Definition

IT risk management is the continuous process through which an organisation identifies, assesses, treats and monitors risks to its information systems and data, including cyberattacks, failures, errors, physical disasters and supplier dependencies. Its purpose is to reduce each risk to a level that is acceptable in light of business priorities.

The four-stage process

  1. Identify critical assets and the threats against them.
  2. Assess each risk by likelihood and impact.
  3. Treat it by reducing, transferring, accepting or avoiding the risk.
  4. Monitor and review continuously because the threat landscape changes quickly.

The shift towards resilience

Prevention and detection remain necessary, but complete risk management also plans for production being compromised. It therefore includes resilience, the ability to restore systems from disconnected backups and tamper-protected restore points. Behavioural analysis flags abnormal writes. Separately, after each transfer, the software air gap disconnects the backup and the append-only write path blocks changes or deletion of validated points.