Todd Tucker is Managing Director of the FAIR Institute
It was a privilege to take the stage after Nick Sanna’s opening remarks at FAIRCON25, and to welcome what turned out to be our largest and most engaged conference audience ever, with nearly 600 attendees!
But what excites me most isn’t just the size of the crowd, it’s the strength of the movement. In the past year, the FAIR community has made tremendous progress on all fronts of our mission: maturing standards, advancing education, and deepening global collaboration.
This past year, the FAIR Institute reached a new level of maturity in its standards development efforts.
We formally defined how our standards program operates through a new Standards Committee charter, bringing greater structure and transparency to the way FAIR standards are developed and governed. This foundational step enables scalable, high-integrity development of standards that reflect practitioner needs.
We also delivered several key artifacts that move the discipline forward:
We also published many practical white papers, including:
And finally, we conducted our first annual State of Cyber Risk Management research, with input from more than 400 cyber risk leaders worldwide. The data clearly demonstrate that quantitative cyber risk management approaches have gone mainstream and that program maturity leads to much greater risk reduction for the enterprise.
Together, these deliverables have laid down the clearest, most actionable blueprint yet for risk-informed cyber decision-making.
Building on that momentum, our active workstreams for 2026 include:
These are open, community-powered initiatives, and your input is always welcome.
As demand for quantitative risk expertise grows, we’re scaling and structuring the FAIR learning journey to meet professionals at every stage of their careers.
In the past year, we launched two cornerstone courses:
Both are now part of the standard path toward FAIR Institute certifications.
Forthcoming courses include:
And we’re organizing our education around role-based certifications:
A special thank you to our Education Advisory Committee! This diverse and global group of more than a dozen experts (from ADP, Mastercard, SAP, Richemont, Nationwide, and many others) is shaping the direction and depth of our offerings.
FAIR is a community and a movement as much as it’s a framework. And it’s gaining momentum with:
What makes this growth especially meaningful is how actively our members are collaborating to shape the future of cyber risk management through working groups and communities of practice.
We currently have active or emerging working groups in areas including:
These working groups are open to practitioners, researchers, and partners who want to contribute to pragmatic, standards-aligned advancement in the field. Whether you’re contributing to a working group, mentoring a new analyst, or speaking at a chapter event — the FAIR community thrives on practitioner engagement.
Want to get involved? Reach out to us at InvolveMe@FAIRInstitute.org.
At FAIRCON25, we saw how far we’ve come and how powerful this community can be when it works together.
To those already involved: thank you for your leadership.
To those just discovering FAIR: welcome aboard! We’re just getting started.
Together, let’s keep building the future of cyber risk management!