Applying FAIR to OT

Justin Turner

S4x24 - ICS Security Conference · Day 2 · Stage 2

Overview

In this insightful talk from S4, Justin Turner delves into the critical subject of cyber risk quantification within Operational Technology (OT) environments, specifically advocating for the adoption of the FAIR (Factor Analysis of Information Risk) framework. The presentation addresses a fundamental challenge faced by security professionals: translating complex, technical cybersecurity risks into tangible financial impacts that resonate with business leadership. Turner highlights the inadequacy of traditional, qualitative risk assessments ("impact times likelihood") when confronted with the need for concrete financial figures, a requirement increasingly underscored by regulatory mandates like the SEC cyber disclosure rules.

Watch on YouTube

Visual summary for Applying FAIR to OT by Justin Turner
Visual summary for Applying FAIR to OT by Justin Turner

Key moments

  1. 0:00 Introduction to FAIR and its origin story
  2. 1:15 Importance of FAIR for SEC cyber disclosure
  3. 2:05 Why traditional risk formulas fall short for OT
  4. 2:35 Understanding risk through FAIR's event scenarios
  5. 3:05 Translating cyber risk into financial terms for leaders
  6. 4:00 Q&A: Applying FAIR to non-cyber and environmental risks

Applying FAIR to OT

Speakers: Justin Turner

Conference: S4

YouTube: https://www.youtube.com/watch?v=cQAqM8wi_mo

Overview

In this insightful talk from S4, Justin Turner delves into the critical subject of cyber risk quantification within Operational Technology (OT) environments, specifically advocating for the adoption of the FAIR (Factor Analysis of Information Risk) framework. The presentation addresses a fundamental challenge faced by security professionals: translating complex, technical cybersecurity risks into tangible financial impacts that resonate with business leadership. Turner highlights the inadequacy of traditional, qualitative risk assessments ("impact times likelihood") when confronted with the need for concrete financial figures, a requirement increasingly underscored by regulatory mandates like the SEC cyber disclosure rules.

The core premise of the talk is that while conventional risk formulas aren't entirely obsolete, they often fall short when attempting to quantify abstract risks, such as a "lack of visibility into OT assets," in monetary terms. FAIR offers a structured, analytical alternative designed to break down these complex risks into measurable components, ultimately expressing potential losses in dollars and cents. This financial translation is crucial for effective decision-making, enabling organizations to justify security investments, prioritize defensive strategies, and communicate risk posture in a language understood by those holding the "purse strings."

Turner's discussion is particularly pertinent for the OT domain, where the consequences of cyber incidents can extend beyond data breaches to include physical damage, environmental impact, safety hazards, and significant operational downtime. By applying FAIR, OT security teams can move beyond subjective risk matrices to provide empirical, financially-driven insights into their risk landscape, fostering a more strategic and impactful approach to cybersecurity in critical infrastructure and industrial control systems.

Background

▶ Watch: Introduction to FAIR and its origin story (0:00)

The genesis of the FAIR framework, as recounted by Justin Turner, stems from a common predicament faced by Chief Information Security Officers (CISOs). The framework's author, Jack Jones, then a CISO at a large insurance company, was famously challenged by leadership with two pivotal questions: "How much risk do we have now?" and, critically, "If we allocate the requested funding and fix things, how much risk will we have after that?" This seemingly straightforward inquiry exposed a significant gap in conventional risk management methodologies. While security teams could articulate risks qualitatively—high, medium, or low impact; probable or improbable likelihood—they often struggled to provide a concrete, financially quantifiable answer to these business-oriented questions.

Traditional risk assessment often relies on a formula of "impact times likelihood." While intuitively appealing, this approach presents substantial difficulties in practice, especially when dealing with less direct, systemic risks. For instance, Turner cites the challenge of quantifying the risk associated with a "lack of visibility into OT assets" or "poor OT asset management." How does one assign a precise numerical likelihood to such a broad issue? And how does one translate its potential impact directly into a dollar figure that holds weight with financial stakeholders? These abstract risks, while undeniably critical, resist easy quantification through traditional means, leading to subjective assessments that lack the precision required for strategic business decisions.

The problem is exacerbated in the Operational Technology (OT) environment. Unlike IT, where data confidentiality and integrity are paramount, OT systems govern physical processes. Risks in OT can lead to equipment damage, production halts, environmental incidents, safety concerns, and even loss of life. The financial implications are often tied to operational downtime, regulatory fines, cleanup costs, and reputational damage, which are complex to model using qualitative scales. Furthermore, OT environments typically feature legacy systems, unique protocols, and a focus on availability over confidentiality, creating a distinct risk profile that traditional IT-centric risk models may not adequately address.

This confluence of factors—the inherent limitations of qualitative risk assessment, the specific challenges of the OT landscape, and the increasing demand from executive leadership and regulators (such as the SEC cyber disclosure requirements for publicly traded organizations) for financially material risk insights—created a fertile ground for methodologies like FAIR. FAIR was developed to bridge this communication gap, providing a standardized, defensible model to analyze and express cyber risk in the universal language of business: money. It aims to move organizations beyond simply acknowledging risks to actively understanding their financial exposure and the return on investment for security countermeasures.

Key Findings

▶ Watch: Why traditional risk formulas fall short for OT (2:05)

The core contribution of Justin Turner's talk is the robust advocacy for FAIR (Factor Analysis of Information Risk) as a superior methodology for cyber risk quantification, particularly within the challenging Operational Technology (OT) domain. The key findings and contributions highlighted by Turner are:

  1. Redefining Risk Quantification Beyond Traditional Formulas: Turner explicitly states that while the classic "impact times likelihood" formula isn't necessarily antiquated, it often proves insufficient for quantifying complex, systemic risks in a financially meaningful way. FAIR offers a more granular and analytical approach, moving beyond vague subjective ratings to a data-driven model.
  1. Focus on Event Scenarios and Threat Chains: Instead of attempting to quantify broad risks like "lack of visibility," FAIR encourages mapping out specific event scenarios or threat chains. This involves identifying a threat actor, their method (e.g., an exploit), the specific assets they aim to impact, and the resulting outcome. This decomposition makes the risk more tangible and measurable. For example, instead of "poor asset management," FAIR would analyze the risk of "an external threat actor using a known vulnerability to compromise an unpatched PLC, leading to a production line shutdown."
  1. Translating Risk into Financial Terms: The most significant finding and objective of FAIR is its ability to translate potential cyber incidents into dollars and cents. Turner emphasizes that this financial quantification is paramount for engaging with business leaders who make decisions based on economic factors. Understanding "what is this going to cost me if I do it?" versus "what is this going to cost me if I don't do it?" becomes achievable and defensible.
  1. Flexibility in Asset Definition: The framework allows for significant flexibility in defining assets. While not explicitly detailed in the provided transcript, this implies that assets in an OT context can include not just IT infrastructure but also critical industrial control systems (ICS), programmable logic controllers (PLCs), human-machine interfaces (HMIs), physical processes, production lines, and even environmental impact factors.
  1. Addressing Regulatory and Leadership Demands: The talk implicitly and explicitly highlights the growing pressure from regulatory bodies, such as the SEC cyber disclosure requirements for publicly traded organizations. These mandates necessitate a more rigorous and quantifiable understanding of cyber risk and its potential material impact. FAIR provides a methodology to meet these demands by helping organizations measure risks against their "materiality threshold."
  1. Applicability Beyond Pure Cyber: While primarily a cyber-focused framework, Turner notes FAIR's flexibility to incorporate non-cyber risks. He uses the example of "environmental factors and variables that may cause an outage," indicating that the underlying principles of impact analysis can be extended to broader business continuity and operational resilience scenarios. This demonstrates the framework's versatility in providing a holistic view of potential disruptions that have a financial consequence.

In essence, the key finding is that FAIR provides a powerful, structured, and financially-oriented lens through which organizations, particularly those managing complex OT environments, can understand, measure, and communicate their cyber risk posture. It moves the conversation from abstract security concerns to concrete financial exposure, empowering more informed and strategic decision-making.

Technical Deep Dive

▶ Watch: Understanding risk through FAIR's event scenarios (2:35)

The technical core of applying FAIR in any environment, especially OT, revolves around a fundamental shift in how risk is conceptualized and broken down. Justin Turner explains that instead of grappling with amorphous risks like "lack of visibility," FAIR mandates the mapping out of specific event scenarios or a threat chain. This structured approach is central to its ability to quantify risk in financial terms.

A threat chain in FAIR is a sequence of events leading to a loss event, comprising several key components:

  1. Threat Actor: This is the entity capable of initiating a harmful event. In an OT context, this could range from sophisticated nation-state actors targeting critical infrastructure, to insider threats (malicious or negligent employees), to hacktivist groups, or even environmental factors (as acknowledged by Turner). Identifying the specific type of actor helps in assessing their capabilities and motivations.
  1. Method (or Threat Event): This refers to the means or technique used by the threat actor to carry out their objective. Turner specifically mentions an exploit as an example. In OT, methods could include exploiting known vulnerabilities in industrial control systems (e.g., unpatched PLCs, exposed HMIs), phishing campaigns targeting OT operators, physical breaches, denial-of-service attacks against network components, or even misconfigurations that create pathways for unauthorized access. The method is crucial because it directly links the actor's intent to a potential impact.
  1. Impact on Assets: The threat actor, using their method, aims to affect one or more assets. Turner highlights the flexibility in defining assets. In an OT environment, assets are diverse and critical. They can include:
  • Physical Assets: PLCs, RTUs, HMIs, SCADA servers, sensors, actuators, network devices (switches, firewalls), turbines, pumps, valves, and entire production lines or power grids.
  • Logical Assets: Control system software, operational data, network configurations, proprietary algorithms.
  • Intangible Assets: Brand reputation, intellectual property (e.g., proprietary manufacturing processes), regulatory compliance.
  • Human Assets: Operators, engineers, maintenance staff whose actions or inactions can be a vector or a target.

FAIR requires a clear definition of the specific asset(s) at risk in a given scenario, as this directly influences the potential loss.

  1. Outcome (or Loss Event): This is the ultimate negative consequence resulting from the successful execution of the threat chain. The outcome must be defined in terms that can be financially quantified. For OT, outcomes are typically severe and often multi-faceted:
  • Operational Downtime: Loss of production, service disruption, inability to control critical processes. This is often the most immediate and significant financial loss.
  • Equipment Damage: Physical destruction or degradation of industrial machinery, requiring repair or replacement.
  • Environmental Damage: Spills, emissions, or other ecological harm, leading to cleanup costs and regulatory fines.
  • Safety Incidents: Injuries or fatalities to personnel, leading to legal liabilities and reputational damage.
  • Loss of Data/IP: Theft of proprietary manufacturing processes, control logic, or sensitive operational data.
  • Regulatory Fines and Penalties: Non-compliance with industry standards or government regulations following an incident.
  • Reputational Damage: Loss of customer trust, market share, and investor confidence.

The technical power of FAIR lies in its ability to decompose these complex scenarios into these constituent factors and then, through a series of quantitative estimations, calculate the probable range of financial loss. Instead of assigning subjective "high" or "low" ratings, FAIR uses ranges for factors like frequency of threat events, vulnerability, technical control strength, and various loss magnitudes (e.g., primary loss from productivity, secondary loss from reputation). This involves collecting data, leveraging expert judgment, and employing Monte Carlo simulations to generate a probabilistic range of annualized loss exposure (ALE) in dollars and cents.

For example, a traditional risk assessment might say: "Risk of PLC compromise: High." FAIR would break this down: "What is the probable frequency of a specific threat actor (e.g., external ransomware group) successfully exploiting a specific vulnerability (e.g., unpatched Siemens PLC vulnerability, CVE-XXXX-YYYY) via a specific method (e.g., phishing leading to network pivot)? If successful, what is the probable range of operational downtime (e.g., 24-72 hours), the cost per hour of downtime, potential equipment damage, and any associated safety or environmental fines?" By asking these specific questions and assigning probabilistic ranges to each factor, FAIR constructs a comprehensive and financially defensible risk model.

This detailed breakdown is particularly beneficial for OT because it forces a granular understanding of the environment, identifying specific assets, their vulnerabilities, potential threat actors, and the various financial consequences of an incident. It moves security discussions from abstract fears to concrete financial planning and allows for targeted investments where they can have the greatest impact on reducing financial risk. The mention of SEC cyber disclosure further underscores the necessity of this detailed, financially-oriented approach, as organizations must now be prepared to report on material cyber risks and incidents in monetary terms.

Demo / Proof of Concept

▶ Watch: Translating cyber risk into financial terms for leaders (3:05)

Justin Turner explicitly states at the end of the provided transcript: "I want to give an introduction of kind of what this is, but then we're also going to highlight one sort of case study example of how this has been done before so that you can kind of see how this might work in in practice."

However, the provided transcript concludes shortly after this statement, before any details of this specific case study or demonstration could be shared. Therefore, while the speaker intended to illustrate the practical application of FAIR in an OT context through an example, the specifics of this demonstration are not available in the given material. It is clear that a practical illustration would involve walking through a specific OT risk scenario, identifying the threat actors, methods, assets, and potential outcomes, and then demonstrating how FAIR's quantitative approach translates these elements into a financial risk assessment. Such a case study would likely highlight the steps involved in estimating loss magnitudes (e.g., cost of downtime, repair, fines) and event frequencies, culminating in a clear, monetary representation of risk exposure.

Defensive Implications

▶ Watch: Q&A: Applying FAIR to non-cyber and environmental risks (4:00)

The application of FAIR to OT cyber risk quantification has profound implications for defensive strategies, shifting the focus from generic security controls to financially optimized risk reduction. Defenders can leverage this framework to make more informed, data-driven decisions that align directly with business objectives.

  1. Strategic Investment Justification: Perhaps the most significant implication is the ability to justify security investments with concrete financial data. Instead of arguing for a new firewall or an OT asset inventory system based on abstract "best practices" or "reducing risk," defenders can now present a clear return on investment (ROI). For example, if a FAIR analysis shows an annualized loss exposure of $5 million due from unpatched PLCs, and a proposed patching program (or compensating control like network segmentation) costs $500,000 but reduces the exposure by $3 million, the financial benefit is immediately clear to leadership. This empowers OT security teams to secure funding for critical initiatives that might otherwise be deprioritized.
  1. Prioritized Risk Mitigation: FAIR enables defenders to prioritize mitigation efforts based on financial impact. By quantifying the potential loss associated with various threat scenarios, organizations can identify the "top risks" not just qualitatively, but in terms of their actual dollar exposure. This allows resources—budget, personnel, time—to be allocated to address the scenarios that pose the greatest financial threat to the organization's OT operations, rather than simply chasing every vulnerability or compliance checkbox. For instance, an OT environment might have numerous vulnerabilities, but FAIR can help identify which ones, if exploited, would lead to the most costly production downtime or environmental damage.
  1. Enhanced Communication with Leadership: The framework provides a common language—dollars and cents—for technical security teams and non-technical business leaders. This bridges the communication gap, allowing security professionals to articulate risk in terms that resonate with executives concerned with profitability, shareholder value, and operational continuity. This fosters a more collaborative approach to risk management, where security is seen as a business enabler rather than just a cost center.
  1. Improved Visibility and Data Collection: As Turner points out, "lack of visibility into OT assets" is a common, yet difficult-to-quantify risk. Implementing FAIR necessitates a deeper understanding of the OT environment to model scenarios accurately. This inherently drives requirements for better OT asset management, network monitoring, vulnerability scanning (where safe and appropriate), and incident response data collection. To quantify risk effectively, defenders will need to invest in tools and processes that provide the granular data necessary for FAIR inputs, such as potential downtime costs, repair expenses, and threat event frequencies. This pushes organizations towards a more mature and data-rich OT security posture.
  1. Tailored Defensive Strategies: FAIR encourages a detailed breakdown of threat chains, forcing defenders to consider specific threat actors, their methods, and the particular assets at risk. This level of detail allows for the development of tailored defensive strategies rather than generic ones. Instead of a blanket approach, defenses can be optimized for the most probable and impactful attack vectors against critical OT components. For example, if a specific type of ransomware affecting a particular HMI is identified as a high financial risk, resources can be focused on hardening that HMI, implementing specific network segmentation, and improving backup/recovery for that system.
  1. Proactive Risk Management: By focusing on future potential loss events, FAIR promotes a proactive approach to risk management. It encourages "what-if" scenario planning and continuous re-evaluation of risk as the threat landscape or organizational context changes. This allows defenders to anticipate potential impacts and implement controls before incidents occur, rather than reacting post-breach.

In summary, adopting FAIR moves OT security from a reactive, compliance-driven, or qualitative exercise to a strategic, quantitative, and financially informed discipline. It empowers defenders to effectively communicate their needs, prioritize their efforts, and demonstrate the tangible value of their work in protecting critical industrial operations.

Key Takeaways

  • FAIR (Factor Analysis of Information Risk) is a robust methodology for cyber risk quantification, designed to translate abstract cybersecurity risks into concrete financial impacts.
  • Traditional "impact times likelihood" risk assessments often struggle to provide meaningful financial quantification for complex risks like "lack of visibility into OT assets."
  • The core of FAIR involves mapping out specific event scenarios or threat chains, identifying the threat actor, their method (e.g., exploit), the assets impacted, and the resulting outcome.
  • The ultimate goal of FAIR is to express potential cyber losses in dollars and cents, enabling business leaders to make financially informed decisions about security investments and risk mitigation.
  • FAIR is particularly relevant for publicly traded organizations due to increasing regulatory demands like SEC cyber disclosure requirements, which mandate a quantifiable understanding of material cyber risks.
  • While primarily cyber-focused, the FAIR framework offers the flexibility to incorporate non-cyber factors (e.g., environmental variables causing outages) that can contribute to overall business impact and financial loss.

About the Speaker(s)

Justin Turner is a speaker at the S4 conference, where he presented on the topic of applying the FAIR framework to Operational Technology (OT) environments for cyber risk quantification. His expertise lies in helping organizations understand and measure cyber risk in financial terms. While the transcript does not provide specific details about his title or company affiliation, his presentation demonstrates a deep understanding of the FAIR methodology and its practical application, particularly in the unique context of industrial control systems and critical infrastructure.

The talk also references Jack Jones as the author and genesis of the FAIR framework. Jack Jones, at the time of developing FAIR, was a CISO at a large insurance company, highlighting the practical, business-driven origins of the methodology.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk by Justin Turner effectively advocates for the FAIR framework as a critical tool for cyber risk quantification in Operational Technology (OT) environments. It articulates the shortcomings of traditional qualitative risk assessments and demonstrates how FAIR's structured approach translates complex OT risks, from physical damage to operational downtime, into tangible financial impacts. The emphasis on financial quantification for business leaders and regulatory compliance (like SEC disclosures) provides immense practical value, making it a highly actionable session for OT security professionals seeking to justify investments and prioritize mitigation strategies.

Heather Calloway (CISO) — MUST SEE

This talk on applying FAIR to OT environments is essential. It delivers precisely what executive leadership and boards demand: a clear, financially quantifiable understanding of cyber risk. Moving beyond vague qualitative assessments, it provides a robust framework to translate technical vulnerabilities into tangible business exposure, enabling strategic investment justification and clear risk ownership, especially critical given current regulatory mandates like SEC cyber disclosure. This is not just theoretical; it offers a direct path to informed decision-making for critical infrastructure security.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference