A hybrid FAIR and XGBoost framework for cyber-risk intelligence and expected loss prediction
Chioma Ngozi Nwafor, Obumneme Nwafor, Sanjukta Brahma, Madhusudan Acharyya · Expert Systems with Applications · 2025
This paper presents a hybrid framework integrating the Factor Analysis of Information Risk (FAIR) model with XGBoost and SHAP explainablity for cyber risk intelligence. We extend traditional FAIR methodology by developing a composite Risk Exposure Score (RES) that unifies frequency, vulnerability, control maturity, loss severity, and operational downtime into a standardised metric for risk stratification and machine learning analysis. Our novel NIST CSF-based control maturity quantification provides objective measures of security effectiveness using technology (40%), process (35%), and people (25%) weightings derived from empirical correlation analysis. Testing on 3000 simulated cyber incident scenarios reveals threshold effects, with Expected Annual Loss exhibiting exponential growth beyond RES values of 0.4. SHAP analysis identifies Primary Loss and Technology Score as the most influential EAL predictors, demonstrating that control maturity effectiveness diminishes significantly in high-exposure environments. We deployed a Streamlit-based dashboard operationalising the framework for risk analysts, cyber insurers, and governance professionals. The system processes threat intelligence data, generates probabilistic risk scenarios, and provides real-time risk calculations through an interactive interface. This research contributes the first deployable integration of FAIR quantitative modelling with explainable ML, addressing the research-to-practice gap in cyber-risk quantification while supporting regulatory compliance requirements under NIS2 and SEC cybersecurity disclosure mandates.