FAIR Risk Assessment: A Simple Way to Explain Cyber Risk in Money
FAIR · Cyber Risk Quantification · Risk Assessment · GRC · Board Reporting · Loss Event Frequency · Loss Magnitude · Cybersecurity Risk
Most cyber risk reports use words like "high", "medium", and "low". These words are easy to understand, but they are also vague. One person's "high risk" may be another person's "medium risk". This makes it hard for executives to compare cyber risk with other business risks.
FAIR, which stands for Factor Analysis of Information Risk, helps solve this problem. Instead of only saying that a risk is high or low, FAIR helps estimate how often a bad event may happen and how much money the organisation may lose if it happens.
In simple terms:
Cyber risk = how often a loss event may happen x how much it may cost
FAIR usually looks at two big questions:
1. Loss Event Frequency: How many times could this happen in a year?
2.Loss Magnitude: If it happens, how much money could we lose?
This does not mean we can predict the future perfectly. We cannot. FAIR is useful because it makes assumptions visible. It helps the business discuss risk with numbers, ranges, and evidence instead of opinions.
Example: Phishing Attack on Finance Team
Imagine a company wants to assess this risk:
A finance employee clicks a phishing email and an attacker uses the account to send fake payment instructions.
The asset at risk is the finance email account and the payment process. The threat actor is a cybercriminal. The loss event is unauthorised use of the account leading to financial fraud, investigation cost, and possible business disruption.
Step 1: Estimate How Often It Could Happen
The team reviews past incidents, phishing simulation results, email security alerts, and industry data.
They estimate:
Low estimate: once every 5 years
Most likely: once every 2 years
High estimate: once per year
Converted into annual frequency:
Low: 0.2 times per year
Most likely: 0.5 times per year
High: 1 time per year
This is the Loss Event Frequency.
Step 2: Estimate The Cost If It Happens
Next, the team estimates the likely loss.
Possible costs include:
- Internal investigation time
- External incident response support
- Payment recovery effort
- Lost productivity
- Legal advice
- Customer or supplier communication
- Possible unrecovered fraud amount
- Control improvements after the incident
The team estimates:
Low loss: EUR 20,000
Most likely loss: EUR 80,000
High loss: EUR 250,000
This is the Loss Magnitude.
Step 3: Calculate The Annual Risk
A simple calculation uses the most likely frequency and most likely loss:
0.5 events per year x EUR 80,000 = EUR 40,000 expected annual loss
This means the company may expect this risk to cost around EUR 40,000 per year on average. In a bad year, the loss could be much higher.
Step 4: Compare Treatment Options
Now the company can compare controls.
Option A: Improve phishing training and simulations
Cost: EUR 10,000 per year
Expected effect: reduce frequency from 0.5 to 0.35 events per year
New estimated risk:
0.35 x EUR 80,000 = EUR 28,000
Risk reduction:
EUR 40,000 - EUR 28,000 = EUR 12,000 per year
Option B: Add stronger payment approval controls
Cost: EUR 18,000 per year
Expected effect: reduce loss from EUR 80,000 to EUR 30,000
New estimated risk:
0.5 x EUR 30,000 = EUR 15,000
Risk reduction:
EUR 40,000 - EUR 15,000 = EUR 25,000 per year
In this example, Option B gives more risk reduction, even though it costs more. This is the value of FAIR: it helps leaders see which control gives better business value.
Why FAIR Helps GRC Teams
FAIR makes cyber risk easier to discuss with the board. It connects security issues to money, business impact, and decision-making. It also helps teams explain why one control should be prioritised over another.
A good FAIR assessment does not need perfect data. It needs clear assumptions, honest ranges, and regular review. Over time, the estimates improve as the organisation collects better evidence from incidents, controls, audits, vendors, and security tools.
The goal is not to make cyber risk look exact. The goal is to make it understandable, comparable, and actionable.
Suggested sources: