SBM · Advanced Level

Technology and Change

Strategic application of technology and management of organisational change. Digital transformation strategy: business model implications; technology adoption lifecycle (Rogers); first-mover vs fast-follower; capabilities required (technical, organisational, cultural); common reasons for failure; success factors. Data analytics and big data strategy: descriptive, diagnostic, predictive, prescriptive analytics; data warehousing; data lakes; structured vs unstructured data; the 5 Vs (volume, velocity, variety, veracity, value); data governance; privacy and ethics. Artificial Intelligence and Machine Learning: types of AI (narrow, general, super); machine learning approaches (supervised, unsupervised, reinforcement, deep learning); generative AI revolution (GPT, Claude, Gemini); business applications (automation, predictive analytics, personalisation, fraud detection, customer service); AI risks (bias, hallucinations, transparency, ethics); AI governance frameworks (EU AI Act, UK approach). Fintech and digital disruption: payments, lending, wealth management, insurance (insurtech), regtech; banking-as-a-service; open banking (PSD2/UK Open Banking); decentralised finance (DeFi); central bank digital currencies (CBDCs). Cybersecurity strategy: cyber risk landscape; common attack types (ransomware, phishing, supply chain, social engineering, insider threat, DDoS); cybersecurity frameworks (NIST, ISO 27001, CIS Controls); UK NCSC guidance; defence-in-depth; identity and access management; incident response; cyber insurance. Major incidents and lessons (Colonial Pipeline, SolarWinds, MOVEit). Change management theories: Kurt Lewin's three-stage model (unfreeze-change-refreeze); Kotter's 8-Step Process; McKinsey 7S framework (strategy, structure, systems, shared values, skills, style, staff); Burke-Litwin Causal Model (transformational vs transactional factors); ADKAR model (Awareness, Desire, Knowledge, Ability, Reinforcement). Managing resistance to change: sources of resistance; communication strategies; involvement and participation; coalition building; quick wins. Leadership for change.

60 min read

Learning Objectives

  • Apply digital transformation strategy frameworks and identify success factors
  • Discuss data analytics maturity and big data implications for business strategy
  • Discuss AI/ML applications, risks, and governance considerations
  • Discuss fintech disruption and its strategic implications across financial services
  • Apply cybersecurity strategy frameworks and risk management approaches
  • Apply change management theories (Lewin, Kotter, McKinsey 7S, Burke-Litwin, ADKAR)
  • Identify sources of resistance to change and apply mitigation strategies
  • Discuss leadership requirements for successful organisational change

Digital Transformation Strategy

Digital transformation is the strategic and cultural change driven by digital technologies that fundamentally alters how organisations operate and deliver value. More than just technology — encompasses business model, processes, culture, capabilities.

Why digital transformation matters:

  • Customer expectations shifted — digital-first interactions expected
  • Disruptive entrants (fintechs, platforms) challenge incumbents
  • Operational efficiency gains
  • Data as strategic asset
  • Competitive necessity in most industries
  • COVID-19 accelerated digital adoption (remote work, e-commerce, telehealth)

Levels of digital transformation:

  1. DIGITISATION: converting analog to digital (paper to PDF; physical filing to electronic)
  2. DIGITALISATION: using digital tech to improve processes (e-commerce, digital marketing, CRM systems)
  3. DIGITAL TRANSFORMATION: business model and culture change (platform business; data-driven decision making; new value propositions)

Technology Adoption Lifecycle (Rogers — Diffusion of Innovations):

  • INNOVATORS (2.5%): risk-takers; technical mindset
  • EARLY ADOPTERS (13.5%): visionaries; respected opinion leaders
  • EARLY MAJORITY (34%): pragmatists; risk-averse but seeing benefits
  • LATE MAJORITY (34%): sceptics; adopt under pressure
  • LAGGARDS (16%): traditionalists; resist change
  • "CHASM" between early adopters and early majority — major challenge for tech firms (Geoffrey Moore — Crossing the Chasm)

First-mover vs fast-follower:

First-mover advantagesFast-follower advantages
Brand association with category Avoid R&D/learning costs
Technology leadership Improve on first-mover's mistakes
Customer lock-in (switching costs) Customer needs better understood
Network effects (platforms) Lower marketing cost (category established)
Patent protection Better cost economics

First-mover disadvantages:

  • High R&D and education costs
  • Mistakes visible (e.g., MySpace before Facebook)
  • Free-rider effects benefit followers
  • Technology may obsolete
  • Customer behaviours not yet established

Industry context matters: high network effects favour first-movers; commodity-like products favour fast followers.

Capabilities required for digital transformation:

1. Technical capabilities:

  • Cloud infrastructure
  • Data engineering and analytics
  • Software development (agile, DevOps)
  • Cybersecurity
  • AI/ML capabilities
  • Integration and architecture

2. Organisational capabilities:

  • Agile working methods
  • Cross-functional teams (vs functional silos)
  • Product management approach (vs project)
  • DevOps culture
  • Test and learn mindset
  • Speed of decision making

3. Cultural capabilities:

  • Customer-centricity
  • Data-driven decision making
  • Innovation and experimentation
  • Risk tolerance (failure as learning)
  • Continuous learning
  • Collaboration over hierarchy

Common reasons for digital transformation failure:

  1. Technology-led, not business-led: implementing tech without business case
  2. Cultural resistance: existing culture rejects change
  3. Lack of leadership commitment: visible support insufficient
  4. Insufficient capabilities: skills gaps; under-investment in talent
  5. Legacy IT constraints: technical debt holding back transformation
  6. Inadequate change management: people-side neglected
  7. Underestimating timeline and cost: 60-70% of transformations fail to meet targets
  8. Vendor over-reliance: outsourced strategy
  9. Data quality and integration issues: foundation not in place

Success factors:

  • STRONG, COMMITTED LEADERSHIP — CEO/board sponsorship
  • CLEAR VISION linked to business outcomes
  • STRATEGIC PRIORITISATION (focus on high-impact areas)
  • BUILD CAPABILITIES (talent, processes, technology)
  • AGILE EXECUTION (small, iterative, fast)
  • CHANGE MANAGEMENT (people, culture, mindset)
  • CUSTOMER FOCUS
  • METRICS AND ACCOUNTABILITY
  • ECOSYSTEM PARTNERSHIPS

Examples of digital transformation:

  • Microsoft (Nadella era): from Windows-centric to cloud-first (Azure); cultural shift to growth mindset
  • Domino's: from pizza company to "tech company that sells pizza" — digital ordering 70%+ of revenue
  • JPMorgan: massive technology investment ($14bn+ pa) to compete with fintechs
  • John Lewis Partnership: omnichannel transformation
  • NHS: digital health records; NHS App; remote consultations

Examples of failed transformations:

  • Kodak: invented digital camera but couldn't transform; bankruptcy 2012
  • Blockbuster: missed streaming transition; eclipsed by Netflix
  • BlackBerry: ignored touchscreen revolution
  • Toys R Us: outsourced online to Amazon; lost capability
  • HMV: did not adapt to digital music

Data Analytics and Big Data Strategy

Data analytics uses data to inform decisions. Big data refers to data sets too large or complex for traditional processing.

Analytics maturity (Gartner):

  1. DESCRIPTIVE: "What happened?" Reports; dashboards; KPIs. Most common.
  2. DIAGNOSTIC: "Why did it happen?" Drill-down; root cause analysis; correlations.
  3. PREDICTIVE: "What will happen?" Statistical models; machine learning. Forecasting.
  4. PRESCRIPTIVE: "What should we do?" Optimisation; recommendation systems; AI-driven decisions.

Each level builds on the previous. Most organisations are descriptive/diagnostic; competitive advantage increasingly from predictive/prescriptive.

The 5 Vs of Big Data:

  • VOLUME: large amounts (terabytes to petabytes)
  • VELOCITY: speed of generation and processing (real-time streaming)
  • VARIETY: structured + unstructured data (text, images, video, sensors)
  • VERACITY: data quality and reliability
  • VALUE: business benefit derived

Sometimes extended with: VARIABILITY, VISUALISATION.

Structured vs unstructured data:

  • Structured: fits in tables (databases, spreadsheets) — ~20% of data
  • Unstructured: free-form (text, images, video, audio, social media) — ~80%
  • Big data analytics increasingly handles unstructured

Data architecture:

  • Data warehouse: structured data; pre-processed; reporting-focused
  • Data lake: raw data (any format); flexible; later processing
  • Data lakehouse: combines warehouse and lake (Databricks)
  • Cloud-based (AWS, Azure, GCP) increasingly common

Data governance:

  • Data ownership and accountability
  • Data quality standards
  • Data lineage (track origin and transformations)
  • Master data management (single sources of truth)
  • Privacy and security controls
  • Retention policies
  • Chief Data Officer (CDO) role increasingly common

Data privacy and ethics:

  • UK GDPR / Data Protection Act 2018
  • Lawful basis (consent, contract, legal obligation, vital interests, public interest, legitimate interests)
  • Data subject rights (access, rectification, erasure, portability, object)
  • Data minimisation principle
  • Privacy by design
  • ICO enforcement (fines up to 4% global turnover)
  • Ethical considerations: algorithmic bias, surveillance, manipulation
  • "Just because we CAN doesn't mean we SHOULD"

Strategic value of data:

  • Customer insights and personalisation
  • Pricing optimisation
  • Risk management (credit decisions, fraud detection)
  • Supply chain optimisation
  • Predictive maintenance
  • Product development (data-driven design)
  • Marketing effectiveness
  • Operational efficiency

Data monetisation:

  • Direct: selling data products (carefully, with consent)
  • Indirect: better decisions, products, services from data
  • Most value usually indirect

Data analytics implementation challenges:

  • Data quality (often poor)
  • Data silos (different systems, departments)
  • Skills gap (data engineers, scientists)
  • Privacy and security
  • Cultural resistance to data-driven decisions
  • Translating insights to action
  • Cost of infrastructure

Data-driven decision making — strategic imperatives:

  • Move from "HiPPO" (Highest Paid Person's Opinion) to data-informed decisions
  • Test and learn culture
  • A/B testing
  • Hypothesis-driven analytics
  • Insights translated to actions
  • Closing the loop (measuring outcomes of decisions)

Artificial Intelligence and Machine Learning

Artificial Intelligence (AI) = systems performing tasks that typically require human intelligence (perception, learning, reasoning, decision-making).

Types of AI:

  • NARROW AI (ANI): specific tasks (image recognition, language translation, game playing). Current state-of-the-art.
  • GENERAL AI (AGI): human-level capability across domains. Theoretical.
  • SUPER AI (ASI): beyond human intelligence. Theoretical.

"AI" in business context typically means ANI.

Machine Learning (ML) approaches:

1. Supervised learning:

  • Trained on LABELLED data (input-output pairs)
  • Examples: image classification (cats vs dogs); credit scoring; spam detection
  • Algorithms: linear regression, decision trees, random forests, neural networks

2. Unsupervised learning:

  • Finds patterns in UNLABELLED data
  • Examples: customer segmentation; anomaly detection; recommendation systems
  • Algorithms: k-means clustering, hierarchical clustering, PCA

3. Reinforcement learning:

  • Agent learns from REWARDS/PENALTIES through interaction
  • Examples: game-playing AI (AlphaGo); robotics; dynamic pricing

4. Deep learning:

  • Subset using NEURAL NETWORKS with multiple layers
  • Excels at: image recognition, natural language processing, speech recognition
  • Requires large data and compute
  • Driving recent AI advances

Generative AI revolution (2022+):

  • Large Language Models (LLMs): GPT-4/5 (OpenAI), Claude (Anthropic), Gemini (Google), Llama (Meta)
  • Generate text, code, images, audio, video
  • Multimodal capabilities (text + images + audio)
  • Foundation models: pre-trained on vast data; fine-tuned for specific applications
  • Significantly more capable than previous AI
  • Lowering barrier to AI use (natural language interface)

Generative AI business applications:

  • Customer service (chatbots, virtual agents)
  • Content generation (marketing, code, reports)
  • Knowledge management (document search, summarisation)
  • Programming assistance (GitHub Copilot, Cursor)
  • Research and analysis
  • Translation
  • Creative work (design, copy, video)
  • Process automation (combined with traditional automation)

AI business applications (broader):

  • Predictive analytics (forecasting, churn prediction)
  • Personalisation (Netflix, Amazon recommendations)
  • Fraud detection (banks, insurance)
  • Computer vision (manufacturing quality control, medical imaging)
  • Natural language processing (sentiment analysis, document automation)
  • Robotic Process Automation (RPA) + AI
  • Drug discovery
  • Autonomous vehicles
  • Predictive maintenance

AI risks and challenges:

1. Bias:

  • Training data biases reflected in outputs
  • Examples: facial recognition less accurate for women, people of colour
  • Hiring algorithms biased against women (Amazon scrapped one)
  • Mitigations: diverse training data; bias testing; explainability

2. Hallucinations:

  • Generative AI can produce confident-sounding but FALSE information
  • Particular risk in factual/professional contexts (law, medicine, accounting)
  • Mitigations: human review; retrieval-augmented generation (RAG); grounding in verified sources

3. Transparency / explainability:

  • "Black box" problem — complex models hard to interpret
  • Regulatory requirements for explanations (EU AI Act, GDPR Article 22)
  • XAI (Explainable AI) techniques developing

4. Data privacy:

  • Training data may contain personal information
  • Generative AI may reproduce training data
  • Compliance with GDPR/UK Data Protection Act 2018

5. Intellectual property:

  • Training data copyright concerns (NYT vs OpenAI litigation)
  • Output copyright unclear
  • Trade secrets exposure

6. Job displacement:

  • Automation may displace some jobs
  • New jobs created but transition challenging
  • Skills shift required

7. Misuse:

  • Deepfakes
  • Misinformation
  • Cybersecurity attacks (AI-enhanced phishing)
  • Autonomous weapons concerns

8. Energy use:

  • Training large models energy-intensive
  • Sustainability concerns

AI governance frameworks:

EU AI Act (effective phased 2024-2027):

  • First comprehensive AI law globally
  • Risk-based approach:
    • UNACCEPTABLE risk: banned (social scoring, real-time biometric ID with exceptions)
    • HIGH risk: strict requirements (medical devices, hiring, credit, law enforcement, education)
    • LIMITED risk: transparency requirements (chatbots disclose AI; deepfakes labelled)
    • MINIMAL risk: light-touch (most AI applications)
  • General-Purpose AI (GPAI) — transparency, training data summaries, copyright compliance
  • Significant fines (up to €35m or 7% global turnover)
  • Affects UK companies with EU customers

UK approach (pro-innovation, principles-based):

  • White Paper "A pro-innovation approach to AI regulation" (March 2023)
  • Five cross-sector PRINCIPLES:
    1. Safety, security, robustness
    2. Transparency and explainability
    3. Fairness
    4. Accountability and governance
    5. Contestability and redress
  • EXISTING REGULATORS apply principles in their domains (FCA, ICO, MHRA, Ofcom, CMA)
  • NO single AI law (unlike EU)
  • AI Safety Institute focused on advanced AI risks
  • Voluntary commitments from leading AI companies

Other frameworks:

  • NIST AI Risk Management Framework (US — voluntary)
  • OECD AI Principles
  • UNESCO Recommendation on Ethics of AI
  • IEEE standards
  • ISO/IEC AI standards developing

AI strategy considerations:

  • Define use cases with clear value
  • Build vs buy vs partner
  • Data foundation prerequisite
  • Talent acquisition (data scientists, AI engineers)
  • Ethical guidelines and governance
  • Risk management and human oversight
  • Change management for adoption
  • Monitoring and continuous improvement
  • Cybersecurity for AI systems

AI in accounting and finance:

  • Audit automation (sample selection, anomaly detection, journal entry testing)
  • Tax computations and compliance
  • Financial forecasting
  • Fraud detection
  • Regulatory reporting
  • Document review
  • Code review for ERP/financial systems
  • Training and education

Fintech and Digital Disruption

Fintech = use of technology to deliver financial services. Major disruption to traditional financial services.

Drivers of fintech:

  • Customer expectations for digital, mobile-first services
  • Lower cost than traditional banks
  • Regulatory openings (e.g., Open Banking)
  • Data and AI advances
  • Cloud computing reducing infrastructure costs
  • Mobile penetration
  • Disintermediation potential

Fintech sectors:

1. Payments:

  • Mobile payments (Apple Pay, Google Pay)
  • Peer-to-peer (Venmo, PayPal)
  • Cross-border (Wise, formerly TransferWise)
  • Buy Now Pay Later (Klarna, Clearpay)
  • Merchant acquiring (Stripe, Square)

2. Lending:

  • Peer-to-peer (Funding Circle, RateSetter)
  • SME lending platforms (iwoca, Capital on Tap)
  • Consumer lending (Klarna, Affirm)
  • Mortgage tech (Habito, Trussle)
  • BNPL (regulatory scrutiny growing)

3. Banking:

  • Challenger banks (Monzo, Starling, Revolut, Nubank, N26)
  • Digital-first; no branches; lower fees; better UX
  • Banking-as-a-Service (BaaS) — embedded financial services
  • Some achieving profitability after years of losses

4. Wealth management (Wealthtech):

  • Robo-advisors (Nutmeg, Wealthfront)
  • Trading platforms (Robinhood, Trading 212)
  • Cryptocurrency exchanges (Coinbase, Binance)
  • Investment apps (Freetrade)

5. Insurance (Insurtech):

  • Direct-to-consumer (Lemonade, Marshmallow)
  • Embedded insurance (at point of sale)
  • Usage-based insurance (telematics for car insurance)
  • Parametric insurance (data-driven, automatic payouts)
  • AI-driven underwriting

6. Regtech (Regulatory technology):

  • Anti-money laundering (AML) automation
  • Know Your Customer (KYC) digital onboarding
  • Transaction monitoring
  • Regulatory reporting automation
  • Compliance management

OPEN BANKING (UK):

  • UK pioneer; mandated by CMA following Retail Banking investigation 2017
  • Aligned with EU PSD2 (Payment Services Directive 2)
  • Customers can SHARE BANK DATA with third parties (with consent)
  • API standards enable secure access
  • Account aggregation and payment initiation services
  • Driving innovation: budgeting apps, lending decisions, payment alternatives
  • Following: Open Finance (extension to other financial products)
  • Open Data principles spreading internationally

Decentralised Finance (DeFi):

  • Financial services on PUBLIC BLOCKCHAINS (mainly Ethereum)
  • Smart contracts replace intermediaries
  • Lending, trading, derivatives, asset management
  • Total value locked grew to $200bn+ at peak (2021)
  • Volatility and risk concerns
  • Regulatory uncertainty; significant scams and failures (FTX, Terra Luna)
  • UK FCA cautious approach

Cryptocurrencies:

  • Bitcoin (2009) — store of value narrative
  • Stablecoins (USDC, USDT) — fiat-backed
  • Volatility makes use as currency limited
  • Regulatory scrutiny intensifying
  • Accounting: typically IAS 38 Intangible (covered in CR module)

Central Bank Digital Currencies (CBDCs):

  • Digital fiat currency issued by central bank
  • UK: "Britcoin" exploration by Bank of England (HM Treasury joint task force)
  • China leading with digital yuan (e-CNY) — pilot programme widespread
  • EU digital euro investigation
  • US slower; concerns about implications
  • Different from cryptocurrency: state-backed, stable, controllable
  • Implications for monetary policy, banking, privacy

Banking-as-a-Service (BaaS):

  • Banks license platforms for non-banks to embed financial services
  • Examples: airlines offering loyalty cards; retailers offering checkout finance
  • Embeds banking into customer journeys
  • Examples of providers: Solaris, Railsbank, Stripe Treasury

Strategic implications for incumbent financial institutions:

Threats:

  • Customer relationships disintermediated
  • Profit pools eroded
  • Talent challenges (tech vs banking)
  • Cost-to-income ratios uncompetitive
  • Customer expectations from fintechs raise bar

Responses:

  1. Acquire: buy fintech challengers (e.g., JPMorgan acquired Frank — though disputes)
  2. Partner: API integration with fintechs (e.g., HSBC + Tradeshift)
  3. Build: own digital bank (e.g., Goldman's Marcus, RBS's Bo — closed)
  4. Invest: corporate venture capital arms
  5. Transform: reinvent core (long, expensive — most are pursuing)

Examples of incumbent transformation:

  • JPMorgan: massive technology investment; cloud migration; AI integration
  • HSBC: digital-first strategy; mobile-banking improvements
  • BBVA: among most digitally advanced traditional banks
  • Lloyds: ongoing transformation programme
  • Goldman: Marcus (consumer); Apple Card partnership

Cybersecurity Strategy

Cybersecurity protects systems, networks, programs, and data from digital attacks. Increasingly material risk for all organisations.

Cyber risk landscape:

  • Cyber attacks GROWING in frequency and sophistication
  • UK Cyber Security Breaches Survey 2024: 50% of UK businesses identified breaches/attacks in last year
  • Average cost of breach for medium/large UK business: tens of thousands to millions
  • Indirect costs (reputation, downtime, customers) often larger than direct
  • State-sponsored actors increasingly active
  • Ransomware emerged as major threat 2010s+

Common attack types:

1. Ransomware:

  • Encrypt files; demand ransom
  • Often double extortion (also threaten to leak data)
  • Examples: WannaCry (NHS impact 2017); Colonial Pipeline (2021); MOVEit (2023)
  • Average ransom payment growing to millions
  • Major business disruption — even if backup restores possible

2. Phishing:

  • Fake emails/messages tricking users into revealing credentials or clicking malicious links
  • Spear phishing (targeted), whaling (executives)
  • Most common entry vector for attacks
  • AI-enhanced (more convincing)

3. Supply chain attacks:

  • Compromise trusted vendor/software to reach customers
  • Examples: SolarWinds (2020); Kaseya (2021); MOVEit (2023)
  • Hard to detect — comes via trusted channel
  • Devastating reach

4. Social engineering:

  • Manipulate humans (vs technology)
  • CEO fraud / Business Email Compromise (BEC)
  • Pretexting; impersonation
  • Increasingly sophisticated (deepfakes)

5. Insider threat:

  • Malicious or negligent employees/contractors
  • Often hardest to detect (legitimate access)
  • Mitigations: access controls; monitoring; segregation of duties

6. DDoS (Distributed Denial of Service):

  • Overwhelm systems with traffic to disrupt services
  • Often cover for other attacks
  • Common in financial services, government, gaming

7. Zero-day exploits:

  • Attacks using previously unknown vulnerabilities
  • No patch available
  • High-value (sold on dark web; used by states)

Cybersecurity frameworks:

NIST Cybersecurity Framework (CSF):

  • US National Institute of Standards and Technology
  • Globally adopted; voluntary
  • Five core functions:
    1. IDENTIFY: assets, business environment, governance, risk assessment, risk management strategy
    2. PROTECT: access control, awareness training, data security, processes, maintenance, protective technology
    3. DETECT: anomalies and events, continuous monitoring, detection processes
    4. RESPOND: response planning, communications, analysis, mitigation, improvements
    5. RECOVER: recovery planning, improvements, communications
  • 2024 update added GOVERN as cross-cutting function

ISO/IEC 27001:

  • International standard for Information Security Management Systems (ISMS)
  • Certifiable; widely adopted
  • Risk-based approach
  • Annex A: 93 controls (in 2022 version) covering organisational, people, physical, technological controls
  • Common requirement for B2B contracts, regulators

CIS Controls (Center for Internet Security):

  • Prioritised set of cybersecurity actions
  • 18 critical controls
  • Implementation Groups (IG1, IG2, IG3) — increasing complexity
  • Practical, actionable

UK NCSC (National Cyber Security Centre):

  • Part of GCHQ; UK's authority on cybersecurity
  • Cyber Essentials scheme:
    • Cyber Essentials (basic — self-assessment)
    • Cyber Essentials Plus (independent assessment)
    • Mandatory for some UK government contracts
  • Active threat intelligence; guidance; incident support
  • 10 Steps to Cyber Security framework

Defence-in-depth principle:

  • Multiple layers of defence
  • If one fails, others provide protection
  • Layers: physical, network, endpoint, application, data, identity
  • Better than single point of failure

Zero Trust architecture:

  • "Never trust, always verify"
  • No implicit trust based on location (inside/outside network)
  • Verify every access request
  • Microsegmentation
  • Continuous monitoring
  • Increasingly adopted

Identity and Access Management (IAM):

  • Right people get right access at right time
  • Multi-factor authentication (MFA)
  • Privileged Access Management (PAM)
  • Single Sign-On (SSO)
  • Joiners-Movers-Leavers process
  • Regular access reviews

Incident response:

  1. PREPARATION: plans, training, technology
  2. IDENTIFICATION: detect and characterise incident
  3. CONTAINMENT: limit spread/damage
  4. ERADICATION: remove threat
  5. RECOVERY: restore systems and operations
  6. LESSONS LEARNED: improve for next time

Notification requirements:

  • UK GDPR/DPA 2018: data breaches notified to ICO within 72 hours of awareness (if risk to individuals)
  • Affected individuals notified if HIGH risk
  • UK financial services: FCA/PRA notification
  • NIS Regulations 2018 (operators of essential services, digital service providers)
  • Telecoms Security Act 2021

Cyber insurance:

  • Insurance for cyber-related losses
  • Coverage: incident response, business interruption, ransom payments, data restoration, third-party liability
  • Premiums rising; coverage tightening; ransomware coverage controversial
  • Underwriters increasingly require security baseline

Major incidents — lessons:

Colonial Pipeline (May 2021):

  • Ransomware shut down major US fuel pipeline (5 days)
  • Significant fuel shortages on US East Coast
  • Paid $4.4m ransom (most recovered by FBI)
  • Lessons: legacy systems vulnerable; OT/IT separation; ransomware critical infrastructure threat

SolarWinds (December 2020):

  • Supply chain attack: trojanised software update affected 18,000+ customers
  • State-sponsored (Russia attributed)
  • Affected US government agencies, major corporations
  • Months before discovery
  • Lessons: supply chain risk; need for monitoring; trusted channel risks

MOVEit (May 2023):

  • Vulnerability in MOVEit file transfer software
  • Exploited by Cl0p ransomware group
  • Hundreds of organisations breached including BBC, British Airways, Boots, Aer Lingus
  • Mass data exfiltration
  • Lessons: third-party software risk; rapid patching; incident transparency

Cybersecurity strategy elements:

  • Risk assessment (what to protect; threats faced)
  • Adoption of recognised framework (NIST CSF, ISO 27001, Cyber Essentials)
  • Defence-in-depth
  • Identity and access management
  • Continuous monitoring and detection
  • Incident response capability
  • Backup and disaster recovery
  • Vendor/supply chain management
  • Awareness and training (humans = weakest link)
  • Cyber insurance (complement to controls)
  • Board-level oversight (UK CGC requirements)

Change Management Theories

Change management = systematic approach to transitioning individuals, teams, and organisations from current state to desired state. Critical for transformation success — most failures attributed to people-side, not technical.

Multiple theoretical models — each highlights different aspects.

1. Kurt Lewin's Three-Stage Model (1947):

Foundational model — simple but powerful.

  1. UNFREEZE: prepare for change
    • Recognise need for change
    • Communicate vision
    • Address resistance
    • Create dissatisfaction with status quo
  2. CHANGE (Move): implement change
    • Execute new processes
    • Provide training and support
    • Address barriers
    • Pilot, learn, scale
  3. REFREEZE: stabilise new state
    • Embed new behaviours
    • Update processes, systems
    • Reinforce through reward systems
    • Make it the new normal

Force Field Analysis (Lewin):

  • Forces FOR change vs forces AGAINST change
  • To enable change: increase forces for OR decrease forces against (often easier)
  • Maps drivers and resistors

Critique of Lewin: too linear; "refreeze" inappropriate for continuous change environments. But foundational.

2. Kotter's 8-Step Process for Leading Change (1996):

One of most widely used frameworks. From John Kotter's "Leading Change".

  1. CREATE A SENSE OF URGENCY: why change is needed NOW; communicate threats and opportunities
  2. FORM A POWERFUL GUIDING COALITION: assemble a group with enough power to lead change
  3. CREATE A VISION FOR CHANGE: vision and strategies for achieving it
  4. COMMUNICATE THE VISION: every channel; constant; modelled by leaders
  5. EMPOWER OTHERS TO ACT ON THE VISION: remove obstacles; change systems; encourage risk-taking
  6. CREATE SHORT-TERM WINS: visible improvements; recognise contributors; maintain momentum
  7. CONSOLIDATE GAINS AND PRODUCE MORE CHANGE: use credibility from wins to tackle bigger changes
  8. ANCHOR NEW APPROACHES IN THE CULTURE: connect new behaviours to organisational success

Kotter's key insight: change fails most often at steps 1-2 (urgency and coalition). Many organisations have vision but lack burning platform or coalition.

Updated Kotter (Accelerate, 2014):

  • Eight ACCELERATORS rather than steps
  • Run concurrently rather than sequentially
  • "Dual operating system" — hierarchy + network
  • For continuous change environments

3. McKinsey 7S Framework:

Diagnostic model identifying SEVEN INTERDEPENDENT FACTORS that must be aligned for organisational effectiveness:

ElementDescription
STRATEGYPlan for competitive advantage
STRUCTUREOrganisational chart; reporting lines
SYSTEMSProcesses; procedures; IT systems
SHARED VALUESCore values; culture (CENTRAL — connects others)
SKILLSCapabilities of organisation and individuals
STYLELeadership style; how managers lead
STAFFPeople; HR practices

Three "HARD" elements (Strategy, Structure, Systems) and four "SOFT" elements (Shared values, Skills, Style, Staff) — all must be aligned.

Application to change:

  • Map current state of all 7 Ss
  • Define future state
  • Identify gaps and interdependencies
  • Plan changes across all 7 (not just one)
  • Common failure: changing strategy without addressing other elements

4. Burke-Litwin Causal Model:

Detailed model identifying 12 organisational variables and their interactions:

TRANSFORMATIONAL factors (revolutionary change):

  • External environment
  • Mission and strategy
  • Leadership
  • Organisational culture
  • Individual and organisational performance

TRANSACTIONAL factors (evolutionary change):

  • Structure
  • Management practices
  • Systems (policies, procedures)
  • Work unit climate
  • Tasks and skills
  • Individual needs and values
  • Motivation

Insight: transformational change requires changing top-level (mission, leadership, culture). Without these, transactional changes alone won't produce real change.

5. ADKAR Model (Prosci):

Individual-level change model — focuses on what each person needs:

  1. AWARENESS: of the need for change
  2. DESIRE: to support and participate in the change
  3. KNOWLEDGE: of how to change
  4. ABILITY: to implement required skills and behaviours
  5. REINFORCEMENT: to sustain the change

Application:

  • Sequential — each step required before next
  • Identify which steps individuals/groups stuck on
  • Different interventions for different stages
  • Useful for planning communications, training, coaching

6. Bridges Transition Model:

Distinguishes CHANGE (situational/external) from TRANSITION (psychological/internal):

  1. ENDINGS: letting go; loss; grief
  2. NEUTRAL ZONE: between old and new; uncertainty; experimentation
  3. NEW BEGINNINGS: identifying with new state

Insight: people experience CHANGE outwardly but must process TRANSITION inwardly. Good change management addresses both.

Comparison of models:

ModelBest for
LewinConceptual foundation; episodic change
KotterStrategic, organisation-wide change
McKinsey 7SDiagnosing alignment issues
Burke-LitwinUnderstanding transformational vs transactional change
ADKARIndividual change journey
BridgesPsychological/emotional aspects

In practice, multiple models often combined.

Managing Resistance and Leading Change

Resistance to change is normal and expected. Understanding sources and managing effectively is critical to change success.

Sources of resistance:

1. RATIONAL/LOGICAL:

  • Disagreement with strategy or analysis
  • Perception that change won't work
  • Concern about disruption costs
  • Better alternative believed available

2. EMOTIONAL/PSYCHOLOGICAL:

  • Fear of unknown
  • Fear of losing competence (skill obsolescence)
  • Loss of identity tied to current role
  • Loss of control
  • Past negative experiences with change

3. PERSONAL/SELF-INTEREST:

  • Job security concerns
  • Compensation/career impact
  • Power/status loss
  • Increased workload
  • Disrupted relationships

4. CULTURAL/SOCIAL:

  • Group norms reinforcing status quo
  • Loss of team/department identity
  • Conflict with values
  • Cultural clash with changes (e.g., post-merger)

5. POLITICAL:

  • Stakeholders losing influence
  • Coalition disruption
  • Resource reallocation
  • Decision authority changes

Kotter and Schlesinger — six methods to deal with resistance:

  1. EDUCATION + COMMUNICATION: when resistance from lack of information; useful but time-consuming
  2. PARTICIPATION + INVOLVEMENT: involve resistors in design; builds commitment; risk of inappropriate solutions
  3. FACILITATION + SUPPORT: training, counselling, time off; helps with adjustment but expensive
  4. NEGOTIATION + AGREEMENT: trade-offs to gain support; quick but expensive precedent
  5. MANIPULATION + CO-OPTATION: appoint resistors to lead change; quick but risky if discovered
  6. EXPLICIT + IMPLICIT COERCION: threats, demotion, dismissal; fast but ethical concerns and can damage culture

No single approach right — combine based on situation, urgency, power dynamics.

Practical strategies:

1. Communication:

  • Multiple channels; multiple times
  • Tell the WHY (not just what and how)
  • Honest about challenges and uncertainties
  • Two-way communication (listen, not just broadcast)
  • Timely, transparent
  • Repetition essential ("communicate vision 10x more than you think")

2. Involvement and participation:

  • Engage stakeholders in design
  • Use insights from those closest to work
  • Build ownership through involvement
  • Address concerns directly

3. Build coalitions:

  • Identify supporters, neutrals, opponents
  • Strengthen supporters; convert neutrals; address opponents
  • "Influence map" of key stakeholders
  • Power coalition critical (Kotter Step 2)

4. Quick wins:

  • Visible early successes
  • Build credibility for change
  • Recognise and celebrate
  • Maintain momentum
  • "Show, don't just tell"

5. Address skills gaps:

  • Training and development
  • Coaching and mentoring
  • Reduces fear of incompetence
  • Builds confidence

6. Align incentives:

  • Performance metrics aligned with change goals
  • Reward systems
  • Career paths in new state
  • Avoid "do new thing while measured on old"

7. Address losses:

  • Acknowledge what people are losing
  • Allow grief / mourning
  • Bridges Transition Model: honour endings
  • Mark transitions ceremoniously

LEADERSHIP for change:

Transformational leadership (Bass):

  • INSPIRATIONAL motivation: vision and confidence
  • INTELLECTUAL stimulation: challenge assumptions
  • INDIVIDUALISED consideration: attention to individuals
  • IDEALISED influence: lead by example; ethical foundation

Most effective for transformational change. Contrasts with TRANSACTIONAL leadership (rewards/punishments based on performance) — better for stability than change.

Authentic leadership:

  • Self-awareness
  • Relational transparency
  • Balanced processing of information
  • Internalised moral perspective
  • Especially important during uncertainty/change

Servant leadership:

  • Leader as servant to followers
  • Empowering rather than directive
  • Useful for empowerment-based changes

Adaptive leadership (Heifetz):

  • Distinguishes "TECHNICAL" problems (clear solutions) from "ADAPTIVE" challenges (require learning)
  • Different leadership approaches needed for each
  • Adaptive leaders: ask questions, mobilise others, regulate distress
  • Useful for transformational change with uncertainty

Key behaviours of effective change leaders:

  • Visible and accessible
  • Walk the talk (model the change)
  • Communicate constantly
  • Listen as much as speak
  • Make tough decisions
  • Acknowledge uncertainty
  • Celebrate progress
  • Persist through setbacks
  • Empower others
  • Stay emotionally intelligent

Why change initiatives fail (multiple studies):

McKinsey research: 70% of change programmes fail to achieve their goals.

Top reasons:

  1. Insufficient leadership commitment / sponsorship
  2. Inadequate communication
  3. Underestimating resistance
  4. Lack of clear vision
  5. Weak coalition / governance
  6. Trying to do too much at once
  7. Insufficient resources
  8. Inadequate skills/capability
  9. Cultural resistance not addressed
  10. Not celebrating and consolidating wins

Success factors:

  • Strong, committed leadership
  • Clear vision and case for change
  • Effective communication
  • Stakeholder engagement
  • Capability building
  • Performance management aligned
  • Cultural change addressed
  • Realistic timelines and resources
  • Quick wins celebrated
  • Continuous learning and adjustment

For SBM exam — change management questions:

  • Apply specific framework (Kotter, McKinsey 7S, etc.) to scenario
  • Identify likely sources of resistance
  • Recommend specific interventions
  • Consider leadership requirements
  • Address culture (often most challenging element)
  • Realistic about timeline and challenges
  • Connect change to broader strategy

Examiner Focus

SBM technology and change questions typically combine: (1) digital transformation strategy with frameworks (Rogers, capabilities); (2) specific technology applications (AI, cybersecurity, fintech); (3) change management theory application (Kotter is most commonly tested); (4) leadership requirements; (5) risk management. Show INTEGRATED thinking across these dimensions.

Common Pitfall

Common error: treating digital transformation as IT project. Real digital transformation requires comprehensive change across all 7S elements (especially shared values/culture). Technology alone fails without cultural and capability transformation. McKinsey 7S is critical diagnostic framework.

Study Tip

Kotter's 8 Steps is most widely tested change framework. Common failures at steps 1-2 (urgency and coalition). Step 6 (short-term wins) often skipped but builds credibility. Step 8 (anchor in culture) often abandoned too early. Match steps to specific case scenario.

Examiner Focus

AI risks for SBM: bias (training data); hallucinations (generative AI); transparency/explainability; data privacy (GDPR); IP concerns; misuse (deepfakes, AI phishing); job displacement; energy use. EU AI Act risk-based categories: unacceptable (banned)/high/limited/minimal. UK approach principles-based via existing regulators.

Watch Out

Cybersecurity strategy: NIST CSF five functions (Identify, Protect, Detect, Respond, Recover) plus Govern in 2024 update. UK Cyber Essentials/Plus and ISO 27001 common certifications. Defence-in-depth principle. UK GDPR: 72-hour breach notification to ICO. Average UK breach cost significant. Board-level oversight required (UK CGC).

Study Tip

Sources of resistance: rational (disagreement with strategy), emotional (fear of unknown, skill obsolescence), personal (job security, status loss), cultural (group norms), political (power dynamics). Kotter-Schlesinger 6 methods: education, participation, support, negotiation, manipulation (risky), coercion (last resort). Combine based on situation.

Study Tip

Leadership for change: TRANSFORMATIONAL leadership (Bass) most effective for transformational change — inspirational, intellectual stimulation, individualised consideration, idealised influence. Contrasts with TRANSACTIONAL leadership (rewards/punishments) better for stability. Adaptive leadership (Heifetz) for adaptive (vs technical) challenges.

Written Practice

Technology and Change: Applied Requirement

Prepare a short advisory section that combines analysis, conclusion, and next actions.

32 mins · 18 marks

A client has asked for a concise integrated advisory note for a finance director on technology and change. Use the key rules, calculations, risks, and professional judgement from this topic to structure your answer.

Answer Prompts

  • Identify the issue and explain why it matters in the scenario.
  • Apply the relevant technical rule, calculation, or framework.
  • State the commercial, ethical, tax, reporting, or assurance implication.
  • Conclude with a clear recommendation or exam-ready judgement.

Marking Focus

  • Application to facts rather than textbook recall
  • Clear structure and answer-first communication
  • Balanced judgement where there is uncertainty
  • Commercially sensible conclusion

Key Definitions

Digital transformation

Strategic and cultural change driven by digital technologies that fundamentally alters how organisations operate and deliver value. More than just technology — encompasses business model, processes, culture, capabilities. Levels: digitisation < digitalisation < digital transformation.

Technology Adoption Lifecycle

Rogers' Diffusion of Innovations: Innovators (2.5%) → Early Adopters (13.5%) → Early Majority (34%) → Late Majority (34%) → Laggards (16%). "Chasm" between early adopters and early majority is major challenge for tech firms (Geoffrey Moore).

Analytics maturity

Four levels (Gartner): DESCRIPTIVE (what happened); DIAGNOSTIC (why it happened); PREDICTIVE (what will happen); PRESCRIPTIVE (what should we do). Most organisations descriptive/diagnostic; competitive advantage from predictive/prescriptive.

5 Vs of Big Data

Volume (large amounts); Velocity (speed of generation/processing); Variety (structured + unstructured); Veracity (quality and reliability); Value (business benefit). Sometimes extended with Variability and Visualisation.

Machine Learning approaches

SUPERVISED (labelled data — classification, regression); UNSUPERVISED (unlabelled — clustering, anomaly detection); REINFORCEMENT (rewards/penalties — game playing, robotics); DEEP LEARNING (neural networks with multiple layers — image recognition, NLP). Generative AI uses deep learning.

EU AI Act

First comprehensive AI law (effective phased 2024-2027). Risk-based: UNACCEPTABLE risk (banned — social scoring); HIGH risk (medical, hiring, credit, law enforcement); LIMITED risk (transparency requirements — chatbots, deepfakes); MINIMAL risk. Up to €35m or 7% global turnover fines. UK approach more principles-based.

Open Banking (UK)

CMA-mandated framework (2017) aligned with EU PSD2. Customers can share bank data with third parties (with consent). API standards enable secure access. Drives innovation: budgeting apps, lending decisions, payment alternatives. Following: Open Finance (extension to other products).

NIST Cybersecurity Framework

Five core functions: IDENTIFY (assets, environment); PROTECT (access, training, data security); DETECT (monitoring, anomalies); RESPOND (planning, communications, mitigation); RECOVER (recovery planning). 2024 update added GOVERN as cross-cutting. Globally adopted; voluntary.

Lewin's Three-Stage Model

UNFREEZE (recognise need; communicate vision; address resistance); CHANGE (implement new processes; training; pilot/scale); REFREEZE (embed new behaviours; update processes; reinforce). Foundational change model. Force Field Analysis: forces for vs against change.

Kotter's 8-Step Process

(1) Create urgency; (2) Build guiding coalition; (3) Create vision; (4) Communicate vision; (5) Empower others to act; (6) Create short-term wins; (7) Consolidate gains; (8) Anchor in culture. Most widely-used framework. Many failures at steps 1-2 (urgency and coalition).

McKinsey 7S Framework

Seven interdependent factors that must be aligned: Strategy, Structure, Systems (HARD); Shared Values (CENTRAL), Skills, Style, Staff (SOFT). Diagnostic tool for organisational effectiveness. Common failure: changing strategy without addressing other elements.

Burke-Litwin Causal Model

Distinguishes TRANSFORMATIONAL factors (external environment, mission, strategy, leadership, culture, performance) from TRANSACTIONAL factors (structure, management, systems, climate, skills, motivation). Transformational change requires changing top-level factors.

ADKAR Model

Individual-level change model (Prosci): AWARENESS (of need); DESIRE (to support); KNOWLEDGE (how to change); ABILITY (to implement); REINFORCEMENT (to sustain). Sequential — each step required before next. Useful for planning communications, training, coaching.

Kotter and Schlesinger's six methods

For dealing with resistance: (1) Education + Communication; (2) Participation + Involvement; (3) Facilitation + Support; (4) Negotiation + Agreement; (5) Manipulation + Co-optation; (6) Explicit + Implicit Coercion. Combine based on situation, urgency, power dynamics.

Transformational leadership

Bass's model. Four components: Inspirational motivation; Intellectual stimulation; Individualised consideration; Idealised influence. Most effective for transformational change. Contrasts with transactional leadership (rewards/punishments) — better for stability.

Adaptive leadership (Heifetz)

Distinguishes TECHNICAL problems (clear solutions, expert-led) from ADAPTIVE challenges (require learning, value changes). Different leadership approaches needed. Adaptive leaders: ask questions, mobilise others, regulate distress. Useful for transformational change with uncertainty.

Key Formulas

Worked Examples

Key Takeaways

  • Digital transformation: more than technology — encompasses business model, processes, culture, capabilities. Levels: digitisation < digitalisation < transformation. Rogers Adoption Lifecycle with "Chasm" (Moore) between early adopters and early majority. Capabilities required: technical, organisational, cultural. Most failures (60-70%) due to people-side, not technology.
  • Data analytics: maturity progression descriptive → diagnostic → predictive → prescriptive. 5 Vs of Big Data: Volume, Velocity, Variety, Veracity, Value. Data architecture: warehouse (structured), lake (raw), lakehouse (combined). Governance critical: ownership, quality, lineage, MDM, privacy. UK GDPR/DPA 2018 compliance essential.
  • AI/ML: Narrow AI dominant; supervised, unsupervised, reinforcement learning; deep learning enables generative AI revolution. Applications: personalisation, fraud detection, predictive analytics, customer service, code generation. Risks: bias, hallucinations, transparency, privacy, IP, job displacement, misuse.
  • AI governance: EU AI Act risk-based (unacceptable banned; high — strict; limited — transparency; minimal — light-touch); fines up to €35m/7% turnover. UK approach principles-based via existing regulators (FCA, ICO, MHRA, Ofcom, CMA). NIST AI RMF, OECD principles, ISO standards.
  • Fintech disrupting all financial services: payments (Apple Pay, Klarna), lending (Funding Circle), banking (Monzo, Starling), wealth (robo-advisors), insurance (insurtech), regtech. Open Banking UK (CMA 2017, PSD2) enables consented data sharing. DeFi, cryptocurrencies, CBDCs, BaaS reshaping landscape.
  • Cybersecurity: increasing threat landscape; ransomware, phishing, supply chain attacks, social engineering, insider threats. Frameworks: NIST CSF (Identify/Protect/Detect/Respond/Recover/+Govern); ISO 27001; CIS Controls; UK NCSC Cyber Essentials/Plus. Defence-in-depth and Zero Trust principles. Major incidents: Colonial Pipeline (2021), SolarWinds (2020), MOVEit (2023).
  • Change management theories: Lewin (Unfreeze-Change-Refreeze; Force Field Analysis); Kotter (8 Steps — most widely used); McKinsey 7S (Strategy, Structure, Systems, Shared Values, Skills, Style, Staff); Burke-Litwin (transformational vs transactional); ADKAR (individual: Awareness, Desire, Knowledge, Ability, Reinforcement); Bridges (Endings, Neutral Zone, New Beginnings).
  • Sources of resistance: rational (disagreement); emotional (fear, identity, control); personal (job security, status); cultural (norms); political (power). Kotter-Schlesinger six methods: education, participation, support, negotiation, manipulation, coercion. Combine based on situation, urgency, power dynamics.
  • Leadership for change: Transformational (Bass — inspirational, intellectual, individualised, idealised); Authentic; Servant; Adaptive (Heifetz — technical vs adaptive challenges). Behaviours: visible, walk the talk, communicate constantly, listen, make tough decisions, acknowledge uncertainty, persist.
  • Why change fails (70% rate): leadership commitment insufficient; communication weak; resistance underestimated; vision unclear; coalition weak; too much at once; resources lacking; capability gaps; culture not addressed; wins not celebrated. Success factors: leadership, vision, communication, engagement, capability, alignment, culture, realism, agility.

Practice Questions

Question 1 of 8

In Rogers' Diffusion of Innovations Adoption Lifecycle, the "Chasm" (Geoffrey Moore) refers to:

Question 2 of 8

The 5 Vs of Big Data are:

Question 3 of 8

The EU AI Act (effective phased 2024-2027) categorises AI systems by:

Question 4 of 8

UK Open Banking (CMA-mandated 2017, aligned with EU PSD2) enables:

Question 5 of 8

NIST Cybersecurity Framework five core functions are:

Question 6 of 8

Kotter's 8-Step Process for Leading Change BEGINS with:

Question 7 of 8

McKinsey 7S framework "soft" elements include:

Question 8 of 8

The ADKAR change management model (Prosci) describes:

Source and Version

Syllabus: ICAEW ACA Advanced Level 2026 · Reviewed: 2026-05-04

ICAEW ACA syllabusLocal syllabus coverage review