Why digital risk officers are more than just flavour of the month

The Boardroom

by Duncan MacRae| 10 July 2014

CEOs increasingly want digital leaders by their sides, according to Gartner.

More than half of CEOs will have a senior 'digital' leader role in their staff by the end of 2015.

This is according to the 2014 CEO and Senior Executive Survey by analyst firm Gartner, which stated that by 2017 one-third of large organisations engaging in digital business models and activities will also have a digital risk officer (DRO) role or equivalent.

By 2020, 60% of digital businesses will suffer major service failures due to the inability of the IT security team to manage digital risk in new technology and use cases. IT, operational technology (OT), the Internet of Things (IoT) and physical security technologies will have interdependencies that require a risk-based approach to governance and management. Digital risk management is the next evolution in enterprise risk and security for digital businesses that are expanding the scope of technologies requiring protection, Gartner asserted.

Paul Proctor, VP Gartner, said: "Digital risk officers will require a mix of business acumen and understanding with sufficient technical knowledge to assess and make recommendations for appropriately addressing digital business risk.

"Many traditional security officers will change their titles to digital risk and security officers, but without material change in their scope, mandate, and skills they will not fulfil this role in its entirety."

The Gartner research suggests the mandate and scope of a DRO is very different than a chief information security officer (CISO) and in many organisations the CISO role will continue with similar scope as in 2014. The DRO will report to a senior executive role outside of IT such as the chief risk officer, chief digital officer or the chief operating officer. They will manage risk at an executive level across digital business units working directly with peers in legal, privacy, compliance, digital marketing, digital sales and digital operations.

The IT security role remains relevant and vital, according to Gartner. However, many CISOs will evolve into DROs as they begin to own or form effective partnerships with digital security teams managing other forms of technology. IT security leaders may continue with their assigned responsibilities that report to the DRO. As physical security management becomes increasingly digital, this will include the physical security teams as well.

The impact of this new structure of digital risk governance and management on IT and IT security operations is expected to be minimal, particularly in those organisations that have already appointed a chief risk officer. However, the potential impact on the culture of IT and IT security teams is major.

IT, OT, IoT and physical security form a new superset of technology that challenges the ability of existing organisational structures, skill sets and tools to consistently and adequately assess, define and manage technology risks. Simply expanding the portfolio of the existing IT security team to include technology risk for all internet-aware technology is not viable. New and existing technology managed outside of the IT organisation requires skills and tools beyond the competence of the IT security team in its current responsibilities, and the teams currently involved in management of these technologies are culturally distinct from the IT organisation.

Gartner added that a consistent, unified approach to digital risk at the organisational level has the potential to deliver cost efficiencies and greater risk assurance for business processes than the fragmented approach currently in place at most organisations. Development of a digital risk management capability requires deconstruction and re-engineering of current organisational structures and allocations of responsibility as well as the development of new capabilities in security and risk assessment, monitoring, analysis and control.

Proctor explained: "By 2019, the new digital risk concept will become the default approach for technology risk management. Digital risk officers will influence governance, oversight and decision making related to digital business.

"This role will explicitly work with non-IT executives in various capacities to better understand digital business risk and facilitate a balance between the need to protect the organisation and the need to run the business. However, the cultural gap between IT and non-IT decision makers presents a significant challenge.

"Many executives believe technology - and therefore technology-related risk - is a technical problem, handled by technical people, buried in IT. If this gap is not bridged effectively, technology and consequent business risk will hit inappropriate levels and there will be no visibility or governance process to check this risk."

 

Comments
Post a comment

Comments may be moderated for spam, obscenities or defamation.
Privcy Policy

We have updated our privacy policy. In the latest update it explains what cookies are and how we use them on our site. To learn more about cookies and their benefits, please view our privacy policy. Please be aware that parts of this site will not function correctly if you disable cookies. By continuing to use this site, you consent to our use of cookies in accordance with our privacy policy unless you have disabled them.