Merck uses a diversity of IT systems and processes in order to optimally focus and adequately support its globalization. This involves a number of potential risks.
Risks resulting from the complexity of internal and external requirements
IT risks with an impact on business results occur when information is not available in time, or is erroneous or unintentionally disclosed, or when the mapped processes have been implemented in IT systems in a way that is too inflexible, too complex or even illegal. Security gaps in IT solutions and insufficient contingency planning measures can quickly become incidents that affect the entire company.
Data protection violations owing to incorrect authorizations can create a negative external impression. The growing connectivity of IT landscapes and the increasing dependency on IT make it necessary for companies to invest heavily in maintenance and enhancement. In conjunction with constantly new legal requirements, data processing represents an increasingly time-consuming and costly activity. As the complexity of the IT landscape increases, so do the potential risks.
Risks resulting from external threats
Worldwide, external threats are becoming increasingly professional in nature, with the trend moving toward targeted industrial espionage and sabotage. In addition, cyberattacks are being used as a means of gaining attention and of protest. This is resulting in risk scenarios for Merck such as the failure of central IT systems, the disclosure of confidential research and business development data, the manipulation of IT systems in chemical process control, an increased burden or adverse impact on IT systems as a result of virus attacks, the temporary hijacking of exposed systems by computer hackers, and the resulting potential revocation of drug registrations due to deficient validation of the relevant IT systems.
Risk minimization strategy
Merck has been generally addressing and minimizing these risks for several years by means of a certified information protection management system based on ISO 27001. This comprises redundant structures of technical components, networks and sites, as well as suitable, tested contingency measures. Thus Merck ensures the necessary availability of business-critical application systems and access to business-relevant data. Globally valid security guidelines are in place for the entire Merck Group. They include appropriate organizational and technical precautions for access control, access rights, virus protection and data protection. The efficacy of these measures is continuously monitored in connection with the information protection management system and reviewed by Group Internal Auditing as well as external auditors. A further process ensures that IT risks are evaluated and appropriate measures taken. Based on the measures taken, we assume that the likelihood of a serious IT risk occurring is low.

search hit 08