Incident management: How to respond to the polycrisis with an integrated approach

Michael Ehrnsperger

Journal of Risk Management in Financial Institutions2025https://doi.org/10.69554/iwqr8979article
ABDC C
Weight
0.50

What the paper says

Incident management — the response to an unplanned interruption or event that potentially harms assets or compromises operations — is the daily business of IT professionals and cyber defence specialists. Guidance on how to implement incident management can be found in international standards; however, the process does not receive sufficient attention from the rest of the organisation. Driven by the digitalisation of the financial sector and the growing threat of cyberattacks, global supervisory authorities have worked over the past five years to strengthen operational resilience. Incident management has been identified as one of the core elements, supported by thorough organisational measures, to provide more transparency, awareness and management attention, but even government influence failed to make this a prominent topic in boardrooms. The threat became a reality, however, with the CrowdStrike outage, the largest information and communication technology (ICT) incident in history, resulting in an estimated financial damage of US$10bn. Since the focus on operational resilience has shifted to ICT, the world has changed dramatically: geopolitical conflicts, extreme weather events and energy insecurity have evolved fast and will challenge organisations in parallel to ICT failures and cyberattacks. This requires a different approach to incident management with more comprehensive oversight, stronger collaboration and integration. As threats are increasingly interconnected, extremely fast coordination and synchronised activation will be required. This paper discusses the building blocks of an integrated incident management system and how operational and strategic elements are related. The paper also reviews European regulations for operational resilience (Digital Operational Resilience Act [DORA]) in the context of a broader implementation approach and how this connects with enterprise risk management (ERM). This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.

Open paper page →

Cite this paper

https://doi.org/https://doi.org/10.69554/iwqr8979

Or copy a formatted citation

@article{michael2025,
  title        = {{Incident management: How to respond to the polycrisis with an integrated approach}},
  author       = {Michael Ehrnsperger},
  journal      = {Journal of Risk Management in Financial Institutions},
  year         = {2025},
  doi          = {https://doi.org/https://doi.org/10.69554/iwqr8979},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Incident management: How to respond to the polycrisis with an integrated approach

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.