Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

The Risk of Technology Dependence: What Happens When Your Organization Can No Longer Use the Technology It Relies On?

The Risk of Technology Dependence: What Happens When Your Organization Can No Longer Use the Technology It Relies On?

By
Key Takeaways
  • Technology Dependency Is a Business Risk: A system does not have to fail to create risk. Regulatory changes, vendor decisions, licensing restrictions, geopolitical developments and changing security requirements can all make continued use difficult or unacceptable.
  • Security Is Only Part of the Question: Technology may be secure and functioning as intended while still creating significant risk because an organization has become too dependent on it to move away easily.
  • End-of-Life Technology Exposes Deeper Dependencies: Organizations often continue using unsupported technology because migrations are delayed, other applications depend on it or replacement proves more complicated than expected.
  • Security Exceptions Can Be an Early Warning: Exceptions may be appropriate in the short term, but recurring or prolonged exceptions can reveal underlying technology dependencies that deserve broader GRC attention.
Deep Dive

Most organizations know what they would do if a critical system went down. There are incident response plans, disaster recovery arrangements and business continuity procedures designed for exactly that scenario. But there is another question we don't ask nearly as often: What happens if the technology hasn't failed, but your organization can no longer use it?

No outage. No cyberattack. No technical failure. The technology could still be working exactly as designed, but a change in regulation, vendor strategy, licensing, geopolitical circumstances or security requirements could suddenly make continued use difficult or unacceptable. That is a different kind of technology risk, and one that I think deserves more attention within GRC.

China's reported move to accelerate the removal of a customized version of Microsoft Windows 10 from some state-linked organizations is a useful example. The circumstances are specific to China, including its wider push to reduce reliance on foreign technology, but the underlying risk is relevant to organizations everywhere. It is the risk of dependency, when dependency becomes the risk.

Modern organizations depend heavily on technology they don't own and can't fully control. Cloud platforms, operating systems, security products, SaaS applications and specialist business software often sit at the heart of critical services. There is nothing inherently wrong with this. Building everything internally would be unrealistic for most organizations, and using established technology providers brings significant benefits. The risk emerges when an organization becomes so dependent on a particular technology that moving away from it becomes extremely difficult.

We spend a lot of time asking whether technology is secure. Is it patched? Is access appropriately controlled? Is sensitive data protected? Are vulnerabilities being managed? Is activity monitored? Those questions are important, but they only tell us part of the story. A technology can be secure today and still represent a significant business risk because of how dependent the organization has become on it.

A vendor can change its licensing model. A product can reach end of life. Regulatory requirements can change. Geopolitical developments can affect technology availability and supply chains. A supplier can change direction. Sometimes the organization itself simply decides it needs to move away from a particular technology and then discovers how deeply embedded that technology has become. At that point, technology dependency is no longer simply an IT issue. It is a business risk.

When "It Still Works" Isn't Enough

I've seen smaller versions of this challenge through my own work in GRC. A system reaches end of life, but the business still depends on it. A legacy application cannot support a newer security requirement. A technology cannot meet the organization's current security standard, but replacing it isn't something that can happen immediately.

The risk conversation then becomes familiar. What controls can we put around it? Is an exception required? How long can the current arrangement continue? Who needs to accept the risk? These are all reasonable questions. Sometimes a security exception is the appropriate short-term solution. But there is a bigger question behind them: Why are we still dependent on the technology creating the risk?

End-of-life technology is a good example. Major products don't normally become unsupported without warning. Vendors often provide lifecycle information well in advance. Yet organizations still find themselves operating systems beyond their supported life.

There can be legitimate reasons for this. A migration project may have been delayed. Another application may depend on the older technology. Funding may have been prioritized elsewhere. The replacement may be significantly more complicated than originally expected. Or perhaps the simplest reason of all: the technology still works.

Then the support deadline arrives and something that was previously a technology lifecycle issue becomes a cybersecurity and business risk. Now compensating controls may be required. An exception may need to be raised. Management may need to accept the exposure while a longer-term solution is developed.

From a GRC perspective, simply managing the exception isn't enough. We should also understand how the organization reached that position and whether similar dependencies exist elsewhere. Otherwise, we risk managing the symptom rather than the cause.

Security Exceptions Can Be an Early Warning

I deal with security exceptions as part of my day-to-day work, and I don't see an exception as automatically being a bad thing. Sometimes a business genuinely cannot meet a security requirement immediately. Good risk management should allow for that. The exposure should be understood, appropriate compensating controls should be considered, and someone should own the risk.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong