Cloud Wars
  • Home
  • Top 10
  • CW Minute
  • CW Podcast
  • Categories
    • AI and Copilots
    • Innovation & Leadership
    • Cybersecurity
    • Data
  • Member Resources
    • Cloud Wars AI Agent
    • Digital Summits
    • Guidebooks
    • Reports
  • About Us
    • Our Story
    • Tech Analysts
    • Marketing Services
  • Summit NA
  • Dynamics Communities
  • Ask Copilot
Twitter Instagram
  • Summit NA
  • Dynamics Communities
  • AI Copilot Summit NA
  • Ask Cloud Wars
Twitter LinkedIn
Cloud Wars
  • Home
  • Top 10
  • CW Minute
  • CW Podcast
  • Categories
    • AI and CopilotsWelcome to the Acceleration Economy AI Index, a weekly segment where we cover the most important recent news in AI innovation, funding, and solutions in under 10 minutes. Our goal is to get you up to speed – the same speed AI innovation is taking place nowadays – and prepare you for that upcoming customer call, board meeting, or conversation with your colleague.
    • Innovation & Leadership
    • CybersecurityThe practice of defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.
    • Data
  • Member Resources
    • Cloud Wars AI Agent
    • Digital Summits
    • Guidebooks
    • Reports
  • About Us
    • Our Story
    • Tech Analysts
    • Marketing Services
    • Login / Register
Cloud Wars
    • Login / Register
Home » How FAIR Helps the Cybersecurity Industry “Speak the Language of Business” With Risk Quantification
Cybersecurity

How FAIR Helps the Cybersecurity Industry “Speak the Language of Business” With Risk Quantification

Chris HughesBy Chris HughesOctober 25, 2022Updated:October 25, 20224 Mins Read
Facebook Twitter LinkedIn Email
FAIR cyber risk
Share
Facebook Twitter LinkedIn Email
Acceleration Economy Cybersecurity

In a previous article, we discussed confronting cybersecurity with data, particularly quantifiable metrics. The cybersecurity industry traditionally has measured and conveyed cyber risk in subjective qualitative terms and concepts. This has led to a disconnect from its business leadership peers, especially as cybersecurity continues to get escalated to the boardroom with emerging changes from the Securities and Exchange Commission (SEC), as well as broad concerns for cyber risks. In this article, we discuss a popular quantitative risk management framework that addresses the concern.

Introducing FAIR

The framework is the Factory Analysis of Information Risk (FAIR) model for cybersecurity and operational risk. FAIR is led by the FAIR Institute, which boasts more than 13,000 worldwide members, 45% of Fortune 1000 organizations, and 23 local chapters. FAIR’s overarching goal is to shift from a compliance-centric approach to a risk-based approach for cyber risk quantification.

FAIR recognizes that in today’s digitally driven society, organizations use technology and software to empower business value delivery. All of those systems and software are subject to cybersecurity risks. That risk is business risk, which must be communicated in business terms and figures, something the cybersecurity industry has traditionally been poor at, despite calls to “speak the language of the business.”

FAIR argues organizations already manage risk, but most are doing it implicitly and should be doing it explicitly. This means shifting to a quantified risk target that the organization measures and manages against. This also requires the organization to have established a coherent risk appetite framework.

A Deeper Dive Into FAIR

FAIR aims to have organizations utilize quantitative risk models that leverage people, processes, and technology to empower organizations to achieve acceptable levels of loss exposures. This means that rather than traditional subjective measures of cyber risk management, organizations have accurate models with meaningful measurements and baseline data to drive well-informed decisions.

FAIR flowchart
Source: FAIR Flowchart

As evident from the above FAIR Flowchart, measuring cybersecurity and operational risk requires a more mature approach, including defining fundamental concepts and metrics that most enterprises simply haven’t done. These include metrics such as loss event frequency and loss magnitude as well as subsequent metrics such as primary loss and secondary risk.

Measuring cybersecurity and operational risk also requires organizations to do fundamental activities such as identifying all their assets and relevant threats as well as understanding the various potential loss events and their associated potential impacts accurately. On the surface, this sounds simple, but organizations have struggled for decades to accurately inventory their hardware and software assets. The issue is only getting worse with the advent of the cloud, where shadow information technology (IT) can proliferate with a few clicks and corporate credit cards.

That said, all is not lost. There are several resources available for individuals and organizations looking to get serious about cyber risk quantification via the FAIR model. There, of course, is the book “Measuring and Managing Information Risk: A FAIR Approach” and even FAIR training and certifications.

Final Thoughts

You may be questioning why all of this matters. The reality is that if we, as a cybersecurity industry, want to be taken seriously by our business peers, it requires speaking their language and this means tying cyber risk to the business, and not in a subjective speculative manner, but through metrics and quantifiable data around assets, risk, and loss. It is hard to advocate for an increased budget for the cyber program or investments in insurance, staff, training, or any related resources if we can’t articulate the current state of the organization’s assets and data as well as the risk associated with them.

As an industry, cybersecurity long has bemoaned being neglected at the proverbial “seat at the table” and the desire to be escalated in the conversation. That escalation requires a maturing not only on the businesses’ part but also among cyber practitioners.


Want more cybersecurity insights? Visit the Cybersecurity channel:

Acceleration Economy Cybersecurity

Board of Directors Cloud Cybersecurity data featured risk Risk Management
Share. Facebook Twitter LinkedIn Email
Analystuser

Chris Hughes

CEO and Co-Founder
Aquia

Areas of Expertise
  • Cloud
  • Cybersecurity
  • LinkedIn

Chris Hughes is a Cloud Wars Analyst focusing on the critical intersection of cloud technology and cybersecurity. As co-founder and CEO of Aquia, Chris draws on nearly 20 years of IT and cybersecurity experience across both public and private sectors, including service with the U.S. Air Force and leadership roles within FedRAMP. In addition to his work in the field, Chris is an adjunct professor in cybersecurity and actively contributes to industry groups like the Cloud Security Alliance. His expertise and certifications in cloud security for AWS and Azure help organizations navigate secure cloud migrations and transformations.

  Contact Chris Hughes ...

Related Posts

Workday Dismisses Agentic AI Arms Race, Focuses on Business Impact

May 16, 2025

Workday Lone Wolf: Focuses on 8 AI Agents vs. Competitors’ Hundreds

May 16, 2025

C-Suite Perspective: What the AI-Powered Org Looks Like, Today and in The Future

May 15, 2025

AI Maturity Declines Year Over Year, But Leaders Push Ahead on Innovation, AI Skills

May 15, 2025
Add A Comment

Comments are closed.

Recent Posts
  • Workday Dismisses Agentic AI Arms Race, Focuses on Business Impact
  • Workday Lone Wolf: Focuses on 8 AI Agents vs. Competitors’ Hundreds
  • C-Suite Perspective: What the AI-Powered Org Looks Like, Today and in The Future
  • AI Maturity Declines Year Over Year, But Leaders Push Ahead on Innovation, AI Skills
  • Microsoft’s Mission to Make Your Company AI First

  • Ask Cloud Wars AI Agent
  • Tech Guidebooks
  • Industry Reports
  • Newsletters

Join Today

Most Popular Guidebooks

Accelerating GenAI Impact: From POC to Production Success

November 1, 2024

ExFlow from SignUp Software: Streamlining Dynamics 365 Finance & Operations and Business Central with AP Automation

September 10, 2024

Delivering on the Promise of Multicloud | How to Realize Multicloud’s Full Potential While Addressing Challenges

July 19, 2024

Zero Trust Network Access | A CISO Guidebook

February 1, 2024

Advertisement
Cloud Wars
Twitter LinkedIn
  • Home
  • About Us
  • Privacy Policy
  • Get In Touch
  • Marketing Services
  • Do not sell my information
© 2025 Cloud Wars.

Type above and press Enter to search. Press Esc to cancel.

  • Login
Forgot Password?
Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.