Regulators expect cybersecurity to be audited periodically by an independent party. Many internal audit teams lack deep cybersecurity expertise; we provide it, working to your audit methodology and reporting lines.
Each audit tests design and operating effectiveness, with findings rated and agreed with management before they reach the audit committee.
Why it matters
How the engagement runs
- 1PlanScope, risks and audit program
- 2FieldworkTesting and evidence collection
- 3ReportFindings agreed with management
- 4Follow upVerification of corrective actions
What you receive
- Audit plan and program
- Working papers
- Audit report for the audit committee
- Follow-up report
