Pillars of Risk Management Technology

0
0
Hire Risk Expert
You agree to our Terms and Conditions of Use, PDPA & Privacy Policy and Cookies Policy

Pillars of Risk Management Technology

TECHNOLOGY RISK

TECHNOLOGY RISK: ONE OF THE ESTABLISHED PILLARS, STILL EVOLVING

On the main Pillars of Risk Management page, I explained why my team and I decided to keep Technology Risk, Enterprise Risk Management, Cyber Risk, Operational Resilience, Business Continuity, Governance & Compliance, Third-Party Risk, Risk Assessment and the Risk Register as the established foundations of this website, even as we added newer areas such as A.I. & Risk, Decision Making, Human Behaviour, Future of Work, Trust, The Science of Risk, The Future Human and Signals.

Technology Risk is one of those established pillars. What makes it particularly interesting today is that the pillar itself has not disappeared, but the technology sitting inside it keeps changing. The questions we once asked about computers, software, backups and system failures have expanded into questions about cloud services, remote work, digital platforms, A.I. and now A.I. agents that may be able to take actions for us. This gives us a useful way to test one of the ideas from the main Pillars page: when the world gives us a seemingly new risk, how much of our established Risk Management thinking still works, which tools need to evolve, and where do we genuinely need something new?

For someone discovering Risk Management for the first time, you may also notice something else as you read this page. You may already have been managing Technology Risk without ever calling it Technology Risk. For experienced risk practitioners, the more interesting question may be the opposite: are the Technology Risk tools we have used for years still adequate for the technologies and dependencies we are creating now?

WHAT IS TECHNOLOGY RISK?

Technology Risk is the possibility that technology we use or depend upon fails, becomes unavailable, does not perform as expected or creates an unintended consequence that affects something we are trying to do.

For an individual, that technology might be a phone, laptop, banking app, cloud-storage account or A.I. assistant. For a small business, it could be its booking system, payment platform, accounting software, customer database, website, internet connection or one of the online services it relies upon to operate.

Technology Risk does not necessarily mean that somebody has hacked you. That would take us into Cyber Risk, which is related but different. Technology can simply stop working. We can choose the wrong technology. An update can cause a problem. Information can be lost. A provider can become unavailable. A system can become obsolete. Sometimes the technology itself continues working perfectly well, but we have become so dependent upon it that we only discover the risk when we can no longer use it.

Technology also creates opportunity, and that part should not be forgotten. We adopt technology because it can make something faster, easier, cheaper or possible in the first place. A small business today can access payment infrastructure, accounting systems, cloud storage, global communications and A.I. capabilities that would once have required considerably greater resources.

This takes us back to another idea from the main Pillars page: Risk Management is not the “police” telling people what they cannot do. Technology Risk Management should not automatically result in “Don't use the technology.” Sometimes the better conclusion is “Yes, use it—but understand what you are becoming dependent upon, put sensible safeguards in place and know what you will do if it does not work as expected.”

HOW DID TECHNOLOGY RISK COME ABOUT?

Technology Risk developed naturally as people and businesses became increasingly dependent upon technology to perform activities that mattered to them.

Think about a small business before so much of everyday work became digital. Customer records could be kept in physical files, appointments written in a diary, payments made in cash or by cheque and accounts maintained on paper. Technology existed, of course, but many activities could continue without an interconnected digital system sitting behind them.

Then computers became part of everyday business. Records became digital. Accounting moved onto software. Email became essential to communication. Websites became part of how customers found businesses. Internet banking changed how money moved, while electronic payment systems changed how customers paid.

The risks changed with these developments, but they appeared to ordinary people as very practical questions: What happens if my computer crashes? Have I backed up my files? What happens if I lose my laptop? What happens if the internet goes down? Can I recover my customer records?

These may sound like ordinary questions today, but they are Technology Risk questions.

The interesting part is that most individuals and small-business owners would never have described themselves as practising Technology Risk Management. Someone who copied important business records onto an external drive probably did not say, “I am implementing a technology-risk control.” She simply did not want to lose everything if the computer failed.

The professional terminology came later. The basic human instinct behind it—to understand what we depend upon and protect ourselves against losing it—was already there.

WHAT TECHNOLOGY RISK QUESTIONS DID PEOPLE USED TO ASK?

The Technology Risk questions asked by individuals and small businesses tended to follow the technology they were using at the time. When information moved from paper onto computers, the obvious concern became losing that information. When businesses became dependent upon email and the internet, connectivity and availability became more important. As electronic payments became common, businesses had to consider what they would do when payment technology was unavailable.

These questions produced practical responses. Backups reduced the consequences of losing information. Passwords and access controls helped prevent inappropriate access. Software updates and antivirus software helped protect computers. Spare equipment and alternative arrangements reduced dependence on one device or one method of working.

Consider the backup as a simple example of how a Risk Management tool evolves. Years ago, an individual might copy important files onto a floppy disk, CD, USB drive or external hard drive. Today those files may be backed up automatically to cloud storage.

The technology used for the backup changed enormously. The underlying Risk Management principle did not: do not allow one technology failure to destroy something you cannot afford to lose.

The same is true of alternative arrangements. A small shop whose electronic payment terminal stopped working might have accepted another method of payment. Someone whose computer failed might have used another device. A business whose online booking system became temporarily unavailable might have recorded appointments manually until the service returned.

Professional Risk Management may describe these ideas using terms such as redundancy, recovery arrangements, contingency planning or Business Continuity. An individual or small-business owner might simply describe the same idea as having another way of doing it if something goes wrong.

WHAT TECHNOLOGY RISK TOOLS CAN AN INDIVIDUAL OR SMALL BUSINESS USE?

A small business can begin managing Technology Risk by identifying the technologies it genuinely depends upon, understanding what would happen if they failed and deciding what safeguards or alternatives are proportionate to the consequences.

One of the simplest tools is a technology inventory. This does not need to be an enormous spreadsheet. List the technologies that actually matter to the business: the payment system, booking platform, accounting software, website, customer records, email, cloud storage, internet connection and any specialist systems needed to provide the service.

Then ask, “Which of these would really hurt my business if I could not use it tomorrow?” That is already a simple form of criticality assessment.

The next question is, “What does this technology itself depend upon?” A booking system may depend upon an internet connection and a SaaS provider. Business records may depend upon cloud storage. A website depends upon a hosting provider. An A.I. application may depend upon another company's foundation model. Asking these questions introduces dependency mapping.

Finally, ask what you would actually do if the technology stopped working. Can you recover the information? Can the work be done another way? Is there another provider? How long could you continue without the system? These questions introduce backup and recovery, alternative arrangements, scenario analysis and Business Continuity.

For those who want to go deeper, the established toolkit includes technology inventories, criticality assessments, dependency mapping, risk assessments, risk matrices, scenario analysis, control assessments, Key Risk Indicators (KRIs), testing, recovery planning and risk registers.

The professional names can make the toolkit sound more complicated than the underlying thought process actually is. At its simplest, we are asking: What do I depend upon? What could happen to it? What have I done about that? What happens if those safeguards are not enough?

HOW DO YOU ASSESS TECHNOLOGY RISK?

A Technology Risk Assessment examines what the technology is being used for, what could affect it, what the consequences could be, what safeguards or controls already exist and whether the remaining exposure is acceptable.

Suppose a small business is considering replacing its existing booking system with a new cloud-based platform. A useful assessment could begin by asking what the business expects to gain from the change, what customer information will be stored there, what happens if the platform is unavailable, whether existing information can be transferred safely, whether the information can later be recovered and how difficult it would be to move to another provider.

Notice that the assessment includes the benefit of using the technology, not merely everything that could go wrong with it. Perhaps the new system saves hours of administrative work every week, reduces missed appointments and allows customers to book outside normal business hours. Those benefits matter when deciding whether the remaining risk is acceptable.

This brings us back to the Risk Management thought process described on the main Pillars page. We are trying to understand what we want to achieve, what could affect it, what our exposure is and whether we are comfortable taking the next step. Technology Risk simply applies that thinking to our relationship with technology.

HOW HAS TECHNOLOGY RISK CHANGED?

Technology Risk has changed because our relationship with technology has changed. We do more with technology, depend upon it for more important activities, increasingly obtain it from somebody else and now allow some technologies to perform tasks that previously required human judgement or action.

One major change is dependency. Payments, communication, banking, appointments, customer records, navigation, shopping and everyday administration are now deeply digital. A technology outage can therefore affect activities that once had straightforward manual alternatives.

Another change is ownership. A small business might once have purchased software and installed it on a computer that it owned. Today it may subscribe to accounting software, cloud storage, payment platforms, customer-management systems and A.I. services that are operated by somebody else. Technology Risk increasingly involves something we depend upon without directly controlling.

The way we work has also changed. Remote and hybrid working expanded dramatically around the COVID-19 period. Home internet connections, cloud collaboration, video meetings, remote access and digital communication became essential to many people's ability to work. Some of those behaviours remained after the immediate disruption passed.

Demographics and working attitudes matter too. Younger generations entering the workforce have grown up with digital services as an ordinary part of life, while solopreneurs and very small businesses can now operate using a collection of online platforms rather than traditional corporate infrastructure. People increasingly expect technology to be available immediately, from anywhere and on different devices. The boundary between “the technology system” and “how we work” has therefore become less distinct.

A.I. introduces another significant change. Technology is moving beyond primarily storing information, processing instructions and connecting people. It can increasingly generate, recommend, decide and act.

These changes do not necessarily create an entirely new discipline every time they occur. They change the questions Technology Risk needs to answer.

HOW IS THE TECHNOLOGY RISK TOOLKIT CHANGING?

The Technology Risk toolkit is evolving from primarily protecting individual devices and systems towards understanding digital dependencies, cloud and external providers, interconnected services, changing work practices and increasingly autonomous technology.

We have not thrown the old toolbox away. Backups remain useful. Access controls remain useful. Software updates remain useful. Testing remains useful. Risk assessments remain useful. What has changed is what we need those tools to examine.

The familiar backup provides a simple example. The earlier question might have been “Have I backed up my computer?”Today a small-business owner may ask “If my cloud provider becomes unavailable, can I still access or recover my business information?” The principle of protecting important information remains, but cloud dependency changes how the principle is applied.

Similarly, the question has moved beyond “Which systems do I own?” towards “Which services does my business actually depend upon, including technology I don't own?” A traditional technology inventory can therefore be supplemented by service mapping and dependency mapping, which reveal connections between business activities, applications, data, cloud services and external providers.

The toolkit evolves because the dependency evolves.

HOW DID CLOUD SERVICES CHANGE TECHNOLOGY RISK?

Cloud and subscription services shifted part of Technology Risk from technology a business owns towards technology a business depends upon but does not directly control.

This has brought enormous benefits to small companies. A business can now access sophisticated accounting systems, customer-management platforms, cloud storage, payment services, collaboration software and A.I. without building any of these capabilities itself.

But an older question such as “Can I fix my computer if it fails?” becomes “What can I do if somebody else's technology that my business depends upon fails?”

This is where backups and recovery begin to sit alongside vendor assessment, data portability, alternative-provider planning, service monitoring and exit arrangements.

There may also be dependencies behind the provider we can see. A software company may depend upon a cloud provider. An A.I. application may depend upon a foundation model supplied by another company. Several services that appear completely separate may ultimately rely upon the same underlying technology.

Risk practitioners increasingly refer to these issues through concepts such as fourth-party dependency, concentration risk and substitutability. For a small business, the language can remain much simpler: If the company I depend upon depends upon somebody else, what happens to me if something goes wrong further down the chain?

This is where Technology Risk naturally connects with another established pillar, Third-Party Risk.

HOW DID COVID-19 AND CHANGING WORK BEHAVIOUR AFFECT TECHNOLOGY RISK?

COVID-19 accelerated Technology Risk changes by making remote access, cloud services, home connectivity and digital collaboration essential to many people's ability to work. It exposed how quickly a technology that had previously been regarded as convenient could become critical.

For many businesses, the question was no longer simply whether the technology inside the office was available. Employees needed to access systems, information and colleagues from somewhere else. Video conferencing, cloud collaboration, remote access, mobile devices and home internet connections became part of the operating environment.

Some temporary arrangements subsequently became permanent working practices. Hybrid work, distributed teams, online meetings and cloud-based collaboration are now ordinary for many people. This means Technology Risk tools also have to follow the work. Technology inventories may need to recognise cloud and remote services. Access controls have to consider different devices and locations. Business Continuity needs to consider whether digital services remain available to a distributed workforce.

COVID did not make the established Technology Risk principles irrelevant. It changed where those principles needed to be applied and revealed dependencies that had previously received less attention.

This is also a useful reminder of the point made on the main Pillars page about risks that can take the world by surprise. We cannot always predict the event. But established Risk Management tools—dependency analysis, scenario thinking, alternative arrangements, recovery planning and Business Continuity—can still help us understand and respond to the consequences.

WHAT ARE RISK PRACTITIONERS BEGINNING TO USE OR ADAPT NOW?

Risk practitioners are increasingly adding new layers to established Technology Risk tools rather than replacing the entire toolkit. The changes are largely a response to cloud dependency, interconnected technology, rapid software change, remote and hybrid work, external technology providers and now A.I. systems that may behave less predictably or operate with greater autonomy.

Traditional technology inventories, for example, can evolve into end-to-end service and dependency maps that show how a business activity depends upon applications, data, infrastructure and external providers. Periodic control reviews may be supplemented by continuous control monitoring, while traditional software-development and change controls increasingly operate alongside automated testing, DevSecOps and cloud configuration monitoring.

Third-party technology assessment is also becoming more sophisticated. Knowing the name of the immediate vendor may no longer be enough where that vendor depends upon another technology provider. This is encouraging greater use of fourth-party mapping, technology concentration analysis and assessment of substitutability.

Scenario analysis becomes particularly useful where historical information is weak. Instead of relying only on the question “How likely is this?”, practitioners can ask “How might this develop, what could happen if it does, and are we prepared?”

A.I. is pushing this evolution further.

CAN TRADITIONAL TECHNOLOGY RISK TOOLS STILL BE USED FOR A.I.?

Many traditional Technology Risk tools remain useful for A.I., but A.I. introduces characteristics that may require those tools to be adapted or supplemented.

Take the established risk assessment. We might traditionally ask what a system is intended to do, what could go wrong, what the consequences could be and what controls exist. Those questions remain useful for A.I., but additional questions appear. What information is the A.I. allowed to access? What is it being used to do? How reliable does its output need to be for that particular use? Does somebody check the answer? What happens if it confidently produces incorrect information? Can the underlying model change even though the business itself has changed nothing? How dependent are people becoming upon its output?

The Technology Risk Assessment has not disappeared. It can be adapted to the characteristics of A.I., with additional approaches such as A.I. system and use-case inventories, risk classification, output evaluation, red teaming, adversarial testing, human-oversight testing and continuous monitoring where appropriate.

This illustrates the relationship between the established Pillars and the newer sections of this website. A new technology does not automatically make an established Risk Management tool obsolete. The more useful question is whether the tool still helps us understand the risk and, if it does not capture enough, what we should add to it.

CAN A RISK MATRIX STILL BE USED FOR NEW TECHNOLOGY?

A risk matrix can still help organise Technology Risk judgements, but emerging technologies expose its limitations when likelihood and consequences are highly uncertain.

For a mature technology, years of incidents and experience may help us judge what could happen and how frequently. For a new A.I. application or agent, the historical information may be much thinner.

We can assign a likelihood of 3 and an impact of 4 and obtain a score of 12. But the calculation does not answer an important question: where did the 3 come from?

Giving uncertainty a number does not necessarily mean we understand it better.

This is why conventional risk ratings can be supplemented with scenario analysis, simulations, stress testing, red teaming, adversarial testing, ranges and ongoing monitoring. Rather than pretending we know precisely how likely an unfamiliar event is, we can explore plausible situations, examine their consequences and decide whether we are sufficiently prepared.

This takes the reader beyond Technology Risk and into The Science of Risk, where we can examine probability, uncertainty, assumptions, complexity and false precision more deeply.

WHAT CHANGES WHEN A.I. CAN ACT, NOT JUST ANSWER?

Agentic A.I. changes Technology Risk because an A.I. system may be given permission to take actions rather than merely provide information for a human to consider.

There is a significant difference between asking A.I. to draft an email for a person to review and allowing an A.I. agent to decide who should receive the email and send it without prior human approval. Similarly, an A.I. system might recommend an appointment time, while an A.I. agent could potentially access the booking system and change the appointment itself.

The Technology Risk questions consequently change. What is the agent permitted to do? Which information and systems can it access? Which actions require human approval? How are its activities recorded and monitored? Can an action be reversed? How can the agent be stopped if it behaves unexpectedly?

Interestingly, several established controls remain recognisable: access controls, permissions, approval limits, segregation of duties, monitoring and incident management. But the way they are applied may need to evolve through agent-permission testing, action boundaries, human-in-the-loop controls, activity logging, fallback arrangements and mechanisms for overriding or stopping automated actions.

This is a good example of an apparently new risk bringing us back to an established pillar. The technology may be new. The questions of authority, access, monitoring and control are not.

The deeper treatment of these questions belongs under A.I. & Risk, particularly where we discuss Agentic A.I. and Human Oversight.

WHAT HAPPENS WHEN PEOPLE BECOME TOO DEPENDENT ON TECHNOLOGY?

Technology dependency is no longer only about whether a system remains available. Increasingly, we also need to ask what happens to human capability when technology performs more and more of the work.

Imagine employees using an A.I. assistant every day to analyse information, prepare documents, solve problems and make recommendations. They may become significantly more productive. But over time another dependency can develop: can they still perform the underlying work if the A.I. is unavailable?

The system may have excellent resilience. The data may be safely backed up. The provider may have good continuity arrangements. Yet the vulnerability may now sit with human capability without the technology.

This means the toolkit may eventually need to consider knowledge continuity, cross-training, manual fallback capability, human-oversight testing and deliberate retention of critical skills alongside conventional technical recovery.

At this point Technology Risk begins connecting with Future of Work and The Future Human. The question has moved from whether the machine can continue working to whether the human can continue working without the machine.

CAN A.I. ALSO BE USED TO MANAGE TECHNOLOGY RISK?

A.I. can itself become a Technology Risk Management tool by helping people analyse large quantities of information, identify patterns, summarise incidents and controls, generate scenarios for consideration and support monitoring or horizon scanning.

This creates an interesting situation: A.I. can be both the technology risk being assessed and a tool used to help assess technology risk.

A small-business owner could ask A.I. to help identify possible failure scenarios before adopting a new technology. A risk practitioner could use it to review incident information, compare controls or explore potential dependencies. Over time, more sophisticated systems may assist with monitoring larger quantities of risk and control information.

But faster analysis is not automatically more reliable analysis. An A.I.-generated assessment can still contain incorrect assumptions, hallucinated information or conclusions based upon poor evidence. A.I. can help us search, organise, compare and explore information, but judgement and verification remain important where the consequences matter.

The tool is evolving. Responsibility for deciding what to do with its output has not disappeared.

WHAT TECHNOLOGY RISK QUESTIONS ARE PEOPLE ASKING NOW?

People increasingly encounter Technology Risk without searching for the words “Technology Risk Management.” This is exactly the point we made on the main Pillars page: the newer questions people ask often lead us back to established Risk Management foundations.

A business owner may ask, “Should I allow my employees to use A.I. with company information?” Part of the answer is Technology Risk, but the question also leads into A.I. & Risk, Cyber Risk, Governance and Third-Party Risk.

Someone else may ask, “Should I allow an A.I. agent to send emails, make bookings or update my systems automatically?” That sounds like a very new Agentic A.I. question, but underneath it sit familiar Technology Risk concepts such as access, permissions, approval, testing, monitoring, incident management and recovery.

A small-business owner may ask, “What happens to my business if my cloud software goes down?” That begins as Technology Risk and quickly connects with Operational Resilience, Business Continuity and Third-Party Risk.

Another person may ask, “What happens if my staff become so dependent on A.I. that they cannot do the work without it?” Technology dependency has now become a Future of Work and potentially Future Human question.

Someone watching rapid technological change might ask, “How do I know which new technology I should be preparing for?” That takes us into Signals → Technology Trends.

The language has changed because the world has changed. The established Risk Management questions have not disappeared. They have acquired new forms.

WHICH NEWER RISKS MAKE THE EVOLUTION OF TECHNOLOGY RISK USEFUL?

The evolving Technology Risk toolkit is particularly relevant to A.I. & Risk, Future of Work, The Future Human and Signals, while also continuing to connect strongly with the established Pillars of Cyber Risk, Operational Resilience, Business Continuity and Third-Party Risk.

A.I. requires us to adapt assessment, testing and monitoring because technology can increasingly generate outputs that are not predetermined in quite the same way as conventional software instructions. Agentic A.I. adds questions of authority and action, making access controls, permissions, approvals, monitoring and human oversight more important.

Future of Work introduces another dimension because automation changes not only technology but jobs, skills, knowledge and organisational dependencies. The Future Human takes the question further by considering what increasing reliance upon intelligent technology might eventually mean for human judgement and capability.

Signals takes us to an earlier stage. Instead of waiting until a new technology has already become an established risk, horizon scanning can help us notice what is changing. Not every emerging technology needs an immediate formal risk assessment, and certainly not every technology headline belongs in a risk register. Sometimes the appropriate tool is simply horizon scanning, a watch list, experimentation or scenario analysis until we know enough to decide whether a formal Technology Risk Assessment is necessary.

This gives us a useful progression: notice what is changing, understand why it may matter, explore what could happen, assess the exposure when appropriate, and decide whether to adopt it, control it, monitor it, wait or walk away.

This is another way the Technology Risk toolkit evolves. Sometimes the new tool is useful because it helps us see the risk before the traditional assessment even begins.

TECHNOLOGY CHANGES. TECHNOLOGY RISK EVOLVES WITH IT.

Technology Risk is one of the established Pillars of Risk Management. It did not evolve from the Pillars, nor is it being replaced by the newer risks on this website. It remains one of the foundations through which many of those newer questions can be understood.

The earliest everyday Technology Risk questions were often quite simple: Have I backed up my files? What happens if my computer crashes? Can I keep working if my system is unavailable?

Those questions have not disappeared. We still back up information, manage access, test systems, plan for failures and think about recovery. Around those established tools, however, we are now adding dependency mapping, cloud and third-party assessments, technology concentration analysis, continuous monitoring, A.I. risk assessments, red teaming, human-oversight testing and controls for increasingly autonomous technology.

Perhaps the most interesting change is that people asking today's questions may not realise that they are asking Technology Risk questions at all. They ask whether they should trust an A.I. output, whether an A.I. agent should be allowed to act by itself, what happens if a cloud provider fails, whether employees can still work without A.I. or which emerging technologies they should be watching.

These sound like completely different questions from “What happens if my computer crashes?”

In many ways, they are. But underneath them sits a familiar Risk Management thought:

What am I becoming dependent upon, what could happen if it does not work the way I expect, and what should I do about it?

That is the continuity between the established pillar and the newer risks. Technology changes. The tools adapt. The questions become more complex. But the fundamental need to understand our dependency on technology remains.

That is why Technology Risk remains one of the Pillars of Risk Management.