Harmonizing Information Technology and Business Strategy Risks: A Holistic Approach to Enterprise Risk Management

Technology Risk is Now a Strategic Risk

Risk is no longer a back-office exercise; it is a strategic initiative that warrants the attention of executive leadership. Enterprise Risk Management (ERM) gives executive leaders a disciplined way to see around corners, connect risk to strategy, and make better decisions before disruption becomes consequence. A well-designed ERM program does more than identify and mitigate threats; it helps organizations recognize emerging opportunities, strengthen resilience, protect stakeholder value, and align risk-taking with the company’s growth objectives. As financial, strategic, operational, technology, cyber, and compliance risks become increasingly interconnected, leaders can no longer afford to manage risk in silos. Now is the time for executive teams to challenge whether their ERM program is truly informing strategy, enabling performance, and preparing the organization for what comes next.

This article delves into the symbiotic relationship between IT and enterprise risk management, advocating for a cohesive strategy that supports resilience, competitive advantage, and sustainable growth in the face of technological disruption. The core takeaway is simple: IT risk should not be managed as a separate technical concern but as an enterprise risk that directly affects strategy, operations, compliance, reputation, and value creation. Organizations continue to adopt AI, including large language models (LLMs), small language models (SLMs), machine learning (ML), generative AI, and emerging agent-based tools. Assessing the related risks and opportunities through an established ERM framework can help leaders understand how technology decisions affect business processes, controls, data integrity, and long-term performance.

The Need for Integration

The role of IT has always been to enable the business to scale, achieve strategic objectives efficiently, and manage risks effectively. Combining IT risk management with overall ERM helps ensure that technology-related risks are considered as part of the broader enterprise risk profile and embedded within the organization’s overall risk culture. This is increasingly important as AI adoption, third-party technology reliance, cybersecurity threats, data privacy expectations, and regulatory scrutiny continue to expand. IT disruptions can affect operations, the reliability of data, compliance obligations, customer trust, and a company’s ability to compete in the market.

Companies should strive to merge their IT risk management with enterprise-wide risk management strategies, especially as they deal with the complicated issues of today’s digital world. Although it’s not without its difficulties, if companies are dedicated and use the right methods, they can evaluate risks more holistically by connecting IT risks and broader strategic business risks. This helps them manage risks more effectively. Additionally, when a company’s IT risks align with its main goals, it can become stronger, move faster, and stand out from the competition.

Guiding Principles

Strong ERM is not built on static checklists; it is built on foresight, ownership, and adaptability. To effectively connect IT risk with enterprise strategy, organizations need proactive risk identification, regular assessment, clear accountability, and a culture where risk-informed decision-making becomes part of how the business operates. As technology, AI adoption, cyber threats, and business priorities continue to evolve, risk management processes must evolve with them. Executive leaders should challenge their teams to look beyond traditional IT risk registers and ask: Where could technology disrupt our strategy? Where can it create competitive advantage? And how can we use it to strengthen resilience, efficiency, and decision-making across the enterprise?

Governance and Culture

Effective governance requires the support and commitment of senior management. Cultivating a risk-aware culture across the organization encourages proactive identification and management of IT risks through the lens of how they support critical business objectives. Integrating IT risk into this process requires a clear understanding of the technology landscape and its impact on business operations. It starts with tone at the top. The IT function can no longer be viewed as an obstacle or merely a cost center but as a value-added support function for the entire organization. A company is only as reliable as the integrity of its data, systems, and technology-enabled processes. Enterprise Risk Management is not fully addressed if it does not account for the technology environment supporting the organization.

Clear communication channels must be established to ensure that relevant risk information is disseminated throughout the organization. This supports a unified approach to managing IT risks within the ERM framework. Aligning business objectives and strategic plans with IT initiatives and security configurations will allow for more streamlined, less obtrusive, and more effective processes than if they were considered separately or not at all.

Cyber Risk Mitigation

A cybersecurity review is a critical complement to an ERM review due to the specialized nature of cyber threats that require focused attention beyond the scope of traditional ERM frameworks. While ERM encompasses a broad spectrum of enterprise risks, including financial, operational, strategic, and compliance risks, cybersecurity reviews delve more deeply into the protection of networks, systems, devices, third-party connections, and data from cyber threats. This has become even more important as organizations face AI-enabled social engineering, ransomware, data leakage, vendor concentration risk, and heightened expectations from boards, regulators, customers, and insurers. A dedicated cybersecurity review helps organizations identify and mitigate specific vulnerabilities within their IT infrastructure and digital assets, while also informing the broader enterprise risk profile. This specialized review is essential for ensuring that cybersecurity measures remain current and effective against emerging threats, thereby complementing the broader risk management strategies established by ERM.

KPIs, Performance Measurement, KRIs, and Tolerance

Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and risk tolerance levels must be established to measure the effectiveness of IT risk management within the ERM framework. An organization’s risk appetite, determined at the enterprise level, will dictate how much risk the organization is willing to tolerate. Aligning IT risks with this methodology helps ensure that technology risks are evaluated and responded to consistently with other organizational risks. This also allows leadership to better connect technical indicators to business impacts. Technical indicators may include control exceptions, system availability, access issues, cyber events, or data quality concerns, while business impacts may include financial reporting reliability, operational disruption, regulatory exposure, customer experience, or strategic execution.

Challenges

While alignment is the key, it does not come without challenges. Many organizations continue to view IT as a separate function, which can make integration with the broader enterprise risk program feel like a significant undertaking. There is also often a language barrier between business and IT teams, further complicating the process. However, this can be addressed by including appropriate technology stakeholders in the risk assessment process, such as data owners, system owners, security leaders, IT support contacts, or business process owners who rely on key applications and data.

Another challenge organizations face is determining who owns the risks. Technology risks may be assigned to IT, but the business impact often extends well beyond the IT function. For example, an access control weakness, system outage, data quality issue, or third-party technology failure may be technical in nature, but the consequences can affect financial reporting, operations, customer delivery, regulatory compliance, and reputation. A mature ERM program helps clarify ownership by distinguishing between the party responsible for managing the technology risk and the business leaders accountable for understanding and responding to the related impact.

When IT risk sits outside the ERM framework, leaders lose visibility into the technology dependencies, cyber exposures, data integrity issues, third-party risks, and AI governance gaps that can directly affect strategy, operations, compliance, reputation, and enterprise value. As technology, AI, cyber threats, and business transformation accelerate, organizations must challenge whether their current ERM program is keeping pace with the risks and opportunities reshaping the business. Executive leaders who evaluate technology risk with the same discipline, urgency, and strategic lens as other enterprise risks position their organizations to adapt faster and perform stronger through disruption.

How Centri Can Help

The strongest ERM programs proactively treat technology risk as a strategic advantage, not an afterthought, giving leaders the visibility and confidence to act before issues become disruptions. Now is the time to assess whether technology risk is fully integrated into enterprise strategy, risk appetite, board reporting, and decision-making. Centri can help organizations evaluate ERM maturity, identify blind spots, and build a practical roadmap for stronger resilience and performance.

At Centri, our Risk Advisory practice is designed with your greatest assets in mind — your people. We’re here to offer you the support, resources, and expertise you need, exactly when you need it most. Our advisory experts specialize in creating right-sized ERM programs, performing ERM maturity assessments and gap analysis, and providing meaningful results and solutions. We work alongside your senior leadership to help understand your current needs and align them with the right solutions. Please contact us for more information or to explore how our expertise in risk advisory and enterprise risk management aligns with the specific needs of your company.

Editor’s note: This article was originally published on July 22, 2024. It was updated on August 7, 2026.

Karyn DiMassa headshot.

Karyn DiMassa

Managing Director | CPA, PMP, CISA, CFE

Karyn is a Managing Director in the IT Risk & Cybersecurity Practice at Centri Business Consulting. She has more than 15 years of combined experience in internal IT audit and external audit support (IT controls), third-party assurance (SOC 1 and SOC 2 reporting), internal controls consulting, project management, IT risk and cybersecurity, and system implementation support. View Karyn DiMassa's Full Bio

About Centri Business Consulting, LLC

Centri Business Consulting provides the highest quality advisory consulting services to its clients by being reliable and responsive to their needs. For 15 years, Centri has delivered trusted expertise to help companies meet their evolving reporting demands. Centri specializes in financial reportinginternal controlstechnical accounting research, outsourced accounting, valuationmergers & acquisitions, and tax, CFO and HR advisory services for companies of various sizes and industries. From complex technical accounting transactions to monthly financial reporting, our professionals can offer any organization the specialized expertise and multilayered skillsets to ensure the project is completed timely and accurately.

Philadelphia
3 Logan Square
26th Floor
1717 Arch Street
Philadelphia, PA 19103
New York City
530 Seventh Avenue
Suite 2201
New York, NY 10018
Raleigh
4509 Creedmoor Rd
Suite 206
Raleigh, NC 27612
Boston
50 Milk St.
18th Floor
Boston, MA 02109
Tysons Corner
1775 Tysons Blvd
Suite 4131
McLean, VA 22102
Denver
One Tabor Center
1200 17th St.
Floor 10
Denver, CO 80202
Tampa
615 Channelside Drive
Suite 207
Tampa, FL 33602
Atlanta
1175 Peachtree St. NE
Suite 1000
Atlanta, GA 30361
Dallas
1920 McKinney Avenue
Dallas, TX 75201
Minneapolis
8481 Jefferson Hwy.
Minneapolis, MN
55369-4588

03/28/2024

Understanding The NIST AI Risk Management Framework & Why It Matters

Need guidance spotting and disclosing uncertain tax positions? This guide will give...

Read More

12/09/2024

Navigating Third-Party Risks in the Insurance Industry

In today’s interconnected world, the insurance industry relies heavily on third-party vendors,...

Read More

08/07/2026

From Defense to Direction: Using the IIA’s Three Lines Model to Drive Stronger Risk Governance

Organizations are operating in an ever-changing and increasingly complex environment. The use...

Read More

02/25/2019

Accounting Update & Risk Considerations for Cloud Computing Arrangements

In August 2018, Financial Accounting Standards Board (FASB) issued ASU 2018-15 Intangibles-Goodwill...

Read More

06/12/2025

The Human Element: How to Turn Your Biggest Risk into Your Best Defense

In an era where firewalls and encryption are stronger than ever, cybercriminals...

Read More

Related Services