VERITY RISK — FAIR Quantification

FAIR Risk Quantification: Cyber Risk in Dollars, Not Colors

Factor Analysis of Information Risk (FAIR) is the Open Group-standardized, quantitative model for information and operational risk. Instead of a red/yellow/green heat map, FAIR produces a defensible, financial estimate of loss exposure — the number your CFO and board can actually act on.

What FAIR Actually Is

A Standard, Not a Framework Armorstack Invented

FAIR (Factor Analysis of Information Risk) was developed by Jack Jones in the early 2000s and is maintained today as an international standard by The Open Group, published as two companion documents that make up the Open FAIR Body of Knowledge: O-RA (Risk Analysis), which defines the process for performing a FAIR-based risk analysis, and O-RT (Risk Taxonomy), which defines the standard taxonomy for information risk. The FAIR Institute, a nonprofit founded by Jones, maintains training, certification, and practitioner resources around the standard.

What makes FAIR different from a maturity score or a heat map is that it decomposes risk into measurable factors — how often a loss event is likely to occur (Loss Event Frequency) and how large the loss is likely to be when it does (Loss Magnitude) — and expresses the result as a probability-weighted range of financial loss, not a single false-precision number and not an ordinal label. That structure is what lets a FAIR estimate be compared directly to a control’s cost, an insurance premium, or another risk on the register.

The Taxonomy

How a FAIR Estimate Is Built

The O-RT taxonomy breaks risk down into factors that can each be estimated from data, historical incidents, and calibrated expert judgment — then combined statistically rather than added on a spreadsheet.

Loss Event Frequency

How often a loss event is expected to occur in a given period, derived from Threat Event Frequency (how often a threat actor attempts an action against an asset) and Vulnerability (the probability that the attempt succeeds given the controls in place).

Loss Magnitude

The likely size of the loss when an event occurs, built from Primary Loss (the direct cost to the organization — incident response, downtime, replacement) and Secondary Loss (costs driven by secondary stakeholders — regulatory fines, litigation, reputational and customer-attrition impact).

Risk

Loss Event Frequency and Loss Magnitude are combined using Monte Carlo simulation to produce a probability distribution of annualized loss exposure — not a single point estimate, but a range with confidence levels, exactly the format financial and actuarial risk is already reported in elsewhere in the business.

Why It Matters

What a Heat Map Can’t Do That FAIR Can

Ordinal risk scores (High/Medium/Low, or 1–5) can’t be added, averaged meaningfully, or compared to a dollar figure. That makes them useless for the two questions leadership actually asks: “is this control worth what it costs?” and “which of these ten risks should we fix first with the budget we have?” A FAIR-quantified risk register answers both directly — a $40,000 control that reduces $2M of annualized loss exposure by 60% is an easy approval; the same control justified only by a “High” rating is a guess dressed up as analysis.

Armorstack’s VERITY team applies FAIR as part of VERITY RISK, and continuously through VERITY Compass, which re-runs quantification as controls and threat conditions change rather than treating it as a once-a-year exercise. Quantified output also strengthens two adjacent conversations: cyber insurance underwriting, where carriers increasingly expect quantified risk narratives, and NIST CSF maturity remediation planning, where FAIR turns a list of gaps into a prioritized, cost-justified roadmap.

FAQ

Frequently Asked Questions About FAIR Quantification

Is FAIR a real, recognized standard, or a vendor-specific methodology?
FAIR is a vendor-neutral standard maintained by The Open Group (a technology standards consortium) through its O-RA and O-RT publications, with the nonprofit FAIR Institute providing training and certification. It is not proprietary to any single vendor, including Armorstack.
Does a FAIR analysis replace our existing risk register?
No — it strengthens it. Most organizations keep a qualitative register for breadth (tracking many risks quickly) and apply FAIR quantification to the highest-priority items where a defensible dollar figure changes the decision, such as a major control investment or a board-level risk appetite discussion.
Where does the data for a FAIR estimate come from?
A blend of your own environment data (incident history, control coverage, asset inventory), industry loss data, and calibrated estimation from subject-matter experts using ranges and confidence intervals rather than single-point guesses — a core FAIR discipline that reduces the overconfidence typical of ad hoc risk scoring.
How long does a first FAIR quantification engagement take?
A focused analysis on a small number of priority risk scenarios typically runs two to four weeks. Request a FAIR analysis for a scoped timeline against your specific risk questions.

Put a Number on Your Top Risks.

VERITY RISK applies the Open FAIR standard to translate your control gaps into annualized loss exposure — so the next budget conversation runs on evidence, not intuition.