summary

profilehi123
gdto_second_edition_ch_8_purchase_june_2018.pdf

Vallabh Sambamurthy & Robert W. Zmud

Guiding the Digital Transformation of Organizations - Second Edition

© 2017 Legerity Digital Press

All rights reserved. �is book or any portion thereof may not be reproduced or used in any manner whatsoever without the express written permission of the publisher, except for the use of brief quotations in a book review.

Legerity Digital Press LLC For more information, please visit: www.ldpress.com, email [email protected] or call toll free 855-855-9868.

ISBN 978-0-9857955-9-7

Grappling with the Risks of Digitalization

Chapter

08

Guiding the Digital Transformation of Organizations By Vallabh Sambamurthy and Robert W. Zmud

Second Edition Copyright © 2017

First Edition Copyright © 2012

All rights reserved. No part of this publication shall be reproduced, distributed, or

transmitted in any form or by any means, electronic or mechanical, including photocopying,

recording, or by any information retrieval system without the prior written permission of the

publisher, except in the case of brief quotations embodied in critical reviews and certain

other noncommercial uses permitted by copyright law. For permission requests, email the

publisher at: [email protected].

Published by Legerity Digital Press, LLC

A catalog record for this book is available from the U.S. Library of Congress.

ISBN 978-0-9857955-9-7

Although every precaution has been taken in the preparation of this book, the

publisher and author assume no responsibility for errors or omissions. Neither is any

liability assumed for damages resulting from the use of this information contained herein.

Ordering information:

For all ordering inquiries, please visit www.ldpress.com, email [email protected] or

call toll free at 855-855-9868. Special discounts are available on bulk purchases by

academic institutions, associations, corporations, and others.

Printed in the United States of America.

Cover Illustration by Aaron Z. Williams

177

Chapter 8. Grappling with the Risks of Digitalization

The enabling nature of digital disruption might best be captured by three ideas:

pervasive digitization, pervasive connectivity and pervasive mobility. Invariably,

pipeline ecosystem participants and network ecosystem participants find themselves

constantly accessing and exchanging digitized content (e.g., data, information,

goods, services and currencies) and it is precisely these type of activities that are

creating an abundance of competitive opportunities for digital strategists able to act

smartly and nimbly.

However, the technological underpinnings of organizations’ digital strategies

also pose significant strategic risks. If digitalization risks are not appropriately

addressed by organizations’ leadership teams, the competitive wins that are realized

are likely to be short-lived, at best. Consider what happened in January 2003 when

a small (376 bytes) data virus infected a single processing device with the Slammer

worm.44 After launching itself onto the Internet, it infected close to 100,000 large

computer systems worldwide in just 30 minutes. The impact was chilling: air and rail

transport were delayed, electrical and pipeline utilities were interrupted, ATMs were

disabled, call centers were shut down, etc. In today’s highly digitized, connected and

mobile world, a single person’s lapse can quickly spread across the platforms to which

the person is directly or indirectly connected.

Nothing demonstrates the challenges presented to digital strategists better

than the paradox surrounding the capture and use of personal data. Data privacy

44 T. Goles, G. White and G. Dietriech, “Dark Screen: An Exercise in Cyber Security,”

MIS Quarterly Executive, June 2005, pp. 303-318.

178

concerns exist wherever personally-identifiable or other sensitive information is

captured, collected, stored and used. That said, tomorrow’s waves of digitalization

innovation and growth will surely involve intelligent analytics, highly-customized

goods and services, and always-available mobile connectivity offering one-touch

transactions, where these transactions require the collection and use of vast

quantities of personal data: socio-demographic data, location data, transaction

histories, etc. People can be motivated – through the expectation that the value of

the goods and services obtained will outweigh potential liabilities – to allow the

capture and collection of these data, but only if trust is established and maintained

that any collected personal data will be protected and will not be used in the absence

of permission to do so.

A key factor differentiating those organizations able to successfully exploit

digitalization for competitive purposes is a set of strong capabilities for managing

digitalization risk. Supporting evidence for the value of managing digitalization risk

is illustrated by a study that found voluntary disclosures of initiatives aimed at

reducing digitalization risks improved organizations’ stock prices by, on average,

6%.45 Effective digitalization risk management, however, involves much more than

enhancing an organization’s cybersecurity. The real challenge is to achieve an

effective balance in stability (as evidenced by efficient, secure, reliable and available

platforms) and agility (as evidenced by a readiness to formulate and implement

timely and innovative competitive moves).

45 L. Gordon, M. Loeb and T. Sohail, “Market Value of Voluntary Disclosures Concerning

Information Security,” MIS Quarterly, September 2010, pp. 567-594.

179

Managing digitalization risks in a manner that balances stability and agility is

a participation sport that demands the involvement of all of an organization’s

members. With the aim of providing a mindset and a foundation conducive for

effectively managing digitalization risk, this chapter covers the following topics:

 Nature of Digitalization Risks

 Risk Management: A General Overview

 Digitalization Risk Management Practices

 The Board of Directors and Digitalization Risk Management

 Accounting for Digitalization Risks in Digital Strategy Formulation

Nature of Digitalization Risks

A digitalization risk refers to the likely occurrence of digitalization-related

incidents that have the potential to negatively impact an organization’s operational

performance and/or competitive position. What are these negative impacts? A useful

way of thinking about these negative effects is the following loss categories:

 Financial loss: theft; fraud; extortion; destruction of uninsured facilities,

equipment and materials; drops in stock valuations; regulatory fines; legal fees, court awards and out-of-court settlements; etc.

 Revenue loss: short-falls in revenue streams or lost revenue streams traced to operational disruptions, reputation loss, the inability to respond effectively to competitors’ actions, etc.

 Intellectual property loss: thefts of digitized ideas, innovations and other forms of creative expression (e.g., trade secrets, blueprints, digitalized

processes, proprietary digital content, digital strategies, business models, etc.).

 Reputation loss: depreciation of an organization’s image or of its brands

that undermines the trust and goodwill held by participants in the various market-focused ecosystems with which the organization participates.

180

These negative impacts can be huge. Consider, for example, the losses suffered by

the TJX Companies after a security breach46 (reported in late 2006) that enabled

hackers to obtain data from over 45 million customer payment cards.47 Access into

the TJX Companies’ s business platform was gained by digitally eavesdropping on the

POS transactions associated with the in-store customer return process. It has been

estimated that the direct costs (the largest portion of which involved contacting and

offering assistance to affected customers) to the TJX Companies for the breach might

have been as high as $1.6 billion.48 Other of these direct costs involved obtaining

legal advice, internal investigations, public relations and regulatory fines. However,

these direct costs do not include the very sizeable revenue and stock valuation losses

that occurred during 2007.

Figure 8-1 provides a visual framework simplifying the complexities of the

digitalization risk context. Here, three entities are brought together: a set of threats,

a set of targets, and the actors most significantly associated with the occurrence of

digitalization-risk incidents. Table 8-1 lists the loss categories typically associated

with each of the types of threats and targets.

46 A security breach refers to an incident that results in the confirmed disclosure of

data to an unauthorized third-party. 47 W. Xu, G. Grant, H. Nguyen and X. Dai, “Security Breach: The Case of TJX

Companies, Inc.,” Communications of the Association of Information Systems, Vol. 23,

November 2008, pp. 575-590. 48 C.R. Speechlys, “The Real Cost of a Data Breach,” Lexology, November 12, 2012:

http://www.lexology.com/library/detail.aspx?g=2aaa771a-2523-4e60-a0bc-306db8323d0e

181

Figure 8-1 Framing the Digitalization Risk Context

Threats

Digitalization Risks

Business Platform Operations

Digital Assets

Internal Controls

Targets

Legal & Regulatory

Natural Disaster

Actions of a Competitor

Platform Architectures

New Digital Technology

Outsiders Cybercriminals

Terrorists Hacktavists

Ecosystem Participants

Insiders Employees

Senior Executives

A c to

rs

Inability to Respond

Malicious Intrusion

External Sourcing

Digitalization Capabilities

Table 8-1 Losses Typically Associated with Digitalization-Risk Threats and Targets

Loss Categories

Threats

Malicious Intrusion Financial, Revenue, Intellectual Property, Reputation

Natural Disasters Financial, Revenue, Intellectual Property, Reputation

Legal & Regulatory Financial, Revenue, Reputation

New Digital Technology Revenue, Reputation

Actions of a Competitor Revenue, Reputation

External Sourcing Financial, Revenue, Intellectual Property, Reputation

Inability to Respond Revenue, Intellectual Property, Reputation

Targets

Business Platform Operations Revenue, Reputation

Digital Assets Financial, Revenue, Intellectual Property, Reputation

Internal Controls Financial, Reputation

Platform Architectures Financial, Revenue, Reputation

Digitalization Capabilities Financial, Revenue, Reputation

Let’s take a look at the actors (described in Table 8-2). Actors are associated

with threat incidents in two ways. Most often, actors are thought of as the

perpetrators of malicious intrusions – or, acts of commission. Cybercriminals (by

182

far the most common type of perpetrator), terrorists and hactavists clearly

instigate digitalization-risk incidents, as can ecosystem participants and

organizations’ employees (either acting alone or collaborating with others).

Table 8-2

Actors Associated with Digitalization-Risk Incidents

Actor Description

Outsider

Cybercriminal Uses hacking techniques & tools in order to take illegal actions for financial gain or to take over digital assets in order to launch a series of illegal actions.

Terrorist Uses hacking techniques & tools for the purpose of causing harm & havoc within an established geo-political order.

Hactavist Uses hacking techniques & tools for the purpose of bringing attention to a social or political issue.

Ecosystem Participant

Pipeline ecosystem participants (suppliers, upstream intermediaries, downstream intermediaries, consumers) and network ecosystem participants (members of interacting communities), who connect to organizations’ business/market platforms to facilitate ecosystem transactions.

Insider

Employee Operational, staff & managerial employees, who connect to the organization’s business platform to carry out their work roles.

Senior Executive

Members of the leadership team, whom are collectively responsible for: seeding & overseeing digital strategy formulation & implementation, setting policies for digitalization, and allocating the resources necessary for effective digitalization.

Just as serious, though typically overlooked, are the acts of omission traced

back to organizations’ employees and senior executives. It is not uncommon for

employees to claim ignorance of their organizations’ digitalization-risk

policies/procedures or to be lax in following these policies/procedures. Because of

employees’ acts of omission, organizations experience greater likelihoods of

experiencing losses regarding three, in particular, digitization-risk incidents:

malicious intrusion, natural disasters and legal/regulatory violations. Even more

problematic, it is not uncommon for organizations’ most senior executives to abdicate

some, if not most, of their managerial and fiduciary responsibilities regarding seeding

and overseeing digital strategy formulation and implementation, setting policies for

183

digitalization, and for allocating the resources necessary for effective digitalization.49

Because of senior executives’ acts of omission, organizations have a greater

likelihood of experiencing incidents regarding all nine digitization-risk threats.

Figure 8-2 illustrates the relationships between threats and targets. Acts of

commission, i.e., malicious intrusion, are most often directed at two threat targets:

business platform operations and digital assets. Business platform operations

refers to the execution of an organization’s digitalized operational and managerial

processes that are hosted on business platforms (and on market platforms); and,

digital assets refer to the digital technologies (hardware and software), digitized

data, and digitization/digitalization capabilities applied in configuring digital platforms

and business platforms. The most common incidents directed at business platform

operations are denial-of-service attacks, where the aim is to disrupt business

continuity either by flooding a platform with transactions, dramatically increasing

transaction volumes (slowing response times) or by inserting a virus that damages

the processing being performed on a platform (hence, shutting down the platform or

producing processing faults that result in the platform being shut down for repair).

The most common incidents directed at digital assets involve theft of digital content,

with content then being used for criminal or business-espionage purposes.

49 A. Masli, V. Richardson, M.W. Watson and R.W. Zmud, “Senior Executives IT

Management Responsibilities: Serious IT-Related Deficiencies and CEO/CFO Turnover,

Management Information Systems Quarterly, September 2016, pp. 687-708.

184

Figure 8-2 Associations Between Threats and Targets

Legal & Regulatory

Natural Disaster

Actions of Competitors

New Digital Technology

Inability to Respond

Malicious Intrusion

Business Platform Operations

Digital Assets

Internal Controls

Platform Architectures

External Sourcing

Digitalization Capabilities

Acts of omission play out across all five threat targets as needed digitalization-

related investments and policies are either not pursued or pursued ineffectively and

as sanctioned digitalization-related investments and policies are poorly implemented

and/or followed. The consequences of not attending to business platform operations

and to digital assets were addressed in the preceding paragraph. An organization’s

internal controls refer to the processing logic and rules embedded within digitalized

financial reporting systems to ensure the correct handling of financial transactions

and the accuracy of produced financial reports. If an organization’s internal controls

are in error or incomplete, the organization’s financial systems are susceptible to

malicious intrusions and the organization – along with its CEO and CFO – are subject

to penalties under the Sarbanes-Oxley Act. If organizations’ platform architectures

are not designed and maintained so as to remain aligned with these organizations’

digital strategies, it is unlikely that appropriate stability/agility balances can be

185

achieved. Finally, organizations lacking the digitalization capabilities to quickly

respond to competitors’ actions or to introduce innovative business models are

unlikely to maintain, let alone enhance, their competitive positions.

Prior to moving on to discussions of risk management and risk management

tactics, let’s briefly examine each of the digitalization-risk threats.

Malicious Intrusions

A malicious intrusion refers to a perpetrator’s success in getting through an

organization’s security-related defenses, i.e., the systems software and digitalized

work procedures aimed at identifying and authenticating all physical and digitized

attempts to access an organization’s digitalized business platforms and digital assets.

Successful intrusion usually begins via either phishing or through a POS device, but

then moves on to a wide gamut of abuses: theft, fraud, sabotage, denial-of-service

attacks, viruses, worms, website defacement, electronic eavesdropping, etc. As

these perpetrators and the hacking tools and techniques they use get better and

better, the time it takes to compromise a victim just gets shorter and shorter.

Today’s public and private digital infrastructures are becoming so large and so

complex that they are beyond the control of any one organization. As a result, no

matter how prudently an organization moves forward with security policies,

procedures and programs, the organization remains exposed to the threat of

malicious intrusion. The objective should not be to prevent all malicious intrusions,

but rather to prevent less-sophisticated intrusion attempts and to minimize the

damage caused by more-sophisticated intrusion attempts through quick detection,

removal and repair.

186

Natural Disasters

Natural disasters (e.g., tornadoes, hurricanes, earthquakes, tsunamis,

nuclear emergencies, collapsed dams, broken gas or water pipes, etc.), are worst-

case scenarios for any organization. If affected directly by a natural disaster,

business operations might be nonfunctional for days, weeks or months – resulting in

significant, if not catastrophic, revenue losses. Even if affected only indirectly by a

natural disaster, most organizations are likely to suffer some disruption to their

inbound/outbound logistics flows. While it is impossible to predict the occurrence of

such events, all organizations need to be prepared to act to minimize the effects of

and quickly recover from any operational disruptions. The implications of critical

business platforms becoming unavailable can be devastating, especially as ever-

greater portions of organizations’ business processes – the lifeblood of most

organizations’ revenue streams – are digitalized.

As natural disasters are unpreventable, the digitalization risk emphasis is on

achieving a graceful degradation in platform operational performance and a quick

recovery. Graceful degradation means that operations affected by a natural

disaster do not immediately shut down, but instead gradually slow down, allowing

time for affected operations to be shifted to other physical locations prior to a

complete shutdown. Both graceful degradation and quick recovery are typically

achieved by designing multiple redundancies into operational sites and activities. For

example, the physical sites housing digitalization operations are outfitted with backup

power systems, have all platform content (data and software) backed up on a regular

basis (say, every two hours) at a distant recovery site, and might even have all

processing activity instantly mimicked at the distant recovery site.

187

Legal and Regulatory Requirements

Organizations today face a broad array of digitalization-related legal and

regulatory requirements requiring protective actions most often aimed at

preventing harm to others. Included among these regulations, that originate from

federal, state and local governmental agencies, are those aimed at:

 Protecting personal data (about customers, employees, visitors, etc.) that is collected, held, processed and provided to others.

 Ensuring the security and accuracy of financial transactions and reports.

 Requiring data collection and information reporting by organizations whose

products, services and work activities are environmentally-sensitive.

 Requiring data collection and information reporting by organizations whose products, services and work activities are potentially harmful to consumers

or employees.

Organizations (and, possibly, specific employees) found noncompliant with statutory

requirements can suffer legal and civil penalties, as well as significant reputation

losses.

What makes the digitalization-related environments especially confusing and

complex is that the nature of regulations (statutory versus voluntary, breadth and

depth of coverage, sanctions for noncompliance, etc.) varies considerably across geo-

political boundaries (e.g., cities, states, nations, the EU, etc.). Table 8-3 describes a

few of the more well-known digitalization-related regulations facing U.S.

organizations.

188

Table 8-3 Examples of U.S. Digitalization-Related Regulations

Regulation Description

Family Educational Rights & Privacy Act of 1974

Educational agencies & institutions receiving funding from the U. S. Department of Education are required to provide students with access to their education records, an opportunity to seek to have the records amended, and some control over the disclosure of information from the records.

Health Insurance Portability & Accountability Act of 1996

Health care providers, insurance providers and employers are required to safeguard the security & privacy of patients’ health records and personal data.

Gramm-Leach-Bliley Act of 1999

Financial institutions are required to protect the security & privacy of the financial information that they collect, hold and process.

Sarbanes-Oxley Act of 2002 Publicly traded companies are required to provide assurance of the security, accuracy & reliability of their financial reporting systems.

State Security Breach Notification Law (First enacted

by California in 2002)

50 States have enacted Security Breach Notification laws requiring businesses to make notifications regarding security breaches. While no similar Federal law exists, bills have been introduced.

Payment Card Industry Data Security Standard

(Initially released in 2004)

Created by the Payment Card Industry Security Standards Council, this standard applies to all institutions that hold, process or exchange cardholder information. The standard strives to prevent credit card fraud through increased controls around data and its exposure to compromise.

New Digital Technologies

The continued advancements with digital technologies result in seeming

endless arrivals of innovative digital products and services, as well as innovative

digitalized solutions from both established and new vendors. While all new

technologies are largely untested when first released, those organizations able and

willing to subject a seemingly-relevant new technology to early assessment and

experimentation stand to gain the most from adopting that technology. Likewise,

those organizations that delay their assessing of what turns out to be a game-

changing technology are likely to have dug themselves into a deep competitive hole.

Actions of Competitors

The business model enhancements and innovations of established

organizations and startups pose a constant threat to any organization. While this has

189

always been the case, what is new today is the rapidity with which competitively-

meaningful actions appear and the fact that the organizations taking action

increasingly lie beyond the boundaries of the primary market ecosystems within

which an organization participates.

What is perhaps most insidious are the rapid inroads that a new competitor

can achieve regarding market share. This can be especially damaging when an

innovative business model creates a protectable, highly-profitable niche within an

existing market, subsequently drawing away participants from established

competitors and attracting a majority of new market participants.

External Sourcing

Most typically, an externalized capability takes the form of a digitalized process

developed by a provider (or another third-party) hosted on the provider’s business

platform and accessed by the client via public or private Internet connections. When

managed well, external sourcing provides an organization with significant cost,

operational and strategic benefits. But, along with these benefits comes a heightened

exposure to digitalization risk. Table 8-4 lists the digitalization risks, organized by

target, most commonly attributed to external sourcing.

190

Table 8-4 Digitalization Risks Associated with External Sourcing

Target Digitalization Risks

Business Platform

Operations

 Operational gains (efficiency, security, scalability, etc.) not realized.

 Provider platforms insufficiently enhanced, over time.

Digital Assets  Provider platforms lack sufficient security.  Data captured by or created by externally-hosted processes are

typically owned by the provider (unless otherwise negotiated).

Internal Controls

 Processes executed on provider platform lack sufficient transaction & reporting integrity.

Platform Architectures

 Provider platform architectures insufficiently enhanced, over time.

 Provider platform architectures lose, over time, an acceptable stability/agility balance.

Digitalization Capabilities

 Loss of internal-to-the-client digitalization capabilities.  Provider fails to enhance digitalization capabilities.  Provider fails to transfer new digitalization capabilities.

Inability to Respond

The most debilitating digitization risk – though the risk that perhaps receives

the least attention – is the inability to respond to competitors’ actions. Given the

power of network effects (affecting consumer communities in pipeline ecosystems

and all communities in network ecosystems), organizations must act effectively and

quickly to meet or, ideally, to advance competitors’ competitive actions. An

organization failing to act or acting in an ineffective or untimely manner is sure to

suffer some erosion in market position – an erosion that will only spiral in the face of

a continuing stream of competitors’ actions.

What is the root cause of an inability to respond to a competitor’s action? A

number of factors come to mind:

 A delay in becoming aware of the competitor’s action.

 An incomplete understanding of the competitor’s business model.

 An incomplete understanding of how the competitor executed the

191

competitive action.

 Inconsistencies between in-place platform architectures and the

architectures needed to implement an effective response.

 Deficiencies in one or more of the platforms needed to implement an

effective response.

 Deficiencies in one or more of the digital assets needed to implement an effective response.

 Deficiencies in one or more of the capabilities needed to implement an effective response.

 Delays encountered in resolving deficiencies in platforms, digital assets and capabilities.

And, as might be expected, failure to respond in an effective and timely manner

increases when more than one of these factors apply to the situation-at-hand.

Risk Management: A General Overview

Risk management is a topic that applies across all aspects of organizational

life, including digitalization. The aim of this section is to provide a general

introduction to the topic area.

It is important to recognize, first of all, that the intent of risk management is

not to eliminate risks, but to manage risks. Risk is an inherent aspect of

organizational life. While we can perfectly predict how an engineered system will

perform, it is impossible to perfectly predict how humans (e.g., operational

employees, managers, executives, consumers, suppliers’ employees, intermediaries’

employees, consultants, etc.) will perform. And, even if you could predict human

behavior by limiting the available choices, would you want to? Investments

promising high returns are generally riskier than investments promising low returns

precisely because we cannot predict the outcomes of high-return investments very

192

well. By limiting the choices available to humans, you also limit the potential for

individuals to act creatively and innovatively.

Risk management strives to accomplish two objectives: creating awareness

and a common understanding across an organization’s members about the existence

and nature of a risk domain; and, putting in place risk management policies,

procedures and programs to ensure that the critical risks in the domain are

appropriately addressed by appropriate individuals. In accomplishing these

objectives, risk management involves three activities: risk planning, risk assessment

and ongoing risk control.

Risk Planning

Risk planning establishes the contexts within which risk management

activities are carried out. Risk planning begins by identifying and categorizing the

areas of risk most likely to affect an organization. Next, each risk area is assigned

an owner. It is the risk owner’s responsibility to perform regular risk assessments,

and to actively manage associated risks. Then, overall risk management policies

need to be developed that provide a context within which risk owners can implement

area-specific risk management policies, procedures and programs. Finally, high-level

objectives are devised to articulate the importance of risk management. Examples

of such high-level objectives might include:50 “Protecting the integrity and security

of client and corporate information is the responsibility of every employee.”; and,

50 Adapted from: H.A. Smith and J. McKeen, “Developments in Practice XXXIII: A

Holistic Approach to Managing IT-based Risk,” Communications of the AIS, December 2009,

p. 525.

193

“We need to embed an attention to digitalization risk management into all work

processes, business functions, work roles and positions, and employees.”

Risk Assessment

During risk assessment, each risk owner, usually with the support of in-

house experts and external consultants, estimates the risk exposure associated

with each of the risk areas for which the owner is responsible. Usually, some variant

of the following formula is used:

Risk Exposure = (Probability of Risk Occurring) X (Expected Loss If Risk Occurs)

Organizations specializing in overall or domain-specific risk management have

considerable knowledge, experience and data that can be tapped to produce

estimates of risk probabilities and expected losses. Just remember that these generic

estimates are only starting points that need to be tailored to the nuances of a given

organization and that expected losses should include both tangible and intangible

losses, as well as short-term and long-term losses. The risk of underestimating

expected losses is that an organization is then likely to under-invest in risk-related

policies, procedures and programs.

Once a risk area has been assessed, the owner must decide (again, with input

from others) how risks are to be addressed. Three actions are possible, alone or in

combination:

 Risk assumption: Accepting that losses are likely to arise if and when an incident occurs in a risk area, covering these losses through internal funds

and third-party insurance.

 Risk deterrence: Taking action to reduce the likelihood that an incident will occur in a risk area.

 Ongoing risk control: Monitoring a risk area such that the incident

194

occurrences are detected and resolved before excessive losses occur.

The risk assessment matrix shown as Figure 8-3 provides general guidance on

selecting an appropriate strategy for a risk area. Risk areas with low incident

probabilities and low expected losses can reasonably be assumed without taking

further action, while risk areas with high incident probabilities and high expected

losses require sophisticated strategies involving combinations of risk assumption, risk

deterrence and ongoing risk control.

Figure 8-3

Risk Assessment Matrix

Monitor continuously to immediately mitigate detected risk incidents

Take preemptive action to reduce the incident likelihood

Monitor continuously to immediately mitigate detected risk incidents

Take preemptive action to reduce the incident likelihood

Monitor continuously to immediately mitigate detected risk incidents

Monitor regularly to mitigate detected risk incidents

Monitor continuously to immediately mitigate detected risk incidents

Take preemptive action to reduce the incident likelihood

Monitor continuously to immediately mitigate detected risk events

Simply assume the risk Monitor regularly to mitigate detected risk incidents

Monitor continuously to immediately mitigate detected risk events

Expected Loss If a Risk Event Occurs

High

High

Medium

Medium

Low

Low

Ongoing Risk Control

Ongoing risk control involves monitoring for risk incidents, detecting that an

incident is about to occur (ideally) or has occurred (more likely), and taking action to

mitigate any losses arising from the incident. Risk mitigation involves tempering

(as much as possible) the consequences of a risk incident by taking corrective actions.

Prior to implementing ongoing control procedures, the risk owner needs to determine

195

the level of cost and effort to put into the procedures. Figure 8-4 illustrates the

complexity of this decision. The rational risk owner desires to neither under-invest

or over-invest in ongoing risk control. Here, again, heavy use is made of others’

knowledge and experience.

Figure 8-4

Determining the Cost of Ongoing Risk Control

Cost

Risk

Expected loss in the Absence of Risk

Deterrence/Mitigation

Cost of Risk Deterrence/Mitigation

Sweet Spot

An Exercise in Digitalization Risk Assessment51

An important element of the Coors Brewing Company’s marketing strategy

involves having retailers place eye-catching point-of-sales (POS) displays in their

stores. In implementing this strategy, Coors works with third-party marketing

partners and third-party providers to produce these display materials. However,

Coors owns the business processes that engage distributors and retailers in ordering

these POS display items. To motivate POS display orders, Coors provides each

51 This hypothetical exercise (used for illustrative purposes only) was developed by the

authors based on material from: J. Buffington and D.J. McCubbery, “Coors Brewing Company

Point of Sales Application Suite: Winning Mindshare with Customers, Retailers, and

Distributors,” Communications of the AIS, Volume 13, 2004, pp. 81-96.

196

wholesaler and retailer with a budget that can only be used to order POS display

items. Coors anticipates that at least some of the wholesalers and retailers will find

the display materials valuable in their efforts to increase sales and, in turn, that they

will order (display materials) beyond the Coors-provided funding.

Coors’ solution for digitalizing the business processes enabling distributors and

retailers to order promotional materials involved the building of a local (loosely

connected to other business platforms) business platform hosting five sets of

functionalities:

 Internet Interaction Portal: Enables distributors and retailers to

communicate with Coors and to gain access to the digitized business processes.

 Ordering General Materials: Enables distributors and retailers to order general promotional materials.

 Ordering Licensed Materials: Enables distributors and retailers to order licensed (i.e., NFL logos) promotional materials.

 Ordering Customized Materials: Enables distributors and retailers to design

and order customized promotional materials.

 Retail Store Display Placement: Enables distributors and retailers to visualize

and optimize, through the use of digitalized tools, the physical placement of promotional materials within a retail store.

These functionalities were collectively aimed at achieving three main objectives:

increasing sales of Coors products, having distributor and retailer staffs performing

much of the work autonomously, and building stronger relationships with the

distributors and retailers.

Now, consider a risk assessment that might have been performed by the risk

owner for this digitalized business platform. Table 8-5 summarizes this risk

assessment. Given this assessment, it would be reasonable to expect that a

digitalization risk management strategy put forward by the risk owner would involve:

197

 Deterring and mitigating malicious intrusions, through the local business platform, into Coors’ global digital platforms and business platforms.

 Ensuring that any future decision process to externalize any of the digital platforms enabling the local business platform carefully examine the

providers’ capabilities to secure their platforms against malicious intrusions.

 Establishing a vigilance regarding the potential for competitors to introduce retail shelf space innovations that could prove effective in taking market

share away from Coors’ products.

 Establishing a vigilance regarding the development of analytics technologies

and solutions aimed at the retail shelf space context.

Table 8-5 Risk Assessment for Coors’ POS Display Business Platform

Threat Situational Assessment Incident

Probability Expected

Losses

Malicious Intrusion

• Coors is a prominent firm selling a product (alcohol) that could be considered controversial.

• Internet exposure & distributor/retailer connectivity.

• Low loss exposure with the local business platform. • High loss exposure with global platforms.

High Low (local)

High (global)

Natural Disasters

• Favorable geographic location (Colorado front range).

Very Low Moderate

Legal & Regulatory

• Limited access to financial systems. • Limited privacy concerns.

Low Low

New Digital Technology

• Analytics technologies. • Collaboration technologies.

Moderate High

Actions of a Competitor

• Retail floor & shelf spaces are highly competitive commodities.

High High

External Sourcing

• Business platform unlikely to be externalized. • Digital platform likely to be externalized.

Moderate Moderate

Inability to Respond

• Analytic capabilities focused on optimizing the use of retail store shelf space.

Moderate High

Digitalization Risk Management Practices

Digitalization risk management practices (i.e., policies, procedures and

programs) cover a very broad range of complex and ever-moving topics – topics for

which it is impossible to do justice in a few pages of text. To provide a glimpse of

what organizations are doing, this section describes a few of the current practices

regarding one threat area: that of malicious intrusions. This threat area was selected

for two reasons. First, since significant cyber-security breaches are reported on by

198

news media on a regular basis today, most people are well aware of the topic.

Second, cyber-security breaches can result in huge financial losses, the size of which

is increasing annually. Data from 2010, for example, indicated that the average cost

of a security breach exceeded US $7 million.52

As a selection of the more common risk management practices for combating

malicious intrusions are described, note that a mix of technical and social mechanisms

are required. All too often, it seems, much more attention is given to the technical

practices, with the just-as-critical social practices being overlooked and/or

underfunded.

Securing Digital and Business Platforms Against Malicious Intrusions

It is impossible for any organization to fully protect itself against malicious

intrusions. That said, all organizations need to understand the intrusion risk

exposures of their digital and business platforms and take commiserate steps to both

harden these platforms and detect (and mitigate) any intrusions that occur.

Hardening a platform involves installation of hardware, software and

physical impediments that increase the effort required by a perpetrator, such that all

but the most determined perpetrators either bypass the platform (moving on to

easier targets) or are so hindered that they quickly give up. Detection involves

putting in place software and manual scanning processes that identify problematic

behaviors transpiring within digital platforms and business platforms.

52 R. Appan and D. Becic, “Impact of Information Technology (IT) Security Information

Sharing among Competing IT Firms on Firm’s Financial Performance: An Empirical

Investigation,” Communications of the Association of Information Systems, Vol. 39, 2016, pp.

214-241.

199

Perhaps the most recognized hardening tactics involve the use of firewalls,

encryption technologies, access control mechanisms, and physical barriers to develop

multi-layered defensive shields around an organization’s digital and business

platforms. Less prominent is identity management software that seeks to identify

(“Who are you?”), authenticate (“Can you prove your identity?”) and authorize

(“What are you allowed to do?”) attempts, legitimate and illegitimate, to access

platforms and their contents. The most difficult of these questions is

authentication. As the technology improves and costs drop, authentication

methods are moving away from examining what you know (e.g., a password) to

examining something you have (e.g., biometrics such as the use of fingerprints, iris

scans, voice scans, etc.).

The most familiar detection tools are those directed at viruses (i.e., malicious

software code), that have eluded the barriers erected in hardening a platform. Less

visible are the huge investments organizations make in (1) capturing and then

analyzing the streams of digitalized transactions being executed on digital and

digitalized platforms, and (2) embedding processing logic into the software handling

these transactions to identify and reroute problematic transactional events.

Intra-Organizational Information Sharing Regarding Malicious Intrusions

As emphasized earlier, digitalization risk management is a participation sport

demanding the involvement of all employees. However, organizations’ employees

demonstrate wide variance in: their awareness of, knowledge of and sensitivity to

security breaches; their platform access privileges; their willingness to act in

compliance with security breach policies and procedures; and, their abilities to act

appropriately in the face of a security breach.

200

Because of these variances, many organizations are including comprehensive

intra-organizational information dissemination and sharing programs as prominent

components of their efforts to prevent and mitigate malicious intrusions. These

programs typically include:

 Awareness Training: All employees are made aware of the basics of cyber-

security risk management (both work-related and home-computer use) and, specific to each employee, those risks most likely to arise as employees carry out their day-to-day work activities.

 Platform Usage Training: Each employee interacting with a specific digital or business platform is provided with the knowledge and skills to effectively

deal with the digitalization risks associated with that platform.

 Specialized Training: All technology professionals and all risk owners are provided with advanced education to develop the capabilities needed for

them to carry out their assigned responsibilities.

 Technical Support: All employees are provided ready access to a cyber-

security support group that can answer questions that arise regarding the risk of malicious intrusions and that can aid an employee when faced with a

probable or actual security breach.

Extra-Organizational Information Sharing about Malicious Intrusions

Organizations’ leadership teams are increasingly recognizing the value of the

external sharing of information about security breaches. Initially, most organizations

were reluctant to report on security breach incidents because of the expectation that

most stakeholders (e.g., consumers, value stream participants, strategic partners,

securities analysts, etc.) would react negatively, at least in the short-term. However,

201

the consequences of reported security breaches, while still negative, have been

declining over time.53,54 Three explanations for this decline are:

 More effective remediation and disaster recovery by firms, as well as a decrease in customers refraining from doing business with firms that experienced a security breach.

 The U.S. Government’s promotion, since 1999, of industry-based trade associations known as information sharing and analysis centers (ISACs). As

of 2016, there are eighteen sector-based ISACs coordinated under a National Council of ISACs.

 The enactment of federal and state security breach notification laws.

As more organizations actively gather and share information on digitalization-

risk threats, vulnerabilities and incidents, as well as best practices in digitalization

risk management, their capabilities to combat malicious intrusions will only improve.

Rather than feeling as if they are working alone against an increasingly hostile world,

organizations’ risk specialists and risk owners will increasingly find themselves

coordinating with and collaborating with their peers in other organizations, including

competitors, in order to drive informed decision making.

The Board of Directors and Digitalization Risk Management

As a general rule, those organizations most successful in applying digitalization

for competitive purposes have developed exceptional capabilities in digitalization risk

management. But, who, ultimately, is accountable for the quality of an organization’s

53 L. Gordon, M. Loeb and L. Zhou (2011), “The Impact of Information Security

Breaches: Has There Been a Downward Shift in Costs?”, Journal of Computer Security, Vol.

19, No. 1, 2011, pp. 33–56. 54 S. Goel and H.A. Shawky, "The Impact of Federal and State Notification Laws on

Security Breach Announcements," Communications of the Association for Information

Systems: Vol. 34, January 2014, pp. 37-50.

202

digitalization risk management capabilities? With a public firm, it is the firm’s Board

of Directors.

However, most Boards of Directors have only gradually – and grudgingly –

stepped up to their oversight responsibilities regarding digitalization risk

management. For example, studies55,56,57 of Boards of Directors portray the following

practices:

 Board members are not actively recruited for their digitalization expertise. Few executives of organizations recognized as digitalization leaders are

members of Boards of Directors.

 Very limited discussions of digitalization take place at Board meetings.

 When digitalization is discussed at Board meetings, these discussions tend to

be after-the-fact updates regarding recent, significant digitalization initiatives.

 Most of this limited discussion of digitalization occurs in Board committee meetings. Most often, this committee tends to be the audit committee,

where the issues raised are done so in reaction to a problematic event.

 Few Boards of Directors have a committee focused exclusively on digitalization.

Overall, a state of complacency regarding digitalization continues, with Board

members believing that their organization’s leadership team has a solid handle on

managing the risks of digitalization. That said, a growing number of exceptions to

this general depiction can be observed in recent trends regarding Boards of Directors

and digitalization.

55 S. Huff, P. Maher and M. Munro, “Information Technology and the Boards of

Directors: Is there an IT Attention Deficit,” MISQ Executive, June 2006, pp. 55-68 56 M. Parent and B. Reich, “Governing Information Technology Risk,” California

Management Review, Spring 2009, pp. 134-152. 57 S. Andriole, “Boards of Directors and Technology Governance: The Surprising State

of the Practice,” Communications of the CAIS, Volume 24, Article 22, 2009, pp. 373-394.

203

What should be the role of Boards of Directors in managing digitalization risk?

Three Board responsibilities are most important. The Board of Directors must assure

that their organization is not overly exposed to digitalization risks that threaten

business continuity, regulatory compliance and competitive success. In order for

these responsibilities to be met, Boards of Directors need to adopt best practices such

as:58,59

 Bringing members with digitalization experience and expertise onto the Board.

 Regularly inviting senior executives whose work responsibilities involve strategically-critical digitalization initiatives to Board meetings.

 Systematically including digitalization issues on the agenda of full Board

meetings. For the most part, the focus of these discussions needs to address strategic rather than tactical issues, including Board reviews of all

major digitalization-related assets, investments and initiatives.

 Establishing a Board digitalization committee.

Accounting for Digitalization Risks in Digital Strategy Formulation

Digitalization risks affect digital strategists’ thinking in two ways: by adding

layers of complexity onto their efforts to enhance existing business models and to

innovate with new business models, and by requiring that the requisite capabilities

are in place to enable both business model formulation and business model

implementation. Table 8-6 describes how each of the four elements of business

models are influenced.

58 M. Bloch, B. Brown and J. Sikes, “Elevating Technology on the Boardroom Agenda,

McKinsey Quarterly, 2013, No. 1, pp. 99-103. 59 H. Sarrazin and P. Willmott, “Adapting Your Board to the Digital Age,” McKinsey

Quarterly, 2016, No. 3, pp. 89-95.

204

Table 8-6 How Business Models Are Affected by Digitalization Risks

Value Propositions Profit Models

 Provide value in return for personal data that is captured, archived and/or used.

 Ensure the security, and hence the trustworthiness, of digital platforms and business platforms.

 Comprehensively and accurately account for the digitalization risk management costs associated with developing, implementing and evolving a business model.

Core Capabilities Dynamic Capabilities

 Digitalization risk management capabilities (accounting for all threat areas).

Tuning of digital strategists’ environmental scanning regarding:  Digitalization threats.  Digital technologies.  Strategic capabilities.  External sourcing providers.  Competitors’ business model

innovations.

Increasingly, critical features of the value propositions being offered to pipeline

ecosystem consumers and network ecosystem participants are dependent on

personal data provided by or collected about individuals. If an individual feels the

quid pro quo is inadequate, the individual is unlikely to engage, partially or fully, in

market ecosystem interactions. Similarly, market ecosystem participants lacking

trust in the platforms enabling a value proposition would be expected to refrain from

platform interactions.

The long-term expectation from aggregating the profit models associated with

a business model is that the business model will prove profitable. However, if a

business model’s risk exposure requires extensive digitalization risk management

capabilities, and if the investment and operating costs associated with these

capabilities are not fully accounted for in the business model’s aggregated profit

models, then what might appear initially to be a very successful business model is

likely to become a huge liability over time.

205

If nothing else, this chapter’s content should have driven home the point that

in a world of pervasive digitalization, digitalization risk management has become a

core capability for all organizations and a strategic capability for some (e.g., financial

services organizations, e-commerce organizations, cloud-based organizations, etc.).

If digitalization knowledge and experience is not represented within organizations’

senior leadership teams, as well as within the Board of Directors of private firms,

then it becomes unlikely that a strong digitalization risk management capability will

be developed.

Finally, and most importantly, as extensive digitalization pervades an

organization’s strategies and operations, the breadth of the organization’s dynamic

capabilities must span an increasingly-wide gamut of markets, competitors, strategic

partners, strategic capabilities and digital technologies.

A Recap and Look Ahead

Competitive success in the face of digital disruption requires organizations’

leadership teams and digital strategists to demonstrate relentless vigilance with

regard to digitalization opportunities and, as covered in this chapter, digitalization

threats. But, how can such a mindset be established within an organization’s

members? In the next chapter, six actions aimed at just such an objective are

described.

GLOSSARY

Authentication – techniques aimed at proving a person’s or a digital entity’s

identity.

Business platform operations – the execution of an organization’s digitalized

operational and managerial processes that are hosted on business platforms (and on market platforms).

Cybercriminal – uses hacking techniques and tools in order to take illegal actions

for financial gain or to take over digital assets in order to launch a series of illegal actions.

Data privacy – concerns that arise wherever personally-identifiable or other sensitive information is captured, collected, stored and used.

Detection – putting in place software and manual scanning processes that identify

problematic behaviors transpiring within digital platforms and business platforms.

Digital assets – digital technologies (hardware and software), digitized data, and

digitization/digitalization capabilities applied in configuring digital platforms and business platforms.

Digitalization risk – the likely occurrence of digitalization-related incidents that

have the potential to negatively impact an organization’s operational performance and/or competitive position.

Financial loss – theft; fraud; extortion; destruction of uninsured facilities, equipment and materials; drops in stock valuations; regulatory fines; legal fees, court

awards and out-of-court settlements; etc.

Graceful degradation – operations affected by a natural disaster do not immediately shut down, but instead gradually slow down, allowing time for affected

operations to be shifted to other physical locations prior to a complete shutdown.

Hactavist – uses hacking techniques and tools for the purpose of bringing attention

to a social or political issue.

Hardening a platform – installation of hardware, software and physical impediments that increase the effort required by a perpetrator such that all but the

most determined perpetrators either bypass the platform (moving on to easier targets) or are so hindered that they quickly give up.

Intellectual property loss – theft of digitized ideas, innovations and other forms of creative expression (e.g., trade secrets; blueprints; digitalized processes; proprietary digital content; the underpinnings of strategies and business models;

etc.).

Internal controls – the processing logic and rules embedded within digitalized financial reporting systems to ensure the correct handling of financial transactions

and the accuracy of produced financial reports.

Legal and regulatory requirements – digitalization-related statutory policies and

rules requiring protective actions, most often aimed at preventing harm to others.

Malicious intrusion – a perpetrator’s success in getting through an organization’s security-related defenses.

Natural disaster – tornadoes, hurricanes, earthquakes, tsunamis, nuclear emergencies, collapsed dams, broken gas or water pipes, etc.

Ongoing risk control – monitoring a risk area such that the incident occurrences are detected and resolved before excessive losses occur.

Reputation loss – depreciation of an organization’s image or of its brands that

undermines the trust and goodwill held by participants in the various market-focused ecosystems with which the organization participates.

Revenue loss – short-falls in revenue streams or lost revenue streams traced to operational disruptions, reputation loss, the inability to respond effectively to competitors’ actions, etc.

Risk assessment – estimate the risk exposure associated with a risk area.

Risk assumption – accepting that losses are likely to arise if and when an incident

occurs in a risk area, covering these losses through internal funds and third-party insurance.

Risk deterrence – taking action to reduce the likelihood that an incident will occur in a risk area.

Risk exposure – the probability of a risk occurring multiplied by the expected loss

to be borne if the risk occurs.

Risk management – creating awareness and a common understanding across an

organization’s members about the existence and nature of a risk domain; and, putting in place risk management policies, procedures and programs to ensure that that critical risks in the domain are appropriately addressed by the appropriate individuals.

Risk mitigation – tempering (as much as possible) the consequences of a risk incident by taking corrective actions.

Risk planning – establishes the contexts within which risk management activities are carried out.

Terrorist – uses hacking techniques and tools for the purpose of causing harm and

havoc within an established geo-political order.

  • Chapter 8. Grappling with the Risks of Digitalization
    • Nature of Digitalization Risks
    • Risk Management: A General Overview
    • Digitalization Risk Management Practices
    • The Board of Directors and Digitalization Riskl Management
    • Accounting for Digitalization Risks in Digital Strategy Formulation
    • A Recap and Look Ahead
  • GLOSSARY