Quantification

The FAIR Model Explained for Risk and Security Leaders

XR
Xcigence Research
Cyber Risk Intelligence Team
9 min read

FAIR — Factor Analysis of Information Risk — is the closest thing cybersecurity has to a standard grammar for risk. Standardized by The Open Group, it does one deceptively powerful thing: it breaks the word "risk" into parts small enough that reasonable people can estimate them and argue productively about the estimates.

What FAIR is (and is not)

FAIR is a taxonomy and analysis method, published by The Open Group as the Open FAIR Risk Taxonomy and Risk Analysis standards.[1] It is not a tool, not a control framework and not a data set. It will not tell you your risk; it tells you what your risk is made of and how to combine the pieces without fooling yourself.

Crucially, FAIR treats risk as the probable frequency and probable magnitude of future loss. That definition rules out several things security teams commonly call risks: a vulnerability is not a risk, a missing control is not a risk, and a threat actor is not a risk. Each is a factor that influences risk.[2] This discipline alone eliminates most of the confusion in a typical risk register.

The top-level equation

Everything in FAIR descends from one relationship:

The FAIR equation
Risk = Loss Event Frequency × Loss Magnitude
How often a loss event occurs, multiplied by how much it costs when it does — both expressed as distributions rather than single numbers.

The model then decomposes each side into estimable sub-factors. The decomposition is the value: it moves the analyst from a question nobody can answer ("what is our ransomware risk?") to questions people genuinely can ("how many credible ransomware attempts reach us in a year?", "how long would recovery actually take?").

Decomposing frequency

Loss Event Frequency (LEF) is the product of how often an adversary acts against you and how often that action succeeds.

Threat Event Frequency (TEF)

How often threat actors attempt the scenario. It further divides into contact frequency (how often the actor encounters the asset — heavily influenced by internet exposure) and probability of action (whether, having found it, they choose to act, driven by perceived value and effort).

Vulnerability (Susceptibility)

In FAIR, "vulnerability" is not a CVE. It is the probability that a threat event becomes a loss event — the outcome of the contest between threat capability and resistance strength (your control effectiveness). A weakness that no reachable actor can exploit contributes almost nothing to risk; a moderate weakness reachable from the internet and present in CISA's known-exploited catalogue[4] contributes a great deal.

Decomposing magnitude

Loss Magnitude splits into primary losses — borne directly and immediately — and secondary losses, which arise from how other parties react.

Loss formTypeCyber example
ProductivityPrimaryOutput lost while systems are down
ResponsePrimaryForensics, IR retainer, internal labour diversion
ReplacementPrimaryRebuilding systems, replacing hardware
Fines & judgementsSecondaryRegulatory penalties, class action settlements
Competitive advantageSecondaryStolen IP, lost pricing or design advantage
ReputationSecondaryChurn, longer sales cycles, financing costs
FAIR loss forms, with typical cyber examples.

The primary/secondary split matters because secondary losses depend on stakeholder reaction, which varies enormously by sector and data type. Costing these forms individually is the subject of how to calculate the financial impact of a cyber breach.

The taxonomy at a glance

LevelFactorQuestion it answers
1RiskWhat is our probable future loss?
2Loss Event FrequencyHow often will a loss actually occur?
2Loss MagnitudeHow much will it cost when it does?
3Threat Event FrequencyHow often is the scenario attempted?
3VulnerabilityWhat share of attempts succeed?
4Contact Frequency / Probability of ActionHow exposed and how attractive are we?
4Threat Capability vs Resistance StrengthWho wins the contest at the control?
Open FAIR factor hierarchy, simplified.

Running an analysis

  • 1. Scope the scenario — name the asset, the threat actor and the effect. Vague scope is the leading cause of unusable results.
  • 2. Estimate each factor as a range — use minimum, most likely and maximum with a confidence level — calibrated estimation, not single guesses.
  • 3. Simulate — run Monte Carlo sampling across the ranges to produce a loss distribution rather than a point answer.
  • 4. Interrogate the drivers — sensitivity analysis shows which factor the answer actually depends on. That factor is where remediation money belongs.
  • 5. Report ranges and assumptions — the assumptions are part of the finding. A FAIR result without its assumptions is not reviewable.

Limits and criticisms

  • Effort — A rigorous FAIR analysis takes real analyst time. It does not scale to hundreds of vendors without automated inputs.
  • Estimate quality — FAIR structures judgement; it does not replace it. Poorly calibrated estimators produce confident nonsense, well-formatted.
  • Data scarcity — Frequency data for rare, high-impact scenarios is genuinely thin, and public breach reporting is incomplete.[5]
  • Scenario blindness — The model quantifies the scenarios you thought of. Novel attack paths sit outside the analysis entirely.

These are limits, not disqualifications. NIST's ERM guidance still treats structured quantitative analysis as the direction of travel for cyber risk governance, precisely because the qualitative alternative cannot be aggregated or compared.[3]

Feeding FAIR with measured evidence

FAIR's weakest link is almost always the frequency side, because it is the factor teams have least direct evidence for — and the one most often set by consensus in a workshop. This is where continuous external measurement changes the economics: contact frequency and susceptibility are substantially observable from outside, and a standardized posture score computed from that evidence becomes a defensible anchor for threat event frequency and vulnerability rather than an opinion.

That is the design intent of the Xcigence engine: the same patented, evidence-based measurement that produces a 300–850 score[6] supplies the frequency inputs a FAIR-style analysis needs, and keeps updating them as exposure changes. See what a cybersecurity risk score is and our published methodology for how that evidence is gathered and weighted.

Part of our guide to
Cyber Risk Quantification

Translating measured likelihood into financial exposure in dollars.

References

  1. [1]The Open Group. Open FAIR — Risk Taxonomy (O-RT) and Risk Analysis (O-RA) standards
  2. [2]FAIR Institute. What is FAIR? Factor Analysis of Information Risk
  3. [3]NIST. NISTIR 8286 — Integrating Cybersecurity and Enterprise Risk Management
  4. [4]CISA. Known Exploited Vulnerabilities (KEV) Catalog
  5. [5]Verizon. Data Breach Investigations Report (DBIR)
  6. [6]USPTO. Patent application US 16/822,691 — Global Dossier record

See your own cyber risk score

Xcigence computes a standardized 300–850 cyber risk score for your organization and every vendor in your ecosystem — no agents, no questionnaires.

We use cookies to improve your experience on our site, analyze site traffic, and assist in our marketing efforts. By clicking "Accept All", you consent to our use of cookies in accordance with GDPR, CCPA, and ISO27001 privacy standards.