Meet Polar Risk on Cybersec NL on the 9th and 10th of September in the Jaarbeurs Utrecht.
—  FAIR

Factor Analysis of Information Risk (FAIR)

The Cyber Risk Assessment uses the internationally recognised FAIR methodology to translate cyber risk into concrete financial impact.
—  CRQ in a nutshell

Cyber risk in numbers.

Cyber Risk Quantification (CRQ) analyses and manages cyber risk on the basis of objective data, usually expressed in money.

The aim is not to predict to the last euro; nobody has a crystal ball. The aim is to reduce uncertainty: what is the realistic worst case?
FROM LABELS TO NUMBERS
Traditional
High · Medium · Low
Qualitative labels. Hard to compare. Other variants include: often, sometimes, never.
Quantitative
Percentages and concrete amounts
Concrete likelihoods and amounts. Risks can be compared with one another.
—  The FAIR model

Breakdown of Likelihood × impact

Like other methods, FAIR sees risk as a combination of likelihood and impact. The difference: FAIR makes explicit what that likelihood and impact are built from.
Cyber Risk
Risk = Likelihood × Impact
Loss Event Frequency
Likelihood
How often does it go wrong?
Threat event frequency
Threat event frequency
How often a threat actually attempts to reach your environment.
Contact frequency
Probability of action
Susceptibility
Susceptibility
The chance that such an attempt actually succeeds.
Resistance strength
Threat capability
×
Loss Magnitude
Impact
How bad is it when it goes wrong?
Primary loss
Primary loss
Costs that follow directly from the incident, such as recovery and downtime.
Lost revenue
Reputational damage
Recovery costs
Secondary loss
Secondary loss
Indirect consequences that may follow from the incident.
Fines
Liability
—  Why FAIR

The value of FAIR

Decisions based on data
Steer on objective numbers instead of gut feel.
Linked to business impact
Translate threats into consequences the board understands.
Risks made comparable
Weigh scenarios and measures on the same scale.
—  FAIR in practice

Four steps to an evidence-based risk analysis

Define the risk scenario
To quantify accurately, it has to be crystal clear what you are talking about:
  • which systems are at risk
  • which threat is at play
  • what the consequence of that is
Together, those three define the scenario and form the basis for every number that follows.
Want to know more about building good risk scenarios? Use the Polar Toolkit!
Collect the data
For each scenario, you collect data that helps you substantiate both the likelihood and the impact as accurately as possible.
Start with the data available within your own organization. There is often more relevant information available than you might initially think. Examples include revenue figures, incident records, or data from your email filter on blocked spam and phishing messages.
Supplement this internal data with reliable external sources, such as sector and market data, scientific research, and publications from reputable institutions such as ENISA and Cyentia. This creates a well-founded and realistic view of the risks for each scenario.
Populate the FAIR model
The FAIR model consists of several elements that help you determine the likelihood and impact of a risk. An important principle is that you work with ranges.
No one has a crystal ball that can predict the exact magnitude of a risk. The FAIR model cannot do this either. Instead of relying on a single exact figure, the model uses statistical distributions.
You therefore translate the collected data into three values: a minimum, a maximum, and a most likely outcome. This can be an amount, a quantity, or a percentage.
Example
Take a GDPR fine, for example. In the most extreme scenario, this can amount to 4% of global annual turnover. In a favorable scenario, the fine may be limited to a few hundred euros. The most likely outcome could, for example, be several thousand euros.
Simulate the FAIR model)
You have now populated the FAIR model with a minimum, a maximum, and a most likely value. These values indicate how large the loss could be, but not yet how often that loss might occur.
In practice, cyber incidents often end without major consequences. The SOC intervenes in time, a laptop is reinstalled, or the cloud provider is back online within half an hour. But when an incident does escalate, the consequences can be significant.
To make this variation in the likelihood and impact of cyber risks visible, the completed FAIR model is calculated thousands of times using Monte Carlo simulations. This produces a realistic distribution of possible outcomes.
Monte Carlo simulation
A Monte Carlo simulation calculates a scenario thousands of times using random values within the selected ranges. This creates a realistic distribution of possible outcomes and provides insight into both likely losses and exceptionally high losses. The method has been widely used for many years in the financial sector and in risk management.
—  FAIR in practice

Where regulation and FAIR meet

FAIR has underpinned the numbers behind cyber risk in the United States for years. That same proven approach now supports European regulation too.

SEC Form 8-K

Listed companies must report cyber incidents with a 'material impact'. In the US, organisations determine that impact with FAIR, both in advance and during an incident, in a way that is evidenced and defensible to the regulator.

NIS2 / Cbw

The EU requires risk management and proportionate measures. With FAIR you evidence that judgement in euros, the same evidence American companies already use to convince their regulator.
—  Polar risk

How we apply FAIR

Polar Risk translates the FAIR method into two concrete services.
Complete

Cyber Risk Assessment

Your relevant cyber risks quantified in euros using the internationally recognized FAIR methodology. Transparent, repeatable, and recalibratable over time.
Targeted

Cyber Economics

The cyber risk of a single strategic decision, quantified in euros. Cloud, acquisition, or cyber insurance: know what your decision truly costs before you make it.

Want to know what FAIR could do for you?

Book a no-obligation conversation with one of our FAIR specialists.