Merck utilizes a wide range of IT systems and processes to provide optimum focus and appropriate support for its globalization. Trends in information technology offer various opportunities for Merck.
Opportunities from the use of mobile platforms and solutions
Mobility offers unique opportunities for reaching and networking employees, partners and customers, and stimulates synergies between value added for the company and individual interests. Mobility not only means the mobile use of online services; it is changing the way people see digital services and bringing business activities closer to employees, customers and partners without limiting them at all. The trend towards mobility suggests that mobile platforms and solutions will become important channels in terms of digital networking.
Opportunities from networked collaboration and digital media
New developments in the field of networked collaboration and digital media are opening up excellent opportunities for contact with employees, partners and customers, and establishing new channels for teamwork, interaction and communication. In R&D at Merck, these developments especially benefit collaboration within the company and with external partners. In addition, socially-driven information technology can also aid interaction in the field of life sciences and thereby foster innovation. Merck has launched a Group-wide program known as “Connect 15”. Its objective is to harmonize corresponding IT systems, to simplify communications around the world and to facilitate cooperation between employees, external partners and customers. In the long term, the program offers the opportunity to reduce operating costs and to enhance productivity within the organization.
Opportunities due to further harmonization of IT systems
Harmonized IT systems that map standardized business processes allow management to steer business consistently worldwide. This enables efficient working, the fast and smooth integration of new businesses and the easier leverage of synergy effects. In addition, this trend is being driven by the growth of cloud solutions, which benefits from the use of configurable standard solutions. The effect of this harmonization will be seen firstly in the reduction of operating costs, while secondly the increased transparency will mean the opportunity to make decisions faster and to greater beneficial effect.
The value added by information technology in day-to-day work is countered by potential risks that arise directly from the advantages of the global availability of electronic data storage.
Risk from e-crime and cyber attacks
With the Internet as a means and the abuse of digital technologies as a new type of crime, e-crime as a whole is developing rapidly and poses a major challenge. This is giving rise to threats to Merck such as the failure of central IT systems, the exposure of confidential data from research and business activities, the manipulation of IT systems in chemical process steering, or greater burdens on or impairment of IT systems due to virus attacks. This scenario also includes the temporary takeover of exposed systems by hackers and consequently the possible revocation of drug registrations due to deficient validation of relevant IT systems.
The entire Merck Group has global security guidelines and information protection management for IT and “non-IT” areas, each with organizational and technical standards for access rights as well as information and data protection. Attention in the IT area is focused on hardening the corresponding systems and, for example, identifying cyber attacks. Group Security is a member of the Alliance for Cyber Security of the German Federal Office for Information Security. A pilot data leakage prevention project is currently being introduced at Merck to protect sensitive business information. The effectiveness of internal (IT) protection measures is monitored on an ongoing basis and reviewed by Group Security, Group Internal Auditing and third-party auditors.
The potential losses resulting from e-crime cannot be generally categorized, not least on account of the multitude of different possible ways it can be committed; its impact on the net assets, financial position and results of operations would depend on the individual case. Despite the protective measures already being taken by Merck to great effect, the occurrence of the risk of e-crime is considered possible, with an estimated substantial impact. It is therefore classed as a medium risk.
Risks due to failure of business-critical IT applications or to failure of data center capacity
IT applications used globally in process steering form the basis for the contractual delivery of products and solutions to the customers of the Merck Group around the world. Fluctuations in the quality of internal IT services can lead to the failure of business-critical IT applications, which would have a direct influence on Merck’s ability to deliver. Similarly, the failure of a data center can impair service quality or trigger the complete failure of critical applications.
The primary objective of Information Services in the Merck Group is to maintain service quality in keeping with the service levels agreed with the Group functions and divisions. To achieve this objective, Merck uses a quality management system certified to ISO 20000:2005, which comprises steering measures to maintain a consistent standard of quality. In addition to day-to-day operating processes, this also provides directives on how to act in a crisis situation in the form of a regularly tested crisis management plan. As part of this crisis management, Merck operates several redundantly designed data centers so that service quality will be maintained even in the event of the failure of one data center.
Despite the mitigating measures taken, functional continuity plans and the unlikely probability of occurrence, the impact of a failure of business-critical IT applications owing to fluctuations in the quality of internal IT services and its influence on the net assets, financial position and results of operations is considered a medium risk.

search hit 30