New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
Back to Glossary

FAIR (Factor Analysis of Information Risk)

Factor Analysis of Information Risk is the only internationally recognized standard quantitative model for information security and operational risk. It provides a framework for expressing cyber risk in financial terms by modeling Loss Event Frequency and Probable Loss Magnitude. Unlike qualitative risk frameworks that rely on color charts or weighted scales, FAIR produces dollar-denominated outputs that support direct business comparisons and decision-making. Black Kite integrates FAIR-based financial quantification directly into the platform, producing probable financial impact ratings across Data Breach, Ransomware, and Business Interruption scenarios. Open FAIR™ is an industry standard, not proprietary to any single vendor.

FAIR, or Factor Analysis of Information Risk, is a model for analyzing information risk by breaking it into measurable factors. It defines risk as the probable frequency and probable magnitude of future loss, then decomposes each of those into contributing factors that can be estimated separately. It is the methodology most cyber risk quantification rests on.

What separates FAIR from a risk assessment framework is that it doesn't tell you what to control. It tells you how to reason about a loss. Frameworks such as NIST CSF and ISO 27001 organize practice. FAIR supplies the analysis underneath, which is why organizations typically run it alongside a framework rather than instead of one, and why it became the basis for cyber risk quantification.

What Does the FAIR Model Actually Measure?

It measures a scenario, not an asset and not a threat. A FAIR analysis always names a specific combination of an asset at risk, a threat actor, and a type of loss, because risk is not a property that a server or a vendor possesses on its own.

Risk in FAIR is the product of two things. Loss event frequency is how often the scenario is expected to occur in a given period. Loss magnitude is what it costs when it does. Everything else in the model exists to make those two estimates defensible.

This is also why two analyses of "vendor risk" can produce wildly different numbers. If one models a data breach scenario and the other models an operational outage, they aren't disagreeing. They are measuring different things, and FAIR forces that difference into the open by requiring the scenario to be stated first.

How Does FAIR Decompose Risk Into Factors?

Each side of the equation splits into sub-factors, and the split is what makes an estimate arguable rather than asserted. The factor tree is the part of FAIR that does the real work.

  • Threat event frequency. How often a threat actor is expected to act against the asset, which itself decomposes into contact frequency and probability of action.
  • Vulnerability. The probability that a threat event becomes a loss event, expressed as threat capability weighed against resistance strength. Neither side sets the figure alone: a weak actor against weak controls can produce a higher value than a capable actor against strong ones.
  • Primary loss. Costs the organization absorbs directly, such as response, replacement, and lost productivity.
  • Secondary risk. What follows from other parties reacting, including regulators, customers, and partners. It carries its own frequency and its own magnitude, because not every incident produces a lawsuit or a fine.

Separating primary from secondary loss is the step most homegrown models skip, and it's usually where third-party scenarios get mispriced. A vendor breach frequently costs the downstream organization far more in notification, regulatory response, and customer attrition than in direct remediation.

What Are the Six Forms of Loss in FAIR?

FAIR names six categories so that loss magnitude gets estimated component by component rather than guessed as a lump sum. Naming them also stops the common error of counting only the obvious costs.

  1. Productivity. Output the organization cannot produce while the event is in progress.
  2. Response. Investigation, containment, legal counsel, notification, and crisis management.
  3. Replacement. Restoring or rebuilding whatever was damaged, from hardware to credentials.
  4. Fines and judgments. Regulatory penalties, settlements, and contractual damages.
  5. Competitive advantage. Value lost when proprietary information reaches a competitor.
  6. Reputation. Reduced future revenue from customers, partners, and markets reassessing the organization.

The last two are the hardest to estimate and the most frequently omitted, which biases most informal risk analyses downward. The spread across real incidents is also wider than most estimates allow for. Black Kite's analysis of the cost of a data breach across roughly 1,700 breached companies put the average at $75.21 million including outliers and $15.01 million with them removed, which is exactly the kind of long tail a range captures and a point estimate hides.

Why Does FAIR Use Ranges Instead of Single Numbers?

Because a single number claims a precision nobody has, and a range can be both honest and useful. FAIR asks for a minimum, a most likely, and a maximum for each factor, along with a confidence level.

Calibrated Estimation Turns Judgment Into Data

Those ranges come from calibrated estimation, a technique borrowed from decision analysis in which analysts are trained until their stated confidence matches their actual accuracy. A calibrated estimator who says they are 90% confident is right about 90% of the time. That training is what makes expert judgment admissible as data rather than opinion.

Simulation Produces a Loss Exceedance Curve

The ranges are then run through simulation, producing a distribution of possible annual losses rather than one figure. The useful output is a loss exceedance curve, which answers questions a point estimate cannot, such as how likely it is that annual loss from a given scenario exceeds a threshold the business has already declared unacceptable.

What Is the Difference Between FAIR and Open FAIR?

FAIR is the model. Open FAIR™ is the published standard built on it. The model was created by Jack Jones, and The Open Group maintains the Open FAIR methodology as an open standard with its own certification, taxonomy, and analysis specifications.

The distinction matters when evaluating claims. A vendor saying its calculations are FAIR-aligned may mean it borrowed the vocabulary. A vendor saying its calculations are Open FAIR-based is pointing at a published specification an auditor can check the work against. The FAIR Institute maintains the practitioner community around both.

The practical consequence is defensibility. Black Kite's analysis of why Open FAIR became the standard works through a case where one vendor rated C- carried roughly $14,000 in probable impact while a vendor rated B+ carried around $75,000. The letter grades ranked them one way. The FAIR analysis ranked them the other, and only one of those two answers can be defended with a method.

How Is FAIR Applied to Third-Party Risk Management?

Scenario by scenario, with a separate frequency and magnitude estimate for each vendor relationship. That is straightforward in principle and close to impossible by hand across a vendor portfolio, which is why FAIR spread through first-party risk management long before it reached third-party programs.

Scenarios Have to Be Mutually Exclusive

A common modeling error is double-counting. Black Kite runs three mutually exclusive scenarios, covering data breach, ransomware, and business interruption, each with its own loss event frequency and its own magnitude drivers. Data breach magnitude follows the volume and sensitivity of exposed records. 

Ransomware magnitude follows downtime cost, ransom, and reputational damage. Business interruption magnitude follows operational disruption. Only when the scenarios don't overlap can their results be summed into a single probable financial impact.

Populating the Model Is the Bottleneck

A FAIR analysis traditionally begins with a workshop and an analyst. In March 2026 Black Kite introduced Open FAIR-based risk assessments that populate the model from assessment responses, uploaded documentation, and continuous monitoring data rather than from a blank template, which is what makes running the analysis across an entire vendor population practical. The resulting figures and the assumptions behind them sit on the cyber risk quantification and financial impact of cyber attacks pages, and a sample Open FAIR™ report shows the output format.

See also: FAIR Scenarios for Ransomware and Business Interruption