Case BE17E1 · GRC · L4 Advanced
Cyber Risk Quantification with FAIR
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- FAIR: Risk = Loss Event Frequency x Loss Magnitude; LEF = Threat Event Frequency x Vulnerability (susceptibility).
- Use calibrated ranges (min / most likely / max) instead of point estimates; run Monte Carlo simulation.
- Output is a loss exceedance curve: probability that annual loss exceeds each dollar amount.
- Loss magnitude splits into primary (response, replacement) and secondary (fines, lawsuits, reputation) losses.
- Enables ROI: compare annualized loss before vs after a control against the control's cost.
If the interviewer pushes back
- How do you defend FAIR estimates when a skeptic says the inputs are just guesses?
- When is a qualitative 5x5 heat map still the better tool?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.