How Cyber Risk Is Changing Audits and Oversight

661 views
β€’
December 1, 2020
by
RSAC Cybersecurity
YouTube video player
How Cyber Risk Is Changing Audits and Oversight

TL;DR

Cyber risk management is becoming a sustained governance, regulatory, and audit priority, so organizations should maintain momentum and strengthen operational resilience. Boards need clearer insights, while internal auditors, external auditors, and regulated companies should monitor federal proposals, regulatory expectations, and the possible expansion of Sarbanes-Oxley scope to include cyber risk management.

Transcript

Um, I've been involved in a lot of different things over those years. Uh, back in the '80s I was involved in financial auditing work. I'm actually a CPA by training, but I moved over into the, uh, consulting side, uh, specifically in cybersecurity over the last, uh, six to eight years. Um, my role within Ernst & Young gives me visibility into a few... Read More

Key Insights

  • Cyber risk management is a governance issue that connects board engagement, regulatory oversight, internal audit, and external audit. Changes in any one area can influence the others, creating a trickle-down effect on how organizations assess controls, report risks, and prepare for examinations.
  • Federal cybersecurity policy is shaped by more than presidential and congressional leadership. Officials assigned responsibility for regulatory oversight can also affect future activity, while funding and regulatory mandates often make cybersecurity policy debates more politically contested even when the underlying risk is broadly recognized.
  • Cybersecurity risk management is not inherently partisan, according to the presenter, but regulatory philosophy differs between political parties. Republicans have typically favored less regulation and oversight, while Democrats have generally advocated more, making election outcomes relevant to future cybersecurity requirements and enforcement priorities.
  • Cybersecurity oversight was distributed across roughly 20 House and Senate committees at the time discussed. This broad jurisdiction demonstrates the issue's importance, but it also contributes to coordination challenges because many separate congressional bodies possess some responsibility for cybersecurity risk management.
  • The Cyber Solarium Commission produced more than 50 legislative proposals after being established through a provision in the 2019 Defense Authorization Bill. Its March report addressed the growing cyber threat to the United States and proposed a more structured federal response.
  • Cyber Solarium Commission recommendations included a cabinet-level cybersecurity role, permanent select committees in the House and Senate, military measures, economic protection, ecosystem reform, and stronger public-private information sharing. Draft versions of individual proposed bills were also produced in July.
  • Sarbanes-Oxley scope could potentially be modified to include cyber risk management under one Cyber Solarium Commission recommendation. The presenter does not predict adoption, but notes that such a change could create significant remediation work similar to the ripple effects associated with earlier Sarbanes-Oxley implementation.
  • Cybersecurity and operational resilience remain regulatory priorities for market participants. Guidance from the Office of Compliance Inspection and Examinations listed leading practices for designing and implementing cyber risk programs, effectively putting organizations on notice about areas regulators considered important.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How is cyber risk management changing audit work?

Cyber risk management is increasingly connected to regulatory examinations, internal audit activities, and external audits. The presenter describes a trickle-down effect in which legislative priorities, regulatory expectations, and board governance shape audit attention. Organizations should therefore expect auditors to examine how cyber risks are governed, how programs are designed and implemented, and whether operational resilience remains an active priority.

Q: Why should boards become more engaged in cybersecurity?

Boards have governance responsibility and need useful insights into how their organizations manage cybersecurity risk. Based on hundreds of board sessions, the presenter observed how directors react to materials supplied by organizational leaders. Better engagement helps boards understand the risk, question management, and connect cybersecurity with the broader evolution of risk management, regulatory scrutiny, and audit expectations.

Q: How can election outcomes affect cybersecurity regulation?

Election outcomes can change control of the White House, Senate, and House, which influences legislative and regulatory priorities. The people assigned responsibility for regulatory oversight also matter. The presenter characterizes Republicans as typically favoring less regulation and Democrats as generally advocating more oversight, while emphasizing that cybersecurity risk management itself is not fundamentally a partisan concern.

Q: What was the Cyber Solarium Commission created to do?

The Cyber Solarium Commission was established through a provision in the 2019 Defense Authorization Bill to address the growing cyber threat to the United States. It brought together members of the House and Senate and received input from government agencies. Its March report presented more than 50 legislative proposals intended to strengthen the country's overall cybersecurity approach.

Q: What did the Cyber Solarium Commission recommend?

The commission recommended measures across several areas, including federal cybersecurity infrastructure, military concerns, economic protection, ecosystem reform, and public-private information sharing. Specific ideas included a cabinet-level cybersecurity position and permanent select committees in the House and Senate. In July, it also produced draft versions of individual bills that could eventually be introduced in Congress.

Q: Could Sarbanes-Oxley requirements expand to cybersecurity?

A Cyber Solarium Commission proposal recommended modifying Sarbanes-Oxley scope to include cyber risk management. The presenter stresses that adoption was uncertain and describes the idea only as part of the policy dialogue. If enacted, however, it could generate substantial attention and remediation activity, comparable to the ripple effects organizations experienced during the earlier implementation of Sarbanes-Oxley requirements.

Q: What regulatory message was sent about operational resilience?

The Office of Compliance Inspection and Examinations communicated that cybersecurity and operational resilience should remain active priorities. Although its direct jurisdiction covered capital-market entities such as broker-dealers and transfer agencies, the message was presented as relevant to listed companies more broadly. Organizations were cautioned against reducing their attention and were given leading practices for cyber risk programs.

Q: How should organizations prepare for increased cyber oversight?

Organizations should maintain momentum in cybersecurity and operational resilience, review regulatory leading practices, and monitor legislative proposals that could change audit scope. They should also improve the quality of cyber risk information provided to boards and consider how governance decisions flow into internal audits, external audits, and regulatory examinations. Claiming ignorance becomes less credible after regulators publish explicit priority areas.

Summary & Key Takeaways

  • Cyber risk management affects board governance, regulatory examinations, internal audits, and external audits. Organizations need to understand how information reaches directors, how boards respond, and how oversight expectations influence audit activities. The presenter draws on cybersecurity consulting, federal outreach, and hundreds of board sessions to connect these areas.

  • Federal cybersecurity policy depends partly on White House leadership, congressional control, regulatory appointments, funding, and mandates. Although cybersecurity risk itself is not presented as partisan, approaches to regulation and oversight can differ. Roughly 20 House and Senate committees reportedly held some jurisdiction over cybersecurity risk management, complicating coordination and policymaking.

  • The Cyber Solarium Commission issued a March report containing more than 50 legislative proposals, followed by July drafts of individual bills. Recommendations addressed federal cybersecurity leadership, permanent congressional committees, military concerns, economic protection, public-private information sharing, and ecosystem reform. One proposal considered adding cyber risk management to Sarbanes-Oxley scope.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š