1 of 16

From Guesswork to Decision Science:

Using FAIR to Quantify Information Security Risk

A Data-Driven Approach to Risk Management for Data Professionals

Margaret Dibor

FAIR Certified Risk Management Specialist | Founder, EtutekiLab | DAMA Webinar Series

2 of 16

About the Speaker

Margaret Dibor

Founder, EtutekiLab | Healthcare Security Specialist

Margaret helps organizations protect their most sensitive asset—patient data. With over 17 years of experience in cybersecurity, privacy, and telecommunications, she has led security programs, achieved ISO 27000 certifications, HIPAA compliance, and met regulatory requirements including GDPR and PIPEDA.

As Founder of EtutekiLab, Margaret builds AI-driven tools that make security maturity and compliance faster, easier, and truly scalable. Her mission is to help organizations reduce risk, build trust, and protect the people who rely on them.

Focus Areas

Safeguarding PHI • Securing digital health platforms • Risk management • Responsible AI adoption • Transforming security into a growth enabler

3 of 16

Today's Agenda

Part 1: The Problem (Why qualitative risk fails)

Part 2: FAIR Framework (Principles and methodology)

Part 3: Practical Applications (Real-world scenarios)

Part 4: Business Communication (Executive reporting)

Part 5: Implementation (Getting started)

4 of 16

Quick Poll

How does your organization quantify cybersecurity risk?

Heat maps (Red/Yellow/Green)

Qualitative ratings (High/Medium/Low)

Dollar values and probabilities

We don't formally assess risk

Combination of methods

5 of 16

Organizations Manage Risk Every Day

💰 Financial Risk

Portfolio: $2.5M

Loss probability: 15%

Expected: $37,500

⚙️ Operational Risk

Supply chain

Probability: 3%/quarter

Cost: $1.2M

🔒 Information Risk

Data breach: "HIGH" 🔴

Vendor access: "MEDIUM" 🟡

???

Why do we use numbers for everything EXCEPT information risk?

6 of 16

What Does "High Risk" Actually Mean?

Scenario: CIO presents "High Risk" data breach to CFO

CIO thinks:

"This could happen in the next 2 years and cost us $500K"

CFO thinks:

"High like high blood pressure? Or high like high stock price? What's the actual number?"

The Problem:

❌ Can't compare across risk types

❌ Can't calculate ROI on controls

❌ Can't prioritize objectively

❌ Different interpretations

7 of 16

The Heat Map Problem

Likelihood →

Low

Low

Med

High

High

Low

Med

Med

High

Crit

Med

Med

High

High

Crit

Med

High

High

Crit

Crit

High

High

Crit

Crit

Crit

↑ Impact

Critical Issues:

1. Arbitrary Definitions

What's "Likely" vs "Very Likely"?

2. Can't Aggregate

What is "Med + High + Med"?

3. No ROI Calculation

Control costs $100K - worth it?

4. Inconsistent

Different people, different ratings

8 of 16

Why This Matters for Data Professionals

📊 Data Stewards

  • Which datasets need most protection?
  • Data quality vs security investment?
  • Cost of breach: PII vs public data?

🏗️ Data Architects

  • Encrypt this database? ($50K)
  • What's the risk reduction value?
  • How to justify investment?

👔 Chief Data Officers

  • Board: "What's our data risk?"
  • Can't answer: "Medium-high"
  • Need: Dollar amounts

🎯 Data Governance

  • Prioritize governance initiatives
  • Demonstrate program value
  • Justify resource allocation

Translate data risk into dollars and probabilities

9 of 16

From subjective guessing...

⬇️

...to Decision Science

Introducing: FAIR (Factor Analysis of Information Risk)

10 of 16

What is FAIR?

Factor Analysis of Information Risk

FAIR is an international standard (ISO/IEC 27005) for quantifying cybersecurity and information risk in financial terms.

Developed by:

Jack Jones, The FAIR Institute (founded 2001)

Used by:

  • 75% of Fortune 100 companies
  • US Department of Defense
  • Major financial institutions

Key Principle:

"Risk is not a feeling. It's a probable frequency and magnitude of future loss."

Risk = Probability × Impact

(How often?) × (How much?)

11 of 16

Three Core Principles of FAIR

1️⃣

Risk is Measurable

Every risk can be expressed as a probability distribution. Example: "Data breach has 20% probability this year, estimated loss $500K-$2M"

2️⃣

Risk is Scenario-Based

Focus on specific, defined scenarios. Not: "Cloud security risk" Yes: "Unauthorized access to customer database via misconfigured S3 bucket"

3️⃣

Analysis Must Be Defensible

Based on evidence and data, not opinion. Transparent assumptions that can be reviewed and updated.

12 of 16

The FAIR Model

Breaking Down Risk into Measurable Components

Risk = Loss Event Frequency × Loss Magnitude

Loss Event Frequency (LEF)

  • Threat Event Frequency: How often does a threat act?
  • Vulnerability: How likely is the threat to succeed?
  • LEF = TEF × Vulnerability

Loss Magnitude (LM)

  • Primary Loss: Direct costs (response, notification)
  • Secondary Loss: Indirect costs (reputation, fines)
  • LM = Primary + Secondary

13 of 16

FAIR - a Risk-Aware Culture

Desired Outcome

A risk-concentrated culture combined with business alignment creates a resilient and proactive security environment

Risk-Concentrated Culture

Decision-makers actively engaged from strategy development through incident response

  • Regular risk posture updates
  • Incident statistics tracking
  • Continuous strategy refinement

Business Awareness Culture

Security embedded in business operations and strategic planning

  • Security as business enabler
  • Cross-functional collaboration
  • Informed risk acceptance

14 of 16

Key Takeaways

Eliminate Guessing Through Systematic Approach

Transform from reactive firefighting to proactive risk management by implementing structured frameworks aligned with business objectives

Critical Success Factors

Establish clear risk strategy with executive sponsorship

Adopt quantitative methods for budget justification and prioritization

Align security initiatives with business goals and compliance requirements

Maintain continuous engagement with decision-makers on risk posture

Foster a culture where security is a business enabler, not a blocker

15 of 16

About EtutekiLab

AI-Powered Security Maturity & Compliance Platform

EtutekiLab transforms cybersecurity and compliance from complex, time-consuming processes into streamlined, AI-driven workflows. Our Chatawork platform helps organizations:

• Accelerate security maturity assessments and gap analysis

• Automate compliance documentation and evidence collection

• Quantify risk using frameworks like FAIR

• Build scalable security programs that grow with your business

Contact Information

📧 hello@etutekilab.com

🌐 www.etutekilab.com

💼 LinkedIn: Margaret Dibor

Services

• Security Maturity Assessments

• Risk Quantification (FAIR)

• Compliance Automation

• AI Security Consulting

16 of 16

Case Study: Data Governance Platform

Scenario: Financial Services Data Team

Managing 200+ data assets • 50M customer records • Subject to GDPR, CCPA, SOX • AI/ML initiatives launching

Before Risk Quantification

• Manual data classification taking 6 months

• No quantified risk for 80% of data assets

• Board questions: 'How much risk?' - no answer

• $300K spent on controls without ROI proof

• AI initiatives stalled over security concerns

• Data access requests delayed by risk debates

After Implementation (8 months)

• Data classification: 6 months → 3 weeks

• 85% of data assets quantified in $ terms

• $1.2M potential breach loss identified

• Controls prioritized: $420K ROI achieved

• AI initiatives approved with risk metrics

• Access decisions reduced from days to hours

Key Results: 280% ROI • Data stewards empowered with quantified risk data • Executive confidence in data strategy increased • Competitive advantage in regulated markets