Insights on Crypto Payments, Infrastructure, and Operations

ICT Risk

Abbreviation: ICT

Pronunciation: I-C-T risk

Also known as: Information and communication technology risk, Technology operational risk, ICT

Definition

ICT risk is the possibility of loss, disruption, security harm, data compromise, or business impact arising from information and communication technology systems, processes, people, or external providers. It is broader than cybersecurity risk because it also includes availability, capacity, change, resilience, data quality, legacy technology, concentration, and third-party dependency failures. Operationally, teams should identify critical services and assets, map dependencies, assess threats and vulnerabilities, and set risk appetite.

Overview

ICT risk is the possibility of loss, disruption, security harm, data compromise, or business impact arising from information and communication technology systems, processes, people, or external providers.

ICT Risk is closely connected to ICT-Related Incident, Payment Technology Risk, and Risk Taxonomy. It is broader than cybersecurity risk because it also includes availability, capacity, change, resilience, data quality, legacy technology, concentration, and third-party dependency failures.

Operational implementation should identify critical services and assets, map dependencies, assess threats and vulnerabilities, set risk appetite, test resilience, monitor providers, manage change, and maintain response and recovery capabilities.

The principal failure modes include system outages, cyberattacks, failed releases, capacity exhaustion, data corruption, third-party failure, obsolete components, and inadequate recovery arrangements.

Useful measures include critical-service exposure, unresolved high risks, outage minutes, control effectiveness, third-party concentration, and recovery test results.

Operationally, teams should identify critical services and assets, map dependencies, assess threats and vulnerabilities, and set risk appetite. Key risks include system outages, cyberattacks, failed releases, and capacity exhaustion.

For ICT Risk, the assessment should evaluate the possibility of loss, disruption, security harm, data compromise, or business impact arising from information and communication technology systems, processes, people, or external providers. The assessment record should separate observed evidence supporting the possibility of loss, disruption, security harm, data compromise, or business impact arising from information and communication technology systems, processes, people, or external providers from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility of loss, disruption, security harm, data compromise, or business impact arising from information and communication technology systems, processes, people, or external providers have changed enough to require a new rating, treatment, or approval.

Key Takeaway

ICT risk is the possibility of loss, disruption, security harm, data compromise, or business impact arising from information and communication technology systems, processes, people, or external providers.

Sources

  1. Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector — European Union (2026-08-03)
  2. The NIST Cybersecurity Framework (CSF) 2.0 — NIST (2026-08-03)
  3. Guide for Conducting Risk Assessments, NIST SP 800-30 Rev. 1 — NIST (2026-08-03)