O Oluma Cyber Security Framework Files · No. 14 Model · Quantitative Risk FAIR The framework that puts a dollar figure on cyber risk. Instead of “high, medium, low,” it asks how often this will happen and how much it will cost — and answers in money leadership understands. Quantitative riskOpen Group O-RT/O-RA$ in dollarsMonte Carlo FAIR LEFLM$ How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem “High risk” means nothing to a CFO Most security programs rate risk on a color scale — red, amber, green; high, medium, low. It feels rigorous, but it’s impossible to act on. Is one “high” twice as bad as another? Should you spend $2M to fix it? A heat map can’t say. Leadership speaks in dollars and probabilities, not colors. Without a way to translate cyber risk into money, security teams couldn’t defend budgets or prioritize honestly — they were guessing with a confident vocabulary. 02 Why It Was Created To measure risk, not just label it FAIR — Factor Analysis of Information Risk — exists to make cyber risk quantifiable. It breaks risk into measurable parts and expresses the result in financial terms, so “how bad is this?” gets a real answer: a range of likely losses over a year. The core ideaRisk isn’t a color. It’s how often a loss event is likely to happen (frequency) multiplied by how much it would cost when it does (magnitude). Estimate both, and you can compare anything to anything. Crucially, it uses ranges and probabilities, not false-precision single numbers — acknowledging uncertainty instead of pretending it away. 03 The Story Behind It From one analyst’s method to an open standard 2000sA practitioner’s modelDeveloped by risk analyst Jack Jones as a rigorous, decomposable way to reason about information risk in financial terms. Open GroupBecomes a standardAdopted by The Open Group as the Risk Taxonomy (O-RT) and Risk Analysis (O-RA) standards, with an Open FAIR certification for practitioners. FAIR InstituteA professional communityA nonprofit institute grew up around it, spreading quantitative risk practice across enterprises and government. ExtensionsBeyond the coreCompanion models like FAIR-CAM (how controls actually reduce risk) and FAIR-MAM (materiality — useful for breach-disclosure decisions) extended the method to new questions. 04 How It Works Decompose, estimate, simulate FAIR takes the vague word “risk” and splits it into a tree of measurable factors. At the top: how frequently a loss event occurs, and how large the loss is. Each branch decomposes further until you reach things experts can actually estimate. Risk= Loss Event Frequency× Loss Magnitude You estimate each factor as a range (minimum, most-likely, maximum), then run a Monte Carlo simulation — thousands of trials — to produce a distribution of annual loss. The taxonomy underneath: LEF Loss Event Frequency TEF Threat Event Frequency Vuln Vulnerability TCap Threat Capability RS Resistance Strength LM Loss Magnitude PL Primary Loss SL Secondary Loss FAIR vs. NIST / ISOFrameworks like NIST CSF, ISO 27001, and CIS tell you what controls to have. FAIR tells you how much risk each gap represents — in dollars. They’re partners: the frameworks set the menu, FAIR helps you decide what to fund first. 05 Real-World Example Turning a scary finding into a decision A security team wants budget to fix a vulnerability. Instead of calling it “critical” and hoping, they run the numbers and hand leadership a dollar range. Their FAIR analysisFrom “critical” to “$4M a year” Scope one clear loss scenario (e.g. a data breach via this flaw) Estimate how often it’s likely to occur per year, as a range Estimate the loss when it does — response, fines, lost business Simulate thousands of outcomes to get a loss distribution Compare that annual loss to the cost of the fix Now the conversation isn’t about fear — it’s “we can spend $300K to avoid a likely $4M”, a decision any executive can make. 06 Who Uses It Where risk meets the boardroom 📊Risk & security teamsGroups that need to prioritize spending and defend budgets with numbers, not colors. 🏦Finance & insuranceSectors already fluent in quantified risk — and cyber-insurance underwriting that runs on it. 🧑💼Boards & executivesLeaders who make funding calls and want risk expressed the way every other business risk is. It doesn’t replace your control frameworks — it gives them a price tag. complements NIST CSFISO 27001CIS Controlsinforms cyber insurance 07 Career Relevance The most future-proof GRC skill As boards demand real numbers, quantitative risk analysis is one of the fastest-rising skills in the field. FAIR is its lingua franca — and it pairs naturally with the data and automation side of GRC. Cyber risk analystQuantify & prioritizeBuild loss scenarios, run the simulations, and translate findings into funding decisions. Open FAIR certifiedA recognized credentialThe Open Group certification signals you can do defensible, quantitative risk work. GRC engineerAutomate the mathWire risk data into models and dashboards so quantification scales — exactly the Python-and-data direction GRC is heading. Being the person who can say “that’s a $6M risk” instead of “that’s red” changes the conversations you get invited to. 08 Strengths & Challenges Honest trade-offs ✦ Strengths Expresses risk in dollars leadership understands Rigorous, decomposable, and defensible Handles uncertainty with ranges, not fake precision An open, recognized standard with certification Makes prioritization and ROI arguments possible ⚠ Challenges Needs good data and calibrated estimates A learning curve — it’s a real discipline Garbage-in, garbage-out if inputs are sloppy Measures risk; doesn’t tell you which controls to build 09 Final Takeaway FAIR turns cyber risk from a color into a number — the language the boardroom actually speaks.Every other framework in this series tells you what to do; FAIR tells you what it’s worth. Learn to break risk into frequency and magnitude and simulate the range, and you can finally answer the question leadership always asks: “how much should we spend, and on what?”