FAIR (Factor Analysis of Information Risk)

FAIR (Factor Analysis of Information Risk) is a taxonomy and methodology for quantitative information risk analysis that decomposes risk into loss event frequency and probable loss magnitude, each broken into contributing factors.

What FAIR Provides

FAIR gives cyber risk quantification a defined vocabulary and decomposition structure. Risk is broken into loss event frequency (how often loss events occur) and loss magnitude (how large the loss is when it occurs). Each is further decomposed: frequency into threat event frequency and vulnerability, magnitude into primary loss and secondary loss with their own component structures.

The decomposition lets analysts reason about specific factors and calibrate them independently rather than trying to estimate risk holistically.

FAIR in the Broader CRQ Ecosystem

FAIR is often used as a conceptual and organizational reference in CRQ programs, particularly for training, communication, and audit contexts. Many quantitative cyber risk analysts hold Open FAIR certifications, and the FAIR terminology appears in industry publications and regulatory guidance.

Modern CRQ platforms typically use FAIR-aligned decomposition without being strictly FAIR-branded. The underlying probabilistic modeling and Monte Carlo simulation often go beyond FAIR's original methodology while remaining consistent with its taxonomy.

FAIR and Quantification Methodology

FAIR itself is a taxonomy and reasoning framework, not a specific implementation. Analysts using FAIR can use various tools and approaches to calibrate distributions, from expert estimation to loss data-driven modeling.

See what is cyber risk quantification (CRQ) for the broader CRQ landscape.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.