FNMF: EBIOS RM & GDPR Risk Analysis

CASE STUDY · IMPACT · NATIONAL MUTUAL INSURER

Cybersecurity across the entire IT system of the Fédération Nationale Mutuelle Française.

14 EBIOS RM scenarios modelled, GDPR compliance by design, and preparation for the NIS2 requirements, with a lasting upskilling of the internal teams.

FNMF : Adservio case study
Client
FNMF (national mutual insurer)
Expertise
Cybersecurity · Risk assessment · GDPR compliance
Tech Stack
EBIOS RM · ANSSI · NIS2 · ISO 27005 · DLP · MFA · audit log
Engagement
5 experts · 12 months
CONTEXT

Project Context

The FNMF manages sensitive personal data at scale (health, HR and financial data) for its members. The cyber landscape was hardening (a rise in attacks on mutual insurers, a well-established GDPR, NIS2 being transposed) and the internal risk management tooling remained largely informal.

Without a solid methodological framework, the prioritisation of cyber investments relied on intuition rather than objective analysis. Controls existed, but their overall coherence against the most critical scenarios was never formalised.

The challenge: to structure a complete EBIOS RM approach compliant with ANSSI standards, bring all processing activities into GDPR compliance, deploy the priority technical and organisational controls, and durably upskill the internal teams, all while preparing for the NIS2 transposition.

Strategic Objectives

(01)

Map the risks

Apply the EBIOS RM method (ANSSI) to map all cyber risks weighing on the FNMF information system, from strategic scenarios down to operational scenarios: 14 active scenarios across the whole perimeter.

(02)

GDPR compliance

Bring all personal data processing into compliance with the GDPR: records of processing, data protection impact assessments (DPIA) on high-risk processing, formalisation of legal bases and purposes.

(03)

Remediation plan

Define a remediation plan prioritised by the impact x likelihood pairing, deploy the technical and organisational controls (MFA, DLP, phishing simulation, IRP), and upskill the internal teams.

Solutions Delivered by Adservio

Adservio deployed a dedicated team (CISO Lead, EBIOS RM expert, DPO, Security Engineers) to structure the cyber approach over 12 months.

(01)

EBIOS RM scoping

Strict application of the ANSSI EBIOS RM method: strategic workshops with management, identification of risk sources, mapping of essential and supporting assets, and elaboration of strategic and operational scenarios.

(02)

Risk assessment

14 operational scenarios modelled (targeted phishing, ransomware, PII leak, admin account compromise, DDoS, exfiltration), with an objectified impact x likelihood pairing and residual risk after controls. Collegial validation with the CISO and management.

(03)

GDPR compliance

Mapping of processing activities, formalisation of the records, impact assessment on sensitive processing (health data), management of data subject rights, formalisation of data processing agreements (DPA) and a post-incident continuity plan.

(04)

Technical controls

Generalised MFA roll-out, DLP across PII flows, quarterly phishing simulations, hardening of the security policy, an incident response plan (IRP) with a 4h RTO, and an immutable audit log with 5-year retention.

(05)

Enablement & coaching

Training of IT and business teams in cyber and GDPR practices, running a fortnightly security committee, embedding security by design in the application lifecycle, and preparing the FNMF for the NIS2 requirements.

14 scenarios, one ANSSI method,
an acceptable residual risk.

Each EBIOS RM scenario is formalised in an auditable DSL (source, target, kill_chain, controls, compliance). The risk register is steered continuously, with an incident MTTR of 3.2 hours and ANSSI · GDPR · NIS2 compliance by construction.

Results

14
EBIOS RM scenarios

Operational scenarios modelled, covering all essential assets.

100%
perimeter covered

Complete mapping validated by management and the CISO.

3.2h
incident MTTR

Mean time to remediation on critical incidents, below the 4h RTO.

< 72h
data subject rights

Operational turnaround for members' GDPR requests.

5 years
audit log retention

Immutable logging retained for regulatory traceability.

NIS2
compliance ready

Early preparation for the NIS2 transposition: governance and incident reporting.

Impact

EBIOS RM 100% covered

Complete mapping validated by management and the CISO: 14 operational scenarios covering all of the FNMF essential and critical supporting assets, with an acceptable residual risk level.

GDPR compliance validated

Internal and external DPO audits passed with no major reservation. Up-to-date records of processing, DPIAs carried out on all high-risk processing, data subject rights operational in under 72h.

Acceptable residual risk

Of the 14 initial scenarios, none any longer presents an unacceptable residual risk level after the controls were put in place. 2 scenarios remain under active surveillance with a continuous remediation plan.

Incident MTTR 3.2h

An operational incident response plan, validated during regular game days: a mean time to remediation of 3.2 hours on critical incidents, below the 4h RTO target.

NIS2-ready

Early preparation for the NIS2 transposition: governance, incident reporting, supply chain management and executive training. The FNMF is ready for the new regulatory requirements.

Lasting cyber culture

A fortnightly security committee anchored in governance, quarterly phishing simulations with a continuously falling click rate, and IT teams trained in DevSecOps practices and the EBIOS RM framework.

TALK TO AN EXPERT

Secure your information system with EBIOS RM

Audit, mapping, technical controls and ANSSI · GDPR · NIS2 compliance by design: let's discuss your cyber and compliance challenges. An Adservio expert gets back to you within 24h.

By submitting this form, you agree to our privacy policy.