(IT24) (INCYBER) Fiabiliser et passer à l’échelle ses analyses de risques par IA...

(IT24) (INCYBER) Fiabiliser et passer à l’échelle ses analyses de risques par IA...

🎙 Charles Mur 👥 7K 📅 April 9, 2026 ⏱ 17 min 👁 77 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

AIrisk analysisEBIOSmulti-agenthuman-in-the-loop

Summary

Charles Mur, from Cyberlift, shares a feedback on integrating AI into risk analysis within the ISP (Integration of Security in Projects) process. He explains the evolution from a simple proof-of-concept using Power Automate and GPT-3.5 to a more sophisticated multi-agent system. The initial POC had limitations in volume, coherence, and transparency. The second version introduced a human-in-the-loop approach, allowing analysts to validate intermediate steps, which improved quality and adoption. However, it still lacked precision and scalability for large contexts. The third version incorporated a RAG stack and a multi-agent architecture, enabling more precise and context-aware risk analysis. The talk highlights the importance of iterating quickly, ensuring context quality, using deterministic tools for calculations, and designing appropriate interfaces. The speaker also addresses questions about risk analysis on the AI solution itself and the use of EBIOS Flash methodology.

137 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners interested in applying AI to risk analysis. The speaker provides a clear, step-by-step account of the challenges and solutions encountered, including specific technical details such as prompt chaining, human-in-the-loop, RAG, and multi-agent systems. The argumentation is solid, based on real-world experience and concrete examples, such as the 44 risk analyses produced in two months. The speaker also honestly discusses limitations and lessons learned, which enhances credibility. However, the presentation is from a vendor perspective, and the claims are not independently verified.

Scientific Rigor, Source Quality, Title Accuracy

The talk is a professional feedback session, not an academic presentation. The speaker does not cite external sources, but the content is based on practical experience. The title accurately reflects the content. The description provides links to the INCYBER forum and LinkedIn, which are relevant but not directly to the technical content. The talk is well-structured and coherent, but the lack of external references limits its scientific rigor.

173 words

Title / Content Match

The title accurately reflects the content, which focuses on making risk analysis reliable and scalable using AI while controlling costs.

Quality & Reliability

7/10

The speaker provides a detailed and structured feedback on integrating AI into risk analysis, based on practical experience. The talk includes concrete examples, limitations, and lessons learned. However, it is primarily a vendor presentation with limited independent verification and no citations to external sources.

Key Moments

Cited Sources

Concurring Sources

  • EBIOS Risk Manager — The methodology referenced in the talk for risk analysis.

Contribution & Novelties

The talk provides a practical, real-world example of integrating AI into risk analysis, highlighting the evolution from simple prompt chaining to a multi-agent system with human-in-the-loop validation. It offers actionable insights for organizations looking to scale their risk analysis processes with AI while managing costs. The emphasis on iterating quickly and reusing agent components is valuable.

Pour aller plus loin :

  • EBIOS Risk Manager — The official French methodology for risk analysis, which the speaker mentions using in a ‘Flash’ version.
  • Retrieval-Augmented Generation (RAG) — A technique used to handle large contexts by retrieving relevant information.
  • Multi-agent systems — The architecture used in the third version to improve precision and reliability.

111 words

Radar Profile

The radar profile shows a balanced performance with high scores in information quantity and quality, moderate technical depth, and slightly lower reliability due to the lack of external citations. This suggests a practical, experience-based talk that is informative but not heavily research-oriented.

Reliability 6/10