🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in🏆 We helped secure 10% of French MiCA licenses · Fixed fees, no lock-in

Operational Services

Risk analysis EBIOS RM : delivered in under 7 days

EBIOS Risk Manager is the reference risk analysis method of ANSSI, the French national cybersecurity agency. It is the founding building block of your NIS2, ISO 27001, MiCA authorisation or accreditation compliance, and it gives your management, your IT department and your CISO a prioritised view of the cyber risks that genuinely weigh on your business.

Thanks to an in-house tool that structures every step, we deliver it on your most critical scopes in under 7 days, with senior consultants, without ever cutting corners on the rigour of the method.

< 7 d
turnaround on your most critical scopes
+60%
productivity gain thanks to our in-house tool

ANSSI method · senior consultants

Our in-house tool

Delivered in under 7 days thanks to our in-house tool

The EBIOS RM method has a reputation for being slow. We have developed an in-house tool that structures and organises every step, from scoping to building the scenarios and the treatment plan. The result: a productivity gain of more than 60%, which lets us run an analysis on your most critical scopes in under 7 days.

That speed never comes from a shortcut on the method: it comes from the tool, from senior consultants who are operational from day 1, and from workshops prepared in advance. You get an analysis that meets the state of the art, faster, and therefore at a controlled cost.

+60%
productivity gain across the full run of the 5 workshops.
Day 1
senior consultants operational from kick-off.
The ANSSI method

EBIOS Risk Manager: the ANSSI reference method

EBIOS RM does not draw up a theoretical list of vulnerabilities: it starts from your business values, what really matters to your activity and your users, and works back to the realistic attack scenarios that threaten them, to produce a prioritised and arbitrated treatment plan.

It is a decision-oriented approach: you know what to address, in what order, and why. It is also the risk-based approach now required by NIS2 compliance and the French Cyber Framework (ReCyF).

The 5 workshops

The 5 workshops, explained simply

Workshop 01

Scoping and security baseline

We confirm the scope, identify your business values, the supporting assets that carry them, the feared events (unavailability, loss of integrity, disclosure, loss of traceability) and the applicable security baseline.

Workshop 02

Risk sources and target objectives

We identify and qualify the "risk source / target objective" pairs that are relevant to you: cybercriminals, hacktivists, states, insiders, supplier failures and so on.

Workshop 03

Strategic scenarios

We build high-level attack scenarios (who, why, through which route), with an assessment of their likelihood and of the threat level.

Workshop 04

Operational scenarios

We translate those scenarios technically into real attack chains: initial access, persistence, lateral movement, exfiltration, impact, mapped to your network, application and cloud architectures.

Workshop 05

Risk treatment

We define the treatment options (reduce, transfer, refuse, accept), propose prioritised organisational and technical measures, arbitrate with your CISO and present the results to management.

The workshops are run with your business owners, your IT department, your CISO and, if needed, your DPO, for a shared view and a common language around risk.

Skills transfer

An analysis that also trains your teams

A deliverable is only useful if it lives on over time. During the workshops, your IT department and your CISO do not just receive a report: they live through the entire EBIOS RM process, and understand both its flow and its logic.

The stated goal: that they can reuse it the following year, independently, on other scopes.

You do not become dependent on us, you build your own skills.

That is how we work: we pass on the method, not just the result.

Deliverables

What you receive

  • Consolidated EBIOS RM report: the approach, the assumptions, the results.
  • Mapping of business values and feared events.
  • Strategic and operational scenario file: attack paths and likelihood factors.
  • Prioritised risk treatment plan: recommended measures, priorities, owners, deadlines.
  • Management presentation pack: major residual risks and the structural decisions to be taken.
One single engagement

Several compliance frameworks, one single effort

In a single engagement, the EBIOS RM analysis brings together most of the prerequisites for your compliance, without doing the same work ten times over. In practice, it gives you all at once:

  • A risk-based approach (required by NIS2 / ReCyF).
  • A first inventory of your information systems.
  • The mapping of your critical suppliers and third parties (ecosystem control).
  • The foundations of your information security policy and of your security action plan.
  • The basis for your continuity and recovery plans (BCP / DRP, maximum tolerable outage durations).
  • The prioritisation of your future penetration tests and configuration or architecture audits.

In short: a well-run EBIOS RM analysis becomes the reusable foundation of all your compliance work. It also feeds directly into your ISO 27001 and MiCA / DORA files and your accreditations.

Who is it for?

Who this analysis is for

Local authorities

The foundation of NIS2 / French Cyber Framework compliance.

See our Local Authorities page

Companies aiming for ISO 27001

Risk analysis sits at the heart of the ISMS.

See our ISO 27001 page

Crypto players

A component of the MiCA authorisation file and of DORA compliance.

See our DORA page

Any organisation

That wants to prioritise its cyber investments on real risks, not on a generic checklist.

Let's take stock of your risks.

30 minutes with a senior consultant to scope your EBIOS RM analysis, with no lock-in and no sales pitch.

Book a meeting: 30 min

We use audience measurement cookies (Google Analytics) to improve your experience. No cookie is set without your consent. Learn more