Risk culture is no longer a taboo subject in companies. Every day, the news brings a new wave of threats whose consequences can be severe for the operations and long-term viability of organizations.
Logically enough, as digitalization increases, CIOs are well placed to play a key role in managing these risks, especially since purely IT risks (cybercrime, datacenter failure, defaulting Contractor…) are credible and pose tangible threats.
But behind the general concepts, it’s the operational reality of all IT projects that needs to be analyzed and managed. Of course, not all IT projects are created equal.
So how do you effectively steer risk management in an IT department? From identification to analysis, from assessment to treatment of risk, how can we arm ourselves with pragmatism and discernment? Here are some answers.
What is a risk?
A risk is a potential problem in the execution of a project or activity, identified in advance. Put another way, a risk is a point of weakness whose occurrence could have a negative impact on the smooth running of a project, by taking it away from the initial scenario imagined when it was launched.
What are the possible risks involved in an IT project?
Risks can be grouped into 3 main categories:
- Product risks: the deliverables may inherently contain technical or functional difficulties, or security gaps, so we need to assess what these complexities are.
- Risks associated with the resources allocated to the project: these may include both human and material resources. Examples of fairly common risks: Budgets that get out of control or are insufficient, a skills shortage, or a lack of team availability.
- Organizational change management (OCM) risks: implementation, availability, user management.
If, in these 3 categories, a point stands out during the analysis phase, it constitutes a potential risk. The challenge is then to assess its severity and the likelihood of its occurrence.
How do you assess risk?
There are numerous risk mapping and assessment methodologies, with the aim of ensuring that nothing is overlooked, and developing a scoring system for prioritizing risks. For a non-expert, Manage project risks can be a frightening prospect, as you quickly get the impression that it requires advanced skills that are difficult to master without dedicated training.
But does that mean we should bury our heads in the sand? Certainly not. Instead, let’s keep in mind that there is no ready-made formula for identifying the risks of an IT project, nor any magic training program. By nature, a risk will depend on numerous factors, both internal and external to the company. Above all, a solid understanding of this context is what will enable us to identify them with discernment, ensuring that we don’t overlook anything.
So, short of perfect mastery of “certified” methodologies for mapping and assessing risks, let’s start by considering that, within a CIO, managing risks is first and foremost a matter of sound, concrete project management, open to the hazards that could have an impact on the course of things.
IT departments are well-positioned to carry out these tasks: “culturally,” a CIO naturally develops analytical and assessment skills that are perfectly aligned with a way of managing project risks. Thus, once a risk has been identified, a key step is to assess it using a scoring system. A risk with a high score will require tracking. A minor risk can be set aside. However, knowing how to score a risk to prioritize it is not so different from knowing how to score a project to evaluate it. Both situations call for the objectivity and pragmatism of mathematical models.
Example of a risk criticality matrix :

How to implement pragmatic Manage project risks?
Depending on its size, a CIO often manages a substantial volume of projects, but not all projects are created equal: they do not all have the same sensitivity, criticality, or scope (in terms of resources allocated, duration, etc.). Managing project risks must thereforebe pragmatic.
This is especially true given that many CIOs—and, more broadly, small and medium-sized businesses—do not have a risk management culture as sophisticated as that found in larger companies—with dedicated departments—or in regulated industries. It would therefore be futile, if not counterproductive, to attempt to track the full scope of identified and incurred risks over time. Only major risks should be tracked.
In concrete terms, it’s important to bear in mind that even a simple project is never free of risks, but that doesn’t mean you have to try to track them all. Identifying the 3-4 really salient risks is generally sufficient.
How do you steer risks?
The most critical risks must, of course, be addressed through a dedicated action plan designed to mitigate them and prevent them from occurring or escalating. These actions may potentially impact the projects’ originally planned timeline and alter the initial scenario. Objective: to mitigate these risks.
But above all, it is important to keep in mind that the risk scoring established at the start of the project is fluid and dynamic: At every project review and with each new report, the entire initial list of risks must be reviewed and re-evaluated to reassess the potential impact of each “hazard” that could disrupt the smooth running of the project. Is risk A, B, or C still just as critical? What is the likelihood that he will intervene?
Therefore, it is important to maintain a historical record of this dynamic management so that a retrospective analysis can be conducted if necessary. In this context, it is appropriate to use Project portfolio tracking tools that provide a common framework for all CIO projects. This will make it possible, for example, during project reviews, to identify deviations, risks, and difficulties using common KPIs and alert thresholds explicitly flagged by the flash reports. Similarly, the more closely project management is integrated with other aspects of IT department management (such as budgets, teams, and vendors), the better the ability to identify and track risks: a budget overrun, overstaffing, or an alert regarding a Contractor can thus be reported and shared in real time, allowing for immediate adjustments to decisions if necessary.
Towards macro risk management
Managing the risks inherent in each project is often the responsibility of the project manager. For the CIO, it is useful to have a broader view of all the risks identified and incurred at the project portfolio level, for example. This consolidated, cumulative view can help identify themes that emerge frequently or almost systematically. These themes then reveal an underlying trend that is no longer cyclical but rather structural. And this could then be the focus of a dedicated action plan aimed at making more fundamental changes to the system.
The challenge of instilling a culture of risk awareness and empowering all stakeholders
Last but not least: a classic pitfall of risk management is to assume that because a risk has been identified, recorded and tracked, and because the right tools have been put in place to deal with it, the subject of Manage project risks has been properly and sufficiently addressed and mastered.
This is not enough. On the contrary, in the face of all the potential vulnerabilities and threats, vigilance must be the watchword for everyone in the CIO, and even beyond.
Every employee needs to be made aware of, and acculturated to, Manage project risks, which should not remain the prerogative of the Information Systems Department and absolve the company’s other departments from increased vigilance in this area.
Thus, within a project, while it is normal for one person—often the project manager—to be responsible for risk mapping, effective management of project risks cannot be achieved unless it is fully integrated into the project’s operational reality and shared by the entire team. In practical terms, this means that within the company, every project stakeholder must be aware of the issues associated with these risks and able to adjust their actions or behavior accordingly. And that this risk awareness is sufficiently shared and embedded within a comprehensive system of collaboration and communication, so that the project manager, the team leader, and the CIO themselves are able to pick up on early warning signs that may amplify, mitigate, or give rise to new risks. The ability to listen will play a key role in effectively managing risks, both within the CIO department and beyond.
Let’s hear it…


