FAIR Risk Assessment: A Simple Way to Explain Cyber Risk in Money

FAIR · Cyber Risk Quantification · Risk Assessment · GRC · Board Reporting · Loss Event Frequency · Loss Magnitude · Cybersecurity Risk

Most cyber risk reports use words like "high", "medium", and "low". These words are easy to understand, but they are also vague. One person's "high risk" may be another person's "medium risk". This makes it hard for executives to compare cyber risk with other business risks.

FAIR, which stands for Factor Analysis of Information Risk, helps solve this problem. Instead of only saying that a risk is high or low, FAIR helps estimate how often a bad event may happen and how much money the organisation may lose if it happens.

In simple terms:

Cyber risk = how often a loss event may happen x how much it may cost

FAIR usually looks at two big questions:

1. Loss Event Frequency: How many times could this happen in a year?

2.Loss Magnitude: If it happens, how much money could we lose?

This does not mean we can predict the future perfectly. We cannot. FAIR is useful because it makes assumptions visible. It helps the business discuss risk with numbers, ranges, and evidence instead of opinions.

Example: Phishing Attack on Finance Team

Imagine a company wants to assess this risk:

A finance employee clicks a phishing email and an attacker uses the account to send fake payment instructions.

The asset at risk is the finance email account and the payment process. The threat actor is a cybercriminal. The loss event is unauthorised use of the account leading to financial fraud, investigation cost, and possible business disruption.

Step 1: Estimate How Often It Could Happen

The team reviews past incidents, phishing simulation results, email security alerts, and industry data.

They estimate:

Low estimate: once every 5 years

Most likely: once every 2 years

High estimate: once per year

Converted into annual frequency:

Low: 0.2 times per year

Most likely: 0.5 times per year

High: 1 time per year

This is the Loss Event Frequency.

Step 2: Estimate The Cost If It Happens

Next, the team estimates the likely loss.

Possible costs include:

- Internal investigation time

- External incident response support

- Payment recovery effort

- Lost productivity

- Legal advice

- Customer or supplier communication

- Possible unrecovered fraud amount

- Control improvements after the incident

The team estimates:

Low loss: EUR 20,000

Most likely loss: EUR 80,000

High loss: EUR 250,000

This is the Loss Magnitude.

Step 3: Calculate The Annual Risk

A simple calculation uses the most likely frequency and most likely loss:

0.5 events per year x EUR 80,000 = EUR 40,000 expected annual loss

This means the company may expect this risk to cost around EUR 40,000 per year on average. In a bad year, the loss could be much higher.

Step 4: Compare Treatment Options

Now the company can compare controls.

Option A: Improve phishing training and simulations 

Cost: EUR 10,000 per year 

Expected effect: reduce frequency from 0.5 to 0.35 events per year

New estimated risk:

0.35 x EUR 80,000 = EUR 28,000

Risk reduction:

EUR 40,000 - EUR 28,000 = EUR 12,000 per year

Option B: Add stronger payment approval controls 

Cost: EUR 18,000 per year 

Expected effect: reduce loss from EUR 80,000 to EUR 30,000

New estimated risk:

0.5 x EUR 30,000 = EUR 15,000

Risk reduction:

EUR 40,000 - EUR 15,000 = EUR 25,000 per year

In this example, Option B gives more risk reduction, even though it costs more. This is the value of FAIR: it helps leaders see which control gives better business value.

Why FAIR Helps GRC Teams

FAIR makes cyber risk easier to discuss with the board. It connects security issues to money, business impact, and decision-making. It also helps teams explain why one control should be prioritised over another.

A good FAIR assessment does not need perfect data. It needs clear assumptions, honest ranges, and regular review. Over time, the estimates improve as the organisation collects better evidence from incidents, controls, audits, vendors, and security tools.

The goal is not to make cyber risk look exact. The goal is to make it understandable, comparable, and actionable.

Suggested sources:

https://www.opengroup.org/open-fair

https://www.opengroup.org/forum/security/riskanalysis

Back to all articles

Features · Integrations · Pricing · Frameworks · About · Blog