You are here: silicon.com > Software > Security Strategy

Security Strategy

Boards underestimate tech risk

Execs struggle with pace of IT change...

Tags: technology, it, audit, board

By Tim Ferguson

Published: 5 September 2007 16:00 GMT

Company executives are failing to address the IT risks facing their organisations despite the subject being higher up the boardroom agenda than ever before.

More than two thirds (68 per cent) of internal audit bosses believe their board isn't able to fully understand IT risks, according to research carried out by PricewaterhouseCoopers (PwC) for the Institute of Internal Auditors (IIA).

Some of the blame lies with the people who assess risk within organisations but who are failing to communicate effectively with the board over the issue.

Read all about IT…

Check out the Editor's Blog for the silicon.com chief's take on the hot tech issues of the moment.

The research found two thirds of internal audit departments are spending less than 20 per cent of their time reviewing IT risk.

PwC said boards don't have practical experience with IT and so don't fully understand the risks and opportunities that technology presents. Almost nine out of 10 (87 per cent) senior managers also said they find the pace of change in IT a major challenge. As a result, boardrooms have an incomplete view of IT risk for their business.

Grant Waterfall from risk assurance services at PwC said boardroom executives are looking for more assurance about IT as technology investment increases.

Gail Eastbrook, CEO of the IIA, said internal audit departments are well placed to respond to this problem if they can initiate discussions between the board and IT department.

But she added this means the skills base within the internal audit departments may need to be reassessed to improve engagement with the rest of the business.

The IT Risk - Closing the Gap report quizzed 250 senior executives, including CIOs and internal audit managers.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Internal Audit, Temp, Norwich

insurance, bank, financial services, internal audit, contract, audit My client, a well known Insurance company, requires a number of internal ...

Data Audit - IT

Responsibilities entail: • Preparing and managing the different Market data audit processes : External: Exchanges and Vendors Internal: ...

PROJECT LEAD

Conduct end Project evaluation to assess how well the Project was managed and prepare an end-Project report (including lessons learned report/ ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: