How to quantify cyber risk using the FAIR model
Cyber security teams rarely struggle to identify risks. The real challenge is determining which risks deserve immediate attention, how much they could cost the business, and whether additional security investments are justified.
The FAIR (Factor Analysis of Information Risk) model approaches cyber risk differently. Instead of relying on subjective ratings, it estimates how often a loss event is likely to occur and the probable business impact if it does. This allows organizations to compare cyber risks using measurable estimates rather than assumptions, supporting more informed investment and risk treatment decisions.
In this guide, you’ll learn how to use the FAIR model to quantify cyber risk and communicate the results in a way that supports business decision-making.
- What does cyber risk quantification mean?
- Using the FAIR model to quantify cyber risk
- Step 1: Decide what you want to quantify
- Step 2: Break the risk into measurable components
- Step 3: Estimate a realistic range for the potential loss
- Step 4: Translate technical events into business exposure
- Step 5: Compare risk treatment options before making security investments
- Step 6: Communicate quantifiable cyber risk in business terms
- How CyberArrow supports cyber risk quantification
- FAQs
What does cyber risk quantification mean?
Cyber risk quantification is the process of estimating cyber risk in measurable business terms instead of assigning qualitative ratings. Rather than describing a ransomware attack or data breach as simply “high risk,” you estimate the probable financial exposure associated with that specific scenario.
This doesn’t mean predicting the exact cost of a future incident. No assessment can eliminate uncertainty. Instead, the goal is to develop reasonable estimates based on available evidence, business context, and documented assumptions.
For example, a FAIR risk assessment helps answer questions such as:
- How likely is this scenario to occur over the next year?
- What financial losses could result if it happens?
- Which security controls would reduce that exposure the most?
- Does the expected reduction in risk justify the investment?
These answers allow executives to evaluate cyber risks alongside other business risks when making strategic decisions.
Using the FAIR model to quantify cyber risk
Once you’ve identified the cyber risk you want to analyze, the next step is to turn that risk into measurable business exposure. The FAIR model does this by breaking a complex cyber risk into smaller variables that can be estimated individually.
Step 1: Decide what you want to quantify
Cyber risk quantification works best when it answers a specific business question. Before building your model, identify the decision the results will support.
For example, your organization may be deciding whether to invest in additional ransomware protection for production systems or whether the current controls provide an acceptable level of protection. Another organization may want to understand the financial exposure associated with a critical cloud provider or estimate the potential impact of a third-party software compromise.
Keep the scope focused on one measurable business scenario.
For instance, a manufacturing company relies on a cloud-based ERP platform to manage procurement, inventory, and production. A cyberattack on the cloud provider causes a prolonged service outage, preventing employees from processing orders and disrupting manufacturing operations.
Unlike a general “cloud outage” risk, this scenario has a clear, measurable business consequence.
Step 2: Break the risk into measurable components
Start by asking a series of focused questions rather than trying to estimate the overall risk at once.
For our ERP outage scenario, consider questions such as:
| Question | Why you should ask |
| How often do major cloud service disruptions occur? | Helps estimate how likely the threat is to materialize. |
| How dependent are critical business processes on this provider? | Determines how much of the business would be affected. |
| What resilience measures already exist? | Backup environments, failover capabilities, and disaster recovery plans influence the likelihood and duration of business disruption. |
| Which business functions would stop operating? | Identifies the operational consequences and financial impact. |
Breaking the scenario into smaller questions makes the analysis easier to validate because each estimate can be supported by evidence rather than intuition.
Step 3: Estimate a realistic range for the potential loss
One of the biggest misconceptions about risk quantification is that it requires you to predict the exact financial impact of an incident. In reality, FAIR acknowledges that uncertainty is unavoidable. Develop a realistic range based on the information available today.
Estimate the potential business losses associated with your scenario. Consider both the immediate costs of responding to the incident and the wider impact on business operations.
Returning to our ERP outage example, ask questions such as:
- How long would production stop if the ERP platform became unavailable?
- What revenue would be delayed during that period?
- Would contractual penalties apply if customer orders were not delivered on time?
- How much would incident response, recovery, and external support cost?
Suppose the outage prevents manufacturing operations for two days. Finance estimates a production loss of $600,000, while IT estimates recovery costs of approximately $150,000. Customer service expects that delayed deliveries will trigger contractual penalties of up to $100,000.
Rather than reporting that the outage would cost exactly $850,000, record a reasonable range that reflects the uncertainty in those estimates. As additional business data becomes available, you can narrow that range and improve the accuracy of future analyses.
Step 4: Translate technical events into business exposure
Explain the operational and financial consequences that follow. Trace the event through the business until you reach measurable outcomes.
For our example, the chain of events might look like this:
| Technical event | Business impact |
| Cloud ERP platform becomes unavailable | Procurement and inventory processes stop |
| Production schedules cannot be updated | Manufacturing output decreases |
| Customer orders are delayed | Revenue is postponed and contractual penalties may apply |
| Recovery activities begin | Additional IT, legal, and consulting costs are incurred |
This approach also makes it easier to compare different cyber risks. A ransomware attack, supplier compromise, or cloud outage may affect different systems, but each can ultimately be expressed as operational disruption, financial loss, regulatory consequences, or reputational impact.
Step 5: Compare risk treatment options before making security investments
Once you’ve quantified cyber risk, use the results to evaluate different risk treatment options. Rather than assuming every cyber risk requires another security tool, compare how each option changes the organization’s financial exposure.
Continue with the ERP outage example. Suppose your analysis shows that a prolonged outage could result in business losses ranging between $700,000 and $1 million. Instead of immediately purchasing a new solution, compare the available options.
One option may be to implement a secondary ERP environment in another cloud region to reduce service disruption. Another may focus on strengthening disaster recovery capabilities and shortening recovery times. You may also decide to diversify critical workloads across multiple providers or negotiate stronger resilience commitments with your cloud vendor.
Each option carries a different implementation cost and is likely to reduce the organization’s exposure by varying amounts. Compare those costs against the estimated reduction in financial loss rather than relying on assumptions or qualitative ratings.
Step 6: Communicate quantifiable cyber risk in business terms
Present the results in language that supports decision-making. Explain the scenario that was analyzed, the estimated range of financial loss, the assumptions used to build the model, and the expected impact of different treatment options.
Keep technical details available to support discussions, but focus the summary on the information leadership needs to approve investments and prioritize risk-reduction activities.
For example, present the findings as:
A prolonged outage affecting the organization’s primary ERP provider is estimated to result in financial losses of $700,000 to $1 million. Implementing multi-region disaster recovery is expected to significantly reduce production downtime and lower the organization’s overall exposure.
This level of reporting allows cyber risk to be discussed alongside operational, financial, and strategic risks. It also creates a consistent basis for comparing different cyber initiatives and demonstrating the value of security investments over time.
How CyberArrow supports cyber risk quantification
Quantifying cyber risk requires more than calculations. You also need a structured way to document assumptions, manage risk records, track treatment plans, and demonstrate how cyber risk changes over time.
CyberArrow GRC helps organizations quantify cyber risk by providing a centralized platform to:
- Maintain a centralized cyber risk register.
- Record quantified risk assessments, supporting evidence, and business assumptions.
- Assign risk owners and monitor treatment plans.
- Track remediation activities and measure their progress.
- Generate dashboards and executive reports for management and board-level stakeholders.
- Integrate cyber risk management with compliance, enterprise risk, and internal audit activities.
By combining structured governance with FAIR-based analysis, organizations can move beyond qualitative risk ratings and make more informed, data-driven decisions about cyber security investments.
FAQs
How does the FAIR model quantify cyber risk?
The FAIR model quantifies cyber risk by analyzing two key factors: the likelihood of a loss event occurring and the probable business impact if it does. Instead of relying on subjective judgments, it uses structured estimates, available evidence, and documented assumptions to calculate potential business exposure.
What data is needed to quantify cyber risk?
Organizations can use a combination of internal and external data, including previous security incidents, vulnerability assessments, threat intelligence, business impact analyses, audit findings, recovery costs, and operational metrics. Where complete data is unavailable, documented assumptions can be used and refined over time.
Why is cyber risk quantification better than qualitative risk ratings?
Qualitative ratings help prioritize risks but don’t explain their potential business impact. Cyber risk quantification provides a more objective view by estimating financial exposure, allowing organizations to compare different risks, evaluate security investments, and communicate cyber risk more effectively to executives and boards.
Can small and medium-sized businesses use the FAIR model?
Yes. Organizations don’t need a large cyber security program to begin using FAIR. Start by quantifying a small set of high-priority cyber risk scenarios affecting critical business operations, then expand the approach as your risk management program matures.