SlideShare a Scribd company logo
Managing Risk in IT
               #12NTCRISK




Richard D. Wollenberger
Jay L. Seagren

                  Managing Risk in IT   Slide 1
Evaluate This Session!
 Each entry is a chance to win an NTEN engraved iPad!




or Online using <#NTC12RISK> at www.nten.org/ntc/eval




                    Managing Risk in IT                 Slide 2
Managing IT Risk in a small-
medium sized organization




          Managing Risk in IT   Slide 3
Managing Risk in IT
•   Introductions
•   What is risk management?
•   Budgets
•   Integration with business needs
•   Managing Staff
•   Managing the computing environment




                  Managing Risk in IT    Slide 4
Who are we?

Richard Wollenberger
  Director of Information Technology
  Parents as Teachers national office
  richard.wollenberger@parentsasteachers.org


Jay Seagren
  Senior Manager, Enterprise Systems,
  The Pew Charitable Trusts
  jseagren@pewtrusts.org



                           Managing Risk in IT   Slide 5
Who’s here today

• Organization size?
• Accidental techie?
• # of IT staff?




                   Managing Risk in IT   Slide 6
IT Resources




  Managing Risk in IT   Slide 7
What is Risk Management?

• Origins of risks
  – From the ancient Italian word riscare
  – The study of risk began during the
    Renaissance
  – Daniel Bernoulli
  – Harry Markowitz




                     Managing Risk in IT    Slide 8
What does this have to do with IT?

 • Every decision you make is about
   managing some kind of risk
   – Which AV system will protect your staff?
   – Which backup system will be easy to use
     (restore from) during an emergency situation?
   – MS vs. Google?
   – Voice/data connections
   – Firewall


                    Managing Risk in IT         Slide 9
Budgets

• Every penny you spend in IT is NOT spent
  on your mission
  – Track every expense related to:
    •   Computer hw/sw
    •   Internet connectivity
    •   Telephone & fax
    •   Printing & copying
    •   Training
         – end user
         – Tech staff (yes, you need ongoing training)

                          Managing Risk in IT            Slide 10
Budget Resources

• www.itlever.com
  – (search for budget or budgeting)
• IT Management
  – (http://itmanagerinstitute.com/free-ebook)
• Tech Republic
  – (link in slide show)




                     Managing Risk in IT         Slide 11
Integration with the business

• You have to sit at the table
• Strategic planning
• You are there to support them
• You are there to improve processes and
  make it easier
• You are there to look for cost efficiencies
    – Hard and soft dollar
• Business continuity (disaster planning)
                      Managing Risk in IT   Slide 12
Sit at the table

• Be a partner with the business
• Have a Service Level Agreement (SLA) so your
  “customers” know what to expect




                   Managing Risk in IT      Slide 13
Strategic planning

• Why is this important?
  – Strategic planning drives the business, and
    you need to be helping steer.




                   Managing Risk in IT            Slide 14
Who they gonna call?




       Managing Risk in IT   Slide 15
What do you need to do?

• Improve business processes




• Find hard and soft dollar cost efficiencies




                   Managing Risk in IT      Slide 16
Staffing

• Are you an
  “Accidental Techie?”




• Do you manage
  other IT staff?


                    Managing Risk in IT   Slide 17
Managing Risk in IT   Slide 18
Outsourcing vs. Insourcing
               Services
•   Office and Collaboration
•   Help desk
•   Constituent Management
•   Security
•   Server and Network




                   Managing Risk in IT   Slide 19
Office and Collaboration

• Google Apps (Low Risk)
  – Free for non-profits <3000 users
  – Now online and offline (Chrome)
  – Bonus: Postini spam filter




                   Managing Risk in IT   Slide 20
Office and Collaboration

• Office 365 (Medium Risk)
  – Requires desktop client
  – Per seat costs ($6-$27/user/month)
  – Bonus: SharePoint




                   Managing Risk in IT   Slide 21
Help Desk
•                                     (low risk – it’s free)


•                          (med risk - about $20/seat/month)




•                                       (med risk – new version
    not available yet – check for pricing with Techsoup.org)




                          Managing Risk in IT                  Slide 22
Constituent Management

•                                            (low risk)
    – $200 - $475/month

•                        (medium risk)


    – 10 licenses free, >10 80% discount
    – Nonprofit Starter pack (free)




                       Managing Risk in IT                Slide 23
Security

• Virus protection
  – Symantec ($25/yr)
  – McAfee ($30/yr)
  – Microsoft System Essentials
     • Free for <10 PCs
  – Microsoft Forefront Endpoint
    ($20/seat)



                     Managing Risk in IT   Slide 24
Disaster Planning

• This is not good:




                  Managing Risk in IT   Slide 25
Disaster Planning and Recovery

• Disaster Planning
  – Scope of plan
     • Room, building, city, region
• Disaster Recovery
  – Online backup and recovery
  – Pricing terms
  – Amazon Web Services
     • (http://media.amazonwebservices.com/AWS
       _Pricing_Overview.pdf)



                         Managing Risk in IT     Slide 26
Server and Network

• Specs
    – What you want vs. what you need
• Tools
    – Is the cloud right for your organization?
•   Processes
•   Procedures
•   Change management
•   Regulation and law compliance

                      Managing Risk in IT         Slide 27
Server and Network – cont.

• Duplicate and mirrored services
• 2 separate data centers
• Different geographic and power grid
  zones
• Carbon copying between the two
• 3rd Party DNS can route to different data
  centers upon failure


                  Managing Risk in IT     Slide 28
3rd Party Providers




      Managing Risk in IT   Slide 29
3rd Party Providers

• Financial pressure and offsite delivery
  model drive the need
• Risk Management starts with Sourcing,
  continues with Contracting and finally
  Vendor Management
• Extend your in-house staff seamlessly if
  managed well


                  Managing Risk in IT        Slide 30
3rd Party Providers – cont.
• Growing number of delivery models, specialized services and
  budget pressure are driving more reliance on 3rd party service
  providers

• 25% of IT budgets are now going to 3rd party providers

• Over 50% of IT managers surveyed will increase their budget
  on SAAS providers.




                           Managing Risk in IT               Slide 31
3rd Party Providers – cont.

• Areas of Risk and Mitigation:
  – Data Security
  – Stability of provider and their service
  – Your brand and reputation
  – Legal and Professional liability




                     Managing Risk in IT      Slide 32
3rd Party Providers – cont.

• Data Security
    • Privacy policies in contract
    • Vendor audit
    • Internal training on Data Security
      awareness
    • Sensitive information (e.g. High
      Wealth Donors) may warrant DLP




                     Managing Risk in IT   Slide 33
3rd Party Providers – cont.

• Stability of provider
     • Basic Balance sheet and Cash Flow analysis
     • Bankruptcy, M and A
• Stability of service
     • Service Levels objectives in contract
     • Incentives and discounts/refunds
     • Vendor Scorecards




                      Managing Risk in IT           Slide 34
3rd   Party Providers – cont.




            Managing Risk in IT   Slide 35
3rd Party Providers – cont.

• Brand reputation
    • Brand usage built in to contracts
    • On site risk assessment
    • Deliverable reviews




                     Managing Risk in IT   Slide 36
3rd   Party Providers – cont.

• Legal and Professional
  liability
    • Business Continuity plan review
    • Standardized best practices
    • Standard Legal Terms and
      Conditions




                     Managing Risk in IT   Slide 37
Managing Risk in IT
              Conclusion
•   Be partner with business
•   Make risk management strategic
•   Evaluate outsourced and cloud offerings
•   Follow Best Practices
•   Use Best of Breed
•   Utilize 3rd party providers wisely



                   Managing Risk in IT    Slide 38
Managing IT Risk in a small-
medium sized organization




          Managing Risk in IT   Slide 39
Evaluate This Session!
 Each entry is a chance to win an NTEN engraved iPad!




or Online using <#NTC12RISK> at www.nten.org/ntc/eval




                    Managing Risk in IT                 Slide 40

More Related Content

PDF
Mis 2 dss
PPTX
BSIDES DETROIT 2015: Data breaches cost of doing business
PDF
Crisis Communications, Social Media and Notification Systems Webinar - Core C...
PPT
Slide01 introductory
PPT
PDF
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
PPT
Chapter 8 Mis Decision Support System
PPT
Software Project Implementation
Mis 2 dss
BSIDES DETROIT 2015: Data breaches cost of doing business
Crisis Communications, Social Media and Notification Systems Webinar - Core C...
Slide01 introductory
HOW TO PLAN AND MANAGE A BCM AND IT DR PROJECT
Chapter 8 Mis Decision Support System
Software Project Implementation

What's hot (17)

PDF
Business oriented risk management approach luís martins
PPTX
Mis & Decision Making
PDF
A Study of Automated Decision Making Systems
PPTX
DSS and decision support system and its types
PPTX
Security challenges in 2017
PPT
Decision support system
PPT
IT Business Continuity Planning 2004
PDF
Selling Data Security Technology
PPTX
Mis chapter 2 infomation, management and decision making
PDF
Gartner Security &amp; Risk Management Summit Brochure
PDF
Community IT Innovators - BYOD for Nonprofits
PDF
Security and Business Continuity Working Together
PDF
Survivors
PPTX
Unit 1 DSS
PDF
Mis student version 2013
Business oriented risk management approach luís martins
Mis & Decision Making
A Study of Automated Decision Making Systems
DSS and decision support system and its types
Security challenges in 2017
Decision support system
IT Business Continuity Planning 2004
Selling Data Security Technology
Mis chapter 2 infomation, management and decision making
Gartner Security &amp; Risk Management Summit Brochure
Community IT Innovators - BYOD for Nonprofits
Security and Business Continuity Working Together
Survivors
Unit 1 DSS
Mis student version 2013
Ad

Viewers also liked (7)

PDF
Designing Online Engagement to Collaborate with Your Community
PPTX
CIL Legal Update- Oliver Martin, RTPI West Midlands CPD
PPT
The new health landscape- Paul Southon, RTPI CPD June13
PPT
Lichen planus afroamerican people
PPT
Vocational Architecture Learning Network
PPT
Introduction To Designing Online Community Nov09
PPT
Creating great places David Engwicht oct 2011
Designing Online Engagement to Collaborate with Your Community
CIL Legal Update- Oliver Martin, RTPI West Midlands CPD
The new health landscape- Paul Southon, RTPI CPD June13
Lichen planus afroamerican people
Vocational Architecture Learning Network
Introduction To Designing Online Community Nov09
Creating great places David Engwicht oct 2011
Ad

Similar to Managing Risk in IT (20)

PPTX
IT Risk Management
PDF
IT Risk Management
PDF
Innovation connections quick guide managing ict risk for business pdf
PDF
The evolving role of IT managers and CIOs
PPT
PPT
Class 2003 05 22
DOCX
case studies on risk management in IT enabled organisation(vadodara)
PPTX
Managing IT Risk and Assessing Vulnerability
PPT
Chapters 7 and 8
DOCX
130C h a p t e r10 Managing IT-Based Risk11 This c.docx
DOCX
130C h a p t e r10 Managing IT-Based Risk11 This c.docx
PPT
Does IT Security Matter?
PDF
A Value Centric Approach to Governance Risk & Compliance
PPTX
High level service v2 slideshare
PDF
Risk management for ICT Technology Dept.
PPTX
Risky Business
PPTX
Assess risks to IT security.pptx
DOCX
CHAPTER 1Risk Management FundamentalsCopyright © 202
PPTX
Information security for business majors
IT Risk Management
IT Risk Management
Innovation connections quick guide managing ict risk for business pdf
The evolving role of IT managers and CIOs
Class 2003 05 22
case studies on risk management in IT enabled organisation(vadodara)
Managing IT Risk and Assessing Vulnerability
Chapters 7 and 8
130C h a p t e r10 Managing IT-Based Risk11 This c.docx
130C h a p t e r10 Managing IT-Based Risk11 This c.docx
Does IT Security Matter?
A Value Centric Approach to Governance Risk & Compliance
High level service v2 slideshare
Risk management for ICT Technology Dept.
Risky Business
Assess risks to IT security.pptx
CHAPTER 1Risk Management FundamentalsCopyright © 202
Information security for business majors

More from NTEN (20)

PPTX
17NTC Overall Speaker Timelines
PPTX
17NTC Speaker Orientation Call
PDF
Call for 17NTC Session Proposals
PDF
2015 Leading Change Summit: Making the Most of LCS
PPTX
Community Organizing Tools from the Experts Webinar
PDF
2013 Nonprofit Engagement Data Management Study: A Graphic Report
PDF
2012 State of Nonprofit Data Report
PDF
Smart Technology Investment for Nonprofits
PPTX
Social Media for Social Good - NCVS Pre-Con Workshp
PDF
Ready, Fire, Aim
PPT
But What Do You Actually Do?: Communicating Your Nonprofit's Work in Ways You...
PPT
The Story of Stuff: How an Environmental Campaigner to New Media Mogul
PDF
Better Nonprofit Websites: 52 Tweaks in 52 Weeks
PPT
Practical Problem Solving Using Mobile Technology
PDF
Zen and Art of Workflow Development
PDF
12 nt cviz
PDF
Tips and Tools for Technology Planning
PDF
Technology Governance: Smart, Sexy and Simple in Seven Steps
PDF
Social Network Fundraising: Facts, Myths, and Strategies that Work
PDF
Maturing Your Organization's Social Culture... by Creating a Policy?
17NTC Overall Speaker Timelines
17NTC Speaker Orientation Call
Call for 17NTC Session Proposals
2015 Leading Change Summit: Making the Most of LCS
Community Organizing Tools from the Experts Webinar
2013 Nonprofit Engagement Data Management Study: A Graphic Report
2012 State of Nonprofit Data Report
Smart Technology Investment for Nonprofits
Social Media for Social Good - NCVS Pre-Con Workshp
Ready, Fire, Aim
But What Do You Actually Do?: Communicating Your Nonprofit's Work in Ways You...
The Story of Stuff: How an Environmental Campaigner to New Media Mogul
Better Nonprofit Websites: 52 Tweaks in 52 Weeks
Practical Problem Solving Using Mobile Technology
Zen and Art of Workflow Development
12 nt cviz
Tips and Tools for Technology Planning
Technology Governance: Smart, Sexy and Simple in Seven Steps
Social Network Fundraising: Facts, Myths, and Strategies that Work
Maturing Your Organization's Social Culture... by Creating a Policy?

Recently uploaded (20)

PPTX
Lecture (1)-Introduction.pptx business communication
DOCX
unit 1 COST ACCOUNTING AND COST SHEET
PPTX
Amazon (Business Studies) management studies
PPTX
ICG2025_ICG 6th steering committee 30-8-24.pptx
PDF
Training And Development of Employee .pdf
DOCX
Euro SEO Services 1st 3 General Updates.docx
PDF
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
PPTX
Dragon_Fruit_Cultivation_in Nepal ppt.pptx
PDF
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
PDF
Nidhal Samdaie CV - International Business Consultant
PPT
Data mining for business intelligence ch04 sharda
PDF
Chapter 5_Foreign Exchange Market in .pdf
PDF
Business model innovation report 2022.pdf
PDF
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise
PDF
Types of control:Qualitative vs Quantitative
PDF
Roadmap Map-digital Banking feature MB,IB,AB
PPTX
CkgxkgxydkydyldylydlydyldlyddolydyoyyU2.pptx
PDF
Power and position in leadershipDOC-20250808-WA0011..pdf
PDF
Laughter Yoga Basic Learning Workshop Manual
PDF
WRN_Investor_Presentation_August 2025.pdf
Lecture (1)-Introduction.pptx business communication
unit 1 COST ACCOUNTING AND COST SHEET
Amazon (Business Studies) management studies
ICG2025_ICG 6th steering committee 30-8-24.pptx
Training And Development of Employee .pdf
Euro SEO Services 1st 3 General Updates.docx
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
Dragon_Fruit_Cultivation_in Nepal ppt.pptx
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
Nidhal Samdaie CV - International Business Consultant
Data mining for business intelligence ch04 sharda
Chapter 5_Foreign Exchange Market in .pdf
Business model innovation report 2022.pdf
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise
Types of control:Qualitative vs Quantitative
Roadmap Map-digital Banking feature MB,IB,AB
CkgxkgxydkydyldylydlydyldlyddolydyoyyU2.pptx
Power and position in leadershipDOC-20250808-WA0011..pdf
Laughter Yoga Basic Learning Workshop Manual
WRN_Investor_Presentation_August 2025.pdf

Managing Risk in IT

  • 1. Managing Risk in IT #12NTCRISK Richard D. Wollenberger Jay L. Seagren Managing Risk in IT Slide 1
  • 2. Evaluate This Session! Each entry is a chance to win an NTEN engraved iPad! or Online using <#NTC12RISK> at www.nten.org/ntc/eval Managing Risk in IT Slide 2
  • 3. Managing IT Risk in a small- medium sized organization Managing Risk in IT Slide 3
  • 4. Managing Risk in IT • Introductions • What is risk management? • Budgets • Integration with business needs • Managing Staff • Managing the computing environment Managing Risk in IT Slide 4
  • 5. Who are we? Richard Wollenberger Director of Information Technology Parents as Teachers national office richard.wollenberger@parentsasteachers.org Jay Seagren Senior Manager, Enterprise Systems, The Pew Charitable Trusts jseagren@pewtrusts.org Managing Risk in IT Slide 5
  • 6. Who’s here today • Organization size? • Accidental techie? • # of IT staff? Managing Risk in IT Slide 6
  • 7. IT Resources Managing Risk in IT Slide 7
  • 8. What is Risk Management? • Origins of risks – From the ancient Italian word riscare – The study of risk began during the Renaissance – Daniel Bernoulli – Harry Markowitz Managing Risk in IT Slide 8
  • 9. What does this have to do with IT? • Every decision you make is about managing some kind of risk – Which AV system will protect your staff? – Which backup system will be easy to use (restore from) during an emergency situation? – MS vs. Google? – Voice/data connections – Firewall Managing Risk in IT Slide 9
  • 10. Budgets • Every penny you spend in IT is NOT spent on your mission – Track every expense related to: • Computer hw/sw • Internet connectivity • Telephone & fax • Printing & copying • Training – end user – Tech staff (yes, you need ongoing training) Managing Risk in IT Slide 10
  • 11. Budget Resources • www.itlever.com – (search for budget or budgeting) • IT Management – (http://itmanagerinstitute.com/free-ebook) • Tech Republic – (link in slide show) Managing Risk in IT Slide 11
  • 12. Integration with the business • You have to sit at the table • Strategic planning • You are there to support them • You are there to improve processes and make it easier • You are there to look for cost efficiencies – Hard and soft dollar • Business continuity (disaster planning) Managing Risk in IT Slide 12
  • 13. Sit at the table • Be a partner with the business • Have a Service Level Agreement (SLA) so your “customers” know what to expect Managing Risk in IT Slide 13
  • 14. Strategic planning • Why is this important? – Strategic planning drives the business, and you need to be helping steer. Managing Risk in IT Slide 14
  • 15. Who they gonna call? Managing Risk in IT Slide 15
  • 16. What do you need to do? • Improve business processes • Find hard and soft dollar cost efficiencies Managing Risk in IT Slide 16
  • 17. Staffing • Are you an “Accidental Techie?” • Do you manage other IT staff? Managing Risk in IT Slide 17
  • 18. Managing Risk in IT Slide 18
  • 19. Outsourcing vs. Insourcing Services • Office and Collaboration • Help desk • Constituent Management • Security • Server and Network Managing Risk in IT Slide 19
  • 20. Office and Collaboration • Google Apps (Low Risk) – Free for non-profits <3000 users – Now online and offline (Chrome) – Bonus: Postini spam filter Managing Risk in IT Slide 20
  • 21. Office and Collaboration • Office 365 (Medium Risk) – Requires desktop client – Per seat costs ($6-$27/user/month) – Bonus: SharePoint Managing Risk in IT Slide 21
  • 22. Help Desk • (low risk – it’s free) • (med risk - about $20/seat/month) • (med risk – new version not available yet – check for pricing with Techsoup.org) Managing Risk in IT Slide 22
  • 23. Constituent Management • (low risk) – $200 - $475/month • (medium risk) – 10 licenses free, >10 80% discount – Nonprofit Starter pack (free) Managing Risk in IT Slide 23
  • 24. Security • Virus protection – Symantec ($25/yr) – McAfee ($30/yr) – Microsoft System Essentials • Free for <10 PCs – Microsoft Forefront Endpoint ($20/seat) Managing Risk in IT Slide 24
  • 25. Disaster Planning • This is not good: Managing Risk in IT Slide 25
  • 26. Disaster Planning and Recovery • Disaster Planning – Scope of plan • Room, building, city, region • Disaster Recovery – Online backup and recovery – Pricing terms – Amazon Web Services • (http://media.amazonwebservices.com/AWS _Pricing_Overview.pdf) Managing Risk in IT Slide 26
  • 27. Server and Network • Specs – What you want vs. what you need • Tools – Is the cloud right for your organization? • Processes • Procedures • Change management • Regulation and law compliance Managing Risk in IT Slide 27
  • 28. Server and Network – cont. • Duplicate and mirrored services • 2 separate data centers • Different geographic and power grid zones • Carbon copying between the two • 3rd Party DNS can route to different data centers upon failure Managing Risk in IT Slide 28
  • 29. 3rd Party Providers Managing Risk in IT Slide 29
  • 30. 3rd Party Providers • Financial pressure and offsite delivery model drive the need • Risk Management starts with Sourcing, continues with Contracting and finally Vendor Management • Extend your in-house staff seamlessly if managed well Managing Risk in IT Slide 30
  • 31. 3rd Party Providers – cont. • Growing number of delivery models, specialized services and budget pressure are driving more reliance on 3rd party service providers • 25% of IT budgets are now going to 3rd party providers • Over 50% of IT managers surveyed will increase their budget on SAAS providers. Managing Risk in IT Slide 31
  • 32. 3rd Party Providers – cont. • Areas of Risk and Mitigation: – Data Security – Stability of provider and their service – Your brand and reputation – Legal and Professional liability Managing Risk in IT Slide 32
  • 33. 3rd Party Providers – cont. • Data Security • Privacy policies in contract • Vendor audit • Internal training on Data Security awareness • Sensitive information (e.g. High Wealth Donors) may warrant DLP Managing Risk in IT Slide 33
  • 34. 3rd Party Providers – cont. • Stability of provider • Basic Balance sheet and Cash Flow analysis • Bankruptcy, M and A • Stability of service • Service Levels objectives in contract • Incentives and discounts/refunds • Vendor Scorecards Managing Risk in IT Slide 34
  • 35. 3rd Party Providers – cont. Managing Risk in IT Slide 35
  • 36. 3rd Party Providers – cont. • Brand reputation • Brand usage built in to contracts • On site risk assessment • Deliverable reviews Managing Risk in IT Slide 36
  • 37. 3rd Party Providers – cont. • Legal and Professional liability • Business Continuity plan review • Standardized best practices • Standard Legal Terms and Conditions Managing Risk in IT Slide 37
  • 38. Managing Risk in IT Conclusion • Be partner with business • Make risk management strategic • Evaluate outsourced and cloud offerings • Follow Best Practices • Use Best of Breed • Utilize 3rd party providers wisely Managing Risk in IT Slide 38
  • 39. Managing IT Risk in a small- medium sized organization Managing Risk in IT Slide 39
  • 40. Evaluate This Session! Each entry is a chance to win an NTEN engraved iPad! or Online using <#NTC12RISK> at www.nten.org/ntc/eval Managing Risk in IT Slide 40