EBIOS Risk Manager is ANSSI's official methodology for cyber risk assessment: it structures the analysis into 5 successive workshops. Starting from your critical missions, we identify targeted threats, build attack scenarios and draw up a prioritised treatment plan.
Published and maintained by ANSSI, EBIOS RM is the reference method in France for digital risk assessment, aligned with ISO 27005.
It combines compliance with a scenario-based approach: rather than a long list of vulnerabilities, it starts from your critical missions and the plausible attackers.
The process is iterative and collaborative, built in workshops with executives, business lines, IT and the CISO — a realistic, shared analysis.
The result: a prioritised risk map and an actionable treatment plan, ready to use for your decisions and your compliance (NIS2, LPM, ISO 27001).
We model realistic attackers and their objectives, not an abstract list of flaws.
The analysis sharpens cycle by cycle and updates as you change.
Business lines, IT and executives build a shared view of risk together.
Compatible with ISO 27001, NIS2 and LPM, recognised by auditors and insurers.
Each scenario is placed according to its severity and its likelihood. The matrix makes the risks to tackle first obvious at a glance.
Defining the scope, the business values, the supporting assets and the existing security baseline.
Identifying and characterising risk sources (RS) and their target objectives (TO): attacker motivation, capability and activity.
Building realistic attack paths from your ecosystem — “Know → Enter → Find → Exploit” — rated for severity G1-G4.
Breaking these down into sequences of technical actions, mapped to known adversary techniques (MITRE ATT&CK) and modelled graphically.
Security measures prioritised using ANSSI's G·P·D·R model (Governance, Protection, Defence, Resilience), with an estimate of residual risk.
From the scoping note to the action plan presented to your executives, we facilitate the whole process and produce clear deliverables at every step. Expect 6 to 10 weeks in general, depending on scope.
We set the boundaries, identify your business values, your supporting assets and the stakeholders to involve. We assess the security baseline already in place.
Deliverable: scoping note & scheduleWe facilitate the 5 EBIOS RM workshops with your business and technical teams: risk sources, target objectives, strategic then operational scenarios are all built in session.
Deliverable: RS/TO matrices & attack scenariosEach scenario is rated for severity and likelihood on the ANSSI scales, then placed on the risk matrix to bring out the priorities.
Deliverable: prioritised risk mapWe define the security measures using the G·P·D·R model, size the effort, estimate residual risk and build a realistic, prioritised action plan.
Deliverable: treatment plan & residual riskWe present the findings to your executives in decision-making language, then support you in implementing the plan and keeping the analysis up to date.
Deliverable: final report & debrief deckNegligible impact on missions
Notable but manageable impact
Major impact on essential missions
The organisation itself is at risk
Unlikely, substantial resources required
Realistic with moderate resources
Likely, ordinary resources suffice
Very likely, scenario already observed
A first 30-minute conversation to scope the perimeter and your deadlines.