EBIOS Risk Manager (Expression of Needs and Identification of Security Objectives) is a digital risk analysis and treatment method developed by ANSSI (the French national cybersecurity agency) in collaboration with Club EBIOS. Its 2018 edition introduced a threat scenario-based approach that distinguishes two levels of analysis: the strategic level, focused on the ecosystem and stakeholders, and the operational level, focused on systems and attack paths.
ANSSI explicitly recommends EBIOS Risk Manager for meeting the risk analysis requirements of the NIS2 Directive (Art. 21), for security accreditation dossiers of French government information systems under the RGS framework, and for the security policies of operators of vital importance (OIV). The method is also used internationally in the defence, healthcare and critical infrastructure sectors.
Founding Concept · The Scenario-Based Approach
EBIOS Risk Manager begins with the organisation's missions and essential business assets, then works systematically to identify relevant risk sources, their targeted objectives, and the strategic then operational scenarios they might pursue. This top-down logic — from strategic intent to technical execution — makes it possible to prioritise security measures against genuinely plausible threats, rather than an exhaustive inventory of vulnerabilities.
The method is structured around five successive workshops that guide teams from the scoping of the study object through to the definition and monitoring of a coherent, justified risk treatment plan.
Workshop 1
Scoping and Security Baseline
Definition of the study perimeter, identification of essential business assets, inventory of supporting assets, and assessment of the existing security baseline against applicable reference frameworks.
Workshop 2
Risk Sources
Identification of relevant risk sources (RS) — malicious actors, competitors, nation-states, insiders — assessment of their motivations, resources and capabilities. Definition of RS / Targeted Objective (TO) pairs to be retained for the study.
Workshop 3
Strategic Scenarios
Construction of scenarios at ecosystem level: identification of critical stakeholders, assessment of their exposure level and indirect attack paths via the supply chain or partners. Gravity of impact is assessed at this stage.
Workshop 4
Operational Scenarios
Technical elaboration of strategic scenarios: identification of attack modes, attack sequences on supporting assets, and assessment of the likelihood of each operational scenario based on risk source capabilities.
Workshop 5
Risk Treatment
Synthesis of residual risks, definition and prioritisation of additional security measures, preparation of the risk treatment plan, formalisation of the monitoring framework and performance indicators. The treatment strategy (reduction, transfer, acceptance, avoidance) is documented and submitted to governance for approval.
EBIOS Risk Manager does not operate in isolation. Its mastery requires understanding the normative frameworks it articulates with, the regulatory contexts that prescribe or recommend its use, and the sectoral tools that specify its application modalities.
EBIOS Risk Manager · ANSSI 2018
French national method for digital risk assessment and treatment — Club EBIOS
Reference ISO Standards
ISO/IEC 27001
ISMS — EBIOS RM fulfils the risk assessment requirement of clause 6.1
ISO/IEC 27005
Information security risk management process — conceptual alignment with EBIOS RM
ISO 31000
Generic risk management principles and framework
ISO/IEC 27002
Security measures catalogue — used in Workshop 1 (baseline) and Workshop 5 (treatment)
Regulatory Environment
NIS2 · (EU) 2022/2555
ANSSI recommends EBIOS RM for meeting the risk analysis requirements of Article 21(2)(a)
Security Accreditation · RGS
EBIOS RM is the reference method for security accreditation dossiers of French government information systems
Sectoral Guides and Tools
ANSSI Sectoral Guides
Healthcare, local authorities, industry — sector-specific adaptations of the method
DICP / DICT Criteria
Availability, Integrity, Confidentiality, Traceability — impact assessment grid for business assets
EBIOS RM Tool
ANSSI open-source software for conducting and documenting EBIOS RM studies
EBIOS Risk Manager is a method of reasoning before it is a method of documentation. What training must transmit is the ability to construct and defend a plausible threat scenario — not to fill in tables. Formal rigour and operational relevance are not in contradiction: they condition each other.
Delivery Context
EBIOS Risk Manager training programmes are designed for information security managers, cybersecurity consultants, teams responsible for security accreditation, and project managers involved in projects subject to risk management obligations. They systematically draw on case studies from real organisations — defence, healthcare, critical operators, financial sector — to ground learning in authentic threat contexts.
Training Formats
EBIOS Risk Manager training is available in classroom and remote formats, in French and English. Programmes cover the full method cycle — from the five workshops to presenting findings to a steering committee — and prepare participants for the corresponding PECB certifications. Particular attention is given to the articulation between EBIOS RM and ISO reference frameworks, which is frequently required in audit or certification contexts.