it's all about the assets

Information risk is the potential for damage to sensitive info - the crown jewels (or assets). Think of risk as a combination of asset, threat source and vulnerability.

Technical people tend to downplay assets, probably because they don't know them too well. Business people know, infra folks don't. And yet, too many biz people expect tech colleagues to take the lead in managing Info Risk. The term "IT Security" only adds to the confusion about who should be on top of the matter.

It's all about the assets.

