Engie: EBIOS RM Risk Analysis on Azure
An industrialised method for the group's Cloud compliance on a worldwide scale.
A reusable methodological framework, policy_as_code (Bicep + Sentinel + OPA), Defender for Cloud and Sentinel, aligning all entities with the group security policy.

Project Context
The ENGIE group operates 26 entities across the world, each with its own Azure workloads and its own cyber practices. Regulatory pressure (NIS2, ISO 27005) and the need for a consistent group security policy called for a thorough overhaul.
Without a shared method, each entity ran its risk analyses in isolation, with uneven quality and a significant effort cost. Consolidation at group level remained largely manual and belated.
The challenge: to create an industrialised Cloud EBIOS RM framework, powered by policy_as_code and a unified CSPM, to align all entities on a common baseline while preserving local agility.
Strategic Objectives
Reusable EBIOS RM method
Build an industrialised, reusable Cloud EBIOS RM method usable by the 26 entities of the ENGIE group worldwide: not a one-shot audit, but a durable framework.
Cloud compliance
Ensure that Azure workloads comply with ISO 27005 and NIS2 standards and with the ENGIE group security policy, through policy_as_code and continuous CSPM via Defender for Cloud and Sentinel.
Worldwide group alignment
Align the 26 group entities (France, Brazil, UK, Solutions, Italy, Germany, and more) on a common baseline of cyber controls, while respecting local and regulatory specificities.
Solutions Delivered by Adservio
Adservio deployed a dedicated Cloud Security team (CISO Lead, EBIOS RM expert, Cloud Architects, SecOps) over 24 months.
Cloud EBIOS RM scoping
Application of the ANSSI EBIOS RM method across the Azure perimeter: risk sources, essential assets, strategic and operational scenarios formalised in auditable YAML.
Industrialisation
Creation of a kit of EBIOS RM templates reusable by the group entities: checklist, pre-modelled scenarios, treatment plans and steering dashboards, for a major acceleration of the rollout.
Policy as Code
Deployment of policy_as_code (Bicep + Sentinel + OPA) covering the ISO 27005 and NIS2 controls, with automatic drift detection and CSPM-driven remediation.
Defender + Sentinel
Roll-out of Defender for Cloud (CSPM) and Sentinel (SIEM/SOAR) at group scale, with incident runbooks, industrialised threat hunting and unified alerting.
Entity CISO coaching
Training and supporting the CISOs of the 26 entities on the industrialised EBIOS RM method, running a cyber community of practice and standardising group reporting.
26 entities, one unified method,
group-wide Cloud compliance.
An industrialised EBIOS RM framework in auditable YAML, policy_as_code with Bicep + Sentinel + OPA, CSPM via Defender for Cloud: Cloud compliance becomes a group asset, not a local project.
Results
Reusable Cloud EBIOS RM framework deployed across 26 entities worldwide.
Cyber controls driven by policy_as_code with continuous drift detection.
Roll-out of a new Azure entity in 6 weeks instead of 4 months.
Full alignment of Azure workloads with ISO 27005 and NIS2 requirements.
Industrialisation of a durable Cloud EBIOS RM method, not a one-shot audit.
A unified view of Cloud risks through Defender for Cloud and Sentinel.
Impact
Industrialised method
Reusable Cloud EBIOS RM framework deployed across 26 group entities worldwide, with pre-modelled scenarios and treatment plan templates.
ISO 27005 compliance
Full alignment of Azure workloads with ISO 27005 and NIS2 requirements, validated during the internal and external audits of the ENGIE group.
Policy as Code 95%
95% of cyber controls automated through policy_as_code (Bicep + Sentinel + OPA), with continuous drift detection and auto-remediation of minor deviations.
Group security policy aligned
All major group entities are now aligned with the ENGIE security policy, with a common control baseline and standardised reporting.
Time-to-compliance −60%
Rolling out a new Azure entity within the group perimeter now takes 6 weeks instead of 4 months, thanks to the EBIOS RM templates.
Unified CSPM
A unified view of Cloud risks at group scale through Defender for Cloud and Sentinel, with consolidated dashboards and incident SLAs met across the 26 entities.
More Client Work
Industrialise your Cloud compliance across your group
Industrialised EBIOS RM, policy_as_code, Defender for Cloud and Sentinel: let's discuss your Cloud cybersecurity challenges. An Adservio expert gets back to you within 24h.





















