Introduction
FAIR Data Breach Scenario
To get data for a FAIR analysis of a data breach, you need two core inputs: loss event frequency, meaning how likely the breach is, and loss magnitude, meaning how much it could cost across a range of outcomes. Both should be scoped to a defined scenario: the number of records, the assets involved, and the threat behind the event.
X-Analytics generates both from your cyber risk profile in minutes. The FAIR Data Breach Scenario Agent lets you set the record volume, asset groups, and threat categories for your scenario, then returns the event probability, loss magnitude at four percentiles, and a breakout of direct, indirect, and opportunity losses, ready to plug into your own FAIR-based simulation.
Bob Vescio, Chief Innovation Officer, walks through the FAIR Data Breach Scenario Agent, pulling X-Analytics data to populate a FAIR-based data breach simulation.
Key takeaways
- The FAIR Data Breach Scenario Agent is one of several X-Analytics Agents built to supply data for FAIR analysis
- Find it in the AI Toolbox by searching "FAIR"
- Scope the scenario by record volume, asset groups, and threat categories
- Outputs include event probability, threat score, control effectiveness, and loss magnitude at the 10th, 50th, 90th, and 97th percentiles
- Losses break out into direct, indirect, and opportunity, so they map cleanly into your FAIR analysis
- Run any record volume your profile supports, from a thousand-record breach to a billion-record breach
What is the FAIR Data Breach Scenario Agent?
The FAIR Data Breach Scenario Agent is an Agent in the X-Analytics AI Toolbox that extracts the data you need to run a FAIR-based data breach simulation. Many security and risk teams use FAIR because it's the approach they know. This Agent lets you keep using it, with inputs drawn from your X-Analytics cyber risk profile instead of gathered by hand.
How do you run a FAIR data breach scenario in X-Analytics?
Search "FAIR" in AI Tools, define the scenario, and select Fetch Variables.
- Open the Agent. Go to AI Tools, search "FAIR," and select the data breach scenario, then select Fetch Data.
- Set the record volume. Choose the size of the breach you want to simulate, such as 200,000 records, a million records, or 200 million records.
- Select asset groups. Choose every asset group that applies. In the walkthrough example: servers and apps, network, end user systems, offline data, and people.
- Select threat categories. Focus the scenario on the threats that matter. In the walkthrough example, the scenario focuses on misuse within the organization.
- Select Fetch Variables. X-Analytics confirms your scenario and returns the data for your FAIR analysis.
What data does the Agent return?
The Agent returns scenario framing, frequency inputs, and loss magnitude across four percentiles. In the walkthrough example, a 200,000-record breach driven by misuse returns:
| Output | Walkthrough example | What it gives your FAIR analysis |
|---|---|---|
| Event probability | 9.61% | Input for loss event frequency |
| Threat score | 2 | Context for the frequency estimate, based on the selected threat categories |
| Control effectiveness | 68.8% | Context for how well current controls resist the scenario |
| Low (10th percentile) | $12.5 thousand | Low end of the loss magnitude range |
| Median (50th percentile) | $7.83 million | Most likely loss magnitude |
| High (90th percentile) | $15.2 million | High end of the loss magnitude range |
| Tail (97th percentile) | $132 million | Worst-case, black swan loss |
| Loss breakout | Direct, indirect, and opportunity | Loss forms to carry into your FAIR analysis |
Figures are examples from the walkthrough. Your results reflect your own profile and the scenario you define.
How do the outputs map to FAIR?
Event probability populates loss event frequency, and the percentile losses populate loss magnitude. The four percentiles match the same severity points X-Analytics uses across its loss curve, so the low, median, high, and tail outcomes in your FAIR analysis line up with the rest of your X-Analytics reporting. The record volume, asset groups, and threat categories you select give you the scenario framing, and the direct, indirect, and opportunity breakout lets you carry each form of loss into your FAIR analysis separately.
What scenarios can you run?
Any data breach scenario your profile supports. Run a thousand-record breach, a 200,000-record breach, a two-million-record breach, or a billion-record breach, as long as your profile holds that many records. Change the asset groups or threat categories to compare scenarios side by side.
What do you walk away with?
- Loss event frequency and loss magnitude inputs for your FAIR analysis, scoped to the scenario you define
- Loss at the 10th, 50th, 90th, and 97th percentiles, with a direct, indirect, and opportunity breakout
- A fast, repeatable way to bring X-Analytics data into the FAIR approach your team already uses
Frequently asked questions
What is X-Analytics?
X-Analytics helps cybersecurity and risk leaders walk into every cyber and AI decision with answers in hand. X-Analytics is AI for cyber risk work, the cyber risk intelligence platform that delivers measurable risk-reducing opportunities in minutes for CISOs, executives, and boards.
Where do I get data for a FAIR analysis?
A FAIR analysis needs loss event frequency and loss magnitude for a defined scenario. The X-Analytics FAIR Data Breach Scenario Agent generates both from your cyber risk profile, scoped to the record volume, asset groups, and threat categories you choose.
What is the X-Analytics FAIR Data Breach Scenario Agent?
An Agent in the X-Analytics AI Toolbox that extracts the data you need to run a FAIR-based data breach simulation, including event probability, loss magnitude at four percentiles, and a direct, indirect, and opportunity loss breakout.
Can I use X-Analytics with FAIR?
Yes. X-Analytics offers several Agents that supply data for FAIR analysis. Search "FAIR" in AI Tools to see them.
What inputs do I need to run the Agent?
Three: the record volume you want to simulate, the asset groups involved, and the threat categories behind the scenario.
Which percentiles does the Agent return?
The 10th percentile (low), 50th percentile (median), 90th percentile (high), and 97th percentile (tail, or worst case).
How large a breach can I simulate?
Any record volume your profile supports, from a thousand records to a billion records, as long as your profile holds that many.
Is X-Analytics a CRQ tool?
X-Analytics is a cyber risk intelligence platform. Cyber risk intelligence includes CRQ components, and X-Analytics carries them through to the decision.
Related: Data Breach Loss Curve, Loss Tables, Threat Calibration, AI Toolbox
Questions? Contact customer success: customersuccess@x-analytics.com
© 2026 X-Analytics. All rights reserved.