Risk
FY2026FAIR modelACME Corp
Prove it holds up →Step 3 · Act
What do I do — and what does it buy us?
Loss modeled in dollars, then a ranked plan. Open a scenario for the FAIR breakdown, or an action for the step-by-step and the score it buys.
Annual loss expectancy
$4.2M
▼ $0.6M vs last quarter
Materiality threshold
$2.5M
Material cyber risk exceeds threshold
Loss removed by plan
$2.9M
Remediation ROI
3.4×
loss avoided per dollar spent
FAIR loss scenarios
Back to gaps →| Scenario | Driver | ALE | Confidence | Top control | Status |
|---|---|---|---|---|---|
| Ransomware | Endpoint encryption / extortion | $1.8M | High | PCI R5 | Open |
| Cloud data exfiltration | External — APT | $1.1M | Medium | NIST PR.DS | Mitigating |
| PHI breach (legacy store) | Unencrypted data at rest | $640K | High | HIPAA §164.312 | Open |
| Insider misuse | Privileged insider | $420K | Medium | SOC 2 CC6 | Open |
| Third-party breach | Supply chain | $310K | Low | NIST ID.SC | Monitoring |
Ranked action plan
Closes 3 gapsEnforce phishing-resistant MFA on all privileged + cloud-admin roles
Satisfies PCI-DSSFedRAMPNIST CSF · ~1 week · Cloud Platform
Encrypt the legacy datastore at rest and rotate keys to the managed KMS
Satisfies HIPAAGDPRNIST CSF · ~2 weeks · Data Engineering
Run the overdue access review and put it on an automated quarterly cadence
Satisfies SOC 2PCI-DSSFedRAMP · ~3 days · IT / GRC
Close these three → posture 71 → 89 across all six frameworks, one quarter of work.
Next
Prove it holds up