skip to content

Using FAIR quantitative risk analysis, how would you answer a board asking how much a ransomware outage could cost per year?

level: seniorimportance: should knowfreq 35%

answer

  1. frequency times magnitude
  2. how often, then how bad
  3. ranges, not point estimates
  4. simulate to a loss distribution
  5. answer with percentiles

basics

~20 s

FAIR splits the scenario into loss event frequency and loss magnitude, estimates each as a calibrated range, and simulates them into an annual loss distribution. The board gets a median and a severe-year figure, not one number or a colour.

solid answer

~50 s

FAIR (Factor Analysis of Information Risk) defines risk as the probable frequency and probable magnitude of future loss. First scope one scenario: ransomware actors encrypt core systems and halt operations. Estimate **loss event frequency**, from threat event frequency and *vulnerability* (in FAIR, the probability that an attack becomes a loss), and **loss magnitude**, split into primary loss (response, recovery, lost productivity) and secondary loss (regulators, customers, litigation, reputation). Each input is a range — minimum, most likely, maximum — from incident data, industry studies and calibrated experts. A Monte Carlo simulation combines them into an annualized loss distribution. The board answer is: "a typical year costs about X; there is a 10% chance of a year above Y; the proposed control moves Y to Z for this cost". NIST SP 800-30 notes quantitative results best support cost-benefit analysis of responses, but lose rigour when subjective inputs are hidden, so state the assumptions.

go deeper

for a junior

Recall that FAIR expresses risk as loss event frequency and loss magnitude, estimated as ranges rather than single values.

for a middle

Explain the factor tree: threat event frequency and vulnerability behind frequency, primary and secondary loss behind magnitude, and why a simulation is used.

for a senior

Show that you can scope a scenario, source and calibrate ranges, present percentiles to executives and use the result to compare a control's cost with the loss it removes.

for a principal

Discuss where quantification earns its cost across the register, how to keep it honest when data is thin, and how the loss distribution sets insurance limits and appetite.

## Why the board's question needs a quantitative answer "How much could ransomware cost us per year?" is a money question. A qualitative rating such as "High" does not answer it, cannot be compared with the cost of a control, and cannot be set against an insurance limit. NIST SP 800-30 Rev. 1 (section 2.3.2) frames the trade-off: **qualitative** assessments "support communicating risk results to decision makers" but their small range of values makes prioritisation difficult; **quantitative** assessments "most effectively support cost-benefit analyses of alternative risk responses", but "rigor is significantly lessened when subjective determinations are buried" in them. FAIR is a widely used method for doing quantitative analysis while keeping the subjectivity visible. ## The FAIR model **FAIR (Factor Analysis of Information Risk)** defines risk as the *probable frequency and probable magnitude of future loss*, and breaks each into factors that can be estimated: | Factor | Meaning | Ransomware example | |---|---|---| | **Loss event frequency (LEF)** | How often per year a loss actually occurs | Successful encryption of core systems | | Threat event frequency | How often an attack is attempted | Intrusion attempts that reach the network | | Vulnerability | Probability an attempt becomes a loss (not a CVE) | Share of attempts that get past controls | | **Loss magnitude (LM)** | How much one event costs | Total cost of one outage | | Primary loss | Borne directly by the organization | Response, recovery, lost productivity, replacement | | Secondary loss | From reactions of others | Regulators, customers, litigation, reputation | FAIR groups loss into six forms: productivity, response, replacement, fines and judgments, competitive advantage and reputation. Listing them stops an analysis from counting only the IT recovery bill. ## Running the analysis 1. **Scope one scenario precisely**: asset (core operations), threat community (financially motivated ransomware groups), effect (loss of availability, possibly data theft). 2. **Estimate frequency** as a range: for example, between once in twenty years and once in three years, most likely once in eight. Sources: internal incident history, sector loss data, and experts trained to give calibrated ranges. 3. **Estimate magnitude** per loss form, again as ranges: days of downtime times revenue and staff cost per day, response spend, regulatory exposure, customer churn. 4. **Simulate.** A Monte Carlo run draws from every range thousands of times and produces a distribution of annual loss. 5. **Read the output** as percentiles or a loss exceedance curve: the probability that annual loss exceeds each amount. ## What to tell the board - **A typical year**: the median annual loss, often small because most years have no event. - **A bad year**: the 90th or 95th percentile, the figure that matters for capital, insurance and appetite. - **The assumptions**: which ranges drive the result, so the board can challenge them. - **The decision**: how the distribution shifts if the proposed control (immutable backups, segmentation, faster restore) is funded, compared with its cost, and what insurance limit would cover the tail. This turns a ransomware conversation into a treatment decision with numbers on both sides. ## Why ranges and not points A single expected-loss figure, the classic frequency-times-single-loss calculation, hides the fact that ransomware losses are heavy-tailed: most years cost little, a few cost a great deal. Ranges carry the estimator's uncertainty through to the result, and a wide output distribution is itself information: it says more data would change the decision. False precision ("$4,213,000 per year") invites exactly the distrust SP 800-30 warns about. ## Limits and pitfalls - **Garbage in**: uncalibrated guesses produce confident nonsense. Record the source of every range. - **Scenario creep**: one analysis per scenario; "cyber risk" as a whole is not a scenario. - **Double counting** between primary and secondary loss. - **Treating the output as a forecast** rather than a decision aid for comparing options. The quantitative answer does not replace the register; it enriches the rows that carry the largest decisions.

  • With no internal ransomware history, where do the frequency ranges come from?
    From sector loss data and incident reports, from the organization's near-misses such as blocked intrusions and malware detections, and from experts trained to give calibrated ranges. The ranges are wider because data is thin, and the analysis records each source so the board can see which assumptions dominate and which data would narrow them.
  • How does the FAIR output inform a treatment decision?
    Run the scenario again with the proposed control applied, for example faster tested restores cutting downtime, and compare the two loss distributions. If the reduction in the tail and in typical annual loss exceeds the control's annual cost, mitigation is justified; the remaining tail can be compared with insurance limits and with the stated risk tolerance.

saying these in an interview costs you the question

  • Quantitative analysis cannot start until precise loss data exists.
  • One expected-loss number is the best answer to give the board.
  • Vulnerability in FAIR means a CVE present on a host.
  • Qualitative High, Medium and Low ratings can be multiplied to get money.
  • A wide output range means the analysis failed.