FAIRTM (Factor Analysis of Information Risk) has emerged as the premier Value at Risk (VaR) model for cybersecurity and operational risk. The FAIRTM Institute is a non-profit professional organization dedicated to advancing the discipline of measuring and managing cyber and operational risk.
It provides information risk, cybersecurity and business executives with the standards and best practices to help organizations measure, manage and report on information risk from the business perspective. The FAIRTM Institute and its community focus on innovation, education and sharing of best practices to advance the FAIRTM model and the cyber and operational risk management professions.
Sep 10, 2025 7:23:14 AM
An OpenFAIR certified practitioner's call for quantitative risk methodology in AI governance certification
Sep 9, 2025 4:58:56 PM
The cybersecurity landscape is evolving rapidly, and staying ahead of emerging threats while managing risk effectively has never been more challenging. That's why the 10th Annual 2025 FAIR Conference (FAIRCON25) in New York City on November 4 & 5, represents a pivotal opportunity for cybersecurity professionals, risk managers, and business leaders to elevate their approach to cyber risk management.
Sep 8, 2025 1:32:06 PM
This post is Part 3 of 3 in a series on actionable TPRM.
Feb 15, 2023 5:09:00 PM
I recently had a conversation with clients around a risk analysis they conducted and noticed as they walked me through it that they seemed to get hung up on the terms “inherent risk” and “residual...
Read More >>Jan 10, 2025 1:51:52 PM
Cybersecurity leaders face an increasingly complex risk landscape where the stakes—financial, operational, and regulatory—continue to climb. The FAIR Institute’s latest white paper, A FAIR Framework...
Read More >>Aug 25, 2025 4:08:56 PM
We are buzzing with anticipation as FAIRCON25 approaches, and for good reason. This isn't just another conference—it is the gathering of the most brilliant minds in cyber risk...
Read More >>