In the light of recent high profile cyberattacks on businesses around the world, including the Ahsley Madison data hack, the US Institute of Internal Auditors (IIA) is urging companies and organisations to take a more holistic view of cybersecurity, by recognising the critical role of internal audit
The institute, together with the Institute of Internal Auditors Research Foundation (IIARF) has published a report called the Internal Audit’s Role in Cyber Preparedness: The Importance of a Holistic Approach. This maintains that organisations must learn to anticipate, withstand, and recover from cyberattacks, and that a key element in this approach is for boards and audit committees to understand the tools and resources available to their organisations when crafting cybersecurity strategies, policies, and protocols.
Richard Chambers, IIA president and CEO, said: ‘Organisations must get beyond simply trying to keep the cyber invaders out. This new report promotes a comprehensive approach and explains how internal audit plays a crucial support at each step in the process.’
The report explores five key areas of cyber preparedness – protection, detection, business continuity, crisis management and communications, and continuous improvement – and the important role a well-resourced and supported internal audit function plays as an ally and assurance provider. It concludes with the warning that: ‘Only organisations that develop the skills to cope with these threats at strategic and tactical levels will survive and grow.’
The Internal Audit’s Role in Cyber Preparedness: The Importance of a Holistic Approach report is available here
Sign up to our newsletter
If you would like to receive regular news alerts about breaking news and developments in tax, accounting and audit, sign up to receive our free newsletter