Emerging IT Risks: Insights from German Banking

被引:0
|
作者
Simon Ashby
Trevor Buck
Stephanie Nöth-Zahn
Thomas Peisl
机构
[1] University of Plymouth,Plymouth Business School
[2] Glasgow University,Adam Smith Business School
[3] Edinburgh Napier University,undefined
关键词
cyber risk; emerging risks; enterprise risk management;
D O I
暂无
中图分类号
学科分类号
摘要
How do German banks manage the emerging risks stemming from IT innovations such as cyber risk? With a focus on process, roles and responsibilities, field data from ten banks participating in the 2014 ECB stress test were collected by interviewing IT managers, risk managers and external experts. Current procedures for handling emerging risks in German banks were identified from the interviews and analysed, guided by the extant literature. A clear gap was found between enterprise risk management (ERM) as a general approach to risks threatening firms’ objectives and ERM’s neglect of emerging risks, such as those associated with IT innovations. The findings suggest that ERM should be extended towards the collection and sharing of knowledge to allow for an initial understanding and description of emerging risks, as opposed to the traditional ERM approach involving estimates of impact and probability. For example, as cyber risks emerge from an IT innovation, the focus may need to switch towards reducing uncertainty through knowledge acquisition. Since individual managers seldom possess all relevant knowledge of an IT innovation, various stakeholders may need to be involved to exploit their expertise.
引用
收藏
页码:180 / 207
页数:27
相关论文
共 50 条