FAIR Institute is a research-driven not-for-profit organization focused on advancing cyber and operational risk management through education, standards, and collaboration. Its work centers on helping organizations use the FAIR methodology to understand, quantify, manage, and communicate risk in business and financial terms rather than relying on qualitative scoring alone.
FAIR Institute combines practitioner education, standards development, member programs, and peer collaboration into a specialized community for cyber risk leaders. Its portfolio spans certification and executive learning, standards extensions such as FAIR-CAM and FAIR-MAM, individual and corporate membership, research boards, local chapters, and the annual FAIR Conference. The result is a focused platform for organizations seeking more defensible and decision-oriented risk management practices.
Offerings, Capabilities, and Integrations
FAIR Institute delivers a mix of standards, training, and community programs that help organizations operationalize quantitative cyber risk management. Its capabilities include role-based education for practitioners through executives, structured certification pathways, applied learning tools, and collaborative forums for sharing implementation practices across industries.
Its standards work extends FAIR into adjacent domains such as control analysis, materiality assessment, and third-party risk. FAIR Institute also positions its methods to work alongside established frameworks and control structures, including NIST, CIS, ISO, and HITRUST-oriented environments, giving members a way to connect quantitative analysis with existing governance, compliance, and security programs.
Products and Services
- FAIR Institute Certification Program: Flagship education and credentialing program that builds and validates the ability to apply FAIR to assess, quantify, manage, and communicate cyber risk. It follows a structured learning path with role-based training and tiered certifications for professionals, leaders, and executives.
- FAIR Third-Party Risk Management specialization: Instructor-led specialization for professionals who run or support third-party risk management programs and want to move from questionnaire-heavy, compliance-led processes to a FAIR-based, risk-informed approach.
- Cyber Risk Management for Executives: Executive-focused online specialization designed for senior leaders and board-facing stakeholders who need to govern cyber risk, align it with business objectives, and improve decision-making and risk communication.
- FAIR Controls Analytics Model (FAIR-CAM): Ancillary FAIR standard that explains how controls affect risk individually and as a system, enabling more rigorous measurement of control efficacy, value, and risk reduction impact.
- FAIR Materiality Assessment Model (FAIR-MAM): Open financial loss model and FAIR extension used to assess the materiality of cyber risk and incidents by expanding loss magnitude into a more detailed cost taxonomy.
- Individual Membership: Membership program for business, risk, and technology practitioners that offers access to the FAIR community, webinars, local chapter meetings, selected learning tools, and tiered benefits through General and Contributing membership options.
- Corporate Membership Program: Organization-level membership that gives participating companies access to FAIR Institute resources for employees, exclusive events, annual conference passes, and participation in research and standards activities.
- FAIR Conference: Annual global conference focused on cyber risk management, featuring practitioner case studies, standards discussions, executive perspectives, workshops, and pre-conference training.
- FAIR-U Workbook for Learners (BETA): Excel-based hands-on learning workbook that lets users build and manipulate FAIR risk scenarios directly to strengthen practical understanding of the model.
- FAIR Academy: Digital learning environment used to access FAIR Institute training, including foundational coursework and executive education offerings.
- Industry Risk Research Boards: Collaborative peer groups organized by industry that help shape FAIR Institute research priorities, discuss pressing risk challenges, and validate research outputs.
- Local Chapters: Regional member communities that provide recurring peer engagement, knowledge sharing, and practical discussion of FAIR adoption across geographies and industries.
Target Customers
FAIR Institute primarily serves cybersecurity, technology risk, operational risk, and business leaders who need a more defensible way to evaluate and communicate risk. Its training and standards are aimed at analysts, risk managers, third-party risk professionals, CISOs, executives, and other decision-makers responsible for cyber risk governance and investment prioritization.
Its customer base spans organizations of different sizes and industries, with visible engagement from sectors such as financial services, healthcare, retail, technology, government, insurance, manufacturing, and transportation. FAIR Institute is especially relevant for enterprises building mature cyber risk programs, companies seeking to align security with financial decision-making, and teams that want structured peer collaboration through membership, chapters, research boards, and events.
Key People
- Nicola (Nick) Sanna: President and Founder
- Jack Jones: Chairman Emeritus
- Todd Tucker: Managing Director
- Pankaj Goyal: Director, Standards & Research
- Bernadette Dunn: Director, FAIR Enablement
- Omar Khawaja: Board Director
Key Facts
- Headquarters: Spokane, Washington, United States
- Employees: 2-10
- Annual Revenue: $1M-$10M
- Parent Company: Safe Security
- Subsidiaries: None
- Publicly Listed: No