Skip to main content
ISO 31000

EBIOS Risk Manager

Official EBIOS RM certification training. Learn the ANSSI 5-workshop risk assessment methodology. PECB-accredited course with practical exercises and exam.

PECBRisk Manager3 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Individuals who want to learn the fundamental concepts of risk management through the EBIOS RM method
  • Professionals involved in risk assessment activities who need structured EBIOS RM skills
  • Managers responsible for overseeing or commissioning EBIOS risk studies within their organisations
  • Managers who need to analyse and communicate the results of an EBIOS risk assessment
  • Information security officers seeking a recognised methodology for assessing information-system risks
  • Consultants supporting organisations in adopting EBIOS RM as their risk assessment framework

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Professionals already holding advanced EBIOS RM expertise who need only a refresher rather than a foundational course
  • Individuals seeking deep technical penetration-testing or vulnerability-exploitation skills, as the course focuses on risk methodology rather than offensive techniques
  • Those expecting a purely theoretical lecture series without hands-on workshop activities, since the programme centres on applied exercises
  • Participants with no interest in information security risk management who are looking for a general project-management qualification

What you'll be able to do

  • 1Explain the foundational concepts and principles of risk management as applied within the EBIOS RM framework
  • 2Describe each of the five EBIOS RM workshops and articulate their role in a complete risk study
  • 3Interpret the key deliverables of an EBIOS study and communicate findings to relevant stakeholders
  • 4Conduct an EBIOS risk assessment study by applying workshop activities in a structured sequence
  • 5Analyse risk origins, strategic scenarios, and operational scenarios to support informed decision-making
  • 6Manage information-system security risks across an organisation using EBIOS RM techniques
  • 7Produce and present risk treatment options derived from EBIOS workshop outputs

Day by day

Day 1Foundations and Early Workshops: Scope, Baseline, and Risk Origins
  • Introduction to the EBIOS RM Method

    Participants explore the history, structure, and guiding principles of the EBIOS Risk Manager method, establishing a shared vocabulary for the workshops that follow.

  • Workshop 1: Scope and Security Baseline

    Participants define the study perimeter, identify essential assets, and establish the security baseline against which risks will be measured.

  • Workshop 2: Risk Origins

    Participants identify and characterise potential threat sources and their motivations, producing the risk-origin pairs that feed into strategic scenario construction.

By end of day

  • Articulate the purpose and five-workshop structure of EBIOS RM
  • Define a study scope and document an organisation's security baseline
  • Catalogue credible risk origins relevant to a given information system
Day 2Strategic and Operational Scenarios, and Risk Treatment
  • Workshop 3: Strategic Scenarios

    Participants build high-level attack paths by mapping risk-origin pairs to feared events, producing strategic scenarios that represent plausible threat trajectories.

  • Workshop 4: Operational Scenarios

    Participants translate strategic scenarios into detailed operational attack sequences, assessing likelihood and evaluating existing security controls.

  • Workshop 5: Risk Treatment

    Participants evaluate residual risks, select appropriate treatment options, and compile a risk treatment plan aligned with the organisation's security objectives.

  • Closing of the Training Course

    The trainer consolidates key learning points across all five workshops, clarifies the structure of EBIOS study deliverables, and guides participants on next steps toward certification.

By end of day

  • Construct and prioritise strategic and operational risk scenarios from identified threat sources
  • Propose and document a risk treatment plan based on workshop analysis
  • Summarise and present an EBIOS study's key deliverables to a non-specialist audience
Day 3Examination Preparation and Competency Consolidation
  • Domain 1: Fundamental Principles and Concepts of Information Security Risk Management

    Review of core risk management principles and their specific expression within the EBIOS RM method, reinforcing the theoretical grounding assessed in the certification exam.

  • Domain 2: Information Security Risk Management Framework Based on EBIOS RM

    Consolidation of how EBIOS RM integrates with broader organisational risk governance frameworks, a competency domain covered by the PECB certification exam.

  • Domain 3: Information Security Risk Assessment Using EBIOS RM

    Practical review of the end-to-end risk assessment process across all five workshops, mirroring the applied competencies evaluated in the PECB EBIOS Risk Manager exam.

By end of day

  • Identify the three competency domains assessed in the PECB EBIOS Risk Manager exam
  • Apply workshop knowledge across all five EBIOS RM stages in an integrated review exercise
  • Recognise gaps in understanding before sitting any separate certification examination

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Training course objectives and structure
  • Introduction to EBIOS RM method
  • Workshop 1 Scope and security baseline
  • Workshop 2 Risk origins
  • Workshop 3 Strategic scenarios
  • Workshop 4 Operational scenarios
  • Workshop 5 Risk treatment
  • Closing of the training course
  • Certificate exam
  • Domain 1: Fundamental principles and concepts of Information Security risk management process based on the EBIOS method
  • Domain 2: Information Security risk management framework based on the EBIOS method
  • Domain 3: Information Security risk assessment using the EBIOS method

To be considered valid, these risk assessment activities should follow best implementation practices and include the following:

  1. Defining a risk management approach
  2. Designing and implementing an overall risk management process for an organization
  3. Defining risk evaluation criteria
  4. Performing risk assessment
  5. Identifying assets, threats, existing controls, vulnerabilities and consequences (impacts)
  6. Assessing consequences and incident likelihood
  7. Evaluating risk treatment options
  8. Performing a risk management review
  • Certificate and examination fees are included in the price of the training course
  • Training material containing over 200 pages of information and practical examples will be distributed
  • An attestation of course completion worth 21 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free

Why should you attend?

ISO/IEC 27001

Educational approach

  • This training is based on both theory and best practices of risk assessment using the EBIOS method
  • Lecture sessions are illustrated with examples based on case studies
  • Practical exercises are based on case studies which include role playing and discussions
  • Practical exercises and examples are similar to the Certificate Exam

Prerequisites

What is the PECB EBIOS Risk Manager course?

The PECB EBIOS Risk Manager course is a practical and in-depth training program focused on mastering the EBIOS risk analysis methodology as defined by ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information). EBIOS is one of the most structured and strategic frameworks for conducting cyber risk assessments, used by public authorities, critical infrastructure operators, and private organizations across Europe. This course teaches participants how to apply the EBIOS Risk Manager approach to identify cyber threats, assess business impact, evaluate risk scenarios, and prioritize treatment measures. It helps organizations align cybersecurity strategy with business needs, regulatory obligations (like NIS2, GDPR), and ISO/IEC 27005 or ISO/IEC 27001 frameworks.

Who should take the PECB EBIOS Risk Manager course?

This course is ideal for cybersecurity and risk professionals, including information security officers, risk analysts, GRC consultants, and compliance managers. It is also valuable for project managers, auditors, and members of internal security or governance teams who are involved in risk evaluation and mitigation planning. Professionals working within regulated industries, government agencies, or organizations with critical infrastructure will especially benefit from mastering EBIOS, as it is often a preferred or required methodology in these environments.

What will I learn in the PECB EBIOS Risk Manager course?

Participants will learn how to conduct a complete risk assessment using the five steps of the EBIOS Risk Manager method: context establishment, feared event identification, risk scenario construction, risk analysis, and risk treatment selection. The course emphasizes how to identify high-stakes assets and business processes, define realistic cyber-attack scenarios, assess their likelihood and impact, and communicate risk insights to both technical and executive stakeholders. Learners also explore how to align EBIOS with ISO/IEC 27005, ISO/IEC 31000, and national regulatory frameworks. Through workshops and case studies, participants will gain hands-on experience in structuring risk studies that support real-world decision-making and prioritization.

How long is the PECB EBIOS Risk Manager course?

The course typically spans three days, combining theory, practical workshops, group exercises, and interactive case studies. It is structured to guide learners through each phase of the EBIOS method in detail, offering templates, tools, and guidance that can be directly applied to organizational risk management projects. The format ensures that by the end of the course, participants will be able to independently conduct structured risk analyses and facilitate workshops within their own teams or client environments.

Is there a certification exam included in the course?

Yes. The course concludes with a formal PECB certification exam. Upon passing, participants are awarded the PECB Certified EBIOS Risk Manager Certificate, an internationally recognized credential that demonstrates proficiency in using the EBIOS methodology to assess and manage cyber risk. This certification is especially valuable in European contexts and for professionals working on compliance, cyber resilience, or regulatory alignment initiatives.

Buyers always ask

What is the difference between completing this training course and obtaining an EBIOS Risk Manager certification?+

Completing the three-day training course means you have attended all sessions and workshops delivered by the instructor. It does not, by itself, result in a certification credential.

Obtaining the PECB EBIOS Risk Manager certification requires separately passing the PECB certification exam and satisfying PECB's credential requirements. Please consult PECB directly for current exam registration details, eligibility rules, and credential requirements.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

What level of risk management experience should I have before attending?+

A working familiarity with core risk management concepts will help you engage productively with the workshop exercises from Day 1. You do not need prior EBIOS-specific experience or a formal qualification to enrol.

Participants with no background in information security risk management may find the pace challenging, as the course moves quickly from foundational concepts into applied workshops.

How does the five-workshop structure of EBIOS RM unfold across the three training days?+

Day 1 introduces the EBIOS RM method and covers Workshop 1 (Scope and Security Baseline) and Workshop 2 (Risk Origins). Day 2 addresses Workshop 3 (Strategic Scenarios), Workshop 4 (Operational Scenarios), Workshop 5 (Risk Treatment), and closes the instructional portion of the course.

Day 3 is dedicated to consolidating and reviewing the three competency domains aligned with the PECB certification exam, helping participants assess their readiness before pursuing the exam independently.

What competency domains does the PECB EBIOS Risk Manager exam cover, and how does the training address them?+

According to PECB, the exam assesses three domains: fundamental principles and concepts of information security risk management based on EBIOS RM; the information security risk management framework based on EBIOS RM; and information security risk assessment using EBIOS RM.

The training course is structured to build knowledge across all three domains progressively, with Days 1 and 2 delivering hands-on workshop practice and Day 3 consolidating understanding in a focused review. However, exam registration, scheduling, and passing criteria are governed solely by PECB.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.