FAIR Institute
FAIR Institute is a not-for-profit standards body that develops and promotes the FAIR (Factor Analysis of Information Risk) framework for quantitative cyber risk management, serving 18,000+ members across half of the Fortune 1000 and 25 U.S. federal agencies.
- Company typePrivate
- Founded2015
- HeadquartersSpokane, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What FAIR Institute does
The FAIR Institute is a research-driven not-for-profit organization headquartered in Spokane, Washington, founded in 2017 to advance the discipline of cyber and operational risk management through education, standards, and collaboration. It is the steward of FAIR (Factor Analysis of Information Risk), the international standard taxonomy and quantitative risk analysis model that enables organizations to measure, manage, and communicate cybersecurity and operational risk in financial terms. The Institute has extended the core FAIR standard into a family of registered models — FAIR-CAM (Controls Analytics Model), FAIR-MAM (Materiality Assessment Model), and FAIR-AIR (AI Risk Playbook) — and jointly launched the GenAI Risk Platform with technical adviser Safe Security. The organization counts more than 18,000 members worldwide, claims representation in 50% of Fortune 1000 companies and 25 U.S. federal agencies, and has trained over 10,000 professionals.
The Institute's business model is a community-led, freemium-nonprofit structure. Individual membership is free and grants access to local chapters, virtual events, and community discussions; contributing and corporate memberships provide gated access to white papers, resources, and event discounts. Revenue is generated primarily through paid corporate memberships, annual conference registrations (FAIR Conference / FAIRCON), regional summits (Europe, Asia-Pacific), contributory training and certification (FAIR Certified Cyber Risk Professional, CCRP), and corporate sponsorship. Distribution is multi-channel: a content-rich blog, gated resource library, regional chapters, major industry event presence (Black Hat, RSA), and the annual FAIR Conference. The strategic agenda is driven by regulatory alignment (SEC Form 8-K materiality, NIST frameworks, FISMA), AI risk management (FAIR-AIR, GenAI Risk Platform), and partnership with standards-adjacent vendors (Safe Security, RiskLens, NIST AISIC).
FAIR Institute firmographics
Firmographics- Name
- FAIR Institute
- Legal name
- FAIR Institute Inc.
- Website
- https://fairinstitute.org
- Company type
- Private
- Founded year
- 2015
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- FAIR Institute is a not-for-profit standards body that develops and promotes the FAIR (Factor Analysis of Information Risk) framework for quantitative cyber risk management, serving 18,000+ members across half of the Fortune 1000 and 25 U.S. federal agencies.
- Ownership category
- akta.pro rank
FAIR Institute industry classification
Industry- Product category
- Cybersecurity Risk Quantification
- akta.pro primary industry
- Third-Party Model/Vendor Risk & Supply-Chain Assurance (HDAAAMAK)
- akta.pro secondary industry
- Safety & Alignment Evaluation (red-teaming, harmful capability testing) (HDAAAMAL)
Keywords
Where FAIR Institute is headquartered
LocationHeadquarters
- HQ city
- Spokane
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
FAIR Institute business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Membership Programs: Individual and corporate membership programs. The website states 'Membership is free' for individual members, but there are contributing membership levels for enhanced access to resources.
- FAIR Conference Events: Annual conference (FAIRCON) with registration fees, early bird pricing, and member discounts for both general and contributing membership levels.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Annual | Individual Membership - Free |
| Subscription | Annual | Contributing Membership |
Go-to-market motion2 records
Distribution channels6 records
Marketing channels8 records
FAIR Institute product offering
Product offeringCore offering
FAIR Institute develops and stewards the FAIR (Factor Analysis of Information Risk) standard — an international taxonomy and quantitative risk analysis model for measuring, managing, and communicating cybersecurity and operational risk in financial terms. It monetizes this standard through training and CCRP certification, paid corporate/contributing membership, the annual FAIR Conference (FAIRCON) and Europe Summit, sponsorships, and partnerships that extend FAIR into automated and AI risk analytics (e.g., the GenAI Risk Platform with Safe Security).
Product overview
The FAIR Institute is a research-driven not-for-profit organization offering a portfolio of standards, models, and educational programs for quantitative cyber and operational risk management. The core offering is FAIR™ (Factor Analysis of Information Risk), the international standard for quantifying cyber risk in financial terms, complemented by specialized models including FAIR-CAM™ for measuring control effectiveness and FAIR-MAM™ for assessing cybersecurity materiality in SEC disclosures. Additional offerings include the FAIR-AIR™ playbook for AI risk management, the GenAI Risk Platform (jointly with Safe Security) for generative AI risk analysis, plus training/certification programs, an annual FAIR Conference, member resource library, and community chapters/working groups for practitioner engagement.
Differentiator
Problem solved
Functional benefit
Brands
- FAIRCON: Annual global conference for cyber and AI risk management, bringing together practitioners and leaders in the field.
- FAIR-CAM (FAIR Controls Analytics Model)
- FAIR-MAM (FAIR Materiality Assessment Model)
- FAIR-AIR
- FAIR Champion Award
Products and services
- FAIR (Factor Analysis of Information Risk) International standard taxonomy and quantitative risk analysis model for cybersecurity and operational risk that enables organizations to measure, manage, and communicate risk from the business perspective in financial terms.
- FAIR-CAM (FAIR Controls Analytics Model) Extension of the FAIR standard that enables empirical measurement of control efficacy and value, accounting for individual control functionality and systemic effects, and mapping to NIST 800-53, CIS Controls, ISO 2700, and HITRUST.
- FAIR-MAM (FAIR Materiality Assessment Model) Standard that helps organizations assess the materiality of cybersecurity risk and incidents, with a detailed taxonomy of loss categories driven by cyber incidents and quantification of impact for SEC Form 8-K disclosures.
- FAIR-AIR (FAIR Artificial Intelligence Cyber Risk Playbook) FAIR-inspired approach to identify AI-related loss exposure and guide risk-based treatment decisions for AI risk within cyber risk management, covering five vectors of GenAI risk.
- GenAI Risk Platform Platform created with Safe Security that includes a GenAI Risk Scenario Library, a FAIR-CAM-based GenAI Controls Library, and a GenAI Index to rate SaaS providers for security features.
- FAIR Training and CCRP Certification Program Education and credentialing program for the FAIR Certified Cyber Risk Professional (CCRP) certification, including FAIR fundamentals training, calibration workshops, and professional development courses.
- FAIR Conference (FAIRCON) Annual global event for cyber and AI risk professionals featuring expert speakers, case studies, research presentations, networking, and hands-on discussions.
Quantifiable outcome
- Helps organizations quickly and reliably disclose legally defensible material risk on SEC Form 8-K within the 4-day requirement
- +2 more outcomes
Companies that use FAIR Institute
Customer profileNamed customers7 records
Segments3 records
Ideal customer profiles3 records
FAIR Institute technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature5 records
FAIR Institute partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core, flagship and minor.
- Safe SecuritycoreSafe Security serves as the technical adviser to the FAIR Institute. Together they created the GenAI Risk Platform, which includes a GenAI Risk Scenario Library, GenAI Controls Library based on FAIR-CAM, and a GenAI Index to rate SaaS players for security features.
- RiskLenscoreRiskLens served as Technical Advisor to the FAIR Institute and joined forces with Safe Security to support the organization's technology platform and analytics capabilities.
- National Institute of Standards and Technology (NIST) - AI Safety Institute Consortium (AISIC)flagshipThe FAIR Institute was invited by NIST to join the US AI Safety Institute Consortium (AISIC), contributing to the development of AI safety standards and practices.
- FBIminorReferences FBI statistics and guidance on business email compromise and audio deepfakes in social engineering risk analysis.
- Verizon (DBIR)minorReferences Verizon Data Breach Investigations Report (DBIR) for statistics on phishing, social engineering, and loss recovery rates in cyber risk analysis.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
FAIR Institute competitors and assessment
Company assessmentDirect peers
- Kovrr: Cyber risk quantification vendor targeting enterprise CISOs and insurance carriers. Direct peer in the commercial CRQ category that consumes or aligns with the FAIR framework.
- Axio: Cyber risk quantification vendor that ships a FAIR-aligned SaaS platform to enterprises. Direct peer on the operational side of FAIR-based CRQ tooling.
- SANS Institute: Cybersecurity research and training organization with a heavy certification and conference portfolio. Comparable in monetizing practitioner training and producing widely adopted security frameworks.
- ISACA: Global not-for-profit professional association for IT governance, risk, and cybersecurity. Comparable member-and-certification model (CISA, CISM, CRISC) and similar standards-body role in the GRC ecosystem.
- Balbix: Cybersecurity risk and exposure quantification platform used by large enterprises. Comparable as an enterprise CRQ offering that competes on quantifying cyber loss exposure in financial terms.
- (ISC)²: Cybersecurity professional association built around the CISSP credential and member chapters. Closely comparable in monetizing certifications and serving Fortune 1000 security leaders.
- The Institute of Internal Auditors (IIA): International professional association setting standards (IPPF) for internal audit and risk. Highly comparable standards-body-plus-certification model and similar board-officer audience.
- OCEG: Not-for-profit standards body and community for governance, risk, and compliance (GRC). Comparable as an open-standards organization that issues frameworks adopted by enterprises and GRC vendors.
Others
- RiskLens: Original FAIR-aligned CRQ platform and former technical adviser to the FAIR Institute; effectively merged into Safe Security. Ecosystem peer given its historical centrality to the FAIR ecosystem.
- Safe Security: Technical adviser to the FAIR Institute and co-developer of the GenAI Risk Platform. Functions as the operational CRQ/FAIR platform vendor; adjacent ecosystem participant rather than a direct NFP peer.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
FAIR Institute social profiles
Digital presenceFAIR Institute financial estimates
Financial estimateRevenue estimate
Valuation estimate
FAIR Institute leadership team
Management profileNumber of profiles
Profiles3 records
FAIR Institute funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
FAIR Institute M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about FAIR Institute
What does FAIR Institute do?
FAIR Institute develops and stewards the FAIR (Factor Analysis of Information Risk) standard — an international taxonomy and quantitative risk analysis model for measuring, managing, and communicating cybersecurity and operational risk in financial terms. It monetizes this standard through training and CCRP certification, paid corporate/contributing membership, the annual FAIR Conference (FAIRCON) and Europe Summit, sponsorships, and partnerships that extend FAIR into automated and AI risk analytics (e.g., the GenAI Risk Platform with Safe Security).
Is FAIR Institute a public or private company?
FAIR Institute is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was FAIR Institute founded?
FAIR Institute was founded in 2015. It employs 1 to 10 people.
Where is FAIR Institute based?
FAIR Institute is headquartered in Spokane, United States, in the North America region.
How does FAIR Institute make money?
Two revenue lines are on record. Membership Programs are the primary driver. The others are FAIR Conference Events.
Who are FAIR Institute's main competitors?
Direct peers on record are Kovrr, Axio, SANS Institute, ISACA, Balbix, (ISC)², The Institute of Internal Auditors (IIA) and OCEG. Others are RiskLens and Safe Security.
Does FAIR Institute have an API?
No public API is recorded for FAIR Institute.
What industry is FAIR Institute in?
FAIR Institute's product category is Cybersecurity Risk Quantification. Its primary akta.pro industry code is HDAAAMAK, Third-Party Model/Vendor Risk & Supply-Chain Assurance, with a secondary code of HDAAAMAL, Safety & Alignment Evaluation (red-teaming, harmful capability testing).