Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Risk

EBIOS Risk Manager

EBIOS Risk Manager (EBIOS RM) is the cyber risk assessment method published by ANSSI, the French cybersecurity agency, and the reference for risk analyses in the French public sector and its regulated suppliers. It runs in five workshops: scope and security baseline, risk origins and target objectives, strategic scenarios across the ecosystem, operational scenarios on the technical path, and risk treatment. Its distinctive move is to model the attacker’s path through partners and suppliers, not only through the organization’s own systems.

The five workshops

Workshop 1 fixes the scope, the business values, the supporting assets and the feared events, and checks the security baseline against the applicable references. Workshop 2 pairs risk origins with the objectives they would pursue. Workshop 3 maps the ecosystem and builds strategic scenarios: which stakeholder an attacker would go through. Workshop 4 turns them into operational scenarios with a likelihood. Workshop 5 synthesizes the risks, decides the treatment and writes the plan with its residual risks.

Why it fits a supplier-heavy world

Most methods score the organization as if it were alone. EBIOS RM scores the ecosystem: a maintenance provider with remote access, a software editor, a subcontractor with a shared network is rated for its exposure and its dependency, and a strategic scenario can start there. That is why the method meets third-party risk management naturally, and why a supplier’s degraded posture should change the likelihood of a scenario rather than sit in a separate tool.

Where it is expected

The French security homologation of a téléservice (RGS) rests on a risk analysis, EBIOS RM being the expected one; health-sector and OIV programs use it; the method is also compatible with ISO 27005 and can feed an ISO 27001 risk treatment plan. In a GRC platform the value is in keeping the workshops’ outputs alive: the feared events become register entries, the operational scenarios inherit the verified status of the controls that cut them, and the treatment plan becomes owned actions.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.