Access and Feeds

Emerging Technology Risks: Casting a Blind Eye

By Dick Weisinger

Emerging Technologies are making life difficult for auditors — and nervous.   Methodologies for calculating risks badly need to be updated in order to better assess risks.  While maybe not a perfect example, and maybe more a question of inadequate due diligence, HP’s recent disastrous $11 billion purchase of Autonomy comes to mind as one deal where technology risks were not carefully thought through.

But consider the many new technologies that companies are now aggressively adopting: cloud computing, smart phones, tablet computers, BYOD, social media, mobile computing, and more.  As attractive as these technologies may be, how can adoption risks associated with these technologies be assessed if these technologies push the envelope and have no long term track record?  This is not to mention that taking on new IT projects have a staggeringly high failure rate — as high as 68 percent.  And, on the other side, how much should the risk of ignoring these new technologies be weighted?

Craig Glindemann, partner at EY, said that “Risks fall into two categories – IT and non-IT.  The non-IT risks are around organisations failing to take advantage on innovation at the same rate as their competitors. IT, on the other hand, is about a host of issues within organizations – such as consumerization or digital security.”  On the IT side, not having a full grasp of the implementations of a new technology can have dramatic ramifications.

A report from Grant Thornton LLP found that the top worries with emerging technologies among auditors are in the areas of:

  • Cybersecurity
  • Mobile technology
  • Business interruption
  • Social media
The Grant Thornton report concluded that “Internal audit faces many challenges in auditing emerging technology risks. Not only is it a nontraditional, complex and fast-evolving area, but there are many portals through which risks can enter.”
Exactly how to quantify risks and incorporate those risks into a long term plan is difficult.  Often, if not well understood, the potential risks with technology are just overlooked.   Only 31 percent of auditors say that they consider risk factors related to technologies like cloud computing when making their audit reports, while 50 percent do not include such risks and 19 percent say that there is no need to.
Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*