The invention relates to a method for analyzing the
IT risk of a network of interest (20) directly or indirectly exchanging network flows with at least one third-party network (30, 40, 50), comprising the following steps: - retrieval of network flows captured by at least one firewall (32, 42, 52) belonging to at least one third-party network; - comparison of the destination and origin internet addresses of each retrieved network flow with at least one
database of toxic internet addresses (64); each network flow incorporating at least one destination or origin
internet address stored in said
database of toxic internet addresses corresponding to a toxic flow; and - identification, for each toxic flow, of the nature of the risk in order to determine whether each toxic flow presents a risk to the network of interest or to one of said at least one third-party network. Figure 2.