Principle Security Principle Security.

Risk quantification · FAIR-lite

Put a dollar range on a cyber scenario

Boards don't act on red-yellow-green. They act on money. Describe one scenario, estimate how often it could happen and what it would cost, and get a board-readable annualized loss range — the FAIR way, in about a minute.

One specific loss event — e.g. "member data breached," "wire fraud via BEC," "core outage."

Once every 3 years

Loss Event Frequency — the honest, uncertain estimate. Drag it.

$
$

Cost includes downtime, recovery, notification, legal, regulatory and reputational loss — the full impact, not just the ransom or the IT bill.

Board risk one-pager

Annualized loss exposure
Most-likely single loss
Expected frequency
If you halve the frequency
If you halve the impact

How this is calculated

This is FAIR-lite. Annualized loss exposure = loss-event frequency × most-likely single-loss magnitude, with a low-to-high band from your cost estimates. FAIR (Factor Analysis of Information Risk) is the open standard for quantifying cyber risk in dollars. The point isn't a precise number — it's a defensible range your board can weigh against the cost of controls. A full FAIR analysis models frequency and magnitude as distributions and runs a Monte Carlo simulation; this gives you the board-level shape in a minute.

Questions

Why a range instead of one number?+

Cyber risk is uncertain. An honest estimate is a band with a most-likely figure — a defensible range beats a precise-looking invention.

How do I lower the exposure?+

Reduce frequency (prevention) or reduce impact (resilience). The one-pager shows the dollar effect of halving each, so you can compare a control's cost to the risk it removes.

Want this for your real risk register?

We build FAIR-based risk quantification into board reporting — the scenarios that matter to your business, modeled properly, in language the board acts on.