← All services
Risk assessment

EBIOS RM risk assessment

EBIOS Risk Manager is ANSSI's official methodology for cyber risk assessment: it structures the analysis into 5 successive workshops. Starting from your critical missions, we identify targeted threats, build attack scenarios and draw up a prioritised treatment plan.

ANSSI's method, in figures

EBIOS RM v1.5

5Workshops
4Severity levels
4Likelihood levels
16Matrix cells
4G·P·D·R categories
∞AI-generated scenarios
✓ Recommended by ANSSI and ENISA ✓ Compatible with ISO 27001, NIS2, LPM
The method

What is EBIOS Risk Manager?

Published and maintained by ANSSI, EBIOS RM is the reference method in France for digital risk assessment, aligned with ISO 27005.

It combines compliance with a scenario-based approach: rather than a long list of vulnerabilities, it starts from your critical missions and the plausible attackers.

The process is iterative and collaborative, built in workshops with executives, business lines, IT and the CISO — a realistic, shared analysis.

The result: a prioritised risk map and an actionable treatment plan, ready to use for your decisions and your compliance (NIS2, LPM, ISO 27001).

Threat-focused

We model realistic attackers and their objectives, not an abstract list of flaws.

Iterative

The analysis sharpens cycle by cycle and updates as you change.

Collaborative

Business lines, IT and executives build a shared view of risk together.

Aligned with the frameworks

Compatible with ISO 27001, NIS2 and LPM, recognised by auditors and insurers.

The deliverable

A prioritised risk map

Each scenario is placed according to its severity and its likelihood. The matrix makes the risks to tackle first obvious at a glance.

Severity →
R3R9
R7
R12
R6
R10R8
R11R5
R4
R2
R1
Likelihood →
Critical · 1 High · 5 Moderate · 5 Low · 1
12 risk scenarios scored
6 in the priority treatment zone
Priority risks
R12
Ransomware — core bankingV4 × G4 · target: core banking
R4
SWIFT transfer fraudV4 × G3 · payment systems
R11
AD compromiseV4 × G3 · directory
The 5 workshops

The method, workshop by workshop

01

Scoping & security baseline

Defining the scope, the business values, the supporting assets and the existing security baseline.

02

Risk sources

Identifying and characterising risk sources (RS) and their target objectives (TO): attacker motivation, capability and activity.

03

Strategic scenarios

Building realistic attack paths from your ecosystem — “Know → Enter → Find → Exploit” — rated for severity G1-G4.

04

Operational scenarios

Breaking these down into sequences of technical actions, mapped to known adversary techniques (MITRE ATT&CK) and modelled graphically.

05

Risk treatment

Security measures prioritised using ANSSI's G·P·D·R model (Governance, Protection, Defence, Resilience), with an estimate of residual risk.

How we support you

How we put it in place

From the scoping note to the action plan presented to your executives, we facilitate the whole process and produce clear deliverables at every step. Expect 6 to 10 weeks in general, depending on scope.

Phase 1

Scoping & kick-off

We set the boundaries, identify your business values, your supporting assets and the stakeholders to involve. We assess the security baseline already in place.

Deliverable: scoping note & schedule
Phase 2

Collaborative workshops

We facilitate the 5 EBIOS RM workshops with your business and technical teams: risk sources, target objectives, strategic then operational scenarios are all built in session.

Deliverable: RS/TO matrices & attack scenarios
Phase 3

Scoring & mapping

Each scenario is rated for severity and likelihood on the ANSSI scales, then placed on the risk matrix to bring out the priorities.

Deliverable: prioritised risk map
Phase 4

Treatment plan

We define the security measures using the G·P·D·R model, size the effort, estimate residual risk and build a realistic, prioritised action plan.

Deliverable: treatment plan & residual risk
Phase 5

Debrief & follow-up

We present the findings to your executives in decision-making language, then support you in implementing the plan and keeping the analysis up to date.

Deliverable: final report & debrief deck
ANSSI scales

Severity & likelihood

Severity scale

G1
Minor

Negligible impact on missions

G2
Significant

Notable but manageable impact

G3
Serious

Major impact on essential missions

G4
Critical

The organisation itself is at risk

Likelihood scale

V1
Minimal

Unlikely, substantial resources required

V2
Significant

Realistic with moderate resources

V3
High

Likely, ordinary resources suffice

V4
Maximum

Very likely, scenario already observed

Let's launch your risk assessment

A first 30-minute conversation to scope the perimeter and your deadlines.