Skip to content

Strategic Business Leader · Enabling success: disruptive technologies

Internet of Things, Digital Platforms and Cyber Risk in ACCA SBL

Updated 11 October 2026 · Fact-checked

The Internet of Things (IoT) links physical devices that collect and share data. A digital platform connects two or more groups, such as buyers and sellers, and earns from their interactions. Both create value but add cyber and data protection risk. In SBL, you identify the opportunity, assess the risk, and recommend controls tied to the scenario.

Understand Internet of Things, Digital Platforms and Cyber Risk

The Internet of Things (IoT) means physical objects fitted with sensors, software and a network connection. They collect data and send it to other systems, often with little human input. Examples are machine sensors in a factory, smart meters, connected vehicles, wearable health monitors and stock trackers in a warehouse.

Businesses use IoT in a few main ways. They monitor assets and predict failures, so maintenance happens before a breakdown. They track goods in the supply chain. They gather usage data to design better products or to price by use, such as insurance based on driving data. They also automate processes and cut cost. The value comes from the data and what you do with it, not from the device itself.

A digital platform is a business model that connects two or more groups and lets them interact, with the owner providing the technology and rules. Think of a marketplace linking buyers and sellers, or a ride-hailing app linking drivers and riders. The platform often owns few physical assets. It earns through commissions, fees, subscriptions or advertising. A key idea is the network effect: the more users on one side, the more valuable the platform is to the other side. This can create fast growth and strong barriers to entry, but the platform must attract both sides, set fair rules and keep trust.

New technology also widens the attack surface. Cyber risk is the risk of loss from attacks on, or failures of, information systems. Each connected device is a possible entry point, and many have weak security. Platforms hold large amounts of personal and payment data, so a breach harms users and the brand. Typical threats include malware, ransomware, phishing, denial of service attacks, insider misuse and weak third-party suppliers.

The consequences are financial loss, operational disruption, legal penalties under data protection law, loss of customer trust and reputational damage. Good management combines governance, technical controls, people and planning. The board owns the risk. Technology staff do not carry it alone. In SBL you must link all of this to the organisation in the case, its strategy, its stakeholders and its ethics.

Key rules to remember

Network effect (idea)
More users on one side → more value for the other side → more users
A reinforcing loop. It helps growth but also means a loss of trust can shrink the platform quickly.
Risk assessment
Risk exposure = likelihood × impact
A scoring idea, not an exact calculation. Use it to rank cyber risks and decide which need action first.
Information security aims (CIA)
Confidentiality, Integrity, Availability
Use as a checklist. Ask which of the three a given threat or control affects.
Risk response options (TARA)
Transfer, Avoid, Reduce, Accept
For cyber risk: insurance or outsourcing (transfer), not collecting data (avoid), controls (reduce), tolerate small risks (accept).
Platform revenue sources
Commission, subscription, advertising, data or listing fees
Name the one that fits the case and explain why.

How to solve Internet of Things, Digital Platforms and Cyber Risk questions

Use this method for any question on IoT, platforms or cyber risk. It keeps your answer applied to the case, which is where the marks are.

  1. 1Read the requirement and note the verb: explain, assess, advise, evaluate or recommend. This sets the depth and the format, such as a report or briefing.
  2. 2Identify the technology in the scenario: connected devices, a platform, stored personal data, or a mix. Pick out facts about the business, its customers and its current controls.
  3. 3Set out the opportunities first when asked: cost saving, new revenue, better data, speed, customer experience. Tie each to a fact in the case.
  4. 4Identify the risks and group them: security, data protection and privacy, operational dependence, supplier or partner risk, ethical and reputational risk.
  5. 5Assess the main risks by likelihood and impact, and say which matter most for this organisation and why.
  6. 6Recommend responses: governance, technical controls, staff training, supplier checks, incident and recovery plans. Link each to a risk.
  7. 7Consider stakeholders and ethics: customers whose data is held, regulators, shareholders and employees. Mention the public interest where relevant.
  8. 8Finish with a clear conclusion or recommendation in the required format, using a professional tone and commercial judgement.

Quickest way: Opportunity, risk, control in three lists

When to use it: Use when time is short, such as in the last tasks of the exam or when planning an answer in a few minutes.

  1. Jot three headings: Opportunity, Risk, Control.
  2. Under each, write two or three points that use named facts from the case, not generic ideas.
  3. Match every control to a risk with an arrow so nothing is left unaddressed.
  4. Add one stakeholder or ethical point and one line of judgement on priority.
  5. Write the answer in the order of the requirement, one short paragraph per point, with the case fact first.

Common mistakes in Internet of Things, Digital Platforms and Cyber Risk

  • Writing a general essay on IoT or cyber security with no link to the case.

    Students recall notes and want to show knowledge.

    Fix: Start each point with a case fact, then explain the impact on that organisation. Cut points you cannot link.

  • Listing only technical controls such as firewalls and encryption.

    Cyber security feels like an IT issue.

    Fix: Add governance, board oversight, staff training, supplier management and incident planning. People and process failures cause many breaches.

  • Treating a platform as just a website or an online shop.

    Students do not separate a platform from a normal seller.

    Fix: Explain that a platform connects groups, owns few assets, and depends on network effects and trust. Name the sides and the revenue source.

  • Giving only benefits or only risks when the requirement asks for evaluation.

    One-sided answers are quicker to write.

    Fix: Give both sides, then weigh them and reach a conclusion for this business.

  • Ignoring data protection and ethics for customer data collected by devices.

    Students focus on security and forget privacy and consent.

    Fix: Mention what data is collected, whether customers know and agree, how long it is kept, and the legal and reputational exposure.

  • Naming specific laws or fines from memory in detail.

    Students try to sound precise.

    Fix: Refer to data protection law in general terms unless the case gives the rule. Accuracy matters more than detail.

Worked examples

Example 1

A manufacturer of industrial pumps plans to fit sensors to all pumps it sells and send performance data to its cloud systems. Customers will pay a monthly fee for monitoring and maintenance. Advise the board on the benefits and the cyber and data risks of this plan. (10 marks)

Show the solution
  1. Identify the technology: IoT sensors sending data to the cloud, with a move from selling products to selling a service.
  2. Benefits: predictive maintenance reduces breakdowns for customers, so the service is valuable. Monthly fees give recurring revenue. Usage data improves product design and spare parts planning. Closer contact raises customer loyalty.
  3. Risks: each sensor is an entry point, and weak device security could let attackers reach customer plants or the manufacturer's systems. A breach could stop customer production, so the impact is high. The data may reveal customer operations and so is commercially sensitive.
  4. Data and legal risk: contracts must say who owns the data and how it is used. Any personal data, for example operator details, brings data protection duties.
  5. Controls: build security into device design, use encryption and authentication, issue regular updates, segment networks, monitor for unusual activity, vet the cloud provider, train staff and agree an incident plan with customers.
  6. Judgement: the plan is attractive, but the board should pilot it, set clear security standards and consider cyber insurance before full roll-out.

Answer: The plan offers recurring revenue, better products and stronger customer ties through predictive maintenance. The main risks are insecure devices, a high-impact breach affecting customers, and unclear data ownership. The board should proceed in stages, with security by design, encryption, monitoring, supplier checks, contracts covering data, and an incident plan.

Example 2

A start-up runs an online platform that connects freelance accountants with small businesses. It earns a commission on each job. Explain how the platform creates value and the risks it faces from its reliance on technology and user data. (10 marks)

Show the solution
  1. Explain the model: two sides, freelancers and small businesses. The start-up owns the technology and rules, not the accountants' time, so it can grow without many assets.
  2. Value for freelancers: access to clients, less marketing cost, payment handling. Value for businesses: choice, speed, price comparison and ratings.
  3. Network effect: more businesses attract more freelancers, and the reverse. This drives growth and makes it harder for rivals to enter, but the platform must build both sides together.
  4. Revenue: commission on each job. Revenue falls if users take deals off the platform, so trust and good service matter.
  5. Cyber and data risks: the platform holds identity, financial and client data, so a breach would hurt users and the brand. Ransomware or downtime would stop all trade. Fake profiles and fraud damage trust.
  6. Responses: strong authentication, encryption of data, identity checks on freelancers, regular security testing, clear privacy notice and consent, backup and recovery plans, and board-level oversight of cyber risk.
  7. Ethics and stakeholders: users trust the platform with sensitive client information, so protecting it is part of its duty and its commercial survival.

Answer: The platform creates value by connecting two groups at low cost, and network effects drive growth and barriers to entry. It earns commission, so trust is critical. Its main risks are data breaches, downtime, fraud and loss of trust. It should apply authentication, encryption, identity checks, testing, recovery plans and board oversight.

Exam tips

  • Always anchor each point to a named fact from the case. Generic technology answers score poorly.
  • For platforms, name the sides, the revenue source and the network effect. Then state the main risk to growth, usually trust or a rival platform.
  • Cover people, process and governance as well as technology when you recommend cyber controls.
  • Link data collected by devices or platforms to privacy, consent and ethics. This also earns professional skills credit.
  • End with a clear recommendation or priority, in the format requested, such as a briefing note to the board.

Practice questions from Enabling success: disruptive technologies

Internet of Things, Digital Platforms and Cyber Risk in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Internet of Things, Digital Platforms and Cyber Risk: frequently asked questions

What is the Internet of Things in simple terms?

It is a network of physical devices with sensors and connections that collect and share data. Businesses use the data to monitor assets, cut costs, improve products and create new services.

How does a platform business model make money?

Common sources are a commission on each transaction, subscription fees, advertising and listing fees. The right choice depends on who values the service most and what they will pay for.

Why does IoT increase cyber risk?

Every connected device is a possible way into the network, and many have weak security or are rarely updated. A single compromised device can give access to wider systems or disrupt operations.

How should I handle cyber risk in an SBL answer?

Identify the main risks for the organisation in the case, rank them by likelihood and impact, and recommend linked controls. Include governance, people and supplier controls, not only technical ones.