CIO roundtable
Risk management is all about the basics

Ask the experts: Take no risks

The results of a recent CIO roundtable that examined the challenges of risk management

Written by Mark Samuels

Participants discussed their experience and came up with a series of best practice tips for IT leaders to focus on to develop their own plans to protect and secure the business:

Back to basics

Risk management is all about going back to basics ­ which, in turn, is all about inclusion and a holistic approach. As we are sharing information, we’ve got to be careful to create a balance and not to add too much control that might stop the desire for innovation.
Colin Windsor, chief information officer, Openreach

I think the holistic view is crucial ­ we need to consider people, process, technology and governance in combination. We’re constantly struggling with human nature and the issues surrounding new social networking technologies. Each individual will look at risk from their own individual view point. It is essential we get ownership right and the people marshalled so the right rules are in place.
Tony Marshall, interim risk manager working for central government

People need to learn. If individuals begin to care enough for their own data, then maybe more people will care about business information.
Ray Stanton, global head of BT’s business continuity, security and governance practice

Leadership

The buck stops with the board. If we are going to address IT and data security, we have a duty to make sure the board is aware and that they have decided on the monetary value of information. The board needs to tell us what they want to protect so that we can implement the right tools to address the business elements of risk.
Amir Mohazab, head of IT, Protiviti

We’re talking about the ability of IT to influence the business ­ and we need to consider whether IT has a high enough profile. Are IT directors actually on the executive board of companies? Traditionally, the board representation of IT is not all that it might have been ­ and that is often still the case today.
Paul Graham, partner, Dundas and Wilson LLP

Education

The IT industry has a propensity to beat itself up when it comes to security problems and to take on business-related problems. We’re basically talking about human failings ­ and that brings us back to issues of process and the correct training of individuals.
Richard Stephens, principal, Lors Online

Effective risk management is all about education and leadership. We need to concentrate on the actions of individuals, which can cause a security breach and a loss of information. As has happened with security and virus control, we’ve got to start putting out some simple messages and educate the people so that risk management is ingrained into the culture.
Peter James, chief information officer, Achilles Information Limited

Risk is a threat that runs through a public sector organisation and we sometimes don’t analyse the processes correctly. Organisations can become complacent with regards to staying refreshed with key issues and disseminating information to staff. The high-profile data loss incidents have shown to public sector staff that they need to tighten their processes to ensure such incidents do not happen again. We must say that we have learnt a lesson and move forward.
Kash Akram, director of business development, Cromwell College of IT and Management

People and processes

Risk management is all about people and processes ­ and technology is only the final part. We’re probably pretty good at learning, but we’re not very good at the training and development because we’ve always got something else to learn. Such an approach means you never actually develop the best practice within the business. We just need to create an effective balance between the business and IT, because business actually has an appetite for risk ­ and that is how it gets a competitive advantage.
Que Tran, IT solutions director, Synovate

Without good risk management, you cannot work out the best way to allocate your resources. You cannot terminate all risk, obviously ­ and you need to manage it. Without undertaking a process of quantifying the risk, it will be impossible to work out which areas you should focus on.
Mark Hughes, director, BT Group security

Roles and responsibilities

Roles and responsibilities really need to be clear ­ and responsibility for risk within the business can’t possibly be with IT. If you address the risks that you can foresee, you will also be addressing most of the risks that you cannot foresee. So, just be active in managing risk.
Kevin Davies, head of information strategy and policy, Highways Agency

As the executives of the business, I think we’ve got two responsibilities. One is to make the business aware of the risk in terms of compliance, governance and measurement. When we go to our business colleagues, we always complain that they cannot tell us what they want. Well, we need to help them tell us what they want. Second, we have a duty as managers to implement the right processes to mitigate some of the risk.
John Wishney, interim executive director

Managing risk: http://managing risk.computing.co.uk

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

Pictire of Mark SamuelsStrategy

Collaborate to innovate

CIOs need to demonstrate how IT leadership is critical to business innovation 21 May 2008

 

Adapting to Climate Change: A New Frontier for Business

Firms may have woken up to the need to tackle global warming, but when it comes to adapting to its impacts too many remain fast asleep to both the risks and opportunities 20 May 2008

As climate change bites, pressure mounts for tougher legislation

Fresh research revealing accelerated rate of climate change prompt renewed calls for more stringent carbon regulations 19 May 2008

related whitepapers

today's top stories

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

Publishing special - Publishers innovate to survive

1) IT could hold the key to the future of publishing 2) Case Study: The Guardian harnesses social and mobile apps 3) How publishers are reacting to the iPad 02 Mar 2010

The dangers and delights of the web

The anonymity that the internet affords can foster lively and robust debate – but it also brings dangers 02 Mar 2010

All mod comms

Unified communications systems can lower communication costs while enabling staff to work in a more flexible and productive way, as Martin Courtney reports 02 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

Public disclosure

Public disclosure

Should companies be compelled to go public on data breaches?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

Stoneleigh Park show ground. Pic: Dave HamsterFeatures

Harnessing the benefits of unified communications

The reasons for adopting unified communications can be as varied and contrasting as the adopters themselves, as Martin Courtney discovers 09 Mar 2010

University of SheffieldFeatures

Case study: University of Sheffield

University shows a high degree of forward thinking with UC 09 Mar 2010

Primary Navigation