Deep diveRisk & Resilience
Cyber risk quantification with FAIR: scenarios, estimates and loss curves
Cyber risk quantification with FAIR expresses a specific loss scenario as two ranges, how often a loss event is likely to happen and how much it would cost when it does, then simulates those ranges to show the probability of losing more than a given amount in a year. This page explains the Open FAIR vocabulary, how to scope and estimate a scenario honestly, how to read the output, and how to use it to compare controls.
On this page
- Why heat maps and vulnerability counts cannot rank security spend
- The FAIR vocabulary to agree before the first workshop
- How FAIR factors combine into annualized loss exposure
- Scoping a risk scenario the model can actually answer
- Four sources of FAIR estimates and when each can be trusted
- From calibrated ranges to a loss exceedance curve
- A hypothetical ransomware scenario on a core order system
- Comparing controls by expected loss reduction
- Where FAIR analyses lose credibility
- Taking the curve to the board, the risk committee and the insurer
- Questions and answers
- Sources
Why heat maps and vulnerability counts cannot rank security spend
A red, amber and green heat map tells a board that two risks are both high. It cannot say whether one is ten times larger than the other, whether a proposed control is worth its cost, or whether residual exposure sits inside appetite. Vulnerability counts have the opposite problem: precise about activity, silent about loss.
FAIR, the Factor Analysis of Information Risk, fills that gap. It is maintained by The Open Group as two standards, the Risk Taxonomy (O-RT) and the Risk Analysis (O-RA), which together form the Open FAIR body of knowledge1. The taxonomy defines what risk is made of; the analysis standard describes how to estimate and combine those parts. The result is a range of annual loss in money, which finance teams can put next to other investments.
ColdAI's risk practice lists cyber risk quantification among its core services, and the hub's insight on speaking the language of the board argues for exactly this shift2. This page is the method behind that argument.
The FAIR vocabulary to agree before the first workshop
- Loss event frequency
- How often, within a year, a threat actor is expected to cause a loss to the asset in scope. It combines threat event frequency and vulnerability.
- Threat event frequency
- How often a threat actor acts against the asset in a way that could cause loss, whether or not the attempt succeeds.
- Vulnerability (susceptibility)
- The probability that a threat event becomes a loss event. In FAIR this is a probability, not a count of software flaws.
- Loss magnitude
- The money lost when a loss event happens, split into primary and secondary loss.
- Primary loss
- Loss borne directly by the organization: lost productivity, response costs and replacement of assets.
- Secondary loss
- Loss that arrives through the reactions of others, such as regulators, customers, litigants or the market. It has its own frequency, because not every event triggers it.
- Calibrated estimate
- A range given by someone trained to state ranges that contain the true value at their stated confidence, usually expressed as minimum, most likely and maximum.
- Loss exceedance curve
- A chart of simulated annual loss showing, for each amount, the probability of losing at least that much in a year.
How FAIR factors combine into annualized loss exposure
- Threat event frequency
How often the threat acts against the asset in a year.
- Vulnerability
Probability that an attempt becomes a loss event.
- Loss event frequency
Expected loss events per year, drawn from the two factors before it.
- Primary loss
Productivity, response and replacement costs borne directly.
- Secondary loss
Fines, claims, customer churn and reputation effects, with their own frequency.
- Loss magnitude
Money lost per event, primary plus secondary.
- Annualized loss exposure
Simulated distribution of yearly loss, read as a loss exceedance curve.
Scoping a risk scenario the model can actually answer
Every FAIR analysis is about one scenario, and a scenario needs three parts: the asset at risk, the threat acting on it and the effect that causes loss, usually a loss of confidentiality, integrity or availability. "Ransomware" is not a scenario. "An external criminal group encrypts the order management system and its backups, halting order intake" is.
Scope narrowly enough that one group of experts can estimate it, and broadly enough that it matters to a decision. If estimators keep saying "it depends", the scenario is hiding several scenarios with different frequencies or losses; split it, and record what is out of scope so nobody double-counts a loss.
Four sources of FAIR estimates and when each can be trusted
No organization has perfect loss data. Good analyses blend sources and record which one drove each range.
| Source | Best for | Main weakness | How to use it |
|---|---|---|---|
| Internal incident and near-miss records | Threat event frequency and response costs | Sparse for rare, severe events | Count attempts as well as losses, and include near misses |
| Control and telemetry data | Vulnerability: how often attacks get past controls | Measures what is logged, not what is missed | Pair with red team or test results where available |
| Calibrated expert elicitation | Loss magnitude and rare-event frequency | Anchoring and overconfidence without training | Train estimators first; elicit minimum, maximum, then most likely |
| External loss data and insurer input | Sense-checking secondary loss ranges | Rarely matches your size, sector or controls | Treat as a reference point, never as a direct input |
From calibrated ranges to a loss exceedance curve
State each input as a range
For every factor, record a minimum, most likely and maximum, with the source and the estimator's confidence.
Choose a distribution
Most FAIR tools fit a skewed distribution such as a beta-PERT to the three points, which allows a long tail towards the maximum without making it likely.
Simulate many years
A Monte Carlo engine draws a frequency and a loss for each simulated year, many thousands of times, and adds up the annual totals.
Read the curve
Plot the probability of exceeding each loss amount. Report the median year and a tail point that matches the board's tolerance, not one average.
Test sensitivity
Vary one input at a time to see which range moves the result most. That input is where better data or a control is worth paying for.
A hypothetical ransomware scenario on a core order system
Comparing controls by expected loss reduction
The useful question is how far a control moves the curve for its cost. Run the scenario with and without the proposed control and compare the median and tail. A control that reduces frequency, such as phishing-resistant authentication, shifts the curve left; one that limits magnitude, such as faster restoration, flattens the tail.
FAIR-CAM, the FAIR Controls Analytics Model, extends the standard to describe how controls affect loss event frequency and magnitude, including controls that work indirectly by improving visibility or decision-making3. Use it, or a simpler documented logic, to stop teams from claiming that every control reduces every factor.
Where FAIR analyses lose credibility
False precision
Early signalResults quoted to the nearest dollar or with a single expected value.
MitigationReport ranges and percentiles, round generously and show the inputs that drive the tail.
Scenarios scoped to fit the data
Early signalEasy-to-measure scenarios dominate while the worst plausible events go unanalyzed.
MitigationPick scenarios from the decisions leadership faces, then find the best available evidence.
Secondary loss ignored or always assumed
Early signalEvery event carries maximum fines, or none does.
MitigationGive secondary loss its own frequency, tied to what actually triggers regulator or customer action.
Taking the curve to the board, the risk committee and the insurer
Boards rarely need the model. They need the scenarios that matter, where each sits against risk appetite, and what each funding option would change. One slide with current and post-investment curves for the top scenarios says more than a page of controls metrics. Our questions boards can put to management on AI and risk shows how to frame that challenge.
The same output informs insurance: comparing the tail of the curve with policy limits and retentions shows whether cover sits where the losses are, as one input alongside broker advice. When security spend competes with other uses of capital, expected loss reduction per unit of spend can enter the same business case discipline as any other investment.
Questions and answers
What data do we need before starting a FAIR analysis?
Less than most teams expect. You need a clearly scoped scenario, people who understand the asset, the threat and the business process, and whatever incident, telemetry and cost records already exist. Calibrated expert ranges can fill gaps, provided each range records its source and confidence. The analysis itself shows where better data would change the answer, which is a better guide to data collection than trying to gather everything first.
How long does a single FAIR scenario analysis take?
It depends on how well the scenario is scoped and how available the estimators are. A first analysis takes longer because the team is learning the vocabulary, training estimators and agreeing loss categories with finance. Later scenarios reuse that groundwork, including standard loss tables for productivity and response costs, so each new scenario mainly needs scoping workshops and a review of the results.
Is FAIR better than qualitative risk scoring?
They answer different questions. Qualitative scoring is quick for triaging a long list of risks and works when the only decision is which items deserve attention. FAIR is worth the extra effort when money is at stake: choosing between controls, sizing insurance or explaining residual exposure against appetite. Many organizations use both, scoring broadly and quantifying the handful of scenarios that drive major decisions.
Sources
- Open FAIR certification: Risk Taxonomy (O-RT) and Risk Analysis (O-RA) standards — The Open Group · checked 10 October 2026
- Risk and Resilience capability: cyber risk quantification and board reporting — ColdAI
- FAIR Controls Analytics Model (FAIR-CAM) — FAIR Institute · checked 10 October 2026