The one-line equation
FAIR stands for Factor Analysis of Information Risk, the model created by Jack Jones and published today by The Open Group as Open FAIR. It defines risk in a single line: risk is loss event frequency multiplied by loss magnitude.
Everything else in the model exists to estimate those two things without guessing.
The frequency branch
Loss event frequency comes out of two factors that multiply.
The first is threat event frequency: how many times a year an actor acts against the asset. The model opens that factor into contact frequency and probability of action, because plenty of traffic touches an asset without trying anything. An exposed server takes automated scanning all day, and only a small fraction of it turns into a directed attempt.
The second factor is vulnerability, which in FAIR's vocabulary carries its own meaning and does not correspond to a CVE. It is the probability that the attempt succeeds, derived by comparing threat capability against the resistance strength of the control. A capable actor against a weak control yields a vulnerability near 1. The same control against an amateur yields a much smaller number.
That split explains why a poorly inventoried external surface raises risk without any new flaw appearing. More reachable assets means more contact frequency, and contact frequency enters the calculation before any conversation about patching.
The magnitude branch
Magnitude divides into primary loss and secondary risk.
Primary loss is what the organization spends and forgoes on its own account: response hours, operational downtime, asset replacement, lost productivity.
Secondary risk comes from the reaction of outside parties, and the model treats it as a separate event with its own frequency and its own magnitude. Not every incident turns into a fine or a headline. The share that does is exactly what secondary loss event frequency estimates, and it is where most homemade analyses go wrong, because they add the maximum fine to every scenario.
FAIR organizes losses into six forms: productivity, response, replacement, fines and judgments, competitive advantage, and reputation. The last two are the hardest to estimate and often dominate the total. Forcing the analyst to name them is half the value of the model.
Why estimates enter as ranges
None of these nodes has a known exact value. FAIR handles that with calibrated estimation: instead of a number, the analyst gives a minimum, a maximum, and a most likely value, and states the confidence level of the range.
Calibration is a trainable skill. A calibrated person lands inside the range they declared about 90% of the time when they say 90%. Someone who has never trained gives ranges that are far too narrow and misses far more often than they think.
A simulation runs over those ranges, almost always Monte Carlo, drawing thousands of scenarios and returning a loss distribution rather than a point. Out of that distribution come the annualized loss expectancy and the tail percentiles used in CRQ practice.
The gain here is honesty about uncertainty. A single number hides it. A range shows its size, and shows which variable deserves research next cycle, because it is the one widening the result most.
What Open FAIR standardizes
The Open Group publishes FAIR as an open standard, with a taxonomy that fixes the name and the position of every factor and a method describing how to run the analysis. There is a practitioner certification as well.
What standardization buys in practice is comparability. Two analyses run by different teams use the same tree, the same name for each node, and the same range discipline, so you can set them side by side and argue about the difference. Without it, every function invents its own spreadsheet and the risk committee receives three numbers that do not speak to one another.
Where analyses go wrong
The most common error is scoping. "Ransomware risk" describes an entire category. A scenario is a specific actor acting on a specific asset with a specific effect, and without that framing there is no way to estimate frequency.
The second is unsupported input. FAIR disciplines the reasoning and supplies no data. If contact frequency comes from a stale inventory, the model returns a well-formed distribution sitting on a wrong assumption, and the neatness of the chart lends it authority it has not earned.
The third is mistaking FAIR for a control framework. NIST CSF and ISO 27001 organize a security program into domains. FAIR measures the exposure that remains afterward. The two coexist well, and swapping one for the other leaves a hole in either direction.