Glossary

EBIOS Risk Manager

EBIOS Risk Manager is the digital risk assessment and treatment method published by ANSSI, the French cybersecurity agency. It builds risk scenarios from risk sources and their targeted objectives, giving explicit weight to the ecosystem — partners and suppliers — as an attack path.

The five workshops

The method runs in five workshops: scoping and security baseline, risk sources and targeted objectives, strategic scenarios (attack paths through the ecosystem), operational scenarios (technical modes of attack), and risk treatment and steering.

Why it matters to TPRM

Workshop 3 is the only step, among mainstream methods, that treats external stakeholders explicitly as attack paths: it rates each stakeholder on dependency, penetration into the information system, cyber maturity and trust, to identify the most exposed. The output maps directly onto the vendor criticality analysis of a TPRM programme, and informs the level of due diligence required per third party.

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account