Non-uniform IT systems and processes jeopardize the optimum focus, compromising adequate support of the globalization process at Merck.
Risks resulting from the complexity of internal and external requirements
IT risks with an impact on the business result occur when information is unavailable or erroneous, unintentionally disclosed or when the processes to be depicted have been implemented in IT systems in a way that is too inflexible, too complex or illegal. Security gaps and insufficient emergency planning measures can quickly become incidents that affect the entire company.
Data protection violations owing to incorrect authorizations create a negative external impression. The increasing dependency on IT as well as the growing interconnectivity of IT landscapes make it necessary for companies to invest heavily in maintenance and enhancement. In conjunction with constantly new legal requirements, data processing represents a time-consuming and costly activity. As the complexity of the IT landscape increases, so do the potential risks.
Risks resulting from external threats
The general risk situation means more professional threats can be expected, with the trend moving toward targeted industrial espionage and sabotage. Significant risk scenarios for Merck include the failure of the central IT systems, the publication of classified confidential research and business development data, the manipulation of IT systems in chemical process control, and the revocation of drug registrations due to deficient validation of the relevant IT systems.
Risk minimization strategy
Merck ensures the necessary availability of business-critical application systems and access to business-relevant data by means of redundant structures of technical components, networks and sites, as well as suitable, tested contingency measures. Security guidelines are in place for the entire Merck Group. They include appropriate organizational and technical precautions for access control, access rights, virus protection and data protection. The efficacy of these measures is continuously monitored and reviewed by Internal Auditing as well as external auditors. A dedicated process ensures that IT risks are evaluated and appropriate measures taken. Based on the measures taken, we assume that the likelihood of a serious IT risk occurring is low.
