---
title: Bank CISOs Debate FAIR in Risk.net Article
description: Pros and cons of the FAIR risk model, as seen by banking industry information security managers.
---

[The FAIR Institute Blog ](https://www.fairinstitute.org/blog)

# [Bank CISOs Debate FAIR in Risk.net Article](https://www.fairinstitute.org/blog/bank-cisos-debate-fair-in-risk-net-article)

 Written by [Jeff B. Copeland](https://www.fairinstitute.org/blog/author/jeff-b-copeland) | Jul 21, 2017 2:36:48 PM

You might say this article, “[Bank Cyber Chiefs at Odds Over Risk Models](http://www.risk.net/risk-management/operational-risk/5303831/bank-cyber-chiefs-at-odds-over-risk-models)” (registration required) by Steve Marlin, just out on [Risk.net](http://risk.net/), takes a snapshot of the current stage of evolution of banking information security executives, progressing towards a bank cyber risk model that’s as rigorous as the industry's models for market and credit risk. 

Marlin cites the [FAIR model](https://www.fairinstitute.org/why-fair) as the banking industry’s “most commonly used approach to quantifying cyber risk…FAIR seeks to provide a straightforward map of risk factors and their interrelationships.” 

But the article goes on to quote banking CISOs stating a series of objections (and misperceptions) about quantitative risk analysis:

- Too many scenarios to model in the banking threat landscape
- Too complicated for executives to follow—checklists are all they can handle
- Too limited for use on an enterprise level

Bank CISOs who are FAIR fans speak up, too.  [Evan Wheeler](https://www.fairinstitute.org/blog/meet-a-fair-institute-member-evan-wheeler) of MUFG Union Bank (and a FAIR Institute Board Member) said FAIR provides "a decomposition of risks and understanding of the relationships between threats, weaknesses and potential impacts in a consistent way that you can model."

[FAIR model creator Jack Jones](https://www.fairinstitute.org/blog/author/jack-jones) is also quoted, extensively answering all the objections. 

“It’s unfortunate that there are still a large number of people who don’t understand that there are reasonable and effective solutions [to modeling cyber risk],” Jack told Risk.net. ”I’ve had numerous conversations with CISOs about FAIR. They see the practical value of it.” 

**For an in-depth guide to educating executive management about the value of the FAIR model and quantitative risk analysis, read Jack’s eBook** [An Executive’s Guide to Cyber Risk Economics](http://www.risklens.com/cyber-risk-economics-ebook?hsCtaTracking=06803bc4-1341-4585-87d8-8b5453677e54%7Ca87f6fff-a6a3-4930-b0ca-62bbadb212eb).

[View full post](https://www.fairinstitute.org/blog/bank-cisos-debate-fair-in-risk-net-article)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Jeff B. Copeland"
  },
  "dateModified" : "2017-07-21T14:52:03.999Z",
  "datePublished" : "2017-07-21T14:36:48Z",
  "headline" : "Bank CISOs Debate FAIR in Risk.net Article",
  "image" : {
    "@type" : "ImageObject",
    "height" : 667,
    "url" : "https://cdn2.hubspot.net/hubfs/1616664/Blog%20Pictures/Stock%20Photos/Bank-CISOs-Debate-FAIR.jpg",
    "width" : 1000
  },
  "mainEntityOfPage" : "https://www.fairinstitute.org/blog/bank-cisos-debate-fair-in-risk-net-article",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "FAIR Institute Blog"
  }
}
```