Skip to content

Research papers

What Open FAIR actually standardizes — and what a PE operator still decides

The Open Group’s Open FAIR Body of Knowledge is a taxonomy and an analysis process, not a loss number. Read it that way and the IC conversation gets shorter.

What Open FAIR actually standardizes — and what a PE operator still decides product viewOpen full-size product view ↗

Most “we do FAIR” slides are doing one of three things: naming a vendor, naming a training class, or hiding a point estimate inside a method that was designed to refuse point estimates. The document that can settle the argument is not a blog post. It is The Open Group’s Open FAIR Body of Knowledge: the Risk Analysis standard (O-RA, Version 2.0.1) and the Risk Taxonomy standard (O-RT, Version 3.0.1), published together as Version 2.0 of the body of knowledge (17 October 2022).

This is a reading note, not a recitation of the paid standard text. The public Open Group pages are enough to get the claim right: Open FAIR is a vendor-neutral, consensus definition of how to decompose and analyze risk so results can be compared across scenarios. It is not a price list, and it is not a Valty feature list.

What the standard is for

O-RT is the vocabulary. It exists so two analysts do not use “threat” or “vulnerability” to mean four different things in the same IC memo. O-RA is the process for doing an analysis once you have that vocabulary. Together they are meant to be risk-domain agnostic: the same decomposition can be applied to information security and, in principle, to other loss scenarios.

That agnostic property is the part operators underuse. If the taxonomy is doing its job, a ransomware scenario and a payment-fraud scenario can be discussed in the same units — frequency and magnitude, with uncertainty kept visible — instead of one arriving as a red heatmap and the other as a legal memo.

The Open Group also publishes a process guide and a spreadsheet tool. Those are implementation aids. They are not a substitute for naming the scenario, the asset, and the evidence you actually have.

What a PE operator should demand

When a portco or an advisor says “FAIR,” ask four questions that the standard makes legitimate and a scorecard does not.

Which scenario? “Cyber risk” is not a scenario. “Credential-stuffing against the customer portal that holds billing files” is.

Which factors were estimated, and from what? A taxonomy without inputs is a poster. If frequency came from “industry average” and magnitude came from “a slide we liked,” say that out loud.

Where is the range? A single dollar is a decision to hide the tails. Open FAIR exists, in part, so that hiding is harder to defend.

What would change the range? If no input can move the result, you are not looking at an analysis. You are looking at a number that has been socially approved.

Valty uses a FAIR-aligned Monte Carlo to connect verified control posture and financial-risk inputs to an EBITDA-impacting cyber loss-exposure range (P10–P90, net of insurance). That is a method choice, with assumptions kept next to the number. It is not a claim that Open FAIR certified the product, and it is not a claim that a design-partner sprint is a completed analysis of your whole fund.

What the standard does not do

It does not pull your CrowdStrike or ERP data. It does not decide risk appetite. It does not net insurance unless you model the transfer as an input. It does not tell an investment committee to cut a check. Those are operating decisions.

It also does not forgive a vendor who turns a modeled tail into an enterprise-value story and calls the result “FAIR.” If you see that move, the problem is not the taxonomy. The problem is the claim.

If you want to see a labeled artifact that keeps method, source, and confidence visible, inspect the sample proof. If you want that work on one portfolio company, apply as a design partner.

Sources

Limitations

This note cites the public catalog pages and publication metadata. It does not reproduce the paid standard text, and it does not treat “FAIR-aligned” as a certificate. A taxonomy cannot replace tenant evidence. Any range still has to show its inputs.

Back to blogMore in Research papers