax on income, war and violence, which can create physical risks that have economic consequences and protections for legal and property rights, without which businesses quickly lose value.
While it is easy to understand why risk varies across countries, it is more difficult to measure that risk, and even more so, to convert those risk differences into risk premiums. Ratings agencies like Moody's and S&P provide a measure of the default risk in countries with sovereign ratings, and I build on those ratings to estimate country and equity risk premiums, by country. The figure below summarizes the numbers used to compute these numbers at the start of 2024:
The starting point for estimating equity risk premiums, for all of the countries, is the implied equity risk premium of 4.60% that I computed at the start of 2024, and talked about in my second data post this year. All countries that are rated Aaa (Moody's) are assigned 4.60% as equity risk premiums, but for lower-rated countries, there is an additional premium, reflecting their higher risk:
You will notice that there are countries, like North Korea, Russia and Syria, that are unrated but still have equity risk premiums, and for these countries, the equity risk premiums estimate is based upon a country risk score from Political Risk Services. If you are interested, you can review the process that I use in far more detail in this paper that I update every year on country risk.
Risk and Investing
The discussion in the last few posts, starting with equity risk premium in my second data update, and interest rates and default spreads in my third data update, leading into risk measures that differrentiate across companies and countries in this one, all lead in to a final computation of the costs of equity and capital for companies. That may sound like a corporate finance abstraction, but the cost of capital is a pivotal number that can alter whether and how much companies invest, as well as in what they invest, how they fund their investments (debt or equity) and how much they return to owners as dividends or buybacks. For investors looking at these companies, it becomes a number that they use to estimate intrinsic values and make judgments on whether to buy or sell stocks:
The multiple uses for the cost of capital are what led me to label it "the Swiss Army knife of finance" and if you are interested, you can keep a get a deeper assessment by reading this paper.
Using the updated numbers for the risk free rate (in US dollars), the equity risk premiums (for the US and the rest of the world) and the default spreads for debt in different ratings classes, I computed the cost of capital for the 47,698 companies in my data universe, at the start of 2024. In the graph below, I provide a distribution of corporate costs of capital, for US and global companies, in US dollars:
If your frame of reference is another currency, be it the Euro or the Indian rupee, adding the differential inflation to these numbers will give you the ranges in that currency. At the start of 2024, the median cost of capital, in US dollars, is 7.9% (8.7%) for a US (global) company, lower than the 9.6 (10.6%) at the start of 2023, for US (global) stocks, entirely because of declines in the price of risk (equity risk premiums and default spreads), but the 2024 costs of capital are higher than the historic lows of 5.8% (6.3%) for US (Global) stocks at the start of 2022. In short, if you are a company or an investor who works with fixed hurdle rates over time, you may be using a rationale that you are just normalizing, but you have about as much chance of being right as a broken clock.
What's coming?
Since this post has been about risk, it is a given that things will change over the course of the year. If your question is how you prepare for that change, one answer is to be dynamic and adaptable, not only reworking hurdle rates as you go through the year, but also building in escape hatches and reversibility even into long term decisions. In case things don't go the way you expected them to, and you feel the urge to complain about uncertainty, I urge you to revisit the Chinese symbol for risk. We live in dangerous times, but embedded in those dangers are opportunities. If you can gain an edge on the rest of the market in assessing and dealing with some of these dangers, you have a pathway to success. I am not suggesting that this is easy to do, or that success is guaranteed, but if investment is a game of odds, this can help tilt them in your favor.