FNMF: EBIOS RM & GDPR Risk Analysis
Cybersecurity across the entire IT system of the Fédération Nationale Mutuelle Française.
14 EBIOS RM scenarios modelled, GDPR compliance by design, and preparation for the NIS2 requirements, with a lasting upskilling of the internal teams.

Project Context
The FNMF manages sensitive personal data at scale (health, HR and financial data) for its members. The cyber landscape was hardening (a rise in attacks on mutual insurers, a well-established GDPR, NIS2 being transposed) and the internal risk management tooling remained largely informal.
Without a solid methodological framework, the prioritisation of cyber investments relied on intuition rather than objective analysis. Controls existed, but their overall coherence against the most critical scenarios was never formalised.
The challenge: to structure a complete EBIOS RM approach compliant with ANSSI standards, bring all processing activities into GDPR compliance, deploy the priority technical and organisational controls, and durably upskill the internal teams, all while preparing for the NIS2 transposition.
Strategic Objectives
Map the risks
Apply the EBIOS RM method (ANSSI) to map all cyber risks weighing on the FNMF information system, from strategic scenarios down to operational scenarios: 14 active scenarios across the whole perimeter.
GDPR compliance
Bring all personal data processing into compliance with the GDPR: records of processing, data protection impact assessments (DPIA) on high-risk processing, formalisation of legal bases and purposes.
Remediation plan
Define a remediation plan prioritised by the impact x likelihood pairing, deploy the technical and organisational controls (MFA, DLP, phishing simulation, IRP), and upskill the internal teams.
Solutions Delivered by Adservio
Adservio deployed a dedicated team (CISO Lead, EBIOS RM expert, DPO, Security Engineers) to structure the cyber approach over 12 months.
EBIOS RM scoping
Strict application of the ANSSI EBIOS RM method: strategic workshops with management, identification of risk sources, mapping of essential and supporting assets, and elaboration of strategic and operational scenarios.
Risk assessment
14 operational scenarios modelled (targeted phishing, ransomware, PII leak, admin account compromise, DDoS, exfiltration), with an objectified impact x likelihood pairing and residual risk after controls. Collegial validation with the CISO and management.
GDPR compliance
Mapping of processing activities, formalisation of the records, impact assessment on sensitive processing (health data), management of data subject rights, formalisation of data processing agreements (DPA) and a post-incident continuity plan.
Technical controls
Generalised MFA roll-out, DLP across PII flows, quarterly phishing simulations, hardening of the security policy, an incident response plan (IRP) with a 4h RTO, and an immutable audit log with 5-year retention.
Enablement & coaching
Training of IT and business teams in cyber and GDPR practices, running a fortnightly security committee, embedding security by design in the application lifecycle, and preparing the FNMF for the NIS2 requirements.
14 scenarios, one ANSSI method,
an acceptable residual risk.
Each EBIOS RM scenario is formalised in an auditable DSL (source, target, kill_chain, controls, compliance). The risk register is steered continuously, with an incident MTTR of 3.2 hours and ANSSI · GDPR · NIS2 compliance by construction.
Results
Operational scenarios modelled, covering all essential assets.
Complete mapping validated by management and the CISO.
Mean time to remediation on critical incidents, below the 4h RTO.
Operational turnaround for members' GDPR requests.
Immutable logging retained for regulatory traceability.
Early preparation for the NIS2 transposition: governance and incident reporting.
Impact
EBIOS RM 100% covered
Complete mapping validated by management and the CISO: 14 operational scenarios covering all of the FNMF essential and critical supporting assets, with an acceptable residual risk level.
GDPR compliance validated
Internal and external DPO audits passed with no major reservation. Up-to-date records of processing, DPIAs carried out on all high-risk processing, data subject rights operational in under 72h.
Acceptable residual risk
Of the 14 initial scenarios, none any longer presents an unacceptable residual risk level after the controls were put in place. 2 scenarios remain under active surveillance with a continuous remediation plan.
Incident MTTR 3.2h
An operational incident response plan, validated during regular game days: a mean time to remediation of 3.2 hours on critical incidents, below the 4h RTO target.
NIS2-ready
Early preparation for the NIS2 transposition: governance, incident reporting, supply chain management and executive training. The FNMF is ready for the new regulatory requirements.
Lasting cyber culture
A fortnightly security committee anchored in governance, quarterly phishing simulations with a continuously falling click rate, and IT teams trained in DevSecOps practices and the EBIOS RM framework.
More Client Work
Secure your information system with EBIOS RM
Audit, mapping, technical controls and ANSSI · GDPR · NIS2 compliance by design: let's discuss your cyber and compliance challenges. An Adservio expert gets back to you within 24h.





















