Why CVE counts fail the board
Most cyber reporting to executives is a translation failure. A slide showing '4,200 critical vulnerabilities, down 6% this quarter' tells a board nothing actionable: it cannot be compared to the cost of the control that would reduce it, it does not say which of those vulnerabilities could actually cause a material loss, and it does not fit into any framework the board already uses to make trade-offs.
The result is that cyber gets funded on fear and anecdote rather than expected value. FAIR exists to fix that — to put cyber risk in the one unit every other business risk already speaks: money.
How FAIR decomposes risk
FAIR models a risk as loss event frequency multiplied by loss magnitude. Loss event frequency is broken down into threat event frequency (how often a threat actor acts against the asset) and vulnerability (the probability that action succeeds). Loss magnitude separates primary loss (direct costs — response, replacement, downtime) from secondary loss (fines, legal, reputational fallout, and the probability those secondary effects actually materialise).
Crucially, analysts do not guess single numbers. They provide calibrated ranges — a minimum, most likely and maximum — reflecting genuine uncertainty. This avoids the false precision that discredits most risk models and forces an honest conversation about what is and is not known.
From ranges to a loss distribution
Because the inputs are ranges, the output is a distribution, not a single figure. A Monte Carlo simulation samples across the input ranges thousands of times to produce a curve of possible annualised losses. From that curve you can read an annualised loss expectancy (the average), but also the tail — the 90th or 95th percentile 'bad year' that often matters more for capital and insurance decisions.
This is the same statistical discipline that market and credit risk teams have used for decades. Expressing cyber risk this way lets it slot directly into an enterprise risk appetite framework rather than living in a separate, incomparable silo.
Technical data makes FAIR credible
FAIR is only as good as its inputs, and this is where technical security data earns its keep. Exploitability signals — whether a vulnerability is on CISA's Known Exploited Vulnerabilities list, its EPSS probability of exploitation — sharpen the 'vulnerability' factor. Asset criticality and attack-path analysis, which trace whether an exposure can actually reach a crown-jewel system, sharpen loss magnitude and threat event frequency.
In other words, exposure management and FAIR are complementary, not competing: the exposure graph tells you which weaknesses are reachable and exploitable, and FAIR converts that reachability into a defensible dollar figure. Fed by live telemetry, the estimate updates as the environment changes rather than being a once-a-year workshop artefact.
Making it operational
The organisations that get value from FAIR treat it as a running capability, not a spreadsheet exercise. They maintain a small library of well-scoped risk scenarios, feed them from live asset, exposure and threat data, and re-run the quantification as conditions change. When a new actively-exploited vulnerability lands on a critical asset, the annualised loss for the relevant scenario moves, and the case for remediation makes itself.
Done well, FAIR changes the security conversation from 'we found a lot of bad things' to 'here is the expected loss, here is what reduces it most per dollar, and here is where it sits against our risk appetite'. That is the language a board can act on.