Due to the difficulty associated with construction of chosen-ciphertext secure key encapsulation mechanisms (KEMs), the Fujisaki-Okamoto (FO) transform is often utilized to construct such a KEM from a chosen-plaintext secure public-key encryption scheme, a primitive which is often considerably easier to directly construct. In this talk, we will discuss one such variant of the FO transform and prove the tightness of its security reduction in the random oracle model. Due to the common use of the FO transform in post-quantum lattice-based KEMs, we will pay close attention to the security of the FO transform in settings where decryption failure might occur, and we will briefly discuss the security of the FO transform in the quantum random oracle model.