Preventing billion-dollar losses: how Integrated Risk Management helps avoid control gaps

Why the attack on Change Healthcare was more than an IT incident

Change Healthcare, a subsidiary of UnitedHealth Group, processes a significant share of all patient transactions in the United States. Attackers gained access to its IT environment through a remote access portal that lacked multi-factor authentication. Nine days after the initial intrusion, they deployed the ransomware they had placed in the system. The consequences were severe: around 190 million people were affected by the incident.1UnitedHealth paid a ransom of 22 million US dollars,2and the total cost of the cyberattack was initially estimated at 2.87 billion US dollars.3Later estimates put the figure at around three billion US dollars by the end of 2024.4 More than 80% of surveyed hospitals reported a negative impact on their cash flow, and 74% reported consequences for direct patient care.5

What stands out here is not just the scale of the damage, but the chain of dependencies the attack exposed. The case illustrates the core idea behind Integrated Risk Management (IRM): risks can only be managed effectively once their organisation-wide impact is understood and the relevant GRC areas (Governance, Risk, and Compliance) are involved. Only then does it become clear which measures are needed to protect the organisation and its critical infrastructure.


Why siloed GRC structures create blind spots

Many organisations already have Risk Management, an Internal Control System, Information Security Management, and Business Continuity plans in place. These are important foundations. What matters, though, is whether these areas are aligned with each other and work with the same information.

In practice, that alignment is often missing. Risks, controls, and contingency plans are frequently managed in separate systems and only reconciled when needed. Additionally, organisations often rely on Excel lists, manual evaluations, and reports that first have to be consolidated for audits or management meetings. The result is an orderly view of individual GRC areas, but no clear picture of how they interact. Simply documenting risks, controls, and contingency plans is not enough, because it leaves the connections between them unclear. As a result, organisations cannot reliably determine whether existing controls effectively reduce material risks or whether emergency plans take internal dependencies into account.

What sets Integrated Risk Management apart from traditional GRC approaches

Traditional GRC approaches often treat Risk Management, Internal Control Systems, Information Security, and Business Continuity Management as separate disciplines. Each area follows its own processes, works with its own data, and reports according to its own logic. This separation reaches its limits as soon as a risk affects several areas at once.

Integrated Risk Management brings these perspectives together. Risks are not just assessed individually; they are linked to the information that matters for managing them, including controls, measures, responsibilities, evidence, Business Continuity scenarios, and regulatory requirements.

The result is not a collection of separate GRC activities, but a shared view of the organisation’s actual risk situation. Organisations can better recognise which risks are connected, which controls are effective, where action is needed, and how changes in one area can affect others.

Crucially, this connection should not only emerge at the reporting stage. It should shape the entire risk lifecycle:

  • Align strategy and objectives with GRC requirements
  • Take the impact on other areas into account during identification and assessment
  • Link measures and controls directly to the risks they address
  • Show whether controls and measures actually work through effectiveness reviews
  • Feed insights from incidents and reporting back into assessment, management, and prioritization

This turns Risk Management from a downstream documentation exercise into an active part of corporate management. Threats, changes, or new requirements can be assessed more accurately because their impact on other areas is considered from the outset.

Which regulatory requirements are accelerating this shift

This shift towards Integrated Risk Management is not only driven by operational risks. New regulatory requirements are also increasing the pressure to manage GRC information more consistently, transparently, and verifiably. NIS2 requires affected organisations to implement Cybersecurity Risk Management, strengthen management accountability, fulfil reporting obligations, and establish Business Continuity measures. DORA sets out a comprehensive framework for financial entities covering ICT Risk Management, incident management, resilience testing, and the management of third-party ICT service providers. The CSRD expands sustainability reporting obligations and requires companies to provide greater transparency on social and environmental risks, as well as the impact of their business activities.

These requirements differ in detail but point in the same direction: organisations must be able to demonstrate how they identify, assess, treat, and monitor risks. That becomes difficult when information is scattered across multiple tools, spreadsheets, and areas of responsibility, leading to duplicate documentation, considerable coordination effort, and gaps in the evidence trail.

For organisations subject to several regulatory frameworks at once, this challenge becomes even greater. Cyber risk, operational risk, outsourcing, controls, sustainability topics, and reporting obligations cannot be managed separately in the long run when they are connected in practice. Integrated GRC management helps organisations capture requirements more consistently, make better use of existing controls and measures, and keep evidence traceable and readily available. This makes it possible to implement new regulations in a structured manner without building separate data sets, evidence trails, and coordination processes for every single requirement.

How organisations can assess their maturity level

Before introducing new processes, tools, or structures, organisations need a clear picture of their current maturity level. Only then can they judge how well Risk Management, the Internal Control System, Information Security, Business Continuity, and other GRC areas already work together, and where gaps remain. What matters is not the number of established disciplines, but the quality of the connections between them.

Typical questions for this assessment include:

  • Are risks linked to their related controls and measures, or documented separately?
  • Do control gaps become visible during day-to-day operations, or only during audits and incidents?
  • Are business continuity plans aligned with risks and dependencies?
  • Is there a consistent view of risks across multiple GRC areas?

The IRM Maturity Check from GBTEC makes this assessment straightforward. It consists of ten questions and shows within a few minutes how integrated your Risk Management is today. Based on the results, you will receive recommendations for the next steps towards a more integrated approach to Risk Management.

How the BIC Platform enables Integrated Risk Management

Integrated Risk Management needs more than additional documentation. What matters is GRC management software that brings core GRC areas together on a shared data foundation and makes their interactions visible. As part of the BIC Platform, BIC GRC unites Enterprise Risk, Internal Controls, Information Security, Business Continuity, Audit Management, and other GRC areas in one integrated approach.

This makes it possible to manage GRC information in context, rather than administering it separately. For example, organisations can see which controls address a risk and which measures are effective. Standardised workflows and a consistent audit trail help document tasks, changes, and strategic decisions in a structured way.

This approach becomes particularly effective when GRC and day-to-day operations are not treated separately. With BIC Process Design, risks and controls can be linked more closely to the processes in which they play a role. Changes to workflows, systems, or responsibilities can therefore be reflected more easily in the relevant control and risk context. This keeps GRC information closer to operational reality and reduces the risk of working with outdated data.

BIC GRC stands for an integrated approach rather than a collection of separate individual solutions. Organisations gain a consistent view of risks, controls, measures, and evidence across multiple GRC areas. This connection is essential if risks are not merely to be documented but managed effectively.

Conclusion

The Change Healthcare case shows that effective Risk Management does not end with recording individual risks. What matters is whether organisations understand how risks, controls, security measures, contingency plans, and other elements interact. Only then can critical dependencies be assessed early enough and the right measures be put in place.

Integrated Risk Management provides the foundation for this. It connects GRC information, makes interactions traceable, and helps manage risks in their business context rather than merely documenting them. For organisations, this means fewer isolated views and greater clarity about where action is needed.

BIC GRC provides an ideal basis for implementing this approach. Organisations can connect core GRC areas consistently, trace dependencies, and provide structured evidence for audits and regulatory purposes.

A clear starting point makes it easier to plan the next steps. The IRM Maturity Check shows how integrated your Risk Management is today and which measures can help you create a clearer overall picture of your risks, controls, and dependencies.

Sources

1 Source: https://www.cybersecuritydive.com/news/change-healthcare-attack-affects-190-million/738369/
2 Source: https://www.cybersecuritydive.com/news/change-healthcare-attack-affects-190-million/738369/
3 Source: https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/change-healthcare-cyberattack-costs-to-reach-2-87b/
4 Source: https://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/the-financial-toll-of-the-change-healthcare-hack-7-numbers/
5 Source: https://www.aha.org/news/news/2024-03-15-aha-survey-change-healthcare-cyberattack-having-significant-disruptions-patient-care-hospitals-finances


Frequently asked questions

What is Integrated Risk Management (IRM)?

Integrated Risk Management, or IRM, connects Risk Management with related GRC areas such as Internal Controls, Information Security, Business Continuity, Compliance, and Audit. Risks are not assessed in isolation but in relation to their impacts, dependencies, and control measures. This creates a clearer view of the organisation’s actual risk situation and of the areas that need to be involved when addressing a risk.

What is ransomware?

Ransomware is malicious software that encrypts data or systems and demands a ransom for their release. In many cases, encryption is not the only issue: attackers also steal data and threaten to publish it in order to increase pressure on the affected organisation. For GRC professionals, ransomware can therefore quickly become a cross-functional risk, as it involves not only restoring IT systems, but also data protection, Business Continuity, communication, and regulatory evidence.

Why is ransomware particularly damaging?

Ransomware is particularly damaging because it triggers attacks on several levels at once: systems are encrypted, data can be exfiltrated, business operations come under pressure, and communication with customers, authorities, or partners becomes an additional challenge. Many attacks combine technical disruption with data theft and extortion. This turns a single incident into an event that goes far beyond restoring IT systems and affects several parts of the organisation at the same time.

Why is the Change Healthcare case relevant to Risk Management?

The Change Healthcare case shows how far-reaching the consequences of a single control gap can be. Attackers gained access to the IT environment through a remote access portal that lacked multi-factor authentication, which led to significant disruption of critical processes across the US healthcare system. For organisations, the key lesson is that risks need to be viewed in their full context. Only then can the potential impact of a risk and the measures needed to address it be recognised in time.

What role does Business Continuity Management (BCM) play in Integrated Risk Management (IRM)?

Business Continuity Management is a core part of Integrated Risk Management, because risks must not only be assessed but also remain manageable in a real crisis. Contingency and recovery plans should therefore be linked to Risk Management, Information Security Management, and the Internal Control System. This makes it clear which scenarios are particularly critical, which precautions need to be in place, and how key business processes can be maintained or restored during a crisis. The Change Healthcare case shows how quickly a cyber risk can affect billing, payment flows, and continuity of care once critical functions become unavailable.

What does GRC management software deliver for integrated GRC management?

GRC management software brings core areas such as Risk Management, the Internal Control System, Information Security Management, Business Continuity Management, Compliance, Audit Management, Data Protection Management, and ESG Management together on a shared platform. With integrated GRC management, risks can be linked to controls, measures, responsibilities, evidence, and regulatory requirements. This provides a stronger basis for recognising dependencies, assessing risks in their full context, and deriving the measures needed.