Industry risks

IT risk management: projects, infrastructure, Agile

IT risk is not only breaches. It is failed projects, infrastructure outages and contractor dependence. We break down how to manage them, including in agile teams (Agile/Scrum).

Updated: June 28, 2026 · Author: Evgeny Telenkov · ≈ 7 min read
IT risk management: projects, infrastructure, Agile

Main groups of IT risks

Risk management in Agile/Scrum

In agile teams risk management is built into the rhythm of work rather than done once a year:

IT risks and continuity

Even with good protection you need a plan for failure: target recovery objectives (RTO/RPO), backups and a disaster recovery plan (DRP). This links IT risk to business continuity.

See how resilient your business really is

13 questions, 5 minutes, free — results on screen and by email.

FAQ

How is IT risk management different in Agile?

It is continuous: risks are reviewed every sprint, a lightweight register is kept and dangerous assumptions are tested with early prototypes, rather than once at the start of the project.

Are IT risks only about cybersecurity?

No. They also include failed projects, infrastructure outages, contractor dependence and data risks. Cybersecurity is an important but not the only part.

Evgeny Telenkov
Evgeny Telenkov
Chief Risk Officer · PhD in Economics · "Best Risk Manager of Russia 2020"
20 years in risk management. Led risk management at Beeline, Nornickel, Rosneft and EY. Built business continuity plans for Nornickel, Rostec, NSD and DIA. Trained 300+ risk and BCM specialists.
More about the approach and expert →