A Standard, Not a Framework Armorstack Invented
FAIR (Factor Analysis of Information Risk) was developed by Jack Jones in the early 2000s and is maintained today as an international standard by The Open Group, published as two companion documents that make up the Open FAIR Body of Knowledge: O-RA (Risk Analysis), which defines the process for performing a FAIR-based risk analysis, and O-RT (Risk Taxonomy), which defines the standard taxonomy for information risk. The FAIR Institute, a nonprofit founded by Jones, maintains training, certification, and practitioner resources around the standard.
What makes FAIR different from a maturity score or a heat map is that it decomposes risk into measurable factors — how often a loss event is likely to occur (Loss Event Frequency) and how large the loss is likely to be when it does (Loss Magnitude) — and expresses the result as a probability-weighted range of financial loss, not a single false-precision number and not an ordinal label. That structure is what lets a FAIR estimate be compared directly to a control’s cost, an insurance premium, or another risk on the register.
How a FAIR Estimate Is Built
The O-RT taxonomy breaks risk down into factors that can each be estimated from data, historical incidents, and calibrated expert judgment — then combined statistically rather than added on a spreadsheet.
Loss Event Frequency
How often a loss event is expected to occur in a given period, derived from Threat Event Frequency (how often a threat actor attempts an action against an asset) and Vulnerability (the probability that the attempt succeeds given the controls in place).
Loss Magnitude
The likely size of the loss when an event occurs, built from Primary Loss (the direct cost to the organization — incident response, downtime, replacement) and Secondary Loss (costs driven by secondary stakeholders — regulatory fines, litigation, reputational and customer-attrition impact).
Risk
Loss Event Frequency and Loss Magnitude are combined using Monte Carlo simulation to produce a probability distribution of annualized loss exposure — not a single point estimate, but a range with confidence levels, exactly the format financial and actuarial risk is already reported in elsewhere in the business.
What a Heat Map Can’t Do That FAIR Can
Ordinal risk scores (High/Medium/Low, or 1–5) can’t be added, averaged meaningfully, or compared to a dollar figure. That makes them useless for the two questions leadership actually asks: “is this control worth what it costs?” and “which of these ten risks should we fix first with the budget we have?” A FAIR-quantified risk register answers both directly — a $40,000 control that reduces $2M of annualized loss exposure by 60% is an easy approval; the same control justified only by a “High” rating is a guess dressed up as analysis.
Armorstack’s VERITY team applies FAIR as part of VERITY RISK, and continuously through VERITY Compass, which re-runs quantification as controls and threat conditions change rather than treating it as a once-a-year exercise. Quantified output also strengthens two adjacent conversations: cyber insurance underwriting, where carriers increasingly expect quantified risk narratives, and NIST CSF maturity remediation planning, where FAIR turns a list of gaps into a prioritized, cost-justified roadmap.
Frequently Asked Questions About FAIR Quantification
Related VERITY RISK Services
Put a Number on Your Top Risks.
VERITY RISK applies the Open FAIR standard to translate your control gaps into annualized loss exposure — so the next budget conversation runs on evidence, not intuition.