Executive Summary
Cyber risk assessment methodologies are commonly compared through their processes, terminology, scoring mechanisms, regulatory origins or implementation complexity.
Such comparisons are useful.
But they often miss a more fundamental question:
What model of cyber risk does each methodology actually construct?
MONARC and EBIOS Risk Manager 1.5 provide a particularly revealing case.
Both belong to the broader field of information security risk management. Both can operate within an ISO/IEC 27005-oriented environment. Both are iterative. Both connect business impact, risk assessment, security measures, treatment and continuous improvement.
Yet they organize knowledge about risk differently.
MONARC primarily constructs risk through the structure of the organization, its activities, assets, dependencies, threats, vulnerabilities and impacts. Its methodology, knowledge base and tooling enable risk models to be progressively built, reused and maintained.
EBIOS Risk Manager 1.5 approaches the problem from another centre of gravity. It combines a security baseline with scenario-driven analysis and gives particular analytical importance to intentional and targeted threats. Business values, feared events, risk sources, objectives, ecosystem dependencies and strategic and operational scenarios progressively construct a representation of how significant cyber risk can materialize.
This white paper proposes that the difference can be understood through two complementary analytical lenses.
MONARC provides predominantly structural risk intelligence.
EBIOS Risk Manager provides particularly strong strategic and adversarial risk intelligence.
This distinction describes their respective analytical centres of gravity. It does not establish an exclusive boundary between the methods. MONARC incorporates threats and risk scenarios. EBIOS Risk Manager necessarily considers supporting assets, dependencies and security controls.
The distinction is therefore not binary.
It is epistemological.
The two methodologies do not merely organize risk assessments differently. They encode different representations of cyber-risk reality.
MONARC helps answer:
What does the organization depend on, how is this system structured, and where does exposure emerge?
EBIOS Risk Manager helps answer:
What matters to the organization, which relevant risk sources could threaten it, for what objectives, and through which strategic and operational paths?
This leads to the central proposition of this white paper.
A mature cyber-risk capability may require both:
- a persistent model of exposure
- a dynamic model of adversarial action
Rather than asking whether MONARC or EBIOS Risk Manager is the superior methodology, organizations should therefore consider whether the two approaches illuminate different dimensions of the same risk environment.
This is the DUAL LENS proposition.
MONARC models the terrain.
EBIOS Risk Manager models the campaign across the terrain.
Used selectively and intelligently, these two lenses suggest a possible evolution from periodic cyber risk assessment toward persistent cyber risk intelligence.
1. Introduction — The Wrong Question
Comparisons between cyber risk methodologies frequently begin with a selection problem:
Which methodology should an organization use?
MONARC?
EBIOS Risk Manager?
ISO/IEC 27005 directly?
Another framework?
The question is legitimate, but it may be premature.
Before comparing implementation effort, scoring models or organizational preferences, another question should be addressed:
What does each methodology make visible?
Every risk methodology is also a representation system.
It determines which objects matter.
It establishes relationships between those objects.
It determines how uncertainty becomes structured information.
It influences what analysts look for, what workshops discuss, what decision-makers receive and ultimately what the organization understands as risk.
MONARC and EBIOS Risk Manager are especially valuable for such a comparison because they operate within broadly compatible information security risk-management principles while implementing substantially different analytical architectures.
The objective of this white paper is therefore not to declare a methodological winner.
It is to compare the models of risk knowledge produced by the two approaches.
The resulting question is more ambitious:
How does each methodology transform uncertainty about cyber risk into knowledge upon which decisions can be made?
2. MONARC — Risk as a Structured System of Dependencies
MONARC, the Optimised Risk Analysis Method, was developed within the Luxembourg cybersecurity ecosystem to provide organizations with a structured, repeatable and reusable approach to information security risk analysis.
Its methodology is qualitative and iterative and draws substantially on the principles of ISO/IEC 27005.
MONARC organizes the risk-management process into four broad phases:
- Context establishment.
- Context modelling.
- Risk evaluation and treatment.
- Implementation and monitoring.
Its distinctive value, however, cannot be reduced to the existence of four phases.
MONARC constructs a reusable model of the organization and its exposure.
- Business processes and information can be represented as primary assets.
- Supporting assets can be associated with them.
- Dependencies between objects can be modelled.
- Impacts can propagate through those dependencies.
- Threats and vulnerabilities can be associated with relevant objects and risk situations.
- Existing models and knowledge can be reused and progressively refined.
This produces an important organizational effect.
Risk knowledge can accumulate.
An analysis does not necessarily disappear into a static report once the assessment has been completed.
Elements of the analysis can contribute to a persistent body of organizational knowledge that can be reused during subsequent assessments.
MONARC's distinctive strength is therefore not merely asset modelling.
It is its capacity to contribute to the transformation of risk analysis into reusable organizational knowledge.
This characteristic makes MONARC particularly relevant to environments requiring recurring assessments, consistency between analyses, portfolio-level governance, progressive refinement and traceability between organizational structures and risk treatment.
These characteristics suggest significant potential for the industrialization of recurring risk analysis.
The term industrialization is an analytical conclusion developed in this white paper. It should not be understood as an official characterization of MONARC by NC3.
MONARC's analytical centre of gravity can consequently be described as structural and systemic.
This does not imply that MONARC ignores dynamics, scenarios, threats or external developments.
It means that its architecture provides a particularly powerful representation of the structure within which risk exists.
3. EBIOS Risk Manager 1.5 — Risk as an Adversarial Trajectory
EBIOS Risk Manager is the French reference method for digital risk assessment and treatment published by ANSSI with the support of Club EBIOS.
EBIOS Risk Manager 1.5 reinforces the methodology's alignment with ISO/IEC 27005:2022 and incorporates experience accumulated through its operational use.
One of its defining characteristics is the articulation between two complementary approaches:
- A security baseline based on established security requirements.
- Scenario-driven analysis for risks requiring deeper investigation.
The method is organized through five workshops:
- Workshop 1 — Scope and Security Baseline.
- Workshop 2 — Risk Sources.
- Workshop 3 — Strategic Scenarios.
- Workshop 4 — Operational Scenarios.
- Workshop 5 — Risk Treatment.
This architecture progressively changes the analytical perspective.
The organization is not represented only as a collection of assets exposed to threats.
It is also represented as an entity pursuing missions, depending on an ecosystem, protecting business values and potentially facing relevant risk sources with particular objectives.
The analysis therefore considers concepts including:
- Business missions.
- Business values.
- Feared events.
- Risk sources.
- Objectives pursued by those risk sources.
- Ecosystem stakeholders.
- Strategic scenarios.
- Operational scenarios.
- Security measures.
- Residual risk.
EBIOS Risk Manager gives particular analytical importance to intentional and targeted threats where scenario analysis provides value.
The method should nevertheless not be reduced to intentional cyberattack analysis.
Its security baseline and broader risk-management architecture remain fundamental to the approach.
Its distinctive strength is the ability to transform significant cyber risk into intelligible strategic and operational trajectories.
The analytical question becomes:
How could a relevant risk source achieve an objective against what the organization values, directly or through its ecosystem?
The centre of gravity of EBIOS Risk Manager can therefore be characterized as strategic and adversarial.
Again, this is an analytical characterization developed for the purposes of this comparison, not an official ANSSI definition of the methodology.
4. Two Methods, Two Centres of Gravity
MONARC and EBIOS Risk Manager operate within the same broad domain but organize risk knowledge differently.
The following comparison summarizes their respective analytical centres of gravity — as centres of gravity, not as mutually exclusive capabilities.
| Dimension | MONARC | EBIOS Risk Manager 1.5 |
|---|---|---|
| Dominant analytical lens | Structural and systemic. | Strategic and adversarial. |
| Initial analytical focus | Context, activities, information, assets and dependencies. | Missions, business values, feared events and security baseline. |
| Characteristic representation of risk | Relationships between assets, dependencies, threats, vulnerabilities and impacts. | Relationships between business values, feared events, risk sources, objectives and scenarios. |
| Dependencies | Strong modelling of object and asset dependencies. | Strong analysis of ecosystem dependencies and their role in strategic scenarios. |
| Threat perspective | Broad threat landscape integrated into the risk model. | Particular analytical emphasis on relevant risk sources and intentional or targeted threats. |
| Vulnerability | Explicit component of the analytical model. | Considered through security posture and the feasibility of operational scenarios. |
| Scenario role | Risk scenarios associated with the structural risk model. | Strategic and operational scenarios form a central analytical mechanism. |
| Knowledge reuse | Strong reuse through knowledge bases, models and iterative refinement. | Reuse of methodological patterns combined with context-specific scenario construction and expertise. |
| Tooling | Tooling and methodology form a closely connected ecosystem. | Methodology is not intrinsically dependent on a specific software platform. |
| Characteristic strength | Structural consistency, reuse and capitalization of risk knowledge. | Strategic understanding of significant and sophisticated cyber-risk scenarios. |
5. Two Risk Ontologies
The distinction becomes more interesting when the comparison moves beyond process.
MONARC and EBIOS Risk Manager do not merely organize risk assessment differently.
They encode different representations of cyber-risk reality.
They can therefore be interpreted as two different risk ontologies.
Here, ontology is used in its information-modelling sense: the categories through which reality is represented and the relationships established between them.
A simplified MONARC representation can be expressed as:
- Context.
- Business activity.
- Primary asset.
- Supporting asset.
- Dependency.
- Threat.
- Vulnerability.
- Impact.
- Risk.
- Recommendation.
- Treatment.
- Monitoring.
A simplified EBIOS Risk Manager representation can be expressed as:
- Mission.
- Business value.
- Feared event.
- Security baseline.
- Risk source.
- Objective.
- Ecosystem stakeholder.
- Strategic scenario.
- Operational scenario.
- Security measure.
- Residual risk.
These sequences are intentionally simplified. They are not intended to replace the official methodological models. Their purpose is comparative.
They reveal that the methods do not simply calculate risk differently.
They decompose reality differently.
This is perhaps the deepest distinction between MONARC and EBIOS Risk Manager.
6. The Asset and the Adversary
Consider an organization that depends on a critical cloud-based business application.
A MONARC-oriented analysis naturally encourages decomposition of the environment.
- Business process.
- Information.
- Application.
- Supporting infrastructure.
- Dependencies.
- Threats.
- Vulnerabilities.
- Impacts.
- Existing controls.
- Risk treatment.
This perspective reveals where exposure is structurally concentrated and how dependencies contribute to risk.
An EBIOS Risk Manager analysis can examine the same environment through another trajectory.
- Business value.
- Feared event.
- Relevant risk source.
- Objective.
- Ecosystem.
- Strategic scenario.
- Operational scenario.
- Security measures.
- Residual risk.
This perspective reveals how a relevant threat actor could exploit the environment to produce a significant business consequence.
The difference can be summarized by a deliberately simplified proposition:
MONARC models the terrain. EBIOS Risk Manager models the campaign across the terrain.
The metaphor should not be interpreted literally.
MONARC also addresses threats and risk scenarios.
EBIOS Risk Manager also requires an understanding of supporting assets and dependencies.
The distinction identifies analytical emphasis rather than methodological exclusivity.
7. Structured Decomposition and Scenario Coherence
A second important difference concerns how uncertainty is reduced.
MONARC provides a structured framework through which impacts, threats, vulnerabilities, dependencies and risk levels can be consistently represented.
This creates repeatability.
It facilitates comparison.
It supports the maintenance of a persistent model.
EBIOS Risk Manager places substantial analytical importance on scenario coherence.
A significant risk becomes intelligible through the relationship between a risk source, an objective, an ecosystem, an attack path and a business consequence.
This creates contextual plausibility.
It supports strategic reasoning.
It makes the logic of sophisticated threats understandable to decision-makers.
The two methods therefore illustrate two different mechanisms for reducing uncertainty.
MONARC reduces uncertainty particularly effectively through structured decomposition, normalization and reuse.
EBIOS Risk Manager reduces uncertainty particularly effectively through contextualized scenario construction and adversarial reasoning.
Neither mechanism is intrinsically superior.
They produce different forms of risk knowledge.
8. The Question of Scale
Risk management becomes significantly more difficult when an organization moves from individual studies to a persistent organizational capability.
Risk assessments must then be:
- Updated.
- Compared.
- Reviewed.
- Audited.
- Transferred between teams.
- Aggregated.
- Reused.
- Connected to treatment plans.
MONARC has characteristics that are particularly useful in this environment.
Reusable models, structured dependencies, knowledge bases and iterative refinement facilitate consistency across recurring analyses.
EBIOS Risk Manager presents a different scaling challenge.
Its scenario-driven analysis can produce substantial strategic insight, particularly for targeted threats, complex ecosystems and sophisticated attack paths.
The relevant question is not whether EBIOS Risk Manager is intrinsically scalable or unscalable.
The potential challenge is maintaining analytical depth when scenario-driven assessments must be replicated across large and heterogeneous portfolios.
This depends substantially on implementation choices, governance, expertise, tooling and the quality of facilitation.
The resulting organizational question is therefore not:
Industrialization or analytical depth?
It is:
How can an organization preserve analytical depth while industrializing the parts of risk management that benefit from repeatability?
9. The Blind Spots
Every analytical methodology creates visibility by simplifying reality.
The relevant question is therefore not whether a methodology has blind spots.
Every methodology does.
The relevant question is which forms of risk may receive less analytical attention because of the architecture of the method.
For MONARC, a potential danger exists when structural modelling becomes an end in itself.
An organization may develop a sophisticated understanding of its assets, dependencies, vulnerabilities and exposure while failing to exercise sufficient adversarial imagination.
The resulting risk is structural completeness without sufficient understanding of how an adaptive adversary might combine those elements.
This is not an intrinsic defect of MONARC.
It is a possible failure mode in its application.
For EBIOS Risk Manager, the symmetrical danger is different.
Scenario-driven analysis can generate sophisticated strategic insight, but organizations may struggle to preserve the same level of contextual depth when assessments multiply across large portfolios.
The resulting risk is analytical sophistication that becomes difficult to reproduce consistently at scale.
Again, this is not an intrinsic defect of EBIOS Risk Manager.
It is a possible implementation challenge.
The symmetry is important.
And it suggests a possible integration.
10. The DUAL LENS Model
A hybrid analytical architecture can be imagined without merging MONARC and EBIOS Risk Manager or weakening their respective methodologies.
The first lens is structural risk intelligence.
MONARC can contribute to maintaining knowledge concerning:
- Critical activities.
- Information.
- Primary and supporting assets.
- Dependencies.
- Threats.
- Vulnerabilities.
- Impacts.
- Risk evaluations.
- Recommendations.
- Treatment status.
The objective is a persistent representation of organizational cyber exposure.
The second lens is strategic and adversarial risk intelligence.
Selected situations can then receive deeper EBIOS Risk Manager analysis addressing:
- Relevant risk sources.
- Objectives.
- Critical ecosystem stakeholders.
- Strategic scenarios.
- Operational scenarios.
- Attack paths.
- Additional security measures.
- Residual risk.
The objective is deeper understanding of significant scenarios in which intelligent adversaries or complex threat dynamics matter.
The relationship between the two lenses can be represented as a feedback loop:
- MONARC structural model.
- Identification of critical exposure.
- Selection for deeper analysis.
- EBIOS Risk Manager strategic and operational analysis.
- Identification of scenarios and additional security measures.
- Reintegration of relevant knowledge into risk governance.
- Monitoring.
- Reassessment.
The objective is not to create a new hybrid methodology.
It is to create an analytical architecture in which two established methodologies can potentially operate at different levels of resolution.
11. From Risk Assessment to Risk Intelligence
The deeper implication extends beyond the comparison between MONARC and EBIOS Risk Manager.
Traditional cybersecurity governance frequently treats risk assessment as a periodic document-production activity.
- A study is initiated.
- Risks are identified.
- Risks are evaluated.
- A report is produced.
- Controls are recommended.
- A treatment plan is established.
- The exercise is eventually repeated.
This model remains useful, but it is increasingly insufficient for highly dynamic environments.
Organizations operate within changing technological, regulatory, geopolitical and supply-chain ecosystems.
Threat actors change.
Dependencies change.
Attack surfaces change.
Business priorities change.
Risk knowledge therefore has to persist beyond the individual assessment.
This suggests an evolution from risk assessment toward risk intelligence.
Risk intelligence, in the sense proposed by this white paper, requires at least two capabilities.
Structural intelligence. The organization continuously understands what it depends on, how those dependencies interact and where exposure is concentrated.
Adversarial intelligence. The organization understands which relevant actors or threat dynamics may exploit those dependencies, for what objectives and through which plausible paths.
Neither capability is sufficient by itself.
Together they provide a richer representation of cyber risk.
12. Implications for ISO/IEC 27005 and ISO/IEC 27001
The comparison also has implications for organizations implementing information security management systems.
ISO/IEC 27001 establishes requirements concerning information security risk assessment and treatment without prescribing a single mandatory methodology.
ISO/IEC 27005 provides guidance for information security risk management.
MONARC and EBIOS Risk Manager demonstrate an important consequence.
Alignment with common risk-management principles does not produce methodological uniformity.
Organizations can construct different analytical architectures while remaining compatible with the broader logic of information security risk management.
Methodological selection should therefore not be reduced to compliance.
The more useful governance question is:
What kind of risk knowledge does the organization need to make better security decisions?
Some environments may place greater emphasis on repeatability, structural consistency and portfolio governance.
Others may require deeper analysis of intentional threats, ecosystems and attack paths.
Mature organizations may require both.
13. Conclusion — Two Lenses, One Risk Architecture
MONARC and EBIOS Risk Manager should not be reduced to a contest between a Luxembourg methodology and a French methodology.
Their comparison reveals something more fundamental about cyber-risk analysis.
MONARC demonstrates the value of structure, dependency modelling, reuse and capitalization.
EBIOS Risk Manager demonstrates the value of intent, ecosystem analysis, strategic scenarios and operational attack-path reasoning.
One provides a particularly strong model of the environment in which risk exists.
The other provides a particularly strong model of how significant threats can move through that environment.
The strategic opportunity is therefore not necessarily to choose between them.
It is to determine whether they can occupy different analytical layers within the same cyber-risk architecture.
This leads to the central proposition of this white paper:
A mature cyber-risk capability requires both a persistent model of exposure and a dynamic model of adversarial action.
MONARC and EBIOS Risk Manager provide two distinct ways of constructing these models.
Their respective strengths should not be artificially merged.
They should remain distinguishable.
That is precisely what makes their combination intellectually interesting.
Two methods.
Two risk ontologies.
Two analytical lenses.
One evolving risk architecture.
The DUAL LENS approach therefore proposes a movement:
- From periodic assessment to persistent knowledge.
- From isolated risk studies to reusable risk models.
- From threat identification to adversarial understanding.
And ultimately,
From cyber risk assessment to cyber risk intelligence.
References
- NC3 Luxembourg — MONARC Method Guidewww.monarc.lu/documentation/method-guide
- NC3 Luxembourg — MONARC — Assessment, Testing & Trainingnc3.lu/assessment-testing-and-training/monarc
- ANSSI — La méthode EBIOS Risk Managercyber.gouv.fr/securisation/analyse-des-risques/methode-ebios-rm
- ANSSI — L'ANSSI met à jour la méthode EBIOS Risk Manager (EBIOS RM 1.5)cyber.gouv.fr/actualites/lanssi-met-a-jour-la-methode-ebios-risk-manager
- ANSSI — EBIOS Risk Manager — The Method (English guide)messervices.cyber.gouv.fr — PDF
- ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risksiso.org/standard/80585.html
- ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirementsiso.org/standard/27001
© 2026 Dominique Bourra. All rights reserved.
Published on Agrapha Dogmata.
MONARC, EBIOS Risk Manager, ISO/IEC 27001 and ISO/IEC 27005 are referenced for analytical and comparative purposes. All respective names, marks, methodologies and standards remain attributable to their respective rights holders.
The DUAL LENS analytical model and the original comparative framework presented in this white paper are © 2026 Dominique Bourra.