FAIR Model
The FAIR Model is a framework used to understand and measure information and cyber risk by expressing it in financial terms rather than as qualitative ratings such as high, medium, or low. It breaks risk down into defined factors so that organizations can quantify the likely frequency and magnitude of loss events. This helps decision-makers compare risks and prioritize them using consistent, measurable estimates.
FAIR (Factor Analysis of Information Risk) is a quantitative model for analyzing and quantifying information and operational risk in financial terms. It codifies risk terminology and expresses risk as loss events, decomposing risk into contributing factors to support the estimation of loss event frequency and loss magnitude. Unlike qualitative risk assessment approaches, FAIR is oriented toward producing financially expressed, quantitative estimates of risk. Note that 'FAIR' is also used for the unrelated Financial Accountability in Research model in the research funding context; that usage is out of scope for this entry, which addresses the information-risk model only.
Why it matters
Many organizations still describe information and cyber risk using qualitative labels such as high, medium, or low. These ratings are easy to produce but difficult to compare, aggregate, or defend, and they give decision-makers limited basis for prioritizing spending or comparing one exposure against another. The FAIR Model matters because it expresses risk in financial terms, allowing risk to be discussed in the same language as other business decisions and enabling more consistent prioritization.
Who it's relevant to
Inside FAIR
Common questions
Answers to the questions practitioners most commonly ask about FAIR.