
CIOs see their role expanded by third parties and adverse events
Discover how CIOs leverage adverse events to expand their role
October 2024
CIOs are experiencing a shift in perspectives due to the impacts of Covid-19 and the global IT outage, which have highlighted the need for more robust third-party risk management and business continuity practices. CIOs are now questioning the single source model for vendor relationships and are adopting supply chain strategies to mitigate risk. They are also becoming more involved in business continuity planning, as they recognize the importance of IT resilience in the face of disruptions.
Some key factors and considerations for CIOs are:
- Third-party risk management: Review and update their third-party risk management processes, taking into account the depth and complexity of third-party relationships.
- Supply chain strategies: Adopt supply chain strategies to mitigate risk, such as creating redundancy and switching suppliers based on reliability and risk factors.
- Business continuity: Share IT perspective to the business continuity program, and ensure that the program is comprehensive and addresses enterprise risk.
- Reputational risk: Be aware of the reputational risk associated with system outages and disruptions, and be prepared to respond quickly and effectively.
- Prioritization: Prioritize risk areas to be more thoughtful about resources and allocate them accordingly.
Dive into our thinking:
CIOs see their role expanded by third parties and adverse events
Discover how CIOs are expanding their role as they navigate third-party risk management, supply chain risk management, and business continuity.
Download PDFView additional insights from the Voice of the CIO
A recurring conversation with CIOs on IT-related issues
Explore more

2024 KPMG US technology survey report: The digital dividend
US businesses are seeing their tech investments deliver profits and performance. But keeping up with the pace of innovation remains a challenge.

Make operational resilience your North Star
In a fluid, often uncertain environment, organizations should cultivate a culture of resilience, embedding robust contingency plans that encompass not just IT infrastructure but also key business operations.

Be organizationally and operationally resilient when — and where — it matters
During an IT outage, cyber-attack, or any significant functional disruption, organizations must focus on restoring critical operations in minutes and hours, not days and weeks.
Meet our team
