FAIR Risk Quantification
Monte Carlo simulation using the FAIR model, exercise-to-FAIR bridge that converts gaps into financial risk scenarios, and annualized loss expectancy percentiles.
After Action implements the Factor Analysis of Information Risk (FAIR) model to translate exercise findings into financial risk language. Monte Carlo simulation produces probabilistic loss estimates that executives and board members can act on.
The FAIR Model
FAIR decomposes cyber risk into quantifiable factors:
Risk = Loss Event Frequency × Loss Magnitude
Loss Event Frequency = Threat Event Frequency × Vulnerability
Loss Magnitude = Primary Loss + (Secondary LEF × Secondary Loss)
Input Parameters
| Parameter | Description | Input Format | |---|---|---| | Threat Event Frequency (TEF) | How often threat events occur per year | Min, Most Likely, Max | | Vulnerability | Probability that a threat event results in a loss | 0 to 1 range | | Primary Loss | Direct costs (response, remediation, business disruption) | Dollar range | | Secondary Loss | Indirect costs (fines, lawsuits, reputation damage) | Dollar range | | Secondary LEF | Probability that secondary losses materialize | 0 to 1 range |
Each parameter accepts a three-point estimate (minimum, most likely, maximum) with an optional confidence rating from 1 to 5.
Monte Carlo Simulation
The engine runs up to 100,000 iterations of the FAIR model using the input distributions. The output includes:
- Annualized Loss Expectancy (ALE) — Mean expected annual loss
- Percentile distribution — 10th, 25th, 50th, 75th, 90th, and 95th percentile loss values
- Loss exceedance curve — Probability of exceeding specific loss thresholds
- Distribution histogram — Visual representation of the loss distribution
Exercise-to-FAIR Bridge
The most powerful feature is the automatic conversion of exercise gaps into FAIR risk scenarios. The bridge works by:
- Gap analysis — Each exercise gap is categorized by type and severity
- Scenario generation — Gaps are mapped to threat scenarios with calibrated input parameters
- Simulation — Monte Carlo runs for each generated scenario
- Aggregation — Results are combined into a portfolio view of organizational risk
For example, a critical detection gap might generate a scenario with higher vulnerability estimates, while a communications gap might increase secondary loss estimates due to regulatory exposure.
Using the Results
Board Communication
FAIR results translate technical findings into financial terms. Instead of reporting that the organization has a critical detection gap, you can report a projected annualized loss expectancy with confidence intervals.
Insurance Conversations
FAIR outputs directly support insurance coverage discussions by quantifying the financial exposure that exercise findings reveal.
Investment Justification
By running FAIR scenarios before and after proposed remediation, teams can calculate the expected risk reduction in dollar terms to justify security investment.