summary
Vallabh Sambamurthy & Robert W. Zmud
Guiding the Digital Transformation of Organizations - Second Edition
© 2017 Legerity Digital Press
All rights reserved. �is book or any portion thereof may not be reproduced or used in any manner whatsoever without the express written permission of the publisher, except for the use of brief quotations in a book review.
Legerity Digital Press LLC For more information, please visit: www.ldpress.com, email [email protected] or call toll free 855-855-9868.
ISBN 978-0-9857955-9-7
Grappling with the Risks of Digitalization
Chapter
08
Guiding the Digital Transformation of Organizations By Vallabh Sambamurthy and Robert W. Zmud
Second Edition Copyright © 2017
First Edition Copyright © 2012
All rights reserved. No part of this publication shall be reproduced, distributed, or
transmitted in any form or by any means, electronic or mechanical, including photocopying,
recording, or by any information retrieval system without the prior written permission of the
publisher, except in the case of brief quotations embodied in critical reviews and certain
other noncommercial uses permitted by copyright law. For permission requests, email the
publisher at: [email protected].
Published by Legerity Digital Press, LLC
A catalog record for this book is available from the U.S. Library of Congress.
ISBN 978-0-9857955-9-7
Although every precaution has been taken in the preparation of this book, the
publisher and author assume no responsibility for errors or omissions. Neither is any
liability assumed for damages resulting from the use of this information contained herein.
Ordering information:
For all ordering inquiries, please visit www.ldpress.com, email [email protected] or
call toll free at 855-855-9868. Special discounts are available on bulk purchases by
academic institutions, associations, corporations, and others.
Printed in the United States of America.
Cover Illustration by Aaron Z. Williams
177
Chapter 8. Grappling with the Risks of Digitalization
The enabling nature of digital disruption might best be captured by three ideas:
pervasive digitization, pervasive connectivity and pervasive mobility. Invariably,
pipeline ecosystem participants and network ecosystem participants find themselves
constantly accessing and exchanging digitized content (e.g., data, information,
goods, services and currencies) and it is precisely these type of activities that are
creating an abundance of competitive opportunities for digital strategists able to act
smartly and nimbly.
However, the technological underpinnings of organizations’ digital strategies
also pose significant strategic risks. If digitalization risks are not appropriately
addressed by organizations’ leadership teams, the competitive wins that are realized
are likely to be short-lived, at best. Consider what happened in January 2003 when
a small (376 bytes) data virus infected a single processing device with the Slammer
worm.44 After launching itself onto the Internet, it infected close to 100,000 large
computer systems worldwide in just 30 minutes. The impact was chilling: air and rail
transport were delayed, electrical and pipeline utilities were interrupted, ATMs were
disabled, call centers were shut down, etc. In today’s highly digitized, connected and
mobile world, a single person’s lapse can quickly spread across the platforms to which
the person is directly or indirectly connected.
Nothing demonstrates the challenges presented to digital strategists better
than the paradox surrounding the capture and use of personal data. Data privacy
44 T. Goles, G. White and G. Dietriech, “Dark Screen: An Exercise in Cyber Security,”
MIS Quarterly Executive, June 2005, pp. 303-318.
178
concerns exist wherever personally-identifiable or other sensitive information is
captured, collected, stored and used. That said, tomorrow’s waves of digitalization
innovation and growth will surely involve intelligent analytics, highly-customized
goods and services, and always-available mobile connectivity offering one-touch
transactions, where these transactions require the collection and use of vast
quantities of personal data: socio-demographic data, location data, transaction
histories, etc. People can be motivated – through the expectation that the value of
the goods and services obtained will outweigh potential liabilities – to allow the
capture and collection of these data, but only if trust is established and maintained
that any collected personal data will be protected and will not be used in the absence
of permission to do so.
A key factor differentiating those organizations able to successfully exploit
digitalization for competitive purposes is a set of strong capabilities for managing
digitalization risk. Supporting evidence for the value of managing digitalization risk
is illustrated by a study that found voluntary disclosures of initiatives aimed at
reducing digitalization risks improved organizations’ stock prices by, on average,
6%.45 Effective digitalization risk management, however, involves much more than
enhancing an organization’s cybersecurity. The real challenge is to achieve an
effective balance in stability (as evidenced by efficient, secure, reliable and available
platforms) and agility (as evidenced by a readiness to formulate and implement
timely and innovative competitive moves).
45 L. Gordon, M. Loeb and T. Sohail, “Market Value of Voluntary Disclosures Concerning
Information Security,” MIS Quarterly, September 2010, pp. 567-594.
179
Managing digitalization risks in a manner that balances stability and agility is
a participation sport that demands the involvement of all of an organization’s
members. With the aim of providing a mindset and a foundation conducive for
effectively managing digitalization risk, this chapter covers the following topics:
Nature of Digitalization Risks
Risk Management: A General Overview
Digitalization Risk Management Practices
The Board of Directors and Digitalization Risk Management
Accounting for Digitalization Risks in Digital Strategy Formulation
Nature of Digitalization Risks
A digitalization risk refers to the likely occurrence of digitalization-related
incidents that have the potential to negatively impact an organization’s operational
performance and/or competitive position. What are these negative impacts? A useful
way of thinking about these negative effects is the following loss categories:
Financial loss: theft; fraud; extortion; destruction of uninsured facilities,
equipment and materials; drops in stock valuations; regulatory fines; legal fees, court awards and out-of-court settlements; etc.
Revenue loss: short-falls in revenue streams or lost revenue streams traced to operational disruptions, reputation loss, the inability to respond effectively to competitors’ actions, etc.
Intellectual property loss: thefts of digitized ideas, innovations and other forms of creative expression (e.g., trade secrets, blueprints, digitalized
processes, proprietary digital content, digital strategies, business models, etc.).
Reputation loss: depreciation of an organization’s image or of its brands
that undermines the trust and goodwill held by participants in the various market-focused ecosystems with which the organization participates.
180
These negative impacts can be huge. Consider, for example, the losses suffered by
the TJX Companies after a security breach46 (reported in late 2006) that enabled
hackers to obtain data from over 45 million customer payment cards.47 Access into
the TJX Companies’ s business platform was gained by digitally eavesdropping on the
POS transactions associated with the in-store customer return process. It has been
estimated that the direct costs (the largest portion of which involved contacting and
offering assistance to affected customers) to the TJX Companies for the breach might
have been as high as $1.6 billion.48 Other of these direct costs involved obtaining
legal advice, internal investigations, public relations and regulatory fines. However,
these direct costs do not include the very sizeable revenue and stock valuation losses
that occurred during 2007.
Figure 8-1 provides a visual framework simplifying the complexities of the
digitalization risk context. Here, three entities are brought together: a set of threats,
a set of targets, and the actors most significantly associated with the occurrence of
digitalization-risk incidents. Table 8-1 lists the loss categories typically associated
with each of the types of threats and targets.
46 A security breach refers to an incident that results in the confirmed disclosure of
data to an unauthorized third-party. 47 W. Xu, G. Grant, H. Nguyen and X. Dai, “Security Breach: The Case of TJX
Companies, Inc.,” Communications of the Association of Information Systems, Vol. 23,
November 2008, pp. 575-590. 48 C.R. Speechlys, “The Real Cost of a Data Breach,” Lexology, November 12, 2012:
http://www.lexology.com/library/detail.aspx?g=2aaa771a-2523-4e60-a0bc-306db8323d0e
181
Figure 8-1 Framing the Digitalization Risk Context
Threats
Digitalization Risks
Business Platform Operations
Digital Assets
Internal Controls
Targets
Legal & Regulatory
Natural Disaster
Actions of a Competitor
Platform Architectures
New Digital Technology
Outsiders Cybercriminals
Terrorists Hacktavists
Ecosystem Participants
Insiders Employees
Senior Executives
A c to
rs
Inability to Respond
Malicious Intrusion
External Sourcing
Digitalization Capabilities
Table 8-1 Losses Typically Associated with Digitalization-Risk Threats and Targets
Loss Categories
Threats
Malicious Intrusion Financial, Revenue, Intellectual Property, Reputation
Natural Disasters Financial, Revenue, Intellectual Property, Reputation
Legal & Regulatory Financial, Revenue, Reputation
New Digital Technology Revenue, Reputation
Actions of a Competitor Revenue, Reputation
External Sourcing Financial, Revenue, Intellectual Property, Reputation
Inability to Respond Revenue, Intellectual Property, Reputation
Targets
Business Platform Operations Revenue, Reputation
Digital Assets Financial, Revenue, Intellectual Property, Reputation
Internal Controls Financial, Reputation
Platform Architectures Financial, Revenue, Reputation
Digitalization Capabilities Financial, Revenue, Reputation
Let’s take a look at the actors (described in Table 8-2). Actors are associated
with threat incidents in two ways. Most often, actors are thought of as the
perpetrators of malicious intrusions – or, acts of commission. Cybercriminals (by
182
far the most common type of perpetrator), terrorists and hactavists clearly
instigate digitalization-risk incidents, as can ecosystem participants and
organizations’ employees (either acting alone or collaborating with others).
Table 8-2
Actors Associated with Digitalization-Risk Incidents
Actor Description
Outsider
Cybercriminal Uses hacking techniques & tools in order to take illegal actions for financial gain or to take over digital assets in order to launch a series of illegal actions.
Terrorist Uses hacking techniques & tools for the purpose of causing harm & havoc within an established geo-political order.
Hactavist Uses hacking techniques & tools for the purpose of bringing attention to a social or political issue.
Ecosystem Participant
Pipeline ecosystem participants (suppliers, upstream intermediaries, downstream intermediaries, consumers) and network ecosystem participants (members of interacting communities), who connect to organizations’ business/market platforms to facilitate ecosystem transactions.
Insider
Employee Operational, staff & managerial employees, who connect to the organization’s business platform to carry out their work roles.
Senior Executive
Members of the leadership team, whom are collectively responsible for: seeding & overseeing digital strategy formulation & implementation, setting policies for digitalization, and allocating the resources necessary for effective digitalization.
Just as serious, though typically overlooked, are the acts of omission traced
back to organizations’ employees and senior executives. It is not uncommon for
employees to claim ignorance of their organizations’ digitalization-risk
policies/procedures or to be lax in following these policies/procedures. Because of
employees’ acts of omission, organizations experience greater likelihoods of
experiencing losses regarding three, in particular, digitization-risk incidents:
malicious intrusion, natural disasters and legal/regulatory violations. Even more
problematic, it is not uncommon for organizations’ most senior executives to abdicate
some, if not most, of their managerial and fiduciary responsibilities regarding seeding
and overseeing digital strategy formulation and implementation, setting policies for
183
digitalization, and for allocating the resources necessary for effective digitalization.49
Because of senior executives’ acts of omission, organizations have a greater
likelihood of experiencing incidents regarding all nine digitization-risk threats.
Figure 8-2 illustrates the relationships between threats and targets. Acts of
commission, i.e., malicious intrusion, are most often directed at two threat targets:
business platform operations and digital assets. Business platform operations
refers to the execution of an organization’s digitalized operational and managerial
processes that are hosted on business platforms (and on market platforms); and,
digital assets refer to the digital technologies (hardware and software), digitized
data, and digitization/digitalization capabilities applied in configuring digital platforms
and business platforms. The most common incidents directed at business platform
operations are denial-of-service attacks, where the aim is to disrupt business
continuity either by flooding a platform with transactions, dramatically increasing
transaction volumes (slowing response times) or by inserting a virus that damages
the processing being performed on a platform (hence, shutting down the platform or
producing processing faults that result in the platform being shut down for repair).
The most common incidents directed at digital assets involve theft of digital content,
with content then being used for criminal or business-espionage purposes.
49 A. Masli, V. Richardson, M.W. Watson and R.W. Zmud, “Senior Executives IT
Management Responsibilities: Serious IT-Related Deficiencies and CEO/CFO Turnover,
Management Information Systems Quarterly, September 2016, pp. 687-708.
184
Figure 8-2 Associations Between Threats and Targets
Legal & Regulatory
Natural Disaster
Actions of Competitors
New Digital Technology
Inability to Respond
Malicious Intrusion
Business Platform Operations
Digital Assets
Internal Controls
Platform Architectures
External Sourcing
Digitalization Capabilities
Acts of omission play out across all five threat targets as needed digitalization-
related investments and policies are either not pursued or pursued ineffectively and
as sanctioned digitalization-related investments and policies are poorly implemented
and/or followed. The consequences of not attending to business platform operations
and to digital assets were addressed in the preceding paragraph. An organization’s
internal controls refer to the processing logic and rules embedded within digitalized
financial reporting systems to ensure the correct handling of financial transactions
and the accuracy of produced financial reports. If an organization’s internal controls
are in error or incomplete, the organization’s financial systems are susceptible to
malicious intrusions and the organization – along with its CEO and CFO – are subject
to penalties under the Sarbanes-Oxley Act. If organizations’ platform architectures
are not designed and maintained so as to remain aligned with these organizations’
digital strategies, it is unlikely that appropriate stability/agility balances can be
185
achieved. Finally, organizations lacking the digitalization capabilities to quickly
respond to competitors’ actions or to introduce innovative business models are
unlikely to maintain, let alone enhance, their competitive positions.
Prior to moving on to discussions of risk management and risk management
tactics, let’s briefly examine each of the digitalization-risk threats.
Malicious Intrusions
A malicious intrusion refers to a perpetrator’s success in getting through an
organization’s security-related defenses, i.e., the systems software and digitalized
work procedures aimed at identifying and authenticating all physical and digitized
attempts to access an organization’s digitalized business platforms and digital assets.
Successful intrusion usually begins via either phishing or through a POS device, but
then moves on to a wide gamut of abuses: theft, fraud, sabotage, denial-of-service
attacks, viruses, worms, website defacement, electronic eavesdropping, etc. As
these perpetrators and the hacking tools and techniques they use get better and
better, the time it takes to compromise a victim just gets shorter and shorter.
Today’s public and private digital infrastructures are becoming so large and so
complex that they are beyond the control of any one organization. As a result, no
matter how prudently an organization moves forward with security policies,
procedures and programs, the organization remains exposed to the threat of
malicious intrusion. The objective should not be to prevent all malicious intrusions,
but rather to prevent less-sophisticated intrusion attempts and to minimize the
damage caused by more-sophisticated intrusion attempts through quick detection,
removal and repair.
186
Natural Disasters
Natural disasters (e.g., tornadoes, hurricanes, earthquakes, tsunamis,
nuclear emergencies, collapsed dams, broken gas or water pipes, etc.), are worst-
case scenarios for any organization. If affected directly by a natural disaster,
business operations might be nonfunctional for days, weeks or months – resulting in
significant, if not catastrophic, revenue losses. Even if affected only indirectly by a
natural disaster, most organizations are likely to suffer some disruption to their
inbound/outbound logistics flows. While it is impossible to predict the occurrence of
such events, all organizations need to be prepared to act to minimize the effects of
and quickly recover from any operational disruptions. The implications of critical
business platforms becoming unavailable can be devastating, especially as ever-
greater portions of organizations’ business processes – the lifeblood of most
organizations’ revenue streams – are digitalized.
As natural disasters are unpreventable, the digitalization risk emphasis is on
achieving a graceful degradation in platform operational performance and a quick
recovery. Graceful degradation means that operations affected by a natural
disaster do not immediately shut down, but instead gradually slow down, allowing
time for affected operations to be shifted to other physical locations prior to a
complete shutdown. Both graceful degradation and quick recovery are typically
achieved by designing multiple redundancies into operational sites and activities. For
example, the physical sites housing digitalization operations are outfitted with backup
power systems, have all platform content (data and software) backed up on a regular
basis (say, every two hours) at a distant recovery site, and might even have all
processing activity instantly mimicked at the distant recovery site.
187
Legal and Regulatory Requirements
Organizations today face a broad array of digitalization-related legal and
regulatory requirements requiring protective actions most often aimed at
preventing harm to others. Included among these regulations, that originate from
federal, state and local governmental agencies, are those aimed at:
Protecting personal data (about customers, employees, visitors, etc.) that is collected, held, processed and provided to others.
Ensuring the security and accuracy of financial transactions and reports.
Requiring data collection and information reporting by organizations whose
products, services and work activities are environmentally-sensitive.
Requiring data collection and information reporting by organizations whose products, services and work activities are potentially harmful to consumers
or employees.
Organizations (and, possibly, specific employees) found noncompliant with statutory
requirements can suffer legal and civil penalties, as well as significant reputation
losses.
What makes the digitalization-related environments especially confusing and
complex is that the nature of regulations (statutory versus voluntary, breadth and
depth of coverage, sanctions for noncompliance, etc.) varies considerably across geo-
political boundaries (e.g., cities, states, nations, the EU, etc.). Table 8-3 describes a
few of the more well-known digitalization-related regulations facing U.S.
organizations.
188
Table 8-3 Examples of U.S. Digitalization-Related Regulations
Regulation Description
Family Educational Rights & Privacy Act of 1974
Educational agencies & institutions receiving funding from the U. S. Department of Education are required to provide students with access to their education records, an opportunity to seek to have the records amended, and some control over the disclosure of information from the records.
Health Insurance Portability & Accountability Act of 1996
Health care providers, insurance providers and employers are required to safeguard the security & privacy of patients’ health records and personal data.
Gramm-Leach-Bliley Act of 1999
Financial institutions are required to protect the security & privacy of the financial information that they collect, hold and process.
Sarbanes-Oxley Act of 2002 Publicly traded companies are required to provide assurance of the security, accuracy & reliability of their financial reporting systems.
State Security Breach Notification Law (First enacted
by California in 2002)
50 States have enacted Security Breach Notification laws requiring businesses to make notifications regarding security breaches. While no similar Federal law exists, bills have been introduced.
Payment Card Industry Data Security Standard
(Initially released in 2004)
Created by the Payment Card Industry Security Standards Council, this standard applies to all institutions that hold, process or exchange cardholder information. The standard strives to prevent credit card fraud through increased controls around data and its exposure to compromise.
New Digital Technologies
The continued advancements with digital technologies result in seeming
endless arrivals of innovative digital products and services, as well as innovative
digitalized solutions from both established and new vendors. While all new
technologies are largely untested when first released, those organizations able and
willing to subject a seemingly-relevant new technology to early assessment and
experimentation stand to gain the most from adopting that technology. Likewise,
those organizations that delay their assessing of what turns out to be a game-
changing technology are likely to have dug themselves into a deep competitive hole.
Actions of Competitors
The business model enhancements and innovations of established
organizations and startups pose a constant threat to any organization. While this has
189
always been the case, what is new today is the rapidity with which competitively-
meaningful actions appear and the fact that the organizations taking action
increasingly lie beyond the boundaries of the primary market ecosystems within
which an organization participates.
What is perhaps most insidious are the rapid inroads that a new competitor
can achieve regarding market share. This can be especially damaging when an
innovative business model creates a protectable, highly-profitable niche within an
existing market, subsequently drawing away participants from established
competitors and attracting a majority of new market participants.
External Sourcing
Most typically, an externalized capability takes the form of a digitalized process
developed by a provider (or another third-party) hosted on the provider’s business
platform and accessed by the client via public or private Internet connections. When
managed well, external sourcing provides an organization with significant cost,
operational and strategic benefits. But, along with these benefits comes a heightened
exposure to digitalization risk. Table 8-4 lists the digitalization risks, organized by
target, most commonly attributed to external sourcing.
190
Table 8-4 Digitalization Risks Associated with External Sourcing
Target Digitalization Risks
Business Platform
Operations
Operational gains (efficiency, security, scalability, etc.) not realized.
Provider platforms insufficiently enhanced, over time.
Digital Assets Provider platforms lack sufficient security. Data captured by or created by externally-hosted processes are
typically owned by the provider (unless otherwise negotiated).
Internal Controls
Processes executed on provider platform lack sufficient transaction & reporting integrity.
Platform Architectures
Provider platform architectures insufficiently enhanced, over time.
Provider platform architectures lose, over time, an acceptable stability/agility balance.
Digitalization Capabilities
Loss of internal-to-the-client digitalization capabilities. Provider fails to enhance digitalization capabilities. Provider fails to transfer new digitalization capabilities.
Inability to Respond
The most debilitating digitization risk – though the risk that perhaps receives
the least attention – is the inability to respond to competitors’ actions. Given the
power of network effects (affecting consumer communities in pipeline ecosystems
and all communities in network ecosystems), organizations must act effectively and
quickly to meet or, ideally, to advance competitors’ competitive actions. An
organization failing to act or acting in an ineffective or untimely manner is sure to
suffer some erosion in market position – an erosion that will only spiral in the face of
a continuing stream of competitors’ actions.
What is the root cause of an inability to respond to a competitor’s action? A
number of factors come to mind:
A delay in becoming aware of the competitor’s action.
An incomplete understanding of the competitor’s business model.
An incomplete understanding of how the competitor executed the
191
competitive action.
Inconsistencies between in-place platform architectures and the
architectures needed to implement an effective response.
Deficiencies in one or more of the platforms needed to implement an
effective response.
Deficiencies in one or more of the digital assets needed to implement an effective response.
Deficiencies in one or more of the capabilities needed to implement an effective response.
Delays encountered in resolving deficiencies in platforms, digital assets and capabilities.
And, as might be expected, failure to respond in an effective and timely manner
increases when more than one of these factors apply to the situation-at-hand.
Risk Management: A General Overview
Risk management is a topic that applies across all aspects of organizational
life, including digitalization. The aim of this section is to provide a general
introduction to the topic area.
It is important to recognize, first of all, that the intent of risk management is
not to eliminate risks, but to manage risks. Risk is an inherent aspect of
organizational life. While we can perfectly predict how an engineered system will
perform, it is impossible to perfectly predict how humans (e.g., operational
employees, managers, executives, consumers, suppliers’ employees, intermediaries’
employees, consultants, etc.) will perform. And, even if you could predict human
behavior by limiting the available choices, would you want to? Investments
promising high returns are generally riskier than investments promising low returns
precisely because we cannot predict the outcomes of high-return investments very
192
well. By limiting the choices available to humans, you also limit the potential for
individuals to act creatively and innovatively.
Risk management strives to accomplish two objectives: creating awareness
and a common understanding across an organization’s members about the existence
and nature of a risk domain; and, putting in place risk management policies,
procedures and programs to ensure that the critical risks in the domain are
appropriately addressed by appropriate individuals. In accomplishing these
objectives, risk management involves three activities: risk planning, risk assessment
and ongoing risk control.
Risk Planning
Risk planning establishes the contexts within which risk management
activities are carried out. Risk planning begins by identifying and categorizing the
areas of risk most likely to affect an organization. Next, each risk area is assigned
an owner. It is the risk owner’s responsibility to perform regular risk assessments,
and to actively manage associated risks. Then, overall risk management policies
need to be developed that provide a context within which risk owners can implement
area-specific risk management policies, procedures and programs. Finally, high-level
objectives are devised to articulate the importance of risk management. Examples
of such high-level objectives might include:50 “Protecting the integrity and security
of client and corporate information is the responsibility of every employee.”; and,
50 Adapted from: H.A. Smith and J. McKeen, “Developments in Practice XXXIII: A
Holistic Approach to Managing IT-based Risk,” Communications of the AIS, December 2009,
p. 525.
193
“We need to embed an attention to digitalization risk management into all work
processes, business functions, work roles and positions, and employees.”
Risk Assessment
During risk assessment, each risk owner, usually with the support of in-
house experts and external consultants, estimates the risk exposure associated
with each of the risk areas for which the owner is responsible. Usually, some variant
of the following formula is used:
Risk Exposure = (Probability of Risk Occurring) X (Expected Loss If Risk Occurs)
Organizations specializing in overall or domain-specific risk management have
considerable knowledge, experience and data that can be tapped to produce
estimates of risk probabilities and expected losses. Just remember that these generic
estimates are only starting points that need to be tailored to the nuances of a given
organization and that expected losses should include both tangible and intangible
losses, as well as short-term and long-term losses. The risk of underestimating
expected losses is that an organization is then likely to under-invest in risk-related
policies, procedures and programs.
Once a risk area has been assessed, the owner must decide (again, with input
from others) how risks are to be addressed. Three actions are possible, alone or in
combination:
Risk assumption: Accepting that losses are likely to arise if and when an incident occurs in a risk area, covering these losses through internal funds
and third-party insurance.
Risk deterrence: Taking action to reduce the likelihood that an incident will occur in a risk area.
Ongoing risk control: Monitoring a risk area such that the incident
194
occurrences are detected and resolved before excessive losses occur.
The risk assessment matrix shown as Figure 8-3 provides general guidance on
selecting an appropriate strategy for a risk area. Risk areas with low incident
probabilities and low expected losses can reasonably be assumed without taking
further action, while risk areas with high incident probabilities and high expected
losses require sophisticated strategies involving combinations of risk assumption, risk
deterrence and ongoing risk control.
Figure 8-3
Risk Assessment Matrix
Monitor continuously to immediately mitigate detected risk incidents
Take preemptive action to reduce the incident likelihood
Monitor continuously to immediately mitigate detected risk incidents
Take preemptive action to reduce the incident likelihood
Monitor continuously to immediately mitigate detected risk incidents
Monitor regularly to mitigate detected risk incidents
Monitor continuously to immediately mitigate detected risk incidents
Take preemptive action to reduce the incident likelihood
Monitor continuously to immediately mitigate detected risk events
Simply assume the risk Monitor regularly to mitigate detected risk incidents
Monitor continuously to immediately mitigate detected risk events
Expected Loss If a Risk Event Occurs
High
High
Medium
Medium
Low
Low
Ongoing Risk Control
Ongoing risk control involves monitoring for risk incidents, detecting that an
incident is about to occur (ideally) or has occurred (more likely), and taking action to
mitigate any losses arising from the incident. Risk mitigation involves tempering
(as much as possible) the consequences of a risk incident by taking corrective actions.
Prior to implementing ongoing control procedures, the risk owner needs to determine
195
the level of cost and effort to put into the procedures. Figure 8-4 illustrates the
complexity of this decision. The rational risk owner desires to neither under-invest
or over-invest in ongoing risk control. Here, again, heavy use is made of others’
knowledge and experience.
Figure 8-4
Determining the Cost of Ongoing Risk Control
Cost
Risk
Expected loss in the Absence of Risk
Deterrence/Mitigation
Cost of Risk Deterrence/Mitigation
Sweet Spot
An Exercise in Digitalization Risk Assessment51
An important element of the Coors Brewing Company’s marketing strategy
involves having retailers place eye-catching point-of-sales (POS) displays in their
stores. In implementing this strategy, Coors works with third-party marketing
partners and third-party providers to produce these display materials. However,
Coors owns the business processes that engage distributors and retailers in ordering
these POS display items. To motivate POS display orders, Coors provides each
51 This hypothetical exercise (used for illustrative purposes only) was developed by the
authors based on material from: J. Buffington and D.J. McCubbery, “Coors Brewing Company
Point of Sales Application Suite: Winning Mindshare with Customers, Retailers, and
Distributors,” Communications of the AIS, Volume 13, 2004, pp. 81-96.
196
wholesaler and retailer with a budget that can only be used to order POS display
items. Coors anticipates that at least some of the wholesalers and retailers will find
the display materials valuable in their efforts to increase sales and, in turn, that they
will order (display materials) beyond the Coors-provided funding.
Coors’ solution for digitalizing the business processes enabling distributors and
retailers to order promotional materials involved the building of a local (loosely
connected to other business platforms) business platform hosting five sets of
functionalities:
Internet Interaction Portal: Enables distributors and retailers to
communicate with Coors and to gain access to the digitized business processes.
Ordering General Materials: Enables distributors and retailers to order general promotional materials.
Ordering Licensed Materials: Enables distributors and retailers to order licensed (i.e., NFL logos) promotional materials.
Ordering Customized Materials: Enables distributors and retailers to design
and order customized promotional materials.
Retail Store Display Placement: Enables distributors and retailers to visualize
and optimize, through the use of digitalized tools, the physical placement of promotional materials within a retail store.
These functionalities were collectively aimed at achieving three main objectives:
increasing sales of Coors products, having distributor and retailer staffs performing
much of the work autonomously, and building stronger relationships with the
distributors and retailers.
Now, consider a risk assessment that might have been performed by the risk
owner for this digitalized business platform. Table 8-5 summarizes this risk
assessment. Given this assessment, it would be reasonable to expect that a
digitalization risk management strategy put forward by the risk owner would involve:
197
Deterring and mitigating malicious intrusions, through the local business platform, into Coors’ global digital platforms and business platforms.
Ensuring that any future decision process to externalize any of the digital platforms enabling the local business platform carefully examine the
providers’ capabilities to secure their platforms against malicious intrusions.
Establishing a vigilance regarding the potential for competitors to introduce retail shelf space innovations that could prove effective in taking market
share away from Coors’ products.
Establishing a vigilance regarding the development of analytics technologies
and solutions aimed at the retail shelf space context.
Table 8-5 Risk Assessment for Coors’ POS Display Business Platform
Threat Situational Assessment Incident
Probability Expected
Losses
Malicious Intrusion
• Coors is a prominent firm selling a product (alcohol) that could be considered controversial.
• Internet exposure & distributor/retailer connectivity.
• Low loss exposure with the local business platform. • High loss exposure with global platforms.
High Low (local)
High (global)
Natural Disasters
• Favorable geographic location (Colorado front range).
Very Low Moderate
Legal & Regulatory
• Limited access to financial systems. • Limited privacy concerns.
Low Low
New Digital Technology
• Analytics technologies. • Collaboration technologies.
Moderate High
Actions of a Competitor
• Retail floor & shelf spaces are highly competitive commodities.
High High
External Sourcing
• Business platform unlikely to be externalized. • Digital platform likely to be externalized.
Moderate Moderate
Inability to Respond
• Analytic capabilities focused on optimizing the use of retail store shelf space.
Moderate High
Digitalization Risk Management Practices
Digitalization risk management practices (i.e., policies, procedures and
programs) cover a very broad range of complex and ever-moving topics – topics for
which it is impossible to do justice in a few pages of text. To provide a glimpse of
what organizations are doing, this section describes a few of the current practices
regarding one threat area: that of malicious intrusions. This threat area was selected
for two reasons. First, since significant cyber-security breaches are reported on by
198
news media on a regular basis today, most people are well aware of the topic.
Second, cyber-security breaches can result in huge financial losses, the size of which
is increasing annually. Data from 2010, for example, indicated that the average cost
of a security breach exceeded US $7 million.52
As a selection of the more common risk management practices for combating
malicious intrusions are described, note that a mix of technical and social mechanisms
are required. All too often, it seems, much more attention is given to the technical
practices, with the just-as-critical social practices being overlooked and/or
underfunded.
Securing Digital and Business Platforms Against Malicious Intrusions
It is impossible for any organization to fully protect itself against malicious
intrusions. That said, all organizations need to understand the intrusion risk
exposures of their digital and business platforms and take commiserate steps to both
harden these platforms and detect (and mitigate) any intrusions that occur.
Hardening a platform involves installation of hardware, software and
physical impediments that increase the effort required by a perpetrator, such that all
but the most determined perpetrators either bypass the platform (moving on to
easier targets) or are so hindered that they quickly give up. Detection involves
putting in place software and manual scanning processes that identify problematic
behaviors transpiring within digital platforms and business platforms.
52 R. Appan and D. Becic, “Impact of Information Technology (IT) Security Information
Sharing among Competing IT Firms on Firm’s Financial Performance: An Empirical
Investigation,” Communications of the Association of Information Systems, Vol. 39, 2016, pp.
214-241.
199
Perhaps the most recognized hardening tactics involve the use of firewalls,
encryption technologies, access control mechanisms, and physical barriers to develop
multi-layered defensive shields around an organization’s digital and business
platforms. Less prominent is identity management software that seeks to identify
(“Who are you?”), authenticate (“Can you prove your identity?”) and authorize
(“What are you allowed to do?”) attempts, legitimate and illegitimate, to access
platforms and their contents. The most difficult of these questions is
authentication. As the technology improves and costs drop, authentication
methods are moving away from examining what you know (e.g., a password) to
examining something you have (e.g., biometrics such as the use of fingerprints, iris
scans, voice scans, etc.).
The most familiar detection tools are those directed at viruses (i.e., malicious
software code), that have eluded the barriers erected in hardening a platform. Less
visible are the huge investments organizations make in (1) capturing and then
analyzing the streams of digitalized transactions being executed on digital and
digitalized platforms, and (2) embedding processing logic into the software handling
these transactions to identify and reroute problematic transactional events.
Intra-Organizational Information Sharing Regarding Malicious Intrusions
As emphasized earlier, digitalization risk management is a participation sport
demanding the involvement of all employees. However, organizations’ employees
demonstrate wide variance in: their awareness of, knowledge of and sensitivity to
security breaches; their platform access privileges; their willingness to act in
compliance with security breach policies and procedures; and, their abilities to act
appropriately in the face of a security breach.
200
Because of these variances, many organizations are including comprehensive
intra-organizational information dissemination and sharing programs as prominent
components of their efforts to prevent and mitigate malicious intrusions. These
programs typically include:
Awareness Training: All employees are made aware of the basics of cyber-
security risk management (both work-related and home-computer use) and, specific to each employee, those risks most likely to arise as employees carry out their day-to-day work activities.
Platform Usage Training: Each employee interacting with a specific digital or business platform is provided with the knowledge and skills to effectively
deal with the digitalization risks associated with that platform.
Specialized Training: All technology professionals and all risk owners are provided with advanced education to develop the capabilities needed for
them to carry out their assigned responsibilities.
Technical Support: All employees are provided ready access to a cyber-
security support group that can answer questions that arise regarding the risk of malicious intrusions and that can aid an employee when faced with a
probable or actual security breach.
Extra-Organizational Information Sharing about Malicious Intrusions
Organizations’ leadership teams are increasingly recognizing the value of the
external sharing of information about security breaches. Initially, most organizations
were reluctant to report on security breach incidents because of the expectation that
most stakeholders (e.g., consumers, value stream participants, strategic partners,
securities analysts, etc.) would react negatively, at least in the short-term. However,
201
the consequences of reported security breaches, while still negative, have been
declining over time.53,54 Three explanations for this decline are:
More effective remediation and disaster recovery by firms, as well as a decrease in customers refraining from doing business with firms that experienced a security breach.
The U.S. Government’s promotion, since 1999, of industry-based trade associations known as information sharing and analysis centers (ISACs). As
of 2016, there are eighteen sector-based ISACs coordinated under a National Council of ISACs.
The enactment of federal and state security breach notification laws.
As more organizations actively gather and share information on digitalization-
risk threats, vulnerabilities and incidents, as well as best practices in digitalization
risk management, their capabilities to combat malicious intrusions will only improve.
Rather than feeling as if they are working alone against an increasingly hostile world,
organizations’ risk specialists and risk owners will increasingly find themselves
coordinating with and collaborating with their peers in other organizations, including
competitors, in order to drive informed decision making.
The Board of Directors and Digitalization Risk Management
As a general rule, those organizations most successful in applying digitalization
for competitive purposes have developed exceptional capabilities in digitalization risk
management. But, who, ultimately, is accountable for the quality of an organization’s
53 L. Gordon, M. Loeb and L. Zhou (2011), “The Impact of Information Security
Breaches: Has There Been a Downward Shift in Costs?”, Journal of Computer Security, Vol.
19, No. 1, 2011, pp. 33–56. 54 S. Goel and H.A. Shawky, "The Impact of Federal and State Notification Laws on
Security Breach Announcements," Communications of the Association for Information
Systems: Vol. 34, January 2014, pp. 37-50.
202
digitalization risk management capabilities? With a public firm, it is the firm’s Board
of Directors.
However, most Boards of Directors have only gradually – and grudgingly –
stepped up to their oversight responsibilities regarding digitalization risk
management. For example, studies55,56,57 of Boards of Directors portray the following
practices:
Board members are not actively recruited for their digitalization expertise. Few executives of organizations recognized as digitalization leaders are
members of Boards of Directors.
Very limited discussions of digitalization take place at Board meetings.
When digitalization is discussed at Board meetings, these discussions tend to
be after-the-fact updates regarding recent, significant digitalization initiatives.
Most of this limited discussion of digitalization occurs in Board committee meetings. Most often, this committee tends to be the audit committee,
where the issues raised are done so in reaction to a problematic event.
Few Boards of Directors have a committee focused exclusively on digitalization.
Overall, a state of complacency regarding digitalization continues, with Board
members believing that their organization’s leadership team has a solid handle on
managing the risks of digitalization. That said, a growing number of exceptions to
this general depiction can be observed in recent trends regarding Boards of Directors
and digitalization.
55 S. Huff, P. Maher and M. Munro, “Information Technology and the Boards of
Directors: Is there an IT Attention Deficit,” MISQ Executive, June 2006, pp. 55-68 56 M. Parent and B. Reich, “Governing Information Technology Risk,” California
Management Review, Spring 2009, pp. 134-152. 57 S. Andriole, “Boards of Directors and Technology Governance: The Surprising State
of the Practice,” Communications of the CAIS, Volume 24, Article 22, 2009, pp. 373-394.
203
What should be the role of Boards of Directors in managing digitalization risk?
Three Board responsibilities are most important. The Board of Directors must assure
that their organization is not overly exposed to digitalization risks that threaten
business continuity, regulatory compliance and competitive success. In order for
these responsibilities to be met, Boards of Directors need to adopt best practices such
as:58,59
Bringing members with digitalization experience and expertise onto the Board.
Regularly inviting senior executives whose work responsibilities involve strategically-critical digitalization initiatives to Board meetings.
Systematically including digitalization issues on the agenda of full Board
meetings. For the most part, the focus of these discussions needs to address strategic rather than tactical issues, including Board reviews of all
major digitalization-related assets, investments and initiatives.
Establishing a Board digitalization committee.
Accounting for Digitalization Risks in Digital Strategy Formulation
Digitalization risks affect digital strategists’ thinking in two ways: by adding
layers of complexity onto their efforts to enhance existing business models and to
innovate with new business models, and by requiring that the requisite capabilities
are in place to enable both business model formulation and business model
implementation. Table 8-6 describes how each of the four elements of business
models are influenced.
58 M. Bloch, B. Brown and J. Sikes, “Elevating Technology on the Boardroom Agenda,
McKinsey Quarterly, 2013, No. 1, pp. 99-103. 59 H. Sarrazin and P. Willmott, “Adapting Your Board to the Digital Age,” McKinsey
Quarterly, 2016, No. 3, pp. 89-95.
204
Table 8-6 How Business Models Are Affected by Digitalization Risks
Value Propositions Profit Models
Provide value in return for personal data that is captured, archived and/or used.
Ensure the security, and hence the trustworthiness, of digital platforms and business platforms.
Comprehensively and accurately account for the digitalization risk management costs associated with developing, implementing and evolving a business model.
Core Capabilities Dynamic Capabilities
Digitalization risk management capabilities (accounting for all threat areas).
Tuning of digital strategists’ environmental scanning regarding: Digitalization threats. Digital technologies. Strategic capabilities. External sourcing providers. Competitors’ business model
innovations.
Increasingly, critical features of the value propositions being offered to pipeline
ecosystem consumers and network ecosystem participants are dependent on
personal data provided by or collected about individuals. If an individual feels the
quid pro quo is inadequate, the individual is unlikely to engage, partially or fully, in
market ecosystem interactions. Similarly, market ecosystem participants lacking
trust in the platforms enabling a value proposition would be expected to refrain from
platform interactions.
The long-term expectation from aggregating the profit models associated with
a business model is that the business model will prove profitable. However, if a
business model’s risk exposure requires extensive digitalization risk management
capabilities, and if the investment and operating costs associated with these
capabilities are not fully accounted for in the business model’s aggregated profit
models, then what might appear initially to be a very successful business model is
likely to become a huge liability over time.
205
If nothing else, this chapter’s content should have driven home the point that
in a world of pervasive digitalization, digitalization risk management has become a
core capability for all organizations and a strategic capability for some (e.g., financial
services organizations, e-commerce organizations, cloud-based organizations, etc.).
If digitalization knowledge and experience is not represented within organizations’
senior leadership teams, as well as within the Board of Directors of private firms,
then it becomes unlikely that a strong digitalization risk management capability will
be developed.
Finally, and most importantly, as extensive digitalization pervades an
organization’s strategies and operations, the breadth of the organization’s dynamic
capabilities must span an increasingly-wide gamut of markets, competitors, strategic
partners, strategic capabilities and digital technologies.
A Recap and Look Ahead
Competitive success in the face of digital disruption requires organizations’
leadership teams and digital strategists to demonstrate relentless vigilance with
regard to digitalization opportunities and, as covered in this chapter, digitalization
threats. But, how can such a mindset be established within an organization’s
members? In the next chapter, six actions aimed at just such an objective are
described.
GLOSSARY
Authentication – techniques aimed at proving a person’s or a digital entity’s
identity.
Business platform operations – the execution of an organization’s digitalized
operational and managerial processes that are hosted on business platforms (and on market platforms).
Cybercriminal – uses hacking techniques and tools in order to take illegal actions
for financial gain or to take over digital assets in order to launch a series of illegal actions.
Data privacy – concerns that arise wherever personally-identifiable or other sensitive information is captured, collected, stored and used.
Detection – putting in place software and manual scanning processes that identify
problematic behaviors transpiring within digital platforms and business platforms.
Digital assets – digital technologies (hardware and software), digitized data, and
digitization/digitalization capabilities applied in configuring digital platforms and business platforms.
Digitalization risk – the likely occurrence of digitalization-related incidents that
have the potential to negatively impact an organization’s operational performance and/or competitive position.
Financial loss – theft; fraud; extortion; destruction of uninsured facilities, equipment and materials; drops in stock valuations; regulatory fines; legal fees, court
awards and out-of-court settlements; etc.
Graceful degradation – operations affected by a natural disaster do not immediately shut down, but instead gradually slow down, allowing time for affected
operations to be shifted to other physical locations prior to a complete shutdown.
Hactavist – uses hacking techniques and tools for the purpose of bringing attention
to a social or political issue.
Hardening a platform – installation of hardware, software and physical impediments that increase the effort required by a perpetrator such that all but the
most determined perpetrators either bypass the platform (moving on to easier targets) or are so hindered that they quickly give up.
Intellectual property loss – theft of digitized ideas, innovations and other forms of creative expression (e.g., trade secrets; blueprints; digitalized processes; proprietary digital content; the underpinnings of strategies and business models;
etc.).
Internal controls – the processing logic and rules embedded within digitalized financial reporting systems to ensure the correct handling of financial transactions
and the accuracy of produced financial reports.
Legal and regulatory requirements – digitalization-related statutory policies and
rules requiring protective actions, most often aimed at preventing harm to others.
Malicious intrusion – a perpetrator’s success in getting through an organization’s security-related defenses.
Natural disaster – tornadoes, hurricanes, earthquakes, tsunamis, nuclear emergencies, collapsed dams, broken gas or water pipes, etc.
Ongoing risk control – monitoring a risk area such that the incident occurrences are detected and resolved before excessive losses occur.
Reputation loss – depreciation of an organization’s image or of its brands that
undermines the trust and goodwill held by participants in the various market-focused ecosystems with which the organization participates.
Revenue loss – short-falls in revenue streams or lost revenue streams traced to operational disruptions, reputation loss, the inability to respond effectively to competitors’ actions, etc.
Risk assessment – estimate the risk exposure associated with a risk area.
Risk assumption – accepting that losses are likely to arise if and when an incident
occurs in a risk area, covering these losses through internal funds and third-party insurance.
Risk deterrence – taking action to reduce the likelihood that an incident will occur in a risk area.
Risk exposure – the probability of a risk occurring multiplied by the expected loss
to be borne if the risk occurs.
Risk management – creating awareness and a common understanding across an
organization’s members about the existence and nature of a risk domain; and, putting in place risk management policies, procedures and programs to ensure that that critical risks in the domain are appropriately addressed by the appropriate individuals.
Risk mitigation – tempering (as much as possible) the consequences of a risk incident by taking corrective actions.
Risk planning – establishes the contexts within which risk management activities are carried out.
Terrorist – uses hacking techniques and tools for the purpose of causing harm and
havoc within an established geo-political order.
- Chapter 8. Grappling with the Risks of Digitalization
- Nature of Digitalization Risks
- Risk Management: A General Overview
- Digitalization Risk Management Practices
- The Board of Directors and Digitalization Riskl Management
- Accounting for Digitalization Risks in Digital Strategy Formulation
- A Recap and Look Ahead
- GLOSSARY