Open cardosec

Case BE17E1 · GRC · L4 Advanced

Cyber Risk Quantification with FAIR

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. FAIR: Risk = Loss Event Frequency x Loss Magnitude; LEF = Threat Event Frequency x Vulnerability (susceptibility).
  2. Use calibrated ranges (min / most likely / max) instead of point estimates; run Monte Carlo simulation.
  3. Output is a loss exceedance curve: probability that annual loss exceeds each dollar amount.
  4. Loss magnitude splits into primary (response, replacement) and secondary (fines, lawsuits, reputation) losses.
  5. Enables ROI: compare annualized loss before vs after a control against the control's cost.

If the interviewer pushes back

  • How do you defend FAIR estimates when a skeptic says the inputs are just guesses?
  • When is a qualitative 5x5 heat map still the better tool?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.