Tag: Cybersecurity

The Crucial Role of Internal Audit in Cybersecurity Strategy

In today’s digital era, cybersecurity transcends mere IT concerns to become a cornerstone of organizational integrity. The evolution of cyber threats demands that organizations not just react but proactively manage these risks. Here lies the critical part of internal audit, a strategic ally in fortifying an organization’s cyber defenses. Here Read More

Rolling Risk Assessments

Risk 2034: A New Survey of the Top Risks in 10 Years

A new survey is taking a look into the future to consider what the top risks may look like in 2034. The survey, conducted by Protiviti, finds that cybersecurity and risks from emerging technology are likely to still be at the center of risk management efforts in the next decade. Read More

What Internal Audit Needs to Know about a New Wrinkle in Cybersecurity: CSD

In the relentless chess match between defenders and attackers on IT systems, traditional security solutions are beginning to show their fatigue. Static rules and signatures miss evolving threats, while broad-brush defenses often sacrifice performance for security. Enter Context-Sensitive Defense (CSD), a new frontier in cybersecurity that promises to adapt and Read More

Survey: Internal Auditors Still More Concerned with Cybersecurity than AI

As the scale of emerging technology risks facing companies continue to multiply, IT auditors play a key role in identifying these threats and helping their organizations to navigate them. A new survey conducted by Protiviti and The Institute of Internal Auditors (IIA) reveals which risks are keeping IT auditors up Read More

Risks from ChatGPT

Six Risks from ChatGPT that Internal Audit Should Know About

Artificial intelligence applications like ChatGPT are becoming common tools in the workplace to do everything from generating job descriptions, writing and editing reports, and to managing schedules (See related article, “How Employees Are Using ChatGPT on the Job“). But the apps aren’t perfect. In fact, they can be error prone Read More

Data backup and storage security

Internal Auditor’s Checklist: Eight Points to Validate Data Backup Security

Imagine this scenario: Your organization is hit with a sophisticated ransomware attack. The team reluctantly agrees to pay the ransom (in bitcoin, of course) and your data-recovery efforts spring into action to get the organization back up and running. But to everyone’s horror, much of the data is missing and Read More

LSU Center for Internal Auditing to Add Cyber, ESG Focus

The LSU Center for Internal Auditing, a university-based internal audit education program, is expanding to include a greater focus on cybersecurity risk and environmental, social, and governance (ESG) issues. In recognition of these changes, the program has been renamed the LSU Center for Internal Auditing & Cybersecurity Risk Management (LSUCIA&CRM). Read More

Audits that are hard but not impossible

Most Internal Auditors Will Hear this Phrase at Some Point; Don't Buy It!
You Can’t Audit That!

GUEST BLOG Over my long career, I have often heard, in one form or another, the phrase: “You just can’t audit that!” The first time I heard it came when I was an internal audit manager for a financial institution. The senior vice president for human resources said she was Read More