Define the risk scenario
To quantify accurately, it has to be crystal clear what you are talking about:
Together, those three define the scenario and form the basis for every number that follows.
Want to know more about building good risk scenarios? Use the Polar Toolkit!
Collect the data
For each scenario, you collect data that helps you substantiate both the likelihood and the impact as accurately as possible.
Start with the data available within your own organization. There is often more relevant information available than you might initially think. Examples include revenue figures, incident records, or data from your email filter on blocked spam and phishing messages.
Supplement this internal data with reliable external sources, such as sector and market data, scientific research, and publications from reputable institutions such as ENISA and Cyentia. This creates a well-founded and realistic view of the risks for each scenario.
Populate the FAIR model
The FAIR model consists of several elements that help you determine the likelihood and impact of a risk. An important principle is that you work with ranges.
No one has a crystal ball that can predict the exact magnitude of a risk. The FAIR model cannot do this either. Instead of relying on a single exact figure, the model uses statistical distributions.
You therefore translate the collected data into three values: a minimum, a maximum, and a most likely outcome. This can be an amount, a quantity, or a percentage.
Example
Take a GDPR fine, for example. In the most extreme scenario, this can amount to 4% of global annual turnover. In a favorable scenario, the fine may be limited to a few hundred euros. The most likely outcome could, for example, be several thousand euros.
Simulate the FAIR model)
You have now populated the FAIR model with a minimum, a maximum, and a most likely value. These values indicate how large the loss could be, but not yet how often that loss might occur.
In practice, cyber incidents often end without major consequences. The SOC intervenes in time, a laptop is reinstalled, or the cloud provider is back online within half an hour. But when an incident does escalate, the consequences can be significant.
To make this variation in the likelihood and impact of cyber risks visible, the completed FAIR model is calculated thousands of times using Monte Carlo simulations. This produces a realistic distribution of possible outcomes.
Monte Carlo simulation
A Monte Carlo simulation calculates a scenario thousands of times using random values within the selected ranges. This creates a realistic distribution of possible outcomes and provides insight into both likely losses and exceptionally high losses. The method has been widely used for many years in the financial sector and in risk management.