2024 FAIR Conference & Training | Washington, D.C.

October 17 & 18, 2023

EMBRACE DIGITAL | Managing Digital Transformation, Cloud, and AI Risk

What is the FAIR Institute?

FAIRTM (Factor Analysis of Information Risk)  has emerged as the premier Value at Risk (VaR) model for cybersecurity and operational risk. The FAIRTM Institute is a non-profit professional organization dedicated to advancing the discipline of measuring and managing cyber and operational risk.

It provides information risk, cybersecurity and business executives with the standards and best practices to help organizations measure, manage and report on information risk from the business perspective. The FAIRTM Institute and its community focus on innovation, education and sharing of best practices to advance the FAIRTM model and the cyber and operational risk management professions.

14500+
Members Worldwide
50%
Fortune 1000 Orgs.
25
Local Chapters
SCAWARDS2019_winner (002)
 

The FAIR Institute is extremely proud to be named one of the
'Three Most Important Industry Organizations of the Last 30 Years'
at the 2019 SC Awards.

Read More here
A STANDARD BY



partners_12

TECHNICAL ADVISOR

 

Safe Security Logo

 

SPONSORS

 IBM       RiskRecon-1

   

Protiviti 2023     Ostrich Cyber Risk Logo

 

EDUCATION PARTNERS

SJSU     WASHSTL        UMass Amherst       Ferris-State       CMU            VT   

   University of Tampa    University of Toronto    Georgia Southern      georgemason     Macquarie 

Learn more about our Education Partners

RECENT BLOGS

Interpreting Maturity: What the 2025 State of Cyber Risk Management Report Really Tells Us

Released last week, the 2025 State of Cyber Risk Management Report paints a compelling picture of progress in the discipline. With 402 cyber risk management (CRM) professionals participating, the report describes a relatively high level of CRM maturity across a wide range of capabilities, including quantitative analysis, automation (including AI), data (including telemetry), third-party risk management, and executive governance. However, as impressive as these results are, they come with an important caveat: Tthis sample is not representative of the industry as a whole.

Read More >>

2025 ‘State of Cyber Risk Management’ Reveals Modern, Outcome-Oriented Approaches

Today, we’re proud to release the FAIR Institute’s 2025 State of Cyber Risk Management report, a comprehensive look at how cyber risk programs are evolving to meet today’s business, regulatory, and operational demands.

Read More >>

From Vegas to Boardrooms: Learn How FAIR Institute Revolutionizes Cyber Risk Management at Black Hat 2025

The FAIR Institute is very excited to dive into Black Hat USA 2025 as a first-time Association Partner - connecting with the brightest minds in cybersecurity and sharing game-changing insights on cyber risk management through quantification!

Read More >>

SEE ALL BLOGS

POPULAR BLOGS

Post Image
Inherent Risk vs. Residual Risk Explained in 90 Seconds

I recently had a conversation with clients around a risk analysis they conducted and noticed as they walked me through it that they seemed to get hung up on the terms “inherent risk” and “residual...

Read More >>
Post Image
A FAIR Framework for Effective Cyber Risk Management

Cybersecurity leaders face an increasingly complex risk landscape where the stakes—financial, operational, and regulatory—continue to climb. The FAIR Institute’s latest white paper, A FAIR Framework...

Read More >>
Post Image
7 Basic Tools for FAIR Cyber Risk Analysis

If you’re looking to try Factor Analysis of Information Risk (FAIR™) in a lightweight way, these tools and resources will get you started – all of them offered by the FAIR Institute or shared by...

Read More >>