You are here: silicon.com > Software > Security Strategy

Security Strategy

Beware IT risks - or watch your rivals get ahead

Mind the security gap, warns Gartner...

Tags: it managers, gartner, risk, security

By Tom Espiner

Published: 18 September 2007 08:45 BST

Businesses must recognise that failing to handle IT risks puts them at a competitive disadvantage, according to analyst house Gartner.

While IT has become increasingly central to business success, many businesses have not adjusted their processes for IT decision making and risk management, Gartner says.

Analyst Richard Hunter said failure to properly take account of - and plan for - IT risks can affect business agility. "Managements that do understand IT risks are pulling ahead, while those that don't are falling behind and getting eaten," said Hunter. "Uncontrolled IT risk dampens an organisation's ability to compete."

He said businesses that tailor business processes to take account of IT risks find they are better able to integrate systems, for example, after an acquisition, and are more capable of divesting themselves of companies they wish to sell.

Hunter, who was speaking at Gartner's IT Security Summit in London, said: "IT risk has changed. IT risk incidents harm constituencies within and outside companies. [Incidents] damage corporate reputations and expose weaknesses in companies' management teams."

IT managers must convey the consequences of IT risks to the business, said Hunter. "It's not simply a case of saying 'there's a risk that the server might go down'. You have to look beyond to say what that server supports in the business - that, if it goes down, you'll lose $50m in the first week, and be out of business in three weeks."

According to the analyst, a company must ask itself whether its IT systems and business processes will continue running in the event of technology failure, and whether the systems will recover from interruptions. Companies should also ask whether the right people have access to the data they need to do their jobs, and whether the wrong people are blocked from accessing that data.

Hunter asked: "Can the company's IT systems be relied on to provide correct, timely, and complete information that meets the requirements of management, staff, customers, suppliers and regulators? And do the organisation's IT systems possess the capability to change if the company acquires another firm, completes a major business process redesign, or launches a new product or service?"

The analyst said a company needs a solid foundation of IT assets, people, and supporting processes and controls that enable executives to manage the right risks in the right order; a risk governance structure and process that integrates IT risk management into every business decision to identify, prioritise and track risks; and a risk-aware culture, nurtured from the top, that attunes people to the causes and solutions for IT risks and that increases vigilance across the organisation.

Tom Espiner writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Martin Brampton Brampton Factor: Open source stands up for its rights Copyright can keep the movement alive...

Bob Tarzey The rise and rise of Infor Quocirca's Straight Talking: Where next for the apps giant?


  • Jobs
ENERGY Market Risk Analyst Required Tier 1 Bank (London)

Providing risk analysis for front office to assist them in decision making taking into account the risk/reward balance. Do you have commodity market ...

IT Auditor - South Coast - 40,000

You will report directly to the Group IT Audit Manager & duties will include: - Work on special projects and investigations - Work with management on ...

Credit Risk/ CVM Analyst - East Midlands

Hands on experience in SAS Programming and any exposure to Consumer lending (risks, change, fraud, collections etc.would be highly desirable. The ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: