What Is FAIR and Why Does It Matter?

FAIR — Factor Analysis of Information Risk — is the only internationally recognised standard for quantifying cyber risk in financial terms. Unlike maturity models that produce scores or colour-coded dashboards, FAIR produces a single monetary figure your CFO and audit committee can act on.

Traditional security reporting answers "are we compliant?" FAIR answers "what is this costing us annually?" That shift in framing is the difference between a security update and a board-level risk decision.

TEF
Threat Event Frequency
How often is your environment likely to face a meaningful attack? Calibrated by industry, geography, and threat actor profile. Indian BFSI organisations face elevated TEF due to UPI/payment rail exposure.
Vulnerability
Control Strength
Given a threat event occurs, how likely is it to result in a loss? Your security maturity level directly reduces this factor. Moving from Level 2 to Level 3 delivers a 20% ALE reduction — quantifiable and board-presentable.
LM
Loss Magnitude
If a breach occurs, what does it actually cost? Direct (incident response, ransom, legal), indirect (reputation, customer churn), and regulatory (DPDP Schedules, RBI penalties). All three flows into LM.
FAIR Core Formula
ALE = TEF × Vulnerability × Loss Magnitude
Annual Loss Expectancy is the single number your CFO will engage with. It represents the expected annual financial loss from a specific threat scenario, factoring in how often attacks occur and how likely they are to succeed.

Indian BFSI Benchmark Data

The figures below are drawn from IBM Cost of Data Breach Report 2024 (India region), RBI IT Examination findings, and CreativeCyber BFSI client engagements. They represent calibrated starting points for ALE modelling — a tailored assessment using your actual control data will refine these substantially.

Industry Base Breach Costs

Sector Base Breach Cost Primary Driver
Banking / PSB ₹18.5 Cr Customer PII volume, RBI reporting obligations
Insurance / IRDAI ₹14.2 Cr Health and claims data sensitivity
NBFC / MFI ₹10.8 Cr KYC data, collections exposure
Fintech / Payments ₹13.6 Cr Transaction data, UPI rail access
AMC / Stock Broker ₹11.4 Cr SEBI CSCRF penalties, demat data

Top Threat Scenarios by TEF (Annual Frequency)

Threat Scenario Annual TEF Primary Vector
Ransomware / Extortion 38% / yr Phishing, exposed RDP, unpatched VPN
Data Theft / Exfiltration 29% / yr Credential stuffing, SaaS misconfig
Malicious Insider 17% / yr Privileged access abuse, USB exfil
Supply Chain Compromise 14% / yr Third-party software, API integrations
Nation-State / APT 9% / yr Spear phishing, zero-day exploitation

Maturity Level Vulnerability Factors

The vulnerability factor scales your ALE based on how strong your controls are. A well-funded Level 4 organisation faces roughly 55% lower expected losses than an ad-hoc Level 1 organisation facing the same threat landscape.

Maturity Level Description Vulnerability Factor
Level 1 Ad-hoc — no repeatable processes 1.6×
Level 2 Developing — some controls in place 1.25×
Level 3 Defined — documented, consistently applied 1.0×
Level 4 Managed — measured, monitored 0.72×
Level 5 Optimising — continuous improvement 0.48×

Worked Example: Mid-Size Banking Organisation

The following example illustrates the FAIR methodology using representative figures for a mid-size Indian banking organisation. It is not a live calculator — your actual numbers will differ based on specific threat intelligence, asset inventory, and control data.

Inputs
Organisation type Banking / PSB
Annual revenue ₹500 Cr – ₹2,000 Cr
Data in scope Customer PII (5,00,000 records)
Primary threat Ransomware / Extortion
Current maturity Level 2 — Developing
Base breach cost ₹18.5 Cr (Banking benchmark)
Revenue multiplier 1.0× (mid-range band)
PII cost per record ₹6,200 (IBM India 2024)
Indirect breach rate 35% of records affected
Annual Loss Expectancy (ALE)
₹10.6 Cr / yr
TEF 0.38 × Vuln 1.25 × SLE ₹22.3 Cr
HIGH RISK
Single Loss Expectancy (SLE)
₹22.3 Cr
₹18.5 Cr base + ₹3.8 Cr PII indirect
3-Year Discounted Exposure
₹22.9 Cr
₹10.6 Cr × 3 × 0.72 discount factor
Recommended Investment (12% Rule)
₹1.27 Cr
12% of annual ALE — FAIR benchmark
ROSI — Return on Security Investment
~3.4×
Saved ALE ₹4.3 Cr per ₹1.27 Cr invested (L2 → L3)
DPDP Penalty Ceiling For 5,00,000 customer PII records, the DPDP Act Schedule penalty ceiling runs independently at ₹200 Cr. This is in addition to the operational ALE above — see Section 5 for the full board exposure figure.

How the Calculation Works

Step 1 — Indirect data exposure: 5,00,000 records × ₹6,200 per record × 35% affected = ₹10.85 Cr indirect loss estimate.

Step 2 — Single Loss Expectancy: ₹18.5 Cr base + (₹10.85 Cr × 0.35 indirect weight) = ₹22.3 Cr SLE.

Step 3 — Annual Loss Expectancy: TEF 0.38 (ransomware frequency) × Vulnerability 1.25 (Level 2) × ₹22.3 Cr = ₹10.6 Cr ALE.

Step 4 — 3-year exposure: ₹10.6 Cr × 3 years × 0.72 (time-value discount) = ₹22.9 Cr.

Step 5 — Investment benchmark: 12% of ALE = ₹1.27 Cr annual security investment. This is FAIR's empirically-derived recommendation for maximising ROSI at this maturity level.

The 12% FAIR Investment Rule

FAIR's empirical finding is that security investment of approximately 12% of ALE produces the best risk-adjusted return across most organisations. The intuition is straightforward: at lower maturity levels, each rupee of control investment delivers outsized vulnerability reduction because the baseline is weak. As maturity improves, the marginal return per rupee decreases — but never falls to zero.

Maturity Transition ALE Reduction Investment Benchmark ROSI
Level 1 → Level 2 40% 12% of ALE ~3.3×
Level 2 → Level 3 20% 12% of ALE ~1.7×
Level 3 → Level 4 28% 12% of ALE ~2.3×
Level 4 → Level 5 33% 12% of ALE ~2.8×
Key Insight The non-linear ROSI curve means Level 1 → 2 and Level 4 → 5 transitions both deliver higher ROSI than Level 2 → 3. The dip at Level 2 → 3 is not a reason to stall — it is the necessary foundation for the higher returns available at Level 3 → 4 and beyond.

DPDP Penalty Overlay

This is where many CISO board presentations fall short: they present ALE without the regulatory penalty layer. For any organisation holding customer PII, these two figures run simultaneously and independently, and both must appear on the same board slide.

Board Exposure — Mid-Size Banking Organisation
Annual Loss Expectancy (operational)
₹10.6 Cr / yr
DPDP Schedule penalty ceiling (customer PII)
₹200 Cr
Total board exposure (ALE + DPDP ceiling) ₹210.6 Cr+
Critical: Do Not Present ALE Alone ALE does not include regulatory penalties. Your total board exposure = ALE + potential DPDP/RBI penalty. Both figures belong in the same board slide. Presenting only ALE to the audit committee understates your organisation's risk by an order of magnitude if you hold significant customer PII.

The DPDP Act's Schedule penalties are determined by the Data Protection Board based on the nature of the breach, the number of data principals affected, and whether the organisation took adequate technical and organisational measures. For organisations holding sensitive personal data at scale, the ₹200 Cr ceiling is a credible exposure — not a theoretical maximum to be discounted.

RBI penalties for technology risk failures and SEBI CSCRF non-compliance run on their own separate tracks and can compound the total exposure further. A complete board risk disclosure accounts for all three flows: operational ALE, regulatory penalties, and sector-specific regulator penalties.

Getting a Validated Assessment

The figures in this article use industry benchmarks. They are useful for initial board framing and budget-setting conversations. A tailored assessment using your actual threat intelligence, asset inventory, control evidence, and loss event history produces figures that are:

  • Defensible to your audit committee
  • Accurate enough for cyber insurance negotiations
  • Specific enough to drive prioritised control investment decisions
  • Aligned with SEBI CSCRF maturity reporting requirements

RiskSage AI automates the FAIR data collection process — connecting your VAPT findings, asset registry, ROPA data, and maturity assessments into a unified ALE model. The platform generates board-ready output in the format your audit committee and CFO will actually read.

RiskSage AI

Automate Your FAIR Assessment

Connect your VAPT findings, asset registry, and maturity data. RiskSage generates a board-ready ALE model with DPDP penalty overlay — calibrated to your actual controls, not industry averages.

Benchmarks sourced from IBM Cost of Data Breach Report 2024 (India), RBI IT Examination findings, and CreativeCyber BFSI client data.