How does IT risk management work?
IT risk management works in a cycle: identify what could disrupt or compromise your technology, rate each risk by likelihood and impact, decide how to treat it, assign the treatment to an owner, and review it on a schedule. Ontech ICTM runs that cycle with a risk register, 5×5 scoring, a heat map and a unified risk score.
Every organisation carries IT risk: a server with no support contract, a single internet provider, an unpatched system, a key person who is the only one who knows how payroll runs. IT risk management makes those risks visible and comparable so that money and effort go to the ones that matter most.
The usual method is a risk register. Each risk is described, given an owner and scored for likelihood and impact before any controls (inherent risk) and again after them (residual risk). Mitigations are recorded with owners and dates, and the register is reviewed so that it reflects today's position, not last year's.
ICTM keeps the register inside its Business Continuity module, so risks sit next to the business impact analyses, plans and supplier dependencies they relate to. A unified risk score then draws on live data from incidents, compliance gaps, continuity risk, security findings and vendor single points of failure, giving management one number with a clear breakdown behind it.
What ICTM does for it risk management
Risk register
Record each IT risk with a name, category, assessor and next review date, linked where relevant to an application, vendor, incident or compliance check.
5×5 likelihood × impact scoring
Score every risk on a five-point likelihood scale and a five-point impact scale. ICTM multiplies them and bands the result as critical, high, medium or low, so risks are rated the same way by every team.
Inherent and residual risk
Capture risk before controls and after them, so you can see how much each mitigation is actually reducing exposure.
Mitigations with owners
Attach mitigation actions to each risk with a named owner, so accountability for reducing a risk is explicit rather than assumed.
Risk heat map
Plot risks on a likelihood-by-impact heat map to show where exposure is concentrated and which risks need attention first.
Unified risk score
One score calculated from live ICTM data — open incidents, compliance gaps, business-continuity risk, security findings and vendor single points of failure — with each contributing factor shown separately.
Vendor concentration risk
ICTM analyses how many of your applications depend on the same supplier and flags single points of failure, feeding supplier exposure into the wider risk picture.
Threshold-based infrastructure risk scores
Rule-based scores for servers and devices from CPU, memory and disk thresholds and asset age, highlighting equipment that deserves attention.
ICTM modules: Business Continuity · Unified Risk · Vendor Risk
How ICTM bands a 5×5 risk score
| Score (likelihood × impact) | Rating | Typical response |
|---|---|---|
| 20–25 | Critical | Treat immediately and escalate to management |
| 12–19 | High | Plan and fund mitigation with a named owner |
| 6–11 | Medium | Mitigate where practical and monitor at each review |
| 1–5 | Low | Accept and review periodically |
Use cases
Building a first IT risk register
Replace a spreadsheet of risks with a scored register, with owners for each mitigation, that stays linked to the systems and plans it describes.
Prioritising the IT budget
Use residual scores and the heat map to show which investments reduce the most risk.
Reporting risk to management
Give executives the unified risk score with its breakdown by incidents, compliance, continuity, security and suppliers.
Supplier dependency reviews
Identify applications that depend on a single supplier before that supplier has an outage.
Preparing for an audit or regulator
Show a documented, reviewed risk register with mitigation owners, which frameworks such as ISO/IEC 27001 expect.
Benefits
Consistent scoring
One scoring method across teams makes risks genuinely comparable.
Clear accountability
Every mitigation has an assigned owner and every assessment a next review date.
Risk connected to operations
The unified score reflects what is actually happening in incidents, compliance and security, not only what was estimated in a workshop.
Better conversations with management
A heat map and a single score with its components are easier to act on than a long spreadsheet.
Frequently asked questions
How are risk scores calculated in ICTM?
Each risk is rated from 1 to 5 for likelihood and from 1 to 5 for impact, and the two are multiplied to give a score from 1 to 25. Scores of 20 or more are critical, 12 to 19 high, 6 to 11 medium and 5 or below low. Each assessment also records an inherent and a residual risk level, so you can compare exposure before and after controls.
What is the difference between inherent and residual risk?
Inherent risk is the level of risk before any controls are applied. Residual risk is what remains after your controls and mitigations are in place. Comparing the two shows how effective your controls are and whether the remaining risk is acceptable to the organisation.
What goes into the unified risk score?
The unified risk score combines five live inputs from ICTM: open incidents, gaps in compliance coverage, business-continuity risk, security findings and supplier single points of failure. Incidents and compliance carry the most weight. The score is shown with its components so you can see what is driving it.
Where does the risk register live in ICTM?
The risk register is part of the Business Continuity module. That keeps each risk close to the business impact analyses, continuity plans and vendor dependencies it relates to, and lets continuity risk feed directly into the unified risk score alongside incidents, compliance and security.
Does ICTM predict future risks automatically?
No. ICTM scores the risks you record and uses rule-based thresholds, such as high disk usage or ageing hardware, to flag infrastructure that needs attention. Judging likelihood and impact remains a decision for the people who understand the business and its services.