Factor Analysis of Information Risk (FAIR)
Factor Analysis of Information Risk (FAIR) is a framework for understanding, analyzing, and quantifying information risk in financial terms rather than in vague ratings like high, medium, or low. It breaks risk down into the specific factors that contribute to it, helping organizations evaluate information and operational risks in a structured, business-oriented way. FAIR is often described as an international standard quantitative model for information security and operational risk.
FAIR is a quantitative risk analysis model built on a taxonomy of the factors that contribute to risk and how those factors relate to and affect one another. It decomposes risk into measurable components to support estimation of loss exposure in financial terms, distinguishing it from purely qualitative approaches. It is positioned as a standard quantitative framework for information security and operational risk, providing a defined structure for identifying the features that underlie a specific risk scenario. In practice, a virtual or fractional CISO may use FAIR to support risk governance and prioritization conversations; the model provides a method for analysis rather than a guarantee of any particular risk outcome, and its usefulness depends on the quality of input data, defined scope, and organizational access to relevant loss and threat information.
Why it matters
Most security programs still communicate risk in qualitative terms such as high, medium, or low. These ratings are easy to produce but difficult to defend, because two people can look at the same scenario and assign different colors to it without any shared basis for the disagreement. FAIR matters because it offers a structured way to express information and operational risk in financial terms, which tends to resonate more directly with boards, executives, and budget owners who make decisions in dollars rather than heat-map colors. For a virtual or fractional CISO, this shift can be the difference between a risk conversation that stalls and one that leads to a funded decision.
The value of quantification is not that it produces a precise number, but that it forces explicit reasoning about the factors underlying a risk scenario. By decomposing risk into its contributing components, FAIR makes assumptions visible and open to challenge, which supports more disciplined prioritization across competing security investments. This is particularly useful when leadership must choose between initiatives that all sound important in qualitative terms but cannot all be funded.
It is worth being clear about the limits. FAIR is a method of analysis, not a guarantee of any particular outcome, and it does not prevent breaches. The quality of a FAIR analysis depends heavily on the quality of the input data, a defined scope, and organizational access to relevant loss and threat information. In organizations with limited historical data or immature risk processes, the outputs should be treated as informed estimates that improve over time, not as authoritative predictions.
Who it's relevant to
Inside FAIR
Common questions
Answers to the questions practitioners most commonly ask about FAIR.