Author: Joseph McCafferty

Equifax

U.S. GAO: Internal Control Failures Contributed to Equifax Data Breach

A new report from the U.S. General Accounting Office examines the causes of the massive 2017 data breach by Equifax that compromised the personal data of more than 148 million Americans. The report contributes the debacle to the company’s failure to use common cybersecurity best practices, poor internal controls, and Read More

Aligning Internal Audit with the Organization’s Strategy

A new report out from the Institute of Internal Auditors’ research arm provides some needed insight on how internal audit can better align itself with the rapidly changing strategic direction of the company. The research, conducted by the IIA’s Internal Audit Foundation, finds that while internal audit has made some Read More

Alarm clock image

What’s Keeping Audit Chiefs Up at Night?

A new survey of the top risks that most concern chief internal auditors finds that cybersecurity and data privacy are among the issues that still cause the most headaches for company officials. The research, conducted by the Chartered Institute of Internal Auditors and based on responses from more than 300 Read More

SEC to change compliance definitions for SOX 404

Moody’s to Pay $16 Million for Internal Control Failures

The Securities and Exchange Commission has announced that Moody’s Investors Service Inc., one of the nation’s largest credit ratings agencies, has agreed to pay a total of $16.25 million in penalties to settle charges involving internal control failures and failing to clearly define and consistently apply credit rating symbols. This marks Read More

As SOX Costs Rise, Internal Audit Still Lags on Automation

It’s been 16 years since the Sarbanes-Oxley Act took effect in 2002, and companies are still wrestling with SOX compliance. Now, a new study shows they are paying more to meet the regulation’s requirements and have generally not done a good job of using technology to automate controls and ease Read More

Daniel Kim

Audit Software Firm Secures $40 Million in Funding

Yesterday, AuditBoard, a cloud-software provider for risk, audit, and compliance work, announced that it had secured a $40 million investment from venture capital firm Battery Ventures. The Los Angeles-based company says it plans to use the funds to support product development, accelerate sales and marketing, and build new business partnerships. Read More

insider threat

IIA Issues Guide on Auditing Insider Threat Programs

The Institute of Internal Auditors issued a new guide on insider threat programs that is designed help internal auditors understand insider threats and related risks by providing an overview of common traits of main players, key risks, and potential impacts. The guide also covers security frameworks, techniques, considerations, and resources Read More

GDPR image

Companies Slow to Abide by New EU Data Privacy Rules

The European Union’s new data privacy rules have been in effect for more than two months now, yet many companies haven’t done much to ensure they are abiding by them, according to a recent survey. The poll, conducted by Deloitte during a webcast in late June, found that only about Read More

It Might Be Time for an Audit of Open Source Software Usage

There’s no debate about the value of using open source software (OSS) when building new business applications—cost, flexibility, quality and ease of use, to name a few—but its use comes with legal obligations and security vulnerabilities that can pose significant risks to organizations. To effectively pre-empt such risks, proactive OSS Read More