ANSSI Method · EBIOS Risk Manager

Threat Scenario-Based Risk Analysis

EBIOS Risk Manager, published by ANSSI in 2018, is the French reference method for assessing and treating digital risks by modelling the threat landscape through the lens of risk sources, their objectives, and plausible attack scenarios.

The Method and Its Context

EBIOS Risk Manager (Expression of Needs and Identification of Security Objectives) is a digital risk analysis and treatment method developed by ANSSI (the French national cybersecurity agency) in collaboration with Club EBIOS. Its 2018 edition introduced a threat scenario-based approach that distinguishes two levels of analysis: the strategic level, focused on the ecosystem and stakeholders, and the operational level, focused on systems and attack paths.

ANSSI explicitly recommends EBIOS Risk Manager for meeting the risk analysis requirements of the NIS2 Directive (Art. 21), for security accreditation dossiers of French government information systems under the RGS framework, and for the security policies of operators of vital importance (OIV). The method is also used internationally in the defence, healthcare and critical infrastructure sectors.

Founding Concept · The Scenario-Based Approach

EBIOS Risk Manager begins with the organisation's missions and essential business assets, then works systematically to identify relevant risk sources, their targeted objectives, and the strategic then operational scenarios they might pursue. This top-down logic — from strategic intent to technical execution — makes it possible to prioritise security measures against genuinely plausible threats, rather than an exhaustive inventory of vulnerabilities.

The method is structured around five successive workshops that guide teams from the scoping of the study object through to the definition and monitoring of a coherent, justified risk treatment plan.

The Five Workshops

Workshop 1

Scoping and Security Baseline

Definition of the study perimeter, identification of essential business assets, inventory of supporting assets, and assessment of the existing security baseline against applicable reference frameworks.

Workshop 2

Risk Sources

Identification of relevant risk sources (RS) — malicious actors, competitors, nation-states, insiders — assessment of their motivations, resources and capabilities. Definition of RS / Targeted Objective (TO) pairs to be retained for the study.

Workshop 3

Strategic Scenarios

Construction of scenarios at ecosystem level: identification of critical stakeholders, assessment of their exposure level and indirect attack paths via the supply chain or partners. Gravity of impact is assessed at this stage.

Workshop 4

Operational Scenarios

Technical elaboration of strategic scenarios: identification of attack modes, attack sequences on supporting assets, and assessment of the likelihood of each operational scenario based on risk source capabilities.

Workshop 5

Risk Treatment

Synthesis of residual risks, definition and prioritisation of additional security measures, preparation of the risk treatment plan, formalisation of the monitoring framework and performance indicators. The treatment strategy (reduction, transfer, acceptance, avoidance) is documented and submitted to governance for approval.

My Teaching Approach

EBIOS Risk Manager does not operate in isolation. Its mastery requires understanding the normative frameworks it articulates with, the regulatory contexts that prescribe or recommend its use, and the sectoral tools that specify its application modalities.

EBIOS Risk Manager · ANSSI 2018

French national method for digital risk assessment and treatment — Club EBIOS

Reference ISO Standards

ISO/IEC 27001

ISMS — EBIOS RM fulfils the risk assessment requirement of clause 6.1

ISO/IEC 27005

Information security risk management process — conceptual alignment with EBIOS RM

ISO 31000

Generic risk management principles and framework

ISO/IEC 27002

Security measures catalogue — used in Workshop 1 (baseline) and Workshop 5 (treatment)

Regulatory Environment

NIS2 · (EU) 2022/2555

ANSSI recommends EBIOS RM for meeting the risk analysis requirements of Article 21(2)(a)

Security Accreditation · RGS

EBIOS RM is the reference method for security accreditation dossiers of French government information systems

Sectoral Guides and Tools

ANSSI Sectoral Guides

Healthcare, local authorities, industry — sector-specific adaptations of the method

DICP / DICT Criteria

Availability, Integrity, Confidentiality, Traceability — impact assessment grid for business assets

EBIOS RM Tool

ANSSI open-source software for conducting and documenting EBIOS RM studies

EBIOS Risk Manager is a method of reasoning before it is a method of documentation. What training must transmit is the ability to construct and defend a plausible threat scenario — not to fill in tables. Formal rigour and operational relevance are not in contradiction: they condition each other.

Dominique Bourra · PECB Platinum Trainer

International Experience

Delivery Context

EBIOS Risk Manager training programmes are designed for information security managers, cybersecurity consultants, teams responsible for security accreditation, and project managers involved in projects subject to risk management obligations. They systematically draw on case studies from real organisations — defence, healthcare, critical operators, financial sector — to ground learning in authentic threat contexts.

Training Formats

EBIOS Risk Manager training is available in classroom and remote formats, in French and English. Programmes cover the full method cycle — from the five workshops to presenting findings to a steering committee — and prepare participants for the corresponding PECB certifications. Particular attention is given to the articulation between EBIOS RM and ISO reference frameworks, which is frequently required in audit or certification contexts.

EBIOS Risk Manager Certified Training · All PECB Levels
Foundation · Lead Practitioner · In-house programmes

Request a programme