The FAIR Model Explained for Risk and Security Leaders
FAIR — Factor Analysis of Information Risk — is the closest thing cybersecurity has to a standard grammar for risk. Standardized by The Open Group, it does one deceptively powerful thing: it breaks the word "risk" into parts small enough that reasonable people can estimate them and argue productively about the estimates.
What FAIR is (and is not)
FAIR is a taxonomy and analysis method, published by The Open Group as the Open FAIR Risk Taxonomy and Risk Analysis standards.[1] It is not a tool, not a control framework and not a data set. It will not tell you your risk; it tells you what your risk is made of and how to combine the pieces without fooling yourself.
Crucially, FAIR treats risk as the probable frequency and probable magnitude of future loss. That definition rules out several things security teams commonly call risks: a vulnerability is not a risk, a missing control is not a risk, and a threat actor is not a risk. Each is a factor that influences risk.[2] This discipline alone eliminates most of the confusion in a typical risk register.
The top-level equation
Everything in FAIR descends from one relationship:
How often a loss event occurs, multiplied by how much it costs when it does — both expressed as distributions rather than single numbers.
The model then decomposes each side into estimable sub-factors. The decomposition is the value: it moves the analyst from a question nobody can answer ("what is our ransomware risk?") to questions people genuinely can ("how many credible ransomware attempts reach us in a year?", "how long would recovery actually take?").
Decomposing frequency
Loss Event Frequency (LEF) is the product of how often an adversary acts against you and how often that action succeeds.
Threat Event Frequency (TEF)
How often threat actors attempt the scenario. It further divides into contact frequency (how often the actor encounters the asset — heavily influenced by internet exposure) and probability of action (whether, having found it, they choose to act, driven by perceived value and effort).
Vulnerability (Susceptibility)
In FAIR, "vulnerability" is not a CVE. It is the probability that a threat event becomes a loss event — the outcome of the contest between threat capability and resistance strength (your control effectiveness). A weakness that no reachable actor can exploit contributes almost nothing to risk; a moderate weakness reachable from the internet and present in CISA's known-exploited catalogue[4] contributes a great deal.
Decomposing magnitude
Loss Magnitude splits into primary losses — borne directly and immediately — and secondary losses, which arise from how other parties react.
| Loss form | Type | Cyber example |
|---|---|---|
| Productivity | Primary | Output lost while systems are down |
| Response | Primary | Forensics, IR retainer, internal labour diversion |
| Replacement | Primary | Rebuilding systems, replacing hardware |
| Fines & judgements | Secondary | Regulatory penalties, class action settlements |
| Competitive advantage | Secondary | Stolen IP, lost pricing or design advantage |
| Reputation | Secondary | Churn, longer sales cycles, financing costs |
The primary/secondary split matters because secondary losses depend on stakeholder reaction, which varies enormously by sector and data type. Costing these forms individually is the subject of how to calculate the financial impact of a cyber breach.
The taxonomy at a glance
| Level | Factor | Question it answers |
|---|---|---|
| 1 | Risk | What is our probable future loss? |
| 2 | Loss Event Frequency | How often will a loss actually occur? |
| 2 | Loss Magnitude | How much will it cost when it does? |
| 3 | Threat Event Frequency | How often is the scenario attempted? |
| 3 | Vulnerability | What share of attempts succeed? |
| 4 | Contact Frequency / Probability of Action | How exposed and how attractive are we? |
| 4 | Threat Capability vs Resistance Strength | Who wins the contest at the control? |
Running an analysis
- 1. Scope the scenario — name the asset, the threat actor and the effect. Vague scope is the leading cause of unusable results.
- 2. Estimate each factor as a range — use minimum, most likely and maximum with a confidence level — calibrated estimation, not single guesses.
- 3. Simulate — run Monte Carlo sampling across the ranges to produce a loss distribution rather than a point answer.
- 4. Interrogate the drivers — sensitivity analysis shows which factor the answer actually depends on. That factor is where remediation money belongs.
- 5. Report ranges and assumptions — the assumptions are part of the finding. A FAIR result without its assumptions is not reviewable.
Limits and criticisms
- Effort — A rigorous FAIR analysis takes real analyst time. It does not scale to hundreds of vendors without automated inputs.
- Estimate quality — FAIR structures judgement; it does not replace it. Poorly calibrated estimators produce confident nonsense, well-formatted.
- Data scarcity — Frequency data for rare, high-impact scenarios is genuinely thin, and public breach reporting is incomplete.[5]
- Scenario blindness — The model quantifies the scenarios you thought of. Novel attack paths sit outside the analysis entirely.
These are limits, not disqualifications. NIST's ERM guidance still treats structured quantitative analysis as the direction of travel for cyber risk governance, precisely because the qualitative alternative cannot be aggregated or compared.[3]
Feeding FAIR with measured evidence
FAIR's weakest link is almost always the frequency side, because it is the factor teams have least direct evidence for — and the one most often set by consensus in a workshop. This is where continuous external measurement changes the economics: contact frequency and susceptibility are substantially observable from outside, and a standardized posture score computed from that evidence becomes a defensible anchor for threat event frequency and vulnerability rather than an opinion.
That is the design intent of the Xcigence engine: the same patented, evidence-based measurement that produces a 300–850 score[6] supplies the frequency inputs a FAIR-style analysis needs, and keeps updating them as exposure changes. See what a cybersecurity risk score is and our published methodology for how that evidence is gathered and weighted.
Translating measured likelihood into financial exposure in dollars.
References
- [1]The Open Group. Open FAIR — Risk Taxonomy (O-RT) and Risk Analysis (O-RA) standards
- [2]FAIR Institute. What is FAIR? Factor Analysis of Information Risk
- [3]NIST. NISTIR 8286 — Integrating Cybersecurity and Enterprise Risk Management
- [4]CISA. Known Exploited Vulnerabilities (KEV) Catalog
- [5]Verizon. Data Breach Investigations Report (DBIR)
- [6]USPTO. Patent application US 16/822,691 — Global Dossier record
Continue reading
Cyber risk quantification expresses exposure in currency and probability instead of red-amber-green. Here is how it works and why boards now expect it.
A practical cost model: the seven loss categories that make up breach impact, how to source credible numbers for each, and where estimates go wrong.
A cybersecurity risk score turns observable security evidence into a standardized number decision-makers can compare, price, and act on. Here is what goes into one and what makes it defensible.
See your own cyber risk score
Xcigence computes a standardized 300–850 cyber risk score for your organization and every vendor in your ecosystem — no agents, no questionnaires.