Skip to content

Home Expertise / Risk & governance

GRC / GRC-01

EBIOS Risk Manager risk assessment

A structured method linking business objectives to cyber-risk scenarios and a treatment plan decided by the organisation.

WHEN IT HELPS

A focused response
to a defined need.

Executives, CISO or business owner; a sensitive new service, budget decisions or a need to justify security priorities.

AT A GLANCE

Family
Risk & governance

Engagement
Advisory

Reference
GRC-01

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Five workshops: scope and security baseline
  • risk origins
  • strategic scenarios
  • operational scenarios
  • treatment and residual-risk monitoring

Deliverables

  • Assessment file
  • prioritised scenarios
  • treatment plan with owners and a residual-risk register

Acceptance evidence

Scope, assumptions, scenarios and treatment decisions are approved; risk acceptance remains with the authorised decision-maker.

DELIVERY

How the work is structured.

Approach

Scope context; engage business owners and decision-makers; assess risks or gaps; decide controls; organise follow-up and evidence.

Prerequisites & responsibilities

Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.

Scope factors

Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.

Questions to clarify

Which business mission needs protection? Which business teams will participate? Who accepts residual risks and funds controls?

IMPORTANT BOUNDARIES

Scenario analysis focuses on intentional threats; the security baseline remains essential. This is neither a scan nor a penetration test.

The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A distributor depends on an ERP and a maintenance provider. Project: workshops with procurement, business teams and IT. Target outcome: prioritise contractor access, recovery and detection against feared business interruption, rather than the latest product pitch.

Scenario 02

A software company launches a portal holding contracts. Project: analyse business assets, the ecosystem and attack paths. Target outcome: integrate security requirements and record residual risk; unavailable stakeholders require rescheduling.

Technology and reference context

ANSSI EBIOS RM method; workshop materials and risk register tailored to the customer.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.