• Current students
      • Student centre
        Enrol on a course/exam
        My enrolments
        Exam results
        Mock exams
      • Course information
        Students FAQs
        Student induction
        Course enrolment information
        F2f student events
        Key dates
        Book distribution
        Timetables
        FAE elective information
        CPA Ireland student
      • Exams
        CAP1 exam
        CAP2 exam
        FAE exam
        Access support/reasonable accommodation
        E-Assessment information
        Exam and appeals regulations/exam rules
        Timetables for exams & interim assessments
        Sample papers
        Practice papers
        Extenuating circumstances
        PEC/FAEC reports
        Information and appeals scheme
        Certified statements of results
        JIEB: NI Insolvency Qualification
      • CA Diary resources
        Mentors: Getting started on the CA Diary
        CA Diary for Flexible Route FAQs
      • Admission to membership
        Joining as a reciprocal member
        Admission to Membership Ceremonies
        Admissions FAQs
      • Support & services
        Recruitment to and transferring of training contracts
        CASSI
        Student supports and wellbeing
        Audit qualification
        Diversity and Inclusion Committee
    • Students

      View all the services available for students of the Institute

      Read More
  • Becoming a student
      • About Chartered Accountancy
        The Chartered difference
        Student benefits
        Study in Northern Ireland
        Events
        Hear from past students
        Become a Chartered Accountant podcast series
      • Entry routes
        College
        Working
        Accounting Technicians
        School leavers
        Member of another body
        CPA student
        International student
        Flexible Route
        Training Contract
      • Course description
        CAP1
        CAP2
        FAE
        Our education offering
      • Apply
        How to apply
        Exemptions guide
        Fees & payment options
        External students
      • Training vacancies
        Training vacancies search
        Training firms list
        Large training firms
        Milkround
        Recruitment to and transferring of training contract
      • Support & services
        Becoming a student FAQs
        School Bootcamp
        Register for a school visit
        Third Level Hub
        Who to contact for employers
    • Becoming a
      student

      Study with us

      Read More
  • Members
      • Members Hub
        My account
        Member subscriptions
        Newly admitted members
        Annual returns
        Application forms
        CPD/events
        Member services A-Z
        District societies
        Professional Standards
        ACA Professionals
        Careers development
        Recruitment service
        Diversity and Inclusion Committee
      • Members in practice
        Going into practice
        Managing your practice FAQs
        Practice compliance FAQs
        Toolkits and resources
        Audit FAQs
        Practice Consulting services
        Practice News/Practice Matters
        Practice Link
      • In business
        Networking and special interest groups
        Articles
      • Overseas members
        Home
        Key supports
        Tax for returning Irish members
        Networks and people
      • Public sector
        Public sector presentations
      • Member benefits
        Member benefits
      • Support & services
        Letters of good standing form
        Member FAQs
        AML confidential disclosure form
        Institute Technical content
        TaxSource Total
        The Educational Requirements for the Audit Qualification
        Pocket diaries
        Thrive Hub
    • Members

      View member services

      Read More
  • Employers
      • Training organisations
        Authorise to train
        Training in business
        Manage my students
        Incentive Scheme
        Recruitment to and transferring of training contracts
        Securing and retaining the best talent
        Tips on writing a job specification
      • Training
        In-house training
        Training tickets
      • Recruitment services
        Hire a qualified Chartered Accountant
        Hire a trainee student
      • Non executive directors recruitment service
      • Support & services
        Hire members: log a job vacancy
        Firm/employers FAQs
        Training ticket FAQs
        Authorisations
        Hire a room
        Who to contact for employers
    • Employers

      Services to support your business

      Read More
☰
  • Find a firm
  • Jobs
  • Login
☰
  • Home
  • Knowledge centre
  • Professional development
  • About us
  • Shop
  • News
Search
View Cart 0 Item

News

  • Home/
  • News
☰
  • News
  • News archive
    • 2024
    • 2023
  • Press releases
    • 2025
    • 2024
    • 2023
  • Newsletters
  • Press contacts
  • Media downloads

Managing technology risk in a fast-changing world

Mar 08, 2024

Managing cyber security and other technology-related risks is becoming an increasingly complex business. Sara McCallister explains why.

With a growing need for technology assurance—from cyber security and transformation programmes to the use of AI, cloud services and third parties—what do internal audit and technology risk professionals need to know to protect organisations today?

Cyber security

Cyber security continues to be a critical business risk for organisations in Ireland and globally.

While data loss and service disruption continue to be two biggest risks associated with a cyber-attack, ransomware attacks are also significant.

According to a 2023 Sophos report, 66 percent of organisations globally have been hit by a ransomware attack in the last year. Cybercriminals succeeded in encrypting data in just over three-quarters (76%) of these attacks.

Third-party management

To manage service continuity risks, information privacy and security, organisations need an effective framework of third party controls.

IT and technology teams are among the most active users of third-party products, such as tools, software-as-a-service (SaaS) solutions and the direct outsourcing of business activities. This gives organisations access to a much wider range of skills and greater flexibility to scale up or down with demand.

Outsourcing the responsibility for these services doesn't outsource the associated risks, however. Organisations need to expand their range of assurance activities to cover third-party providers.

Generative AI

The risks associated with generative AI are critical due to its widespread adoption.

Concerns include the potential for biased outputs, security vulnerabilities and misuse of generated content for malicious purposes. Deep fakes, misinformation and ethical dilemmas also pose challenges.

As generative AI becomes integral to different sectors, understanding and mitigating these risks is essential to maintaining trust, safeguarding privacy and ensuring responsible deployment.

Timely attention to these concerns is crucial in preventing unintended consequences, protecting against malicious uses and establishing robust frameworks for the ethical and secure implementation of generative AI.

Transformation programmes

Organisations are adopting and experimenting with leaner and faster approaches to delivering transformation.

Many are dealing with the challenge of legacy IT, outdated infrastructure and applications that are still in use and prevent more modern practices, exposing them to availability risks and cyber security vulnerabilities.

Cloud assurance

In recent years, the use of cloud solutions has increased rapidly. Organisations use cloud solutions to host their critical systems, such as enterprise resource planning (ERP) and customer-facing applications, or sensitive data, such as personal or intellectual property.

The proposed changes to the UK Corporate Governance Code (the Code) have heightened the focus on organisations’ financial and IT control frameworks ahead of the 2025 deadline. This would include controls in cloud environments.

Organisations still face challenges around cloud controls and assurance, inconsistent approaches across assurance teams, cloud concentration risks and lock-in with vendors.

There is also a shortage of cloud-risk specialists who can help organisations to determine whether practices are aligned with recommendations from the Cloud Security Alliance and cloud service providers.

Identity and access management

One of the foundational pillars of securing your organisation's data is ensuring you are adequately managing access to this information. This includes authenticating access, authorising access based on genuine business needs and monitoring and reviewing access to data.

Organisations need robust frameworks in place to manage access to their information and reduce the risk of inappropriate or unauthorised access, which could cause significant loss.

Technology resilience

In a technology-dependent world, it is often critical that an organisation's IT infrastructure and applications are resilient and continue to operate at acceptable levels during unexpected events or when elements of its technology environment are compromised.

Data management and quality

The risks associated with data management and quality are paramount as they directly impact decision-making, business operations and regulatory compliance.

Robust data management mitigates cyber security risks, safeguarding sensitive information from breaches.

Compliance with data protection regulations, such as GDPR, hinges on accurate data handling.

Addressing these risks ensures organisations can trust their data, supporting decision-making, maintaining customer trust and complying with legal requirements in a data-driven business landscape.

Sara McCallister is Partner, Business Risk Operations, Grant Thornton

The latest news to your inbox

Please enter a valid email address You have entered an invalid email address.

Useful links

  • Current students
  • Becoming a student
  • Knowledge centre
  • Shop
  • District societies

Get in touch

Dublin HQ

Chartered Accountants
House, 47-49 Pearse St,
Dublin 2, D02 YN40, Ireland

TEL: +353 1 637 7200
Belfast HQ

The Linenhall
32-38 Linenhall Street, Belfast,
Antrim, BT2 8BG, United Kingdom

TEL: +44 28 9043 5840

Connect with us

Something wrong?

Is the website not looking right/working right for you?
Browser support
CAW Footer Logo-min
GAA Footer Logo-min
CCAB-I Footer Logo-min
ABN_Logo-min

© Copyright Chartered Accountants Ireland 2020. All Rights Reserved.

☰
  • Terms & conditions
  • Privacy statement
  • Event privacy notice
  • Sitemap
LOADING...

Please wait while the page loads.