Information and communication technology (ICT) risks are no longer only technical problems: given digital transformation and increasingly complex operating environments, they have become fundamental elements of corporate strategic governance and operational resilience. This point was made by Zsakó Enikő, chair of the Magyar Közgazdasági Társaság (MKT) Ellenőrzési Szakosztálya, at a recent professional event. The invited speaker was Homolya Dániel, Managing Director for Integrated Risk Management at OTP Bank Nyrt.
Homolya noted: “we can only move fast if we have good brakes” — arguing that an organisation performs well when the business side is risk‑aware and risk management is business‑aware.
Global trends: misinformation, AI harms and cybersecurity gaps
Referring to the World Economic Forum Global Risks Report, Homolya outlined global risk trends. Misinformation and deliberate disinformation now rank among the four most significant global risks. The adverse consequences of artificial intelligence rose from 13th to 8th place in one year, and lack of cybersecurity appeared as a new category.
On a short horizon (two years) geopolitical and technological risks dominate; over the longer term, alongside environmental risks, technological risks remain among the greatest challenges. The Allianz Risk Barometer corroborates this picture: cyber incidents are among the most significant business risks, and the share of surveyed companies that view AI‑related risks as significant rose from 10 percent to 32 percent in one year.
EU regulatory background (2022–2024)
Homolya reviewed the EU regulatory landscape developed between 2022 and 2024 to address ICT risks. Key instruments include:
- the NIS2 Directive on the security of network and information systems, an EU‑wide cybersecurity regulation extending beyond the financial sector;
- the Digital Operational Resilience Act (DORA), aimed at strengthening the resilience of digital infrastructures and services; while primarily applying to financial institutions, it also covers the supplier ecosystem;
- the Critical Entities Resilience (CER) Directive;
- Operational Continuity In Resolution (OCIR) elements within resolution frameworks, which aim to preserve continuity during financial distress;
- an EU cyber resilience law addressing products with digital elements.
In addition, guidance from the Magyar Nemzeti Bank (MNB), the European Banking Authority (EBA) and expectations from the European Central Bank (ECB) form important parts of the supervisory environment.
Homolya highlighted DORA's five pillars:
- a unified, executive‑level supervised ICT risk management framework;
- rapid detection, handling and standardised supervisory reporting of ICT incidents;
- regular, risk‑based resilience testing;
- strict oversight of critical third‑party providers and contractual control requirements to manage third‑party ICT risks;
- secure, structured information sharing among industry participants.
Five main ICT risk categories and the role of third parties
Drawing on a non‑exhaustive list from the European Banking Authority, Homolya identified five main ICT risk categories:
- availability and continuity risks (e.g. inadequate capacity management, missing business continuity plans);
- security risks (phishing, DDoS attacks, unauthorized access);
- change management risks (often arising during developments or upgrades);
- data quality and data governance risks;
- ICT outsourcing risks (dependency on external providers and absence of exit plans).
When managing third‑party risks, Homolya stressed continuous measurement of partners' operational, ICT and reputational risks as well as concentration of exposures — analogous to monitoring concentration within a loan portfolio. He noted that using a single, globally widespread operating system can itself create concentration risk for an organisation.
Links to internal processes and audit
ICT risk is a specialized, continuously monitored subcategory of operational risk. Homolya explained the connections to risk and control self‑assessment (RCSA) practices and internal audit. Internal audit provides an independent assurance over the effectiveness of the framework, while ICT risk controls offer important inputs for risk‑based audit planning.
Questions, answers and practical lessons
Homolya observed that although NIS2, DORA, CER and related EU rules appeared between 2022 and 2024, the underlying principles they cover — such as cybersecurity and change management — existed long before. He argued the regulation provides a sufficiently general framework for modular development; the real question is whether different regulatory strands will consolidate into a single coherent framework and whether supervisors can respond flexibly to rapid technological change.
Asked which risks a CEO should worry about most, Homolya pointed to geopolitical and technological risks and urged rigorous consideration of business continuity. From his own career he drew two lessons: risks often combine (for example, market turbulence coinciding with change‑management issues from an expired licence), and it is critical to know the organisation's open risk exposures precisely.
On artificial intelligence — a risk topic that has grown significantly in the surveys cited — Homolya struck an optimistic tone: he sees AI primarily as an efficiency‑enhancing tool that must be governed and validated (for instance by comparing results from multiple AI platforms). He noted that the financial sector is cautious in applying AI, partly due to the EU AI Regulation, and that change management for AI raises similar questions as traditional system development. He concluded that AI will not replace risk managers who can handle it, and firms must prepare business continuity plans for potential AI failures.
For a specific supplier risk, Homolya recommended early‑warning key risk indicators, stronger contractual and service‑level agreements (SLAs), and case‑by‑case consideration of insourcing versus outsourcing. He also reported that his organisation has at times moved previously outsourced processes back in‑house after identifying external dependencies.
Closing: concrete threats that require action
In her closing remarks, Zsakó Enikő emphasised that global risk trends shift year to year. Although the presentation highlighted AI's positive potential, she warned that the technology's risks will likely attract growing attention in the coming years. Effective risk management, she said, requires not only risk and internal audit functions but also a cultural shift across the organisation supported by senior management.
Homolya closed by reminding the audience that cyber incidents and IT disruptions — whether a virus impacting a global logistics company or incidents affecting hospitals — are not abstract risks but real threats that affect all economic actors and must be addressed.
This report is based on the event recording.



