Companies Aren't Proactive With IT Risk Assessments, Report Finds | eWeek

IT Risk Assessments Suffer From Lack of Automation, Planning: KPMG

1088_RiskSufferAutomation
Feb 16, 2018
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More


IT Risk Assessments Suffer From Lack of Automation, Planning: KPMG

IT Risk Assessments Suffer From Lack of Automation, Planning: KPMG

The vast majority of organizations are taking a “reactive and siloed” approach to IT risk assessments, according to a recent survey from KPMG. The accompanying report, titled “Disruption is the New Norm,” reveals that most companies only consult with risk assessment teams about projects after IT issues have already emerged. Few are constantly deploying data analytics to develop key risk indicators. Nor are they investing in automated tools to collect risk-related data. More than 200 senior executives responsible for IT risk management took part in the research, which was conducted by Forbes Research. This slide show presents highlights from the report—which contains additional survey research from KPMG—with charts provided courtesy of KPMG.


New Tech Brings Concerns

New Tech Brings Concerns

Among survey respondents, 46 percent said the deployment of new technologies within their organization would spur an expansion of their tech risk management efforts. One-half said emerging tech within their industries may also drive such an expansion.


Passive Response Remains Commonplace

Passive Response Remains Commonplace

Tech risk management is perceived as “reactive and siloed” among 87 percent of companies. More than seven of 10, in fact, said tech risk teams are brought into projects “after the fact,” only after issues begin to arise.


Assessments Lacking for Mobile, IoT Adoption

Assessments Lacking for Mobile, IoT Adoption

KPMG reports that 47 percent of organizations are adopting mobile apps and devices without assessing associated risks. When it comes to the internet of things (IoT), 46 percent are adopting this technology without assessing the risks.


Advertisement

Compliance Role Dominates

Compliance Role Dominates

Nearly two-thirds of organizations view tech risk assessment as “an arm of compliance.” Just over one-third perceive of it as an “arm of cybersecurity.”


Risk Mitigation Investments to Increase

Risk Mitigation Investments to Increase

Nearly nine of 10 survey respondents believe that the assessment of tech risk drives value for their organization. Almost one-half predict that tech risk spending will increase over the next three years.


KRI Delivery Brings Mixed Results

KRI Delivery Brings Mixed Results

Ninety-two percent of organizations use key risk indicators (KRIs) to measure the likelihood that individual events will bring harm, according to the report. But 87 percent of companies only “sometimes but not consistently” leverage data analytics to develop key risk indicators.


Excel Remains Tool of Choice

Excel Remains Tool of Choice

Two-thirds of organizations are still using common tools—like Excel—to develop KRIs. Nearly one of five develop their own tools in-house.


Automation Tools in Short Supply

Automation Tools in Short Supply

One-half of companies collect data for risk reports via informal, ad hoc processes, such as having conversations with team members and collecting anecdotes. Only 18 percent are using automated processes to ensure IT risk data is collected regularly through system-based sources.


Organizations Are Underprepared for Threats

Organizations Are Underprepared for Threats

Just 40 percent of companies are “well prepared” for a cyber-event. Among incidents, more than 30 percent are linked to software glitches.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.