The five workshops
Workshop 1 fixes the scope, the business values, the supporting assets and the feared events, and checks the security baseline against the applicable references. Workshop 2 pairs risk origins with the objectives they would pursue. Workshop 3 maps the ecosystem and builds strategic scenarios: which stakeholder an attacker would go through. Workshop 4 turns them into operational scenarios with a likelihood. Workshop 5 synthesizes the risks, decides the treatment and writes the plan with its residual risks.
Why it fits a supplier-heavy world
Most methods score the organization as if it were alone. EBIOS RM scores the ecosystem: a maintenance provider with remote access, a software editor, a subcontractor with a shared network is rated for its exposure and its dependency, and a strategic scenario can start there. That is why the method meets third-party risk management naturally, and why a supplier’s degraded posture should change the likelihood of a scenario rather than sit in a separate tool.
Where it is expected
The French security homologation of a téléservice (RGS) rests on a risk analysis, EBIOS RM being the expected one; health-sector and OIV programs use it; the method is also compatible with ISO 27005 and can feed an ISO 27001 risk treatment plan. In a GRC platform the value is in keeping the workshops’ outputs alive: the feared events become register entries, the operational scenarios inherit the verified status of the controls that cut them, and the treatment plan becomes owned actions.