Balancing Information Risk With Commercial Opportunity

IRM balance

Embarking on an Information Risk Management (IRM) strategy can be daunting. As you discover more about the potential threats — both inside and outside the organisation — you can easily feel overwhelmed.

At the same time, this knowledge often triggers a new fear — that the steps you need to take for your own protection could stifle your business and actually damage your prospects. One thing’s for sure — over-the-top levels of protection can impact on the efficiency of your business processes and cost you money.

But smart IRM is all about balance. It’s not about putting your head in the sand. But it’s not about strangling your business with draconian controls and cumbersome processes either. It is about making the right business decisions based on a real understanding of the risks.

That’s why it’s vital that IRM is driven by the business not the other way around! You can take a pragmatic approach — one that reduces risk without damaging the business.

“Only 10% (of risks) are likely to require the highest protection.”

Jay Heiser, Gartner vice president

And yet many businesses and organisations are still unsure how to implement an effective IRM strategy.

“Basic information risk management can stop up to 80% of the cyber attacks seen today, but experience suggests that few organisations get it right.”

IOD paper: Countering the Cyber Threat to Business, Spring 2013

The immediate dangers of not acting

Not implementing effective IRM is not just about leaving your business open to risk. It can actually hamper the way you do business. Because there are potential risks with some new technologies — such as cloud computing or BYOD, for instance — businesses often don’t embrace them for fear of the unknown risks! That results in missed opportunities whilst the competition takes full advantage. Not taking action can actually make you less commercially effective.

The benefits of smart IRM

There is a smarter way.

IRM is about facing the risks head on and making a strategic decision that balances protection with commercial need:

  1. Flexibility . IRM gives you the facts about risk as they affect your business and allows you to take your own path — one that is tailored and works for your business.
  2. Better decision-making . IRM helps you to identify your most important assets and the threats you face. It allows you to assess the impact on your business and to decide if you can live with the resultant risk. If you can’t, then you can take action to get the balance right.
  3. Putting the risk in context. Information risk is a living agenda item, not a “once and done” task. The context changes as your business grows and risks change too. If you put the risk into context you’ll get the level of security that’s right for your business at that time: not too much, not too little. It’s a lean, efficient approach.
  4. It’s more than a tick box exercise . Achieving an information security standard can be a very positive step but if it’s only a tick box exercise it is unlikely to offer any effective improvements in security posture and maturity. Standards can also give you a false sense of security — they are often a one-size-fits-all solution. IRM makes sure you are tackling the real issues on a continual basis.

Not all risks are the same

Removing 100% of information risk is impossible — not least because your weakest link can be your people. And the measures required wouldn’t do your business any favours either. The beauty of smart IRM, is that you can choose how to handle each risk:

Treated — action is taken to reduce the risk to a more acceptable level
Transferred — the risk is offset, for example by buying insurance
Terminated — the cause of the risk is removed completely
Tolerated — the risk is acceptable without any further treatment

The action you take depends entirely on your business objectives.

IRM enables you to focus and target investment. The fact is that, done well, smart IRM can actually bring new efficiencies that can save you money.

“All information security budget spend should be driven by quantified risk mitigation. Not by vendors, not by the press and not by technical staff. Follow these principles and you will not only reduce the impact of real world threats on the business, but may also reduce how much you spend on it.”

Mark Heathcote of IT firm Xceed.

It’s up to you and your board to lead the way — don’t let those with a different agenda devise your strategy. What are you waiting for?

Secure your information and strengthen your business

We have lots more valuable advice on Information Risk Management to help you balance risk with commercial opportunity.

We’re here to help when you need it.

Got questions on IRM? I’d love to help. Call me, Dave James on 01452 881712 or email me at [email protected] .

Other articles you might like:

You may also be interested in:

Building business resilience

Building business resilience - through Information Security, Business Continuity and Disaster Recovery

How strong is your business resilience to threats to IT, information and physical security? And how can security standards like ISO 27001 and ISO 22301 help?

Ascentor's cyber security review 2020

Ascentor’s cyber security review of 2020

It was the year a different kind of virus dominated. But that didn’t stop cyber criminals exploiting it. We look back at 2020.

Cyber security myths of SMEs

Cyber security myths putting SMEs at risk

SMEs have long been a favourite hunting ground for cyber criminals and, in the worst case scenario, may not survive. We look at some of the myths that put SMEs at risk of cyber crime.