0x30F - Spécial - Cybersécurité, sûreté, risque dans un grand groupe

0x30F - Spécial - Cybersécurité, sûreté, risque dans un grand groupe

🎙 PolySécure Podcast 👥 539 📅 June 23, 2026 ⏱ 45 min 👁 24 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

cybersecurityrisk managementEBIOS RMaerospacesupply chain

Summary

In this special episode of PolySécure Podcast, Pascal Manni, RSSI for Airbus Canada, discusses the role of a Chief Information Security Officer (CISO) in a large aerospace group. With over 15 years at Airbus, including stints in France and China, Pascal brings a unique perspective on integrating cybersecurity and safety into a newly acquired program (the A220). He outlines four pillars of security: industrial and supply chain, product (regulated by aviation authorities), digital, and people/workspaces. A key challenge is harmonizing vocabulary across the global group, which has developed its own taxonomy to communicate with regulators and internal divisions. The core of the discussion is the EBIOS RM methodology, developed by ANSSI, which consists of five workshops: defining scope and assets, identifying risk sources, strategic risk analysis, operational measures, and treatment planning. Pascal emphasizes the importance of involving the business from the start, with the CISO acting as a translator between engineering, regulatory, and security requirements. He also highlights the unique aspects of aerospace, where product safety extends beyond delivery through maintenance and contractual relationships, and the growing importance of supply chain security. The episode concludes with a discussion on vulnerability management, incident response, and the need for mature metrics to report to executive levels.

204 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, experience-based insights into implementing a risk management framework (EBIOS RM) in a complex, multinational aerospace company. Pascal provides concrete examples of how the methodology is applied, such as using NIST-based compliance questionnaires and adapting them to Airbus’s language. The argumentation is coherent and well-structured, systematically walking through the five workshops and explaining their purpose and interconnections. He effectively argues for a business-driven approach, where the CISO facilitates rather than owns risk, and emphasizes the importance of a common vocabulary to align diverse stakeholders. The discussion of supply chain vulnerabilities and the need for contractual security annexes adds depth. However, the argumentation is largely anecdotal and lacks quantitative evidence or comparative analysis with other frameworks, which limits its generalizability.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate: the speaker references established methodologies (EBIOS RM, NIST) and regulatory bodies (ANSSI, Transport Canada), but does not provide formal citations or data. The quality of sources is acceptable for an expert opinion, but the lack of verifiable references reduces its academic weight. The title accurately reflects the content, which focuses on cybersecurity, safety, and risk management in a large group. No comments were provided, so no analysis of public reception is included.

219 words

Title / Content Match

The title accurately reflects the content, which focuses on cybersecurity, safety, and risk management within a large group.

Quality & Reliability

8/10

The speaker is a seasoned RSSI with 15 years at Airbus, providing practical insights into risk management in a large aerospace group. The content is based on direct professional experience and references established methodologies (EBIOS RM, NIST). However, it is an opinion-based podcast without formal citations or peer-reviewed sources, and the low viewership suggests limited external validation.

Key Moments

Cited Sources

  • EBIOS Risk Manager (ANSSI) — Mentioned as the methodology used by Airbus for risk analysis.
  • NIST Cybersecurity Framework — Referenced as the basis for compliance questionnaires adapted to Airbus's language.

Concurring Sources

  • EBIOS Risk Manager (ANSSI) — The methodology described in the episode is officially documented by ANSSI.
  • NIST Cybersecurity Framework — The framework is widely used for cybersecurity risk assessments, as mentioned in the episode.

Contribution & Novelties

The episode provides a rare, in-depth look at how a major aerospace company operationalizes cybersecurity and safety risk management, specifically through the EBIOS RM methodology. It offers practical insights into adapting a national framework (EBIOS RM) to a global corporate context, including the development of a common vocabulary and the integration of multiple regulatory requirements. The discussion of supply chain security and the extension of risk management beyond product delivery adds value. The speaker’s experience in different cultural contexts (France, China, Canada) enriches the perspective.

Pour aller plus loin :

  • EBIOS Risk Manager — Official ANSSI guide for the methodology.
  • NIST Cybersecurity Framework — Framework used for compliance assessments.
  • ISO/IEC 27005 — International standard for information security risk management, related to the topic.

123 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, reflecting the rich practical experience shared. The technical level is solid, indicating a good balance between accessibility and depth. The overall reliability is high due to the speaker's expertise, though the lack of formal citations slightly reduces the score.

Reliability 8/10