FAIR Risk Assessment

FAIR risk assessment: A step-by-step guide

Many cyber security risk assessments end with a color-coded heat map. A risk is labeled High, another is Medium, and security teams move on to the next item on the register. While this approach helps prioritize work, it rarely answers the questions that matter most to business leaders: 

 

How much could this risk cost? Is the current level of risk acceptable? Would investing in another security control reduce the exposure enough to justify the cost?

 

A FAIR risk assessment approaches these questions differently. Instead of assigning subjective ratings, it evaluates a specific loss scenario, estimates its likelihood, and measures its potential business impact. The outcome is a more objective assessment that helps security, risk, and business teams make informed decisions.

 

In this guide, you’ll learn how to perform a FAIR risk assessment using a practical workflow that you can adapt to your own organization.

 

 

Before you begin: Define the decision you’re trying to support

 

Before opening a spreadsheet or gathering technical data, identify the business decision the assessment is intended to support.

 

A FAIR assessment should answer a specific question. For example:

 

  • Should you invest in stronger email security controls?
  • Does a critical supplier introduce more cyber risk than your organization is willing to accept?
  • Would implementing privileged access management reduce financial exposure enough to justify the investment?

 

Starting with a clear objective keeps the assessment focused. Without it, the scope can quickly expand into a broad discussion about “cyber risk” that produces little value.

 

How to conduct a FAIR risk assessment

 

A FAIR risk assessment is built around a single loss scenario rather than a list of unrelated risks. As you work through the assessment, collect evidence, document your assumptions, and validate your estimates with relevant stakeholders. 

 

This approach helps you produce consistent risk assessments that support business decisions instead of relying on subjective risk ratings.

 

Step 1: Define a clear loss scenario

 

The quality of your assessment depends on how well you define the scenario. Avoid describing risks in broad terms such as ransomware, data breach, or cyberattack. These descriptions are too general to assess consistently because they combine multiple threats, assets, and business impacts into a single statement. Instead, describe one specific event that could result in a measurable business loss.

 

A well-defined FAIR loss scenario should answer four questions:

 

Question  Example 
What asset is involved? Finance system and Microsoft 365 account
Who is the threat actor? External cybercriminal 
What action occurs? Credential theft through phishing
What loss could occur? Fraudulent wire transfers and financial loss

 

Notice how the scenario focuses on a single business event rather than on every possible outcome of a phishing attack. This makes it easier to collect evidence, estimate likelihood, and evaluate potential losses.

 

Throughout this guide, we’ll assess the following scenario:

 

A phishing email compromises a finance employee’s Microsoft 365 account, allowing an attacker to initiate fraudulent wire transfers.

 

Step 2: Gather evidence before estimating the risk

 

Once you’ve defined the scenario, collect evidence that supports your assessment. The FAIR risk management framework encourages estimates based on available information rather than assumptions alone.

 

Review previous phishing incidents, security alerts, email gateway reports, vulnerability assessments, penetration testing results, and audit findings. These sources provide valuable insight into how frequently similar attacks occur and how effective your existing controls are.

 

Then expand your research beyond the organization. Threat intelligence reports, industry breach reports, insurer claims data, and sector-specific advisories can help you understand how often similar organizations experience comparable attacks.

 

In our example, you might discover that the organization blocked hundreds of phishing emails over the past year, yet several still reached users’ inboxes. Recent phishing simulations also showed that a small percentage of employees clicked malicious links. 

 


 

Step 3: Estimate how likely the loss event is to occur

 

The next step is to estimate the likelihood that the scenario will result in a business loss. Rather than asking whether phishing is a “high risk,” consider the factors that influence the likelihood of the specific scenario you’ve defined.

 

Ask yourself:

 

  • How often are similar phishing campaigns targeting your industry?
  • How exposed is the affected system?
  • How effective are your current preventive controls?
  • How likely is an attacker to succeed if they attempt this attack?

 

Suppose your organization enforces multi-factor authentication for all finance users, provides quarterly phishing awareness training, and uses advanced email filtering. These controls may reduce the likelihood that credential theft will result in unauthorized access, even if phishing emails continue to reach employees.

 

On the other hand, if privileged accounts rely solely on passwords or employees rarely receive security awareness training, the probability of a successful attack may be considerably higher.

 

Step 4: Estimate the potential business impact

 

Evaluate what the organization could lose if it happens. FAIR refers to this as loss magnitude; the probable impact of a loss event expressed in business terms.

 

Identify the direct costs your organization would incur immediately after the incident. For the phishing scenario, these may include incident response activities, forensic investigations, recovery efforts, legal support, customer notifications, and any fraudulent payments that cannot be recovered.

 

Then look beyond the immediate response. Cyber incidents often have wider business consequences that continue long after systems have been restored. Consider questions such as:

 

  • Could critical business operations be disrupted?
  • Would customers lose confidence in your services?
  • Could contractual obligations or service level agreements be affected?
  • Are there regulatory or legal consequences if sensitive information is exposed?

 

Imagine the phishing attack results in a fraudulent transfer of $250,000. Although the financial loss is significant, it may not represent the total business impact. If payment processing is suspended during the incident investigation, finance teams may be unable to process supplier invoices, causing operational delays and affecting business relationships. The organization may also incur investigation costs, legal fees, and additional expenses to strengthen its security controls after the incident.

 

Step 5: Validate your assumptions

 

Before finalizing the results, review the assessment with the people who understand the systems, business processes, and financial impacts involved.

 

Security teams can validate technical assumptions about threats and existing controls, while business owners can explain how operational disruptions would affect critical services. Finance teams often provide valuable input when estimating recovery costs, business interruption losses, and potential financial exposure.

 

Ask questions throughout the review process.

 

  • Does the available evidence support the estimated likelihood?
  • Have you overlooked any existing controls that could reduce the risk?
  • Are the estimated business impacts realistic based on previous incidents or business operations?
  • Would another team arrive at a different conclusion using the same evidence?

 

Document any assumptions that cannot be verified and explain why they were made. FAIR does not require perfect data, but it does require transparency. 

 

Step 6: Evaluate risk treatment options

 

Review the results of your assessment and determine whether the current level of risk is acceptable or requires additional action. Rather than assuming every risk should be reduced, compare treatment options and evaluate how each would affect the organization’s exposure.

 

Returning to our phishing scenario, several options may be available. You could introduce phishing-resistant multi-factor authentication, strengthen email filtering, provide targeted awareness training for finance staff, or implement additional controls around payment approvals. 

 

Each option involves a different cost, implementation effort, and expected reduction in risk.

 

If a proposed control costs significantly more than the reduction in potential loss, another treatment option may provide better value. In some cases, leadership may decide to accept the remaining risk because it falls within the organization’s defined risk appetite.

 

This is where FAIR provides an advantage over traditional qualitative assessments. Instead of debating whether a risk is “High” or “Medium,” you can compare the expected reduction in business exposure against the cost of implementing additional controls, allowing leadership to make more informed investment decisions.

 

Step 7: Keep the assessment current

 

Review the assessment whenever a significant change could affect either the likelihood or the business impact of the loss scenario. Common triggers include the deployment of new systems, changes to critical suppliers, the introduction of new security controls, major cyber incidents, or changes to regulatory requirements.

 

Suppose the organization deploys phishing-resistant multi-factor authentication across all finance users. That control affects the likelihood that attackers can successfully use stolen credentials, so the assessment should be updated to reflect the new environment. Likewise, if the finance function expands into new regions or begins processing higher-value transactions, the potential financial impact of a successful attack may also increase.

 

Integrating FAIR into your risk management program

 

A single FAIR risk assessment provides valuable insight into one loss scenario, but organizations gain the greatest value when FAIR becomes part of their broader risk management process.

 

Apply the methodology to your most critical cyber risks rather than attempting to assess every scenario at once. Focus on areas where decisions involve significant financial exposure, major technology investments, or business-critical services. As teams become more familiar with the methodology, expand the approach to additional business units and risk scenarios.

 

To maintain consistency across assessments:

 

  • Use a standard template for documenting loss scenarios, assumptions, evidence, and estimates.
  • Maintain a central risk register that records assessment results and treatment decisions.
  • Revisit assessments whenever business operations, technology, or the threat landscape changes.
  • Review results with business, security, risk, and finance stakeholders before making significant risk decisions.

 

Integrating FAIR into your existing governance and enterprise risk management processes helps ensure that cyber risks are evaluated alongside operational, financial, and strategic risks rather than in isolation.

 

How CyberArrow supports FAIR risk assessments

 

Conducting a FAIR assessment is only one part of effective cyber risk management. Organizations also need a structured way to document assessments, assign ownership, track remediation activities, and monitor risks over time.

 

CyberArrow GRC helps organizations operationalize FAIR-based risk assessments by enabling teams to:

 

  • Document and manage risk assessments from a centralized platform.
  • Maintain risk registers with clearly defined owners, treatment plans, and review dates.
  • Record supporting evidence, assumptions, and assessment outcomes for future reference.
  • Track remediation activities and monitor their progress.
  • Generate dashboards and reports for management and board-level decision-making.
  • Integrate risk assessments with enterprise risk, compliance, and audit activities.

 

Organizations can make more informed risk decisions while maintaining visibility into cyber risks across the business by combining FAIR’s quantitative approach with centralized governance, risk, and compliance processes.  

 

See what our clients have to say about CyberArrow GRC:

 

Emirates Testimonial


 

FAQs

 

What information do you need to perform a FAIR risk assessment?

A FAIR assessment typically uses information such as incident history, threat intelligence, vulnerability assessments, security controls, business impact analyses, and input from business stakeholders to estimate the likelihood and impact of a loss scenario.

 

How often should FAIR risk assessments be updated?

Rather than following a fixed annual schedule, update FAIR assessments whenever significant changes affect the underlying risk. Examples include new technologies, changes to critical suppliers, major cyber incidents, or the implementation of new security controls.

 

Can FAIR be used with ISO 31000 or ISO 27001?

Yes. FAIR complements frameworks such as ISO 31000 and ISO 27001 by providing a structured methodology for quantifying cyber risk. While those frameworks establish how organizations manage risk, FAIR helps estimate the likelihood and financial impact of specific cyber risk scenarios.

 

Is FAIR suitable for organizations of all sizes?

Yes. Organizations can begin by applying FAIR to a small number of high-priority risk scenarios and expand its use as their cyber risk management program matures.

Avatar photo
CyberArrow team