At the end of the training, the participant will be able to:
Understand the EBIOS method
Map risks
Know the basic aspects of risk management for information security, using the EBIOS method
Conduct risk management with the EBIOS Risk Manager method
Analyze and communicate the results of an EBIOS study
Certification
Practical details
Teaching methods
The materials, instruction, and exam are in French.
Course schedule
1
The EBIOS Risk Manager method
Risk management fundamentals.
Overview of EBIOS.
Spotlight on cybersecurity (priority threats).
Main definitions of an EBIOS Risk Manager.
2
Framing and security base
Identifying the technical and business scope.
Identifying the feared events and assessing their severity levels.
Determining the security base.
Hands-on work
Identifying the feared events.
3
Sources of risk.
Identifying risk origins (ROs) and their target objectives (TOs)
Assessing the relevance of these pairs.
Assessing the RO/TO pairs and selecting the ones deemed a priority for the analysis.
Assessing the severity of the strategic scenarios.
Hands-on work
Assessing the RO/TO pairs.
4
Strategic scenarios
Assessing the threat levels associated with stakeholders.
Building a digital threat map of the ecosystem and critical stakeholders.
Writing strategic scenarios.
Defining security threats to the ecosystem.
Hands-on work
Assessing the threat levels associated with stakeholders. Writing strategic scenarios.
5
Operational scenarios
Writing operational scenarios.
Assessing likelihoods.
Threat modeling, ATT&CK.
Common attack pattern enumeration and classification (CAPEC).
Hands-on work
Writing operational scenarios.
6
Handling risk
Conducting a summary of risk scenarios.
Defining the treatment strategy.
Defining the security measures in a security continuous improvement plan (SCIP).
Evaluating and documenting residual risks.
Setting up a risk monitoring framework.
Hands-on work
Defining the security measures in a SCIP (security continuous improvement plan).
7
Review and preparation for the exam
Review of the program.
Mock exam and group correction. Tips for the exam.
8
Certification
At the end of the course, a participation certificate worth 21 CPD (Continuing Professional Development) credits is issued.
The exam consists of answering 12 questions in two-and-a-half hours.
A minimum score of at least 70% is required to pass.
Exam
Taking the PECB-certified EBIOS Risk Manager exam.
Customer reviews
4,1 / 5
Customer reviews are based on end-of-course evaluations. The score is calculated from all evaluations within the past year. Only reviews with a textual comment are displayed.
GUILLAUME D.
02/02/26
4 / 5
A little more experience-sharing would be good for training
JEAN-PHILIPPE L.
03/12/25
5 / 5
In the electronic version of the course, the slides appear as images, which makes it impossible to search for the text.
ALEXIS V.
05/11/25
5 / 5
The course is very interesting and well structured, allowing us to understand the logic behind the Ebios method.
FRANCK-WILSON A.
05/11/25
5 / 5
Very good
ADRIEN-LOYCE C.
05/11/25
4 / 5
Very competent trainer, content consistent with the course. Overall satisfied.
LEPY MAXIME M.
13/10/25
5 / 5
Very good training and trainer. For the exercises, the major one is more complicated because it's hard to do from a distance.
AZRI GHITA E.
13/10/25
5 / 5
The trainer was highly qualified, listened well and was able to answer questions clearly.
TIFENN C.
13/10/25
4 / 5
very good
ANTHONY M.
13/10/25
4 / 5
A little dense, you need to know a minimum of risk management before starting EBIOS (ideally you should have passed ISO 27005 beforehand) and you need to practise well, even if I realise that it takes an enormous amount of time, especially the case studies.
ALEXANDRE G.
13/10/25
5 / 5
The speaker was a great listener and teacher.
YANN R.
06/10/25
4 / 5
It's a shame we had to rush through the last few workshops. Perhaps I should point out to some participants that a bit too much 'off-topic' at the start made it impossible to stick to the schedule. I think it would have been possible to stay later on day 2, but the quality of the course remained very high. Thank you
SANDRINE F.
21/07/25
4 / 5
speed up explanations and use more case studies (especially in workshops 4 and 5)
FRÉDERIC P.
21/07/25
5 / 5
- It's a good idea to set a specific end time for the exercises, as this gives you something to look forward to;- Some exercises are difficult to do in the files provided, as they are based on images in particular, which cannot be modified.
INÈS R.
21/07/25
4 / 5
Positive points: alternating practical exercises and theoretical sections at each stage of the RM EBIOS method, quizzes to check that each part has been properly understood.Good quality of the discussions.Areas for improvement: The Kodelart case study is far too long (17 pages). This adds to the difficulty unnecessarily, as a lot of the information is not useful for carrying out the exercises.3-day course seems to me to be the most appropriate length.
DJAMEL D.
07/07/25
4 / 5
it's a shame that the lessons and exercises are not provided in paper format
DANIEL L.
07/07/25
4 / 5
Case studies that don't adapt very well or simply to the method. For greater cohesion, perhaps use one or two of the participants' results as a guideline and generate discussion or points of view on each participant's results.
MARKENSCIA B.
07/07/25
5 / 5
Full content
COSTA PIERRE-EMMANUEL D.
07/07/25
4 / 5
The PECB quiz was OK but the exercise wasn't very clear and there was no paper (even though it's environmentally friendly). Some subjects could have been covered in more depth, but you have to satisfy as many people as possible.
NICOLAS T.
07/07/25
4 / 5
case study too long a bit off the groundno paper support case printing problem on day 1 could have been corrected on the other daysvery good trainer with practical cases to validate knowledge
DAVID B.
07/07/25
4 / 5
It would have been interesting to have the course material (paper) beforehand or on the day.
NICOLAS B.
05/05/25
4 / 5
The trainer seemed to have a good grasp of his subject, and his flow of words was particularly fast, especially during the quizzes and exercises, which sometimes made it difficult to understand what he was saying and how long it lasted. I would have liked to have had more time for the practical cases. I had the impression that I didn't have the time to do the exercises, as the trainer gave the answers straight away: a bit of a shame for the reflection and exchanges in the group, which were limit
ALEXANDRE L.
05/05/25
5 / 5
The trainer has a very good grasp of the subject and conveys it with passion. However, his course seems to lack flexibility and adaptability.
JÉRÉMY B.
05/05/25
4 / 5
Good documentation, quality speakers.
LISA R.
05/05/25
4 / 5
The training was very interesting, but the first morning could have been devoted to Workshop 1. The introduction, which is currently the order of the day, is very vague and energy-consuming. It would be wiser to get to the heart of the matter quickly and cover the security foundation in more detail. As far as the course material is concerned, the ANSSI material is more effective than the one proposed.
TRAINER QUALIFICATIONS
The experts leading the training are specialists in the covered subjects. They have been approved by our instructional teams for both their professional knowledge and their teaching ability, for each course they teach. They have at least five to ten years of experience in their field and hold (or have held) decision-making positions in companies.
ASSESSMENT TERMS
The trainer evaluates each participant’s academic progress throughout the training using multiple choice, scenarios, hands-on work and more.
Participants also complete a placement test before and after the course to measure the skills they’ve developed.
TEACHING AIDS AND TECHNICAL RESOURCES • The main teaching aids and instructional methods used in the training are audiovisual aids, documentation and course material, hands-on application exercises and corrected exercises for practical training courses, case studies and coverage of real cases for training seminars.
• At the end of each course or seminar, ORSYS provides participants with a course evaluation questionnaire that is analysed by our instructional teams.
• A check-in sheet for each half-day of attendance is provided at the end of the training, along with a course completion certificate if the trainee attended the entire session.
TERMS AND DEADLINES
Registration must be completed 24 hours before the start of the training.
ACCESSIBILITY FOR PEOPLE WITH DISABILITIES
Do you need special accessibility accommodations? Contact Mrs. Fosse, Disability Manager, at psh-accueil@orsys.fr to review your request and its feasibility.
Dates and locations
Dernières places
Date garantie en présentiel ou à distance
Session garantie
No session at the moment, we invite you to consult the schedule of distance classes.