Skip to main content
Category: Risk Analysis and Quantification

FAIR Model

Also known as: FAIR, Factor Analysis of Information Risk
Simply put

The FAIR Model is a framework used to understand and measure information and cyber risk by expressing it in financial terms rather than as qualitative ratings such as high, medium, or low. It breaks risk down into defined factors so that organizations can quantify the likely frequency and magnitude of loss events. This helps decision-makers compare risks and prioritize them using consistent, measurable estimates.

Formal definition

FAIR (Factor Analysis of Information Risk) is a quantitative model for analyzing and quantifying information and operational risk in financial terms. It codifies risk terminology and expresses risk as loss events, decomposing risk into contributing factors to support the estimation of loss event frequency and loss magnitude. Unlike qualitative risk assessment approaches, FAIR is oriented toward producing financially expressed, quantitative estimates of risk. Note that 'FAIR' is also used for the unrelated Financial Accountability in Research model in the research funding context; that usage is out of scope for this entry, which addresses the information-risk model only.

Why it matters

Many organizations still describe information and cyber risk using qualitative labels such as high, medium, or low. These ratings are easy to produce but difficult to compare, aggregate, or defend, and they give decision-makers limited basis for prioritizing spending or comparing one exposure against another. The FAIR Model matters because it expresses risk in financial terms, allowing risk to be discussed in the same language as other business decisions and enabling more consistent prioritization.

Who it's relevant to

Risk Managers
Those responsible for identifying, assessing, and prioritizing information and cyber risk may use FAIR to express exposures in financial terms, supporting more consistent comparison across risks rather than reliance on qualitative ratings alone.
Cyber and Information Security Leaders
Security leaders seeking to communicate cyber and operational risk to business decision-makers may find FAIR useful for framing risk in financial language that aligns with broader business decisions.
Executives and Boards
Decision-makers who must allocate resources across competing priorities may draw on FAIR-based estimates of loss event frequency and magnitude to inform how they prioritize and treat risks, while recognizing that outputs are estimates dependent on underlying assumptions.
Internal Auditors and Assurance Functions
Assurance professionals evaluating an organization's risk analysis processes may encounter FAIR as the quantitative framework underlying management's risk estimates. Consistent with independence principles, their role is to assess how such estimates are produced and used, not to perform the risk management activity itself.

Inside FAIR

Loss Event Frequency (LEF)
The probable number of times within a given timeframe that a threat agent is expected to inflict loss on an asset. In FAIR, this is commonly decomposed further into threat event frequency and vulnerability.
Threat Event Frequency (TEF)
The probable frequency, within a defined period, that a threat agent acts against an asset. It is typically informed by contact frequency and the probability that contact results in an attempt.
Vulnerability
In FAIR terms, the probability that a threat event becomes a loss event, expressed as the interplay between threat capability and the strength of relevant controls (resistance strength). This differs from the common usage of vulnerability as a specific technical weakness.
Loss Magnitude (LM)
The probable size of loss resulting from a loss event, often analyzed across primary loss (borne directly by the organization) and secondary loss (arising from reactions of secondary stakeholders such as customers or regulators).
Primary and Secondary Loss
Primary loss refers to consequences experienced directly as a result of the event; secondary loss refers to further losses driven by the responses of secondary stakeholders. Both feed into the overall loss magnitude estimate.
Quantitative, Probabilistic Output
FAIR expresses risk as a distribution of probable financial loss rather than a single point value or an ordinal rating, commonly using ranges and simulation techniques to reflect uncertainty.

Common questions

Answers to the questions practitioners most commonly ask about FAIR.

Does the FAIR Model replace the need for a broader risk management framework such as ISO 31000 or COSO ERM?
No. FAIR is a quantitative model for analyzing and measuring information and operational risk in financial terms; it addresses the assessment and analysis of specific risk scenarios rather than the full governance, policy-setting, and treatment structures provided by frameworks such as ISO 31000 (issued by ISO) or COSO ERM (issued by the Committee of Sponsoring Organizations of the Treadway Commission). Organizations commonly use FAIR alongside such frameworks, applying it to quantify risks that the broader framework identifies and governs.
Does FAIR produce a single precise dollar figure that predicts what a loss will actually be?
No. FAIR expresses risk as a distribution of probable loss magnitudes and frequencies, typically presented as ranges with associated likelihoods rather than a single deterministic number. The outputs reflect estimates built from calibrated inputs and are intended to inform decision-making about relative and probable exposure, not to guarantee or forecast the outcome of any specific event.
What inputs are typically needed to run a FAIR analysis?
A FAIR analysis generally decomposes risk into contributing factors, commonly including the frequency of loss events and the magnitude of loss should they occur, with magnitude often separated into primary and secondary loss components. Estimating these factors typically requires scoping a specific risk scenario, gathering available data, and using calibrated expert estimates where hard data is limited. The specific data sources and estimation approaches vary by organization and scenario.
How should a FAIR scenario be scoped before analysis begins?
Scoping typically involves defining the asset at risk, the threat community or actor, the type of loss event, and the effect being considered, so that the factors being estimated remain consistent. Clearly bounding the scenario helps avoid conflating distinct risks into a single analysis. The level of granularity commonly depends on the decision the analysis is intended to support.
How can FAIR outputs be used to support risk treatment decisions?
Because FAIR expresses exposure in financial terms and as loss distributions, its outputs can be used to compare scenarios, prioritize among competing risks, and evaluate the potential effect of proposed controls or other treatment options on estimated loss frequency or magnitude. Such comparisons may inform, but do not by themselves determine, decisions that also depend on an organization's risk appetite, resources, and governance context.
Who is typically involved in performing a FAIR analysis, and how does this relate to assurance independence?
FAIR analyses are commonly performed by risk analysts or risk management functions, often drawing on subject-matter experts to supply calibrated estimates. Where an independent assurance function reviews or relies on such analyses, the distinction between management's estimation activity and independent evaluation of it should be maintained, consistent with the objectivity expected of assurance functions. This entry does not cover specific tooling or implementation methods for calibration.

Common misconceptions

FAIR is a control framework that tells an organization which controls to implement.
FAIR is an analytical model for quantifying risk in financial terms; it is a method for measurement and analysis, not a catalog of controls or a compliance framework. It is typically used alongside, not in place of, control frameworks and standards.
FAIR produces a precise, guaranteed loss figure.
FAIR yields probabilistic estimates expressed as ranges and distributions that reflect uncertainty in the inputs. The quality of the output depends heavily on the quality of the input estimates and assumptions, and it does not guarantee actual outcomes.
Vulnerability in FAIR means the same thing as a technical vulnerability or CVE.
In FAIR, vulnerability is a probability that a threat event becomes a loss event, derived from the relationship between threat capability and control strength. This is a distinct, model-specific meaning that differs from the common technical usage.

Best practices

Scope each analysis clearly by defining the asset, the threat community, and the specific loss event before estimating frequency or magnitude, so that inputs remain consistent and comparable.
Decompose estimates into their FAIR components (such as threat event frequency, vulnerability, and loss magnitude) rather than guessing top-level risk directly, to make assumptions explicit and reviewable.
Express inputs and outputs as ranges or distributions that capture uncertainty, and document the reasoning and data sources behind each estimate.
Distinguish primary loss from secondary loss when estimating magnitude, and consider the reactions of secondary stakeholders where relevant to the scenario.
Calibrate estimators and use available data and expert judgment to reduce bias, revisiting analyses as new information becomes available.
Use FAIR outputs to inform risk treatment and prioritization decisions in support of the organization's risk appetite and tolerance, while recognizing that the model complements rather than replaces qualitative judgment and control frameworks.
Promotional banner for the Penetration Report Template Kit