What Is FAIR and Why Does It Matter?
FAIR — Factor Analysis of Information Risk — is the only internationally recognised standard for quantifying cyber risk in financial terms. Unlike maturity models that produce scores or colour-coded dashboards, FAIR produces a single monetary figure your CFO and audit committee can act on.
Traditional security reporting answers "are we compliant?" FAIR answers "what is this costing us annually?" That shift in framing is the difference between a security update and a board-level risk decision.
Indian BFSI Benchmark Data
The figures below are drawn from IBM Cost of Data Breach Report 2024 (India region), RBI IT Examination findings, and CreativeCyber BFSI client engagements. They represent calibrated starting points for ALE modelling — a tailored assessment using your actual control data will refine these substantially.
Industry Base Breach Costs
| Sector | Base Breach Cost | Primary Driver |
|---|---|---|
| Banking / PSB | ₹18.5 Cr | Customer PII volume, RBI reporting obligations |
| Insurance / IRDAI | ₹14.2 Cr | Health and claims data sensitivity |
| NBFC / MFI | ₹10.8 Cr | KYC data, collections exposure |
| Fintech / Payments | ₹13.6 Cr | Transaction data, UPI rail access |
| AMC / Stock Broker | ₹11.4 Cr | SEBI CSCRF penalties, demat data |
Top Threat Scenarios by TEF (Annual Frequency)
| Threat Scenario | Annual TEF | Primary Vector |
|---|---|---|
| Ransomware / Extortion | 38% / yr | Phishing, exposed RDP, unpatched VPN |
| Data Theft / Exfiltration | 29% / yr | Credential stuffing, SaaS misconfig |
| Malicious Insider | 17% / yr | Privileged access abuse, USB exfil |
| Supply Chain Compromise | 14% / yr | Third-party software, API integrations |
| Nation-State / APT | 9% / yr | Spear phishing, zero-day exploitation |
Maturity Level Vulnerability Factors
The vulnerability factor scales your ALE based on how strong your controls are. A well-funded Level 4 organisation faces roughly 55% lower expected losses than an ad-hoc Level 1 organisation facing the same threat landscape.
| Maturity Level | Description | Vulnerability Factor |
|---|---|---|
| Level 1 | Ad-hoc — no repeatable processes | 1.6× |
| Level 2 | Developing — some controls in place | 1.25× |
| Level 3 | Defined — documented, consistently applied | 1.0× |
| Level 4 | Managed — measured, monitored | 0.72× |
| Level 5 | Optimising — continuous improvement | 0.48× |
Worked Example: Mid-Size Banking Organisation
The following example illustrates the FAIR methodology using representative figures for a mid-size Indian banking organisation. It is not a live calculator — your actual numbers will differ based on specific threat intelligence, asset inventory, and control data.
How the Calculation Works
Step 1 — Indirect data exposure: 5,00,000 records × ₹6,200 per record × 35% affected = ₹10.85 Cr indirect loss estimate.
Step 2 — Single Loss Expectancy: ₹18.5 Cr base + (₹10.85 Cr × 0.35 indirect weight) = ₹22.3 Cr SLE.
Step 3 — Annual Loss Expectancy: TEF 0.38 (ransomware frequency) × Vulnerability 1.25 (Level 2) × ₹22.3 Cr = ₹10.6 Cr ALE.
Step 4 — 3-year exposure: ₹10.6 Cr × 3 years × 0.72 (time-value discount) = ₹22.9 Cr.
Step 5 — Investment benchmark: 12% of ALE = ₹1.27 Cr annual security investment. This is FAIR's empirically-derived recommendation for maximising ROSI at this maturity level.
Section 04The 12% FAIR Investment Rule
FAIR's empirical finding is that security investment of approximately 12% of ALE produces the best risk-adjusted return across most organisations. The intuition is straightforward: at lower maturity levels, each rupee of control investment delivers outsized vulnerability reduction because the baseline is weak. As maturity improves, the marginal return per rupee decreases — but never falls to zero.
| Maturity Transition | ALE Reduction | Investment Benchmark | ROSI |
|---|---|---|---|
| Level 1 → Level 2 | 40% | 12% of ALE | ~3.3× |
| Level 2 → Level 3 | 20% | 12% of ALE | ~1.7× |
| Level 3 → Level 4 | 28% | 12% of ALE | ~2.3× |
| Level 4 → Level 5 | 33% | 12% of ALE | ~2.8× |
DPDP Penalty Overlay
This is where many CISO board presentations fall short: they present ALE without the regulatory penalty layer. For any organisation holding customer PII, these two figures run simultaneously and independently, and both must appear on the same board slide.
The DPDP Act's Schedule penalties are determined by the Data Protection Board based on the nature of the breach, the number of data principals affected, and whether the organisation took adequate technical and organisational measures. For organisations holding sensitive personal data at scale, the ₹200 Cr ceiling is a credible exposure — not a theoretical maximum to be discounted.
RBI penalties for technology risk failures and SEBI CSCRF non-compliance run on their own separate tracks and can compound the total exposure further. A complete board risk disclosure accounts for all three flows: operational ALE, regulatory penalties, and sector-specific regulator penalties.
Section 06Getting a Validated Assessment
The figures in this article use industry benchmarks. They are useful for initial board framing and budget-setting conversations. A tailored assessment using your actual threat intelligence, asset inventory, control evidence, and loss event history produces figures that are:
- Defensible to your audit committee
- Accurate enough for cyber insurance negotiations
- Specific enough to drive prioritised control investment decisions
- Aligned with SEBI CSCRF maturity reporting requirements
RiskSage AI automates the FAIR data collection process — connecting your VAPT findings, asset registry, ROPA data, and maturity assessments into a unified ALE model. The platform generates board-ready output in the format your audit committee and CFO will actually read.
Automate Your FAIR Assessment
Connect your VAPT findings, asset registry, and maturity data. RiskSage generates a board-ready ALE model with DPDP penalty overlay — calibrated to your actual controls, not industry averages.
Benchmarks sourced from IBM Cost of Data Breach Report 2024 (India), RBI IT Examination findings, and CreativeCyber BFSI client data.