From Guesswork to Decision Science:
Using FAIR to Quantify Information Security Risk
A Data-Driven Approach to Risk Management for Data Professionals
Margaret Dibor
FAIR Certified Risk Management Specialist | Founder, EtutekiLab | DAMA Webinar Series
About the Speaker
Margaret Dibor
Founder, EtutekiLab | Healthcare Security Specialist
Margaret helps organizations protect their most sensitive asset—patient data. With over 17 years of experience in cybersecurity, privacy, and telecommunications, she has led security programs, achieved ISO 27000 certifications, HIPAA compliance, and met regulatory requirements including GDPR and PIPEDA.
As Founder of EtutekiLab, Margaret builds AI-driven tools that make security maturity and compliance faster, easier, and truly scalable. Her mission is to help organizations reduce risk, build trust, and protect the people who rely on them.
Focus Areas
Safeguarding PHI • Securing digital health platforms • Risk management • Responsible AI adoption • Transforming security into a growth enabler
Today's Agenda
Part 1: The Problem (Why qualitative risk fails)
Part 2: FAIR Framework (Principles and methodology)
Part 3: Practical Applications (Real-world scenarios)
Part 4: Business Communication (Executive reporting)
Part 5: Implementation (Getting started)
Quick Poll
How does your organization quantify cybersecurity risk?
Heat maps (Red/Yellow/Green)
Qualitative ratings (High/Medium/Low)
Dollar values and probabilities
We don't formally assess risk
Combination of methods
Organizations Manage Risk Every Day
💰 Financial Risk
Portfolio: $2.5M
Loss probability: 15%
Expected: $37,500
⚙️ Operational Risk
Supply chain
Probability: 3%/quarter
Cost: $1.2M
🔒 Information Risk
Data breach: "HIGH" 🔴
Vendor access: "MEDIUM" 🟡
???
Why do we use numbers for everything EXCEPT information risk?
What Does "High Risk" Actually Mean?
Scenario: CIO presents "High Risk" data breach to CFO
CIO thinks:
"This could happen in the next 2 years and cost us $500K"
CFO thinks:
"High like high blood pressure? Or high like high stock price? What's the actual number?"
The Problem:
❌ Can't compare across risk types
❌ Can't calculate ROI on controls
❌ Can't prioritize objectively
❌ Different interpretations
The Heat Map Problem
Likelihood →
Low
Low
Med
High
High
Low
Med
Med
High
Crit
Med
Med
High
High
Crit
Med
High
High
Crit
Crit
High
High
Crit
Crit
Crit
↑ Impact
Critical Issues:
1. Arbitrary Definitions
What's "Likely" vs "Very Likely"?
2. Can't Aggregate
What is "Med + High + Med"?
3. No ROI Calculation
Control costs $100K - worth it?
4. Inconsistent
Different people, different ratings
Why This Matters for Data Professionals
📊 Data Stewards
🏗️ Data Architects
👔 Chief Data Officers
🎯 Data Governance
Translate data risk into dollars and probabilities
From subjective guessing...
⬇️
...to Decision Science
Introducing: FAIR (Factor Analysis of Information Risk)
What is FAIR?
Factor Analysis of Information Risk
FAIR is an international standard (ISO/IEC 27005) for quantifying cybersecurity and information risk in financial terms.
Developed by:
Jack Jones, The FAIR Institute (founded 2001)
Used by:
Key Principle:
"Risk is not a feeling. It's a probable frequency and magnitude of future loss."
Risk = Probability × Impact
(How often?) × (How much?)
Three Core Principles of FAIR
1️⃣
Risk is Measurable
Every risk can be expressed as a probability distribution. Example: "Data breach has 20% probability this year, estimated loss $500K-$2M"
2️⃣
Risk is Scenario-Based
Focus on specific, defined scenarios. Not: "Cloud security risk" Yes: "Unauthorized access to customer database via misconfigured S3 bucket"
3️⃣
Analysis Must Be Defensible
Based on evidence and data, not opinion. Transparent assumptions that can be reviewed and updated.
The FAIR Model
Breaking Down Risk into Measurable Components
Risk = Loss Event Frequency × Loss Magnitude
Loss Event Frequency (LEF)
Loss Magnitude (LM)
FAIR - a Risk-Aware Culture
Desired Outcome
A risk-concentrated culture combined with business alignment creates a resilient and proactive security environment
Risk-Concentrated Culture
Decision-makers actively engaged from strategy development through incident response
Business Awareness Culture
Security embedded in business operations and strategic planning
Key Takeaways
Eliminate Guessing Through Systematic Approach
Transform from reactive firefighting to proactive risk management by implementing structured frameworks aligned with business objectives
Critical Success Factors
✓
Establish clear risk strategy with executive sponsorship
✓
Adopt quantitative methods for budget justification and prioritization
✓
Align security initiatives with business goals and compliance requirements
✓
Maintain continuous engagement with decision-makers on risk posture
✓
Foster a culture where security is a business enabler, not a blocker
About EtutekiLab
AI-Powered Security Maturity & Compliance Platform
EtutekiLab transforms cybersecurity and compliance from complex, time-consuming processes into streamlined, AI-driven workflows. Our Chatawork platform helps organizations:
• Accelerate security maturity assessments and gap analysis
• Automate compliance documentation and evidence collection
• Quantify risk using frameworks like FAIR
• Build scalable security programs that grow with your business
Contact Information
📧 hello@etutekilab.com
🌐 www.etutekilab.com
💼 LinkedIn: Margaret Dibor
Services
• Security Maturity Assessments
• Risk Quantification (FAIR)
• Compliance Automation
• AI Security Consulting
Case Study: Data Governance Platform
Scenario: Financial Services Data Team
Managing 200+ data assets • 50M customer records • Subject to GDPR, CCPA, SOX • AI/ML initiatives launching
Before Risk Quantification
• Manual data classification taking 6 months
• No quantified risk for 80% of data assets
• Board questions: 'How much risk?' - no answer
• $300K spent on controls without ROI proof
• AI initiatives stalled over security concerns
• Data access requests delayed by risk debates
After Implementation (8 months)
• Data classification: 6 months → 3 weeks
• 85% of data assets quantified in $ terms
• $1.2M potential breach loss identified
• Controls prioritized: $420K ROI achieved
• AI initiatives approved with risk metrics
• Access decisions reduced from days to hours
Key Results: 280% ROI • Data stewards empowered with quantified risk data • Executive confidence in data strategy increased • Competitive advantage in regulated markets