Georgia Healthcare Group PLC Annual Report 2018 Strategic Report Principal risks and uncertainties continued Principal Risk/Uncertainty Key Drivers/Trends Mitigation Information technology and operational We face information technology We hold confidential data about our patients In 2017-2018, we have formed an Information and operational risk. and customers given the nature of our and Corporate Security Department at healthcare services and must be vigilant Group level and appointed experienced A cyber attack, security breach or to guard data privacy. professionals to it. A strategy and action unauthorised access to our systems plan has been defined and set for 2018 could cause important or confidential Cyber security threats are increasing year and further. data to be misappropriated, misused, after year. disseminated or lost. We have completed a centralised, GHG-wide The Group has expanded and has IT infrastructure (hardware and network) that In addition, improper access or information increasingly complex operations to manage, has enhanced the Group’s overall information misappropriation may lead to insider trading including the pharmaceutical business and cyber security level. or other illegal actions by employees acquired in the previous years. or others. We continue to design and implement new business processes and risk management Software or network disruption may also structures to better manage the business cause the Group to experience lost revenue, and to help mitigate our operational risks. failed customer transactions or non-timely submission of regulatory or other reports. Internal Audit conducts regular reviews of IT controls such as the policies for information Non-recurring operational risks include storage, availability and access, while incurring loss or unexpected expenses from updating its assessment of risks and system failure, human error, fraud or other recommendations. Internal Audit reports unexpected events. to the Audit Committee on its findings. Impact Any of the above could lead to disruption of our business and operations, affect patient and customer loyalty, subject us to state and Governmental investigation, litigation, damages, penalties and/or reputational damage. 58