IT risk management is the discipline of identifying, assessing, and managing the risks associated with an organisation's information technology. It covers systems, infrastructure, data, applications, and the processes through which technology is governed, changed, and maintained. It is broader than cybersecurity, more specific than enterprise risk management, and more operationally critical than most governance frameworks have historically treated it.
The scope of IT risk matters to define precisely because the common combination with cybersecurity causes organisations to manage only part of the actual technology risk they carry. A major system migration that disrupts operations for several days, a data quality problem that produces inaccurate management information, a legacy system that becomes progressively more difficult to support: these are material IT risks with no malicious actor involved. Managing them requires the same disciplined identification, assessment, and treatment as managing cyber threats, but through different lenses and different controls.
IT risk encompasses five broad categories that together constitute the full technology risk landscape most organisations face.
Availability risk covers the risk that systems and services are unavailable when needed. This includes both planned and unplanned outages, degraded performance, and the increasingly common pattern of partial availability where systems operate but with significantly reduced capability. As technology underpins virtually every business process in most modern organisations, availability risk has grown from a technical concern to a strategic one.
Integrity risk covers the risk that data and systems contain errors, have been corrupted, or have been altered without authorisation. Data integrity failures can produce incorrect management information, regulatory reporting errors, and flawed outputs from automated processes, with consequences that may not be immediately visible but that compound over time.
Confidentiality risk covers the risk of unauthorised access to or disclosure of sensitive information. This is the dimension most closely associated with cybersecurity, but confidentiality failures also occur through inadequate access controls, poor data classification, and insecure data handling practices that have nothing to do with external threats.
Change risk covers the risk introduced by changes to systems, applications, and infrastructure. Technology change is one of the most consistent sources of operational incidents. Inadequately tested changes, changes that interact unexpectedly with other systems, and changes that create new vulnerabilities or degrade existing controls all generate risk that is within the organisation's control to manage.
Third-party and cloud risk covers the risks arising from dependence on external technology providers, cloud infrastructure, and managed service providers. This category has grown significantly as organisations have moved more of their technology estate to external providers, creating dependencies that may not be fully understood or adequately governed.
The NIST Cybersecurity Framework, most recently updated as CSF 2.0 in 2024, organises technology risk management around six core functions: govern, identify, protect, detect, respond, and recover. The 2024 update added the govern function explicitly, reflecting the recognition that governance, accountability, and strategy must sit above and connect all other cybersecurity activities.
NIST CSF is widely adopted beyond its original US critical infrastructure context because it is outcome-focused and flexible. It describes what good technology risk management achieves without prescribing specifically how every organisation must achieve it, making it adaptable across sectors and sizes.
ISO 27001 is the international standard for information security management systems. Unlike NIST CSF, it is certifiable: organisations can be independently assessed against the standard and awarded certification. ISO 27001 certification has become a common requirement for technology suppliers and service providers, making it commercially significant as well as operationally important.
ISO 27001 takes a management system approach, requiring the organisation to establish a systematic process for identifying information security risks, implementing controls, and continuously improving security performance. Annex A provides a reference set of controls covering access management, cryptography, physical security, operations, communications, supplier relationships, incident management, and compliance.
Most mature organisations use elements of both frameworks rather than choosing one exclusively. ISO 31000, the international risk management standard, provides the overarching risk management philosophy within which both frameworks sit. NIST CSF and ISO 27001 address the technology-specific disciplines within that broader framework. ISO 31000's principle that risk management should be integrated into governance and decision-making applies directly to how technology risk connects to enterprise risk management.
Effective IT risk management starts with knowing what is being protected. A comprehensive, current inventory of information assets, covering systems, applications, databases, network infrastructure, and the data held within them, is the prerequisite for meaningful risk assessment. The classification of each asset by criticality and sensitivity determines which risks associated with it are most significant and which controls are warranted.
Asset inventories degrade quickly in most organisations without active maintenance. New systems are deployed, cloud services are adopted, and legacy assets remain in use well beyond their planned retirement dates. A discovery process that supplements manual records with automated scanning of the technology environment is considerably more reliable than documentation alone.
For each significant asset, IT risk management asks what could threaten its availability, integrity, or confidentiality, and what vulnerabilities exist that could be exploited. The NIST IR 8286 guidance on integrating cyber security risk into enterprise risk management provides a practical framework for this identification and assessment process, distinguishing between threats, the potential events that could cause harm, and vulnerabilities, the specific weaknesses that would allow threats to materialise.
Likelihood and impact assessment for IT risks should draw on threat intelligence specific to the organisation's sector, the organisation's own incident history, vulnerability scan data, and industry benchmarking. Generic likelihood assumptions that do not reflect the actual threat environment are a common source of inaccuracy in IT risk registers.
Controls in IT risk management operate across the same preventive, detective, and corrective categories as other risk disciplines, but with specific application to the technology environment. Access management controls limit who can interact with systems and data. Change management controls govern how systems are modified. Monitoring and detection controls identify anomalous activity and potential incidents. And IT general controls govern the reliability of the technology environment within which application controls operate.
The testing of IT controls, particularly IT general controls, is addressed in detail in frameworks including the PCAOB's Auditing Standard AS 2201 for financial reporting contexts and in the broader internal audit literature. The principle is consistent: controls documented in a policy but untested against evidence of actual operation do not provide meaningful assurance.
Technology risk has historically been managed within the IT function with limited board visibility. That model is becoming inadequate across most regulated sectors. The FCA's systems and controls sourcebook expects boards of regulated firms to have sufficient oversight of technology risk. DORA explicitly places board-level accountability for ICT risk management in its regulatory requirements. And the NIS2 Directive introduces personal management liability for cybersecurity failures.
For boards, this means receiving risk reporting that translates technical risk into governance terms, having adequate collective knowledge to engage with technology risk meaningfully, and holding management accountable for the quality of the IT risk programme rather than deferring entirely to technical expertise.
Significant technology risks should not be managed in isolation within the IT function. They are organisational risks with financial, operational, regulatory, and reputational consequences that belong in the enterprise risk register alongside other material risks.
The connection requires translation. A vulnerability assessment finding that identifies unpatched critical systems is a technical finding. Its governance significance is the operational disruption or data exposure that could result if the vulnerability were exploited, and the regulatory consequence if that disruption or exposure affected regulated activities or personal data. The IT risk function and the enterprise risk function need to work together to ensure this translation happens systematically rather than ad hoc.