Sentrio

Open FAIR: cyber risk as a distribution, not a rating

FAIR (Factor Analysis of Information Risk) is an international standard, maintained as Open FAIR by The Open Group, for expressing cyber risk in financial terms rather than subjective scales like High, Medium or Low. Instead of rating a risk by intuition, it decomposes it into two measurable factors: how often a loss event is expected to occur, and how much it costs when it does. Sentrio uses Open FAIR as the ontology of its quantitative model, and shows every result as a range with its provenance.

The terms you need to know

LEF
Loss Event Frequency
How many times per year a loss event is expected to occur. It derives from how often a threat comes into contact with the asset, the probability that it acts, and the proportion of those attempts that defeat existing controls. An LEF of 0.5 means the event is expected once every two years.
TEF
Threat Event Frequency
How often a threat community acts against the asset in a year, whether or not it succeeds. It is the observable anchor: attempts you can count, before the controls decide the outcome.
Vuln
Vulnerability
The probability that a threat event becomes a loss event: the share of attempts that defeat the controls in place. Loss Event Frequency is Threat Event Frequency multiplied by Vulnerability.
LM
Loss Magnitude
What a loss event costs. Primary loss is what the organization pays directly: response, replacement, disruption. Secondary loss is what follows: fines, litigation, lost customers. Sentrio monetizes only what the organization pays; harm to people is shown as a declared, non-monetized impact next to the number.

The formulas

Risk

Risk = Loss Event Frequency × Loss Magnitude

Loss event frequency

LEF = Threat Event Frequency × Vulnerability

Loss magnitude

LM = Primary Loss + Secondary Loss

The result

Annual loss = a distribution: percentiles, P(no loss), exceedance curve

Why a distribution, not a number

A single expected value hides how wide the uncertainty is and how often a year passes with no loss at all. Sentrio’s engine draws frequency and magnitude with their ranges and produces the annual loss distribution: percentiles, the probability of a zero-loss year, and the exceedance curve, before insurance or transfers. Next to the range goes its quality: how well sustained each input is and where it comes from.

Lack of data widens the estimate; it never hides a number. A threat hitting the same vertical in the same region, contextualized to the organization, is a legitimate input and goes to the board with its wide range and its provenance sentence.

How a scenario is read

Illustrative figures to show the reading, not customer data or a Sentrio result.

  1. 1

    Scenario: ransomware encrypting the billing servers, for the population of servers that run invoicing.

  2. 2

    Accepted frequency (LEF): 0.2 to 0.6 events per year, anchored on observed attempts and the controls in place.

  3. 3

    Accepted magnitude (LM): USD 300,000 to 1,200,000 per event across response, downtime and notification.

  4. 4

    Annual loss: P50 ≈ USD 190,000 · P90 ≈ USD 640,000 · probability of a zero-loss year ≈ 67%

  5. 5

    Quality: frequency is a declared estimate, magnitude is documented, controls evidence is partial. The bottleneck is frequency; completing it narrows the range.

That is a sentence a board can act on: a range, what sustains it, and what would narrow it. “High” is not.

Controls and the number

Controls bound the distribution once their contribution is evidenced; they never give a precise number. A control that exists in the inventory gets no credit for existing. Detecting never reduces risk by itself; it enables the response. Sentrio does not use FAIR-CAM or derived content; the causal layer of controls is Sentrio’s own.

Frequently asked questions

What is the FAIR methodology?

FAIR (Factor Analysis of Information Risk) is an international standard, maintained as Open FAIR by The Open Group, that expresses cyber risk in financial terms. It decomposes each risk scenario into the expected frequency of loss events and the magnitude of loss per event, so the result is traceable back to explicit assumptions rather than to an opinion.

What is the difference between Threat Event Frequency and Loss Event Frequency?

Threat Event Frequency counts how often a threat acts against the asset, successful or not. Loss Event Frequency counts how often that action becomes a loss. The difference between them is Vulnerability: the share of attempts the controls in place fail to stop.

Why a range rather than a single number?

A single number hides how uncertain it is and how often nothing happens. A distribution shows the typical year, the bad year, and the probability of no loss at all, and it lets a board compare a scenario against its risk appetite honestly.

What data do you need to start?

None is required to create a scenario. General organization data, data that belongs to a process or an asset, and scenario-specific data are loaded once and inherited. Missing data widens the range; it does not block the calculation. Telemetry narrows the picture, but nothing waits for it.

Why replace High, Medium and Low scales?

Qualitative scales cannot be summed, compared or budgeted against. Two "High" risks can differ by an order of magnitude in expected loss, and an ordinal scale cannot justify a budget to a CFO. Expressing risk in currency, with its range, makes it comparable with any other financial decision.

See your estate as a map before the next budget cycle.

Thirty minutes with the team is enough to walk one route end to end.

Talk to the team