Evaluate

    Risk assessment: ISO/IEC 27005 and EBIOS RM

    A documented, repeatable information security risk assessment — by ISO/IEC 27005 where it feeds an ISMS certification, or by EBIOS Risk Manager where a scenario-driven analysis is expected. You get a risk register your auditor can follow and a narrative your board can act on.

    Duration

    3–5 weeks

    Built on

    ISO/IEC 27005 · EBIOS Risk Manager · ISO/IEC 27001:2022

    Indicative price

    €8,500–19,000 per engagement

    Who this is for

    • Risk owner or CISO

      Needs a register that survives challenge from an auditor and from a CFO in the same week.

    • Board or executive committee

      Has to make investment decisions and cannot do it from a colour-coded grid.

    • Compliance lead

      Needs the risk process ISO/IEC 27001 requires but does not prescribe.

    • Operations in regulated or industrial settings

      Wants the analysis to start from realistic attack scenarios rather than an asset list.

    Most risk registers are a list of fears with colours next to them

    The typical register is assembled in a workshop, scored on a five-by-five grid by whoever was in the room, and never opened again until the auditor asks. It cannot be repeated, because nobody wrote down what a '4' means. It cannot be defended, because the scores encode opinions nobody recorded. And it cannot drive investment, because everything important ends up amber.

    ISO/IEC 27001 requires you to run a risk assessment but deliberately does not tell you how. That freedom is the problem: without a documented method and explicit criteria, the second assessment will not resemble the first, and the difference between them will be invisible. The value is almost entirely in the criteria — a scale that four different people apply identically is what makes risk management a process rather than an annual workshop.

    ISO/IEC 27005 gives you that process, and it is the right choice when the assessment has to support an ISMS and satisfy a certification auditor. It is thorough, it is traceable, and it produces exactly what clause 6.1 expects.

    EBIOS Risk Manager approaches it from the other end. Instead of starting with assets, it starts with who would attack you and what they want, then builds strategic scenarios across your ecosystem — including your suppliers — and derives operational attack paths from them. The output is a narrative, which is why boards engage with it and why it carries weight in Francophone markets and in ANSSI-aligned contexts.

    We run either, and sometimes both: EBIOS to frame the conversation with leadership, ISO/IEC 27005 to produce the register the auditor needs. What we do not do is score a spreadsheet and hand it over.

    How we do it

    1. 01

      Choose the method and set the frame

      2–3 days

      Which method, and why. Context, boundaries, and who owns the outcome. If the assessment has to serve both a board and an auditor, we say so now and design for both.

    2. 02

      Establish risk criteria

      3–5 days

      Impact scales in your terms — euros, downtime, regulatory exposure, safety, reputation — and likelihood defined so that two people reading it reach the same number. Acceptance criteria agreed with whoever is empowered to accept risk.

    3. 03

      Identify

      1 week

      Under ISO/IEC 27005: assets, processes, threats, vulnerabilities and consequences within scope. Under EBIOS RM: risk origins and their target objectives, then strategic scenarios across your ecosystem.

    4. 04

      Analyse and evaluate

      1 week

      Scoring against the criteria, with the reasoning recorded alongside each score. Under EBIOS RM, operational scenarios and attack paths derived from the strategic ones.

    5. 05

      Treatment

      3–5 days

      Treatment option per risk — reduce, transfer, avoid, accept — with a control selection that traces back to the analysis, an owner, and a date. Residual risk formally accepted by someone with the authority to accept it.

    6. 06

      Communicate and embed

      2–3 days

      The board narrative, the register handover, and the review cadence. We train your people to run the next cycle themselves.

    Named artefacts

    What you receive

    • Documented risk assessment methodology, repeatable without us
    • Risk criteria — impact, likelihood and acceptance — agreed and written down
    • Risk register, populated, scored and owned, with the reasoning recorded per entry
    • Strategic and operational scenarios, where EBIOS RM is used
    • Risk treatment plan with owners and dates
    • Residual risk acceptance record, signed by the accepting authority
    • Board-level risk narrative — what could happen, what it would cost, what we propose
    • Review cadence and handover pack

    What we need from you

    • Someone empowered to accept risk on behalf of the organisation. Without that person the treatment plan cannot be closed.
    • Asset and process information, and access to the people who run them.
    • Incident history, including near misses. These calibrate likelihood better than any external dataset.
    • Two to three hours from the executive team to agree impact criteria. This is the single most valuable meeting in the engagement.

    What changes

    1. 01A register your certification auditor can follow from criteria to score to treatment.
    2. 02Risk expressed in units your board already uses, so investment decisions become possible.
    3. 03A method your own people can repeat next year, cheaply.
    4. 04Residual risk explicitly accepted by someone, rather than implicitly accepted by everyone.
    5. 05Supplier and ecosystem risk included rather than assumed away.

    What it costs

    €8,500–19,000 per engagement

    All prices exclude VAT.

    Questions

    Which method should we choose?

    If the assessment has to support ISO/IEC 27001 certification, ISO/IEC 27005. If you need leadership to engage with the analysis, or you operate in a Francophone or ANSSI-aligned context, EBIOS Risk Manager. If both matter, we use EBIOS to frame the conversation and ISO/IEC 27005 to produce the register — the work overlaps more than it duplicates.

    Do you offer the EBIOS Risk Manager certification course?

    We use the method in our consulting work. Our accredited training catalogue covers ISO/IEC 27001, ISO/IEC 42001 and ISO/IEC 38500 — see the training pages for what we currently deliver.

    How long before it needs redoing?

    Review at least annually, and on any significant change — a new system, a new supplier, an incident, a change of scope. The point of a documented method is that the review is a fraction of the cost of the first pass.

    Can you quantify risk in money?

    Where the data supports it, yes, and it makes the board conversation far easier. Where it does not, we say so rather than manufacturing a number — a fabricated euro figure is worse than an honest ordinal scale.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.