How to Begin IT Risk Management: Five Steps to Getting What You Want

What does it take to get attention for IT initiatives in today's enterprise? In most cases, according to Symantec Senior Director Jennie Grimes, it means making a compelling business case-and getting the right information to the right people in the right language.

IT risk management initiatives are definitely worthy of executive attention. Our economy is increasingly dependent on the Internet and IT systems, making the risks in these systems far more visible and significant than ever. But, it's a discipline with a myriad of stakeholders: CIOs, CISOs, enterprise risk management teams, compliance and regulation staff, and internal and external auditors.

Step #1: Choose your words wisely
There are two types of CIOs-infrastructure managers and strategic thinkers. The latter will succeed with their IT risk management agenda because they speak in terms of business advantages, not outages.

For example, rather than talking about a "zero day threat," consider simulating the impact of a potential incident in terms of potential business loss. Instead of talking about RTOs and RPOs, speak in terms of lost revenue and customers during an outage. Instead of highlighting unimplemented ISO controls, speak about the lost effectiveness of employees who need to share information both inside and outside the firewall. It also doesn't hurt to point out the impact on productivity when employees can't effectively share information effectively.

Step #2: Use a High-Medium-Low spectrum of potential business loss
Part of using the right language is moving away from absolutes. Inevitably, a single prediction of loss will start a battle of statistics and probability debate and your request will get lost in the process. Instead, provide stakeholders with a variety of scenarios and have data to back it up. Consider whether you are a low risk company, moderately tolerant, or highly tolerant and then go to work with some calculations. Come prepared to back up your recommendations with numbers. Understand that you probably won't get exactly what you are asking for, but by presenting accurate potential scenarios, you might get your mid-range goal.

Step #3: Use headlines to your benefit
Many of today's business leaders dread the thought of the "orange jumpsuit retirement program." There's a steady stream of privacy and data leakage issues that will continue to make the headlines. Those held responsible have ranged from unsuspecting backup administrators to employees who unwittingly left laptops in car trunks to mid-level managers involved in publishing quarterly financial reports to executives operating with full knowledge of potential breaches. Make use of these "public hangings" to illustrate the real risks and move away from the incident probability statistic deadlock.

Step #4: Move your message up the chain (and sideways, too)
Consider all your potential champions and work to win them over. IT risk management isn't an exclusively IT-driven discipline. Work with the compliance team, the IT group, the legal group, the auditors, the enterprise risk management group, and the business leaders. Create cross-company initiatives to align each of these groups. This requires as much time communicating outside of IT as inside IT.

Step #5: Identify your milestones
Before going in with your request, identify three milestones you expect to meet and explain in business terms how these milestones will provide returns to both the business and to IT.

For example, starting with a proof of concept for a content filtering project will have much more value if users from audit, legal and a line of business are involved in choosing terms to flag, track and quarantine. A security incident reporting process may get more enthusiastic response if users understand that increasing their awareness helps save corporate dollars and image.


IT risk management will become increasingly important as key organizational stakeholders begin to see the importance of an ongoing program. In the mean time, IT risk professionals can colleagues and establish a baseline program by using the right language and the right information to garner support internally.

Jennie Grimes is a senior director for Symantec's IT Risk Management Program office.