
EBIOS Risk Manager
Course Overview
Organizations face increasingly sophisticated cyber threats that require a systematic and risk-based approach to cybersecurity. The EBIOS Risk Manager methodology enables organizations to identify strategic and operational risks, analyze attack scenarios, evaluate impacts, and determine effective security measures.
This course provides participants with a comprehensive understanding of the EBIOS Risk Manager methodology through practical exercises, case studies, and real-world scenarios. Participants will learn how to conduct risk assessments, engage stakeholders, model threat scenarios, prioritize risks, and develop actionable risk treatment plans aligned with organizational objectives.
Target Audience
This course is intended for:
- Information security managers
- Risk managers
- Cybersecurity consultants
- Information security officers
- Information system architects
- IT managers
- Governance, Risk, and Compliance (GRC) professionals
- Internal and external auditors
- Business continuity professionals
- Professionals responsible for conducting cybersecurity risk assessments
Learning Objectives
Upon successful completion of this course, participants will be able to:
- Understand the principles and methodology of EBIOS Risk Manager.
- Explain the five workshops of the EBIOS Risk Manager approach.
- Identify business assets and security needs.
- Analyze the threat ecosystem and threat sources.
- Develop strategic and operational risk scenarios.
- Evaluate cyber risks and prioritize treatment actions.
- Define appropriate security objectives and risk treatment strategies.
- Integrate EBIOS Risk Manager into organizational risk management processes.
- Prepare for the PECB EBIOS Risk Manager certification examination.
Duration
5 Days (Four days of instructor-led training followed by the certification examination on Day 5.)
Classroom
Participants attend instructor-led classroom sessions that combine lectures, practical workshops, case studies, collaborative discussions, and hands-on risk assessment exercises based on the EBIOS Risk Manager methodology.
Certification
After successfully passing the examination and meeting the applicable certification requirements, participants may apply for the:
PECB Certified EBIOS Risk Manager
The certification demonstrates the candidate’s competence in conducting and managing cybersecurity risk assessments using the EBIOS Risk Manager methodology.
Course Agenda
Day 1: Introduction to EBIOS Risk Manager
- Training course objectives and structure
- Overview of EBIOS Risk Manager
- Cybersecurity risk management principles
- Workshop 1: Framing and Security Baseline
- Identification of business assets and security objectives
Day 2: Threat Sources and Risk Scenarios
- Workshop 2: Risk Sources
- Identification and analysis of threat actors
- Stakeholder analysis
- Strategic scenario development
- Threat ecosystem analysis
Day 3: Operational Risk Analysis
- Workshop 3: Strategic Scenarios
- Workshop 4: Operational Scenarios
- Attack path analysis
- Likelihood and impact assessment
- Risk evaluation
Day 4: Risk Treatment and Validation
- Workshop 5: Risk Treatment
- Security objectives
- Selection of security measures
- Risk treatment planning
- Risk communication
- Course review and examination preparation
Day 5: Certification Examination
- PECB Certified EBIOS Risk Manager Certification Examination
Exam Duration
- Exam Duration: 3 hours
- Exam Format: Closed-book examination consisting of multiple-choice and scenario-based questions.
- Passing Score: Determined by PECB in accordance with its certification policies.
Successful candidates who meet PECB’s certification requirements may apply for the PECB Certified EBIOS Risk Manager credential.
