Business Transformation Requires Transformational Leaders

Leadership and teaming skills are front and center in times of rapid change. Meet today’s constant disruption head on with expert guidance in leadership, business strategy, transformation, and innovation. Whether the disruption du jour is a digitally-driven upending of traditional business models, the pandemic-driven end to business as usual, or the change-driven challenge of staffing that meets your transformation plans — you’ll be prepared with cutting edge techniques and expert knowledge that enable strategic leadership.

Subscribe to Arthur D. Little's Culture & Leadership Newsletter

Insight

[From the Editor: This week's Cutter IT Advisor is from Cutter Fellow Robert N. Charette and Brian Hagen's introduction to the July 2012 issue of Cutter IT Journal, "Fixing ERM: From IT Security to Human Behavior" (Vol. 25, No. 7). Learn more about Cutter IT Journal.]

The avalanche of digital data that has resulted in Big Data storage and analytics is leading to additional issues as data volumes continue to grow in volume, variety, and velocity. A critical issue for the enterprise is how to maintain control of these immense pools of structured and unstructured data.

In this issue, we depart from our usual Executive Report format to bring you multiple viewpoints on a contentious topic: whether agile has transitioned from being an upstart methodology adopted in innovative organizations to being the methodology of choice for the “early majority” of Geoffrey Moore’s chasm. Have organizations indeed “crossed the chasm” in viewing agile as mainstream and in adopting it?

In Part I of this Executive Update series, we looked at the barriers to and possible benefits of collaboration. I examined the "four pillars of collaboration," which provide a foundation that supports collaboration and collaborative structures.

"So the question remains on the table: is ERM unfixable, or can something be done to make it live up to its promise as an effective and relevant business practice?"

-- Robert N. Charette and Brian Hagen, Guest Editors

GETTING IN ON THE GROUND FLOOR

Enterprise risk management (ERM) can be viewed as a framework that consumes, aggregates, and reports analysis accumulated from diverse business units and factors that affect organizational risk. Historically, ERM deployments have tended to begin at a 40,000-foot corporate level, gaining authorization and executive commitment before trickling down into the enterprise.

FLAWED ASSUMPTIONS OF PROBABILITY THEORY

Risk analysis is the core of enterprise risk management (ERM). For example, to conduct a cost-benefit analysis of new security safeguards and controls, organizations first have to perform risk analysis. Risk analysis starts with the identification of risks and assigning values such as probabilities of risk occurrence and the expected amount of damage.

Over the years, the information security function has morphed from a very technologically based discipline to a function that, by circumstance, has become more aligned with business objectives. This increased synchronicity with the business is based on the true nature of security itself -- which is to provide a set of controls to protect assets from threats.