Related Projects


Computer-based systems are deeply embedded in organisations. This complicates the analysis of risk associated with such systems. The traditional view is that systems have flaws and on the basis of the frequency of manifestation and severity of the consequences we should assess the risk in order to drive the management of flaws. Organisations comprise many different groups whose risk perception may differ radically and whose needs for and attitude to system change also varies depending on role and environment. So two important lines of work in the Risk Theme are: how to exploit the Social Science literature on risk perception to help manage risk in complex organisations; and how to manage the risks of change in complex computer-based systems.


One leading example of the Social Science literature is Mary Douglas’ work on Cultural Theory[15]. There she demonstrates how different constitutions of social groupings within an organisation will shape their perception of risk. We have used Douglas’ ideas to analyse potential risks in organisations focussing on how the dominance of particular groups de-emphasises certain classes of risk [2]. In the area of standards Douglas’ work would suggest that standards writers would tend to emphasise the role of deviants as a source of risks. This is very evident in the NIST security risk assessment guideline[16] which emphasises deviants and tends to neglect internal threats due to excessive diligence of some groups (e.g. system administrators in applying the latest patches). This provides the basis for a technique for identifying organizational risks that might otherwise be overlooked.

In a large-scale study of dependable process transfer from one location to another we have discovered the structure and modularity of organizations can pose significant risks for organizations. In particular the loss of information across modular boundaries can expose complex organizations to significant risks.

In studying change we have been particularly interested in exploring hybrid socio-technical approaches to mitigating the risks of change in complex organisations. One particular approach we have studied in depth is corealisation where a developer is embedded in the organisation and is capable of taking account of competing needs in the organisation[3]. We have also studied the role of trust in managing risk and as a potential source of risk arising from failures of trust [4,5]. This provides strong linkage to the Responsibility Theme.

At a macroscopic scale a fascinating example of risk in large systems is the case of Long Term Capital Management (LTCM). Donald MacKenzie has published several papers on LTCM’s innovative use of a mathematical model for hedge funds[7-14]. MacKenzie's work explores the lessons market mechanisms have for the construction of large-scale computer-based systems. In particular he explores the connection between diversity in computer systems and diversity of portfolio together with social mechanisms that defeat attempts to maintain diversity in a changing market. Here there is a strong link to the Diversity Theme. In the area of standards we have analysed the European norm for medical device risk assessment[1]. We are also commencing work on the analysis of the NIST Risk Assessment Standards[16].



