Skip to content
Oluma Cyber Security Awareness
Model · Quantitative Risk

FAIR

The framework that puts a dollar figure on cyber risk. Instead of “high, medium, low,” it asks how often this will happen and how much it will cost — and answers in money leadership understands.

Quantitative riskOpen Group O-RT/O-RA$ in dollarsMonte Carlo
01 The Problem

“High risk” means nothing to a CFO

Most security programs rate risk on a color scale — red, amber, green; high, medium, low. It feels rigorous, but it’s impossible to act on. Is one “high” twice as bad as another? Should you spend $2M to fix it? A heat map can’t say.

Leadership speaks in dollars and probabilities, not colors. Without a way to translate cyber risk into money, security teams couldn’t defend budgets or prioritize honestly — they were guessing with a confident vocabulary.

03 The Story Behind It

From one analyst’s method to an open standard

2000s
A practitioner’s model
Developed by risk analyst Jack Jones as a rigorous, decomposable way to reason about information risk in financial terms.
Open Group
Becomes a standard
Adopted by The Open Group as the Risk Taxonomy (O-RT) and Risk Analysis (O-RA) standards, with an Open FAIR certification for practitioners.
FAIR Institute
A professional community
A nonprofit institute grew up around it, spreading quantitative risk practice across enterprises and government.
Extensions
Beyond the core
Companion models like FAIR-CAM (how controls actually reduce risk) and FAIR-MAM (materiality — useful for breach-disclosure decisions) extended the method to new questions.
04 How It Works

Decompose, estimate, simulate

FAIR takes the vague word “risk” and splits it into a tree of measurable factors. At the top: how frequently a loss event occurs, and how large the loss is. Each branch decomposes further until you reach things experts can actually estimate.

Risk= Loss Event Frequency× Loss Magnitude

You estimate each factor as a range (minimum, most-likely, maximum), then run a Monte Carlo simulation — thousands of trials — to produce a distribution of annual loss. The taxonomy underneath:

LEF Loss Event Frequency
TEF Threat Event Frequency
Vuln Vulnerability
TCap Threat Capability
RS Resistance Strength
LM Loss Magnitude
PL Primary Loss
SL Secondary Loss
FAIR vs. NIST / ISO

Frameworks like NIST CSF, ISO 27001, and CIS tell you what controls to have. FAIR tells you how much risk each gap represents — in dollars. They’re partners: the frameworks set the menu, FAIR helps you decide what to fund first.

06 Who Uses It

Where risk meets the boardroom

📊
Risk & security teams
Groups that need to prioritize spending and defend budgets with numbers, not colors.
🏦
Finance & insurance
Sectors already fluent in quantified risk — and cyber-insurance underwriting that runs on it.
🧑‍💼
Boards & executives
Leaders who make funding calls and want risk expressed the way every other business risk is.

It doesn’t replace your control frameworks — it gives them a price tag.

complements NIST CSFISO 27001CIS Controlsinforms cyber insurance
07 Career Relevance

The most future-proof GRC skill

As boards demand real numbers, quantitative risk analysis is one of the fastest-rising skills in the field. FAIR is its lingua franca — and it pairs naturally with the data and automation side of GRC.

Cyber risk analyst
Quantify & prioritize
Build loss scenarios, run the simulations, and translate findings into funding decisions.
Open FAIR certified
A recognized credential
The Open Group certification signals you can do defensible, quantitative risk work.
GRC engineer
Automate the math
Wire risk data into models and dashboards so quantification scales — exactly the Python-and-data direction GRC is heading.

Being the person who can say “that’s a $6M risk” instead of “that’s red” changes the conversations you get invited to.

09 Final Takeaway

FAIR turns cyber risk from a color into a number — the language the boardroom actually speaks.

Every other framework in this series tells you what to do; FAIR tells you what it’s worth. Learn to break risk into frequency and magnitude and simulate the range, and you can finally answer the question leadership always asks: “how much should we spend, and on what?”