Back to Blog

Cyber Risk Quantification for Mid-Market: FAIR Without an Enterprise Risk Team

FAIR was built for risk teams of 20+. Mid-market companies have one person doing security part-time. Full FAIR rigor in a Friday afternoon, no enterprise overhead.

Quick Answer

FAIR was built for risk teams of 20+. Mid-market companies have one person doing security part-time. Full FAIR rigor in a Friday afternoon, no enterprise overhead.

The FAIR (Factor Analysis of Information Risk) methodology was built for risk teams of twenty or more. Enterprise risk functions, dedicated quantitative analysts, six-figure platform licenses, multi-quarter implementation timelines. The methodology is excellent. The packaging assumes you're not the only person doing security at your company.

The 33 million US small and mid-sized businesses that need cyber risk quantification have one person doing security part-time. They don't have a quantitative risk team. They don't have a six-figure budget for a CRQ platform. They have a CFO who wants the security budget defended in dollars and a board that's tired of heat maps.

The FAIR methodology works perfectly for that company. The mid-market just needs a different way to apply it — full quantitative rigor, no enterprise overhead, executable in a Friday afternoon.

45%
of organizations use or plan to use the FAIR model for cyber risk quantification — making it the dominant CRQ methodology globally (FAIR Institute, 2025 State of Cyber Risk Management Report)
90%
of FAIR users report success with the model — strong satisfaction signal among organizations that have implemented it (FAIR Institute, 2025)
15–20%
of organizations have deployed fully automated CRQ — leaving a wide gap between recognition (95% of leaders see the value) and practice (FAIR Institute, 2025)

Why FAIR feels heavy at mid-market scale

FAIR's reference implementation assumes you have time and people. The enterprise version of an annual FAIR program looks like this: dedicated FAIR analyst staff, scenario-modeling workshops with multiple stakeholders, Monte Carlo simulation across thousands of scenarios, formal calibration of expert judgments, peer-reviewed risk register, quarterly reassessment cycles, integration with enterprise risk management platforms.

None of that is wrong. All of it is overkill for a 50-person SaaS company.

The methodology itself is fine. The implementation pattern is what doesn't scale down. Mid-market companies that try to follow the enterprise pattern either give up at the workshop stage or produce risk assessments so elaborate that nobody can update them, which means they get done once and then sit in a folder.

The Reality at Mid-Market

A 50-person SaaS company doing CRQ "correctly" by the enterprise playbook would spend more on the CRQ program than on the security controls the program is supposed to inform. The math doesn't pencil. The mid-market needs a 90/10 implementation — 90% of the FAIR rigor with 10% of the operational overhead.

What FAIR actually requires (the core, stripped of overhead)

FAIR has six factors. That's it. Strip away the workshops, the platform, the analyst staff — what's left is six numbers you need per scenario to produce a defensible annual loss expectancy.

FAIR Factor
What It Asks
Mid-Market Shortcut
Threat Event Frequency (TEF)
How often will the threat actor attempt this attack annually?
Verizon DBIR sector-specific tables; Hiscox SME survey base rates
Vulnerability (Vuln)
What probability that the attempt succeeds given current controls?
Self-assessment against the specific controls in the scenario, calibrated against publicly known incident patterns
Loss Event Frequency (LEF)
TEF × Vuln — how often will the loss event actually occur?
Straightforward multiplication
Primary Loss Magnitude
Direct dollar impact when the loss event occurs
Asset value at risk × percent affected × cost per affected unit (records × $1.80/record notification, $200K incident response baseline, etc.)
Secondary Loss Magnitude
Indirect impact — churn, reputation, regulatory fines
Customer concentration × churn probability × ACV (for revenue exposure); regulatory base rates per framework
Annual Loss Expectancy
LEF × (Primary + Secondary) — the dollar number that goes on the slide
Direct calculation

Six numbers. Three of them (TEF, Vuln, asset value) require thirty minutes of work per scenario, sourcing to published benchmarks. The other three are derived. That's the entire FAIR methodology, applied honestly, at mid-market scale.

The Friday afternoon implementation

The full mid-market CRQ exercise — across five scenarios, sufficient to defend a security budget — takes about four hours. Once. Then thirty minutes per scenario per quarter to refresh.

Hour 1 — Pick the five scenarios that matter

Crown jewel inventory: which 3–5 systems support revenue, retention, or compliance within a 30-day window. For each crown jewel, identify the top one or two attack scenarios with realistic probability of materializing this year. Five scenarios total is the right number — fewer misses material risk, more diffuses focus.

Hour 2 — Source the threat event frequencies

For each scenario, find the published TEF in sector-specific incident data. Verizon DBIR is the canonical source; Hiscox Cyber Readiness Report covers SME-specific rates; sector-specific reports (HIMSS for healthcare, FBI IC3 for fraud) fill the gaps. Document the source per scenario.

Hour 3 — Score the vulnerability per scenario

For each scenario, list the specific controls that prevent or contain the loss event. Rate each on a 1–5 scale honestly (1 = not implemented; 5 = fully implemented and tested). The composite gives a vulnerability percentage. "We have MFA" is not 5 if MFA isn't enforced on three admin accounts.

Hour 4 — Compute the loss magnitudes

Asset value at risk × percent affected × cost per affected unit, for primary loss. Customer-concentration-driven revenue exposure for secondary loss. Sum. Per scenario. Total across five scenarios is your annual loss expectancy headline.

Where the rigor sits

The 90% of FAIR rigor that matters at mid-market scale is in three places.

Sourced probabilities. Every TEF cites a specific report and year. Every vulnerability score lists the specific controls evaluated. No hand-waving, no "we estimated." The CFO can cross-examine every input.

Honest vulnerability scoring. The single most common failure mode in mid-market CRQ is over-rating controls. "We have MFA" is not the same as "MFA is enforced on every privileged account with no exceptions, verified weekly." The first sentence belongs to a vulnerability score of 3, not 5. Honesty here is what makes the ALE defensible later.

Per-scenario worksheets, not aggregate hand-waving. Five scenarios, each with its own worksheet showing inputs and citations. Aggregate "our cyber risk is $740K" sentences without backup don't survive board questioning. Five worksheets that sum to $740K do.

What you can skip at mid-market

Monte Carlo simulation across thousands of variations. Formal expert calibration workshops. Custom CRQ platform licenses. Quarterly multi-stakeholder review meetings. Integration with enterprise GRC suites. Peer-reviewed risk registers. The 200+ scenario register that enterprise FAIR programs maintain.

What you cannot skip

Sourced probabilities per scenario. Honest vulnerability scoring (especially for controls you think you have). Five-scenario per-worksheet structure. Quarterly refresh on the worksheets you already built. Documentation of changes between quarters. The dollar-denominated output the CFO actually uses.

What this enables, in order

The CFO budget defense, the one-page board pack, the cyber insurance renewal conversation, the enterprise security questionnaire response, the M&A diligence narrative — every one of these downstream artifacts is just a different framing of the same five-scenario ALE worksheet.

That's the operational leverage. The CRQ exercise once, the downstream artifacts forever. Mid-market companies that build this discipline produce board-ready, audit-ready, CFO-ready cyber risk artifacts on demand, with the same underlying methodology behind every one. The artifacts compound. The workshop-driven enterprise pattern produces one risk register per year and then sits.

The Mid-Market CRQ Test

After the four-hour exercise, you should be able to answer three questions in under sixty seconds each:

1. "What's our total annualized cyber loss exposure?" — single dollar number, sourced.
2. "Which control investment reduces the most ALE per dollar?" — top of the prioritization list.
3. "What happens to our ALE if we close the top three control gaps?" — pre-computed delta.

If any of those takes more than sixty seconds, the methodology isn't operational — it's still academic.

The bottom line

FAIR works for mid-market. The methodology is right; the implementation pattern needs adjusting. Five scenarios, six factors each, four hours once, thirty minutes per scenario per quarter. The output is a dollar-denominated risk number that defends the security budget, answers board questions, simplifies insurance renewals, and survives audit. The 33 million US small and mid-sized businesses that need this don't need to wait for an enterprise-tier CRQ program to do it.

Run mid-market CRQ without the enterprise overhead

vCISO Lite ships the five-scenario FAIR methodology pre-configured for mid-market — sourced threat event frequencies by sector, vulnerability scoring against the control profile you actually have, primary and secondary loss magnitudes computed from your asset register, and the per-scenario worksheets that the CFO, the board, and the auditor all draw from. Same FAIR rigor, none of the enterprise weight. Built for the 33 million US small and mid-sized businesses that don't have a quantitative risk team.

If you're standing up cyber risk quantification for the first time, or replacing a heat-map register that's not driving decisions, visit vcisolite.com to learn more and get started.

Where this matters next

Cybersecurity risk assessment: a practical guidethe assessment workflow that feeds the FAIR worksheets.

How CFOs defend the cybersecurity budget at the board tablethe three-line budget defense that the FAIR worksheets compose into.

Inside a cyber cost of deal: a worked examplethe same five-scenario methodology applied to the M&A buyer side, with full ALE math.

Platform: Executive Reportingthe CRQ engine wired into board reports — FAIR-based Annual Loss Expectancy per scenario, dollar-denominated, ranked by remediation ROI.

Use Case: Quantify Riskthe outcome: dollar-denominated cyber risk the CFO defends and the board funds — in one hour, not one quarter, at mid-market scale.

Where this matters next

Security Metrics and KPIs That Actually Matter — Your board doesn't care about your CVSS scores. Your CEO wants to know if you're secure

How CFOs Defend the Cybersecurity Budget at the Board Table — The CFOs who get cybersecurity budgets approved without 20 follow-up questions translate security spend into dollar-denominated…

Why your KRIs stopped predicting anything — Open your last board report. Find the Key Risk Indicators page

Calibration: how we know our indicators are actually right — Anyone can build a risk dashboard. The hard part is convincing an auditor that the numbers are correct

Share this article:

Ready to build your security program?

See how easy it can be.