(DT24) (INCYBER) Fence : l'outil d'analyse des risques cyber pour le spatial, l'aéro, l'IT, l'OT...

(DT24) (INCYBER) Fence : l'outil d'analyse des risques cyber pour le spatial, l'aéro, l'IT, l'OT...

🎙 Charlie Mont 👥 7K 📅 April 12, 2026 ⏱ 28 min 👁 61 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

Fencerisk analysisEBIOS RMISO 27005NIS2

Summary

This presentation introduces Fence, a cyber risk analysis tool developed by Airbus Protect. The speaker, Charlie Mont, an architect specializing in IAM, explains that Fence is an on-premise solution designed for risk assessment, compliance assessment, and upcoming audit capabilities. It supports multiple methodologies including EBIOS RM, ISO 27005, and sector-specific standards like IEC 62443 and TS 50701. The tool allows for customizable knowledge bases, such as MITRE ATT&CK, and offers features like risk tracking, global consolidated views, and API integration. The demo covers the user interface, risk assessment workflows, scenario generation, and compliance mapping. The presentation highlights the tool’s flexibility, collaboration features, and deployment options, including air-gapped environments. The speaker also discusses the roadmap for 2026, including audit functionality and enhanced API write capabilities. A Q&A session addresses API integration with penetration test reports and NIS2 national implementations.

138 words

Critical Evaluation

Value of the Information & Strength of the Argument

The presentation provides a comprehensive overview of the Fence tool’s capabilities, demonstrating its value for organizations needing structured cyber risk analysis. The argumentation is based on the tool’s features and the speaker’s expertise, but it is essentially a product pitch. The tool’s alignment with recognized standards (EBIOS RM, ISO 27005) adds credibility, but the lack of independent validation or case studies limits the strength of the argumentation. The speaker effectively explains how the tool addresses common pain points, such as compliance tracking and risk visualization, but the claims are not backed by empirical evidence.

Scientific Rigor, Source Quality, Title Accuracy

The presentation is rigorous in its technical detail, but it relies solely on the speaker’s expertise and product documentation. No external sources are cited, and the only links provided are to the INCYBER forum and LinkedIn page, which are not directly related to the content. The title accurately reflects the content, focusing on the Fence tool for cyber risk analysis. The speaker demonstrates a strong understanding of the subject, but the lack of independent sources or references to external research limits the scientific rigor. The presentation is more of a product demonstration than a scientific discourse.

205 words

Title / Content Match

The title accurately reflects the content, which focuses on the Fence tool for cyber risk analysis across various sectors.

Quality & Reliability

7/10

The speaker is a cybersecurity architect with deep product knowledge, but the presentation is a product demo, not an independent study. Claims are plausible and aligned with known standards, but no external verification is provided.

Key Moments

Cited Sources

Contribution & Novelties

The presentation offers an in-depth look at a specialized cyber risk analysis tool, highlighting its support for multiple standards and its flexibility. The main novelty is the tool’s ability to consolidate risk and compliance assessments across various frameworks, which is valuable for organizations facing complex regulatory environments.

Pour aller plus loin :

  • EBIOS Risk Manager — Official French methodology for risk assessment, directly relevant to the tool’s core methodology.
  • ISO/IEC 27005 — International standard for information security risk management, referenced in the presentation.
  • NIS2 Directive — EU directive on cybersecurity, which the tool supports for compliance assessment.

97 words

Radar Profile

The radar profile shows a balanced tool with strong scores in information quantity and quality, moderate technical depth, and slightly lower reliability due to the lack of independent sources. This suggests a comprehensive but product-centric presentation.

Reliability 6/10