This document discusses managing risk in IT for small to medium sized organizations. It covers evaluating risks from budgets, staffing, third party providers and disasters. Key points include integrating IT with business needs, having IT represented in strategic planning, and properly managing third party providers through contracts, audits and service level agreements. The overall message is that effective risk management should be a strategic partnership between IT and the business.