Cybersecurity goes beyond IT as it's a critical factor in financial reporting and audit quality. Auditors have an increasing responsibility to understand how risks and incidents can affect financial reporting and what to do if they should occur. We're addressing your responsibility to your organization's cybersecurity risks and incidents, what's not your responsibility, and information into best practices.
Summary
Learn how auditors distinguish between cybersecurity risks (potential threats) and incidents (actual events) and evaluate their impact on financial reporting and internal controls. It reinforces that auditors focus on assessing risk and financial impact—not preventing or managing cybersecurity.
An Auditor's Responsibility for Cybersecurity Risks
As cybersecurity threats continue to grow in frequency and complexity, auditors are increasingly need to understand how cybersecurity risks (potential threats) and cybersecurity incidents (realized events) may affect an organization’s financial statements, related disclosures, and internal control over financial reporting (ICFR).
However, an auditor’s responsibility does not include managing, designing, or implementing cybersecurity programs. Instead, the auditor’s role is to assess how cyber-related risks and incidents affect the audit, with particular attention to financial reporting and ICFR.
Understanding the Scope of Responsibility
Auditors are not cybersecurity professionals hired to secure an organization’s systems. Their responsibility is more narrowly defined by auditing standards and focused on the areas that affect financial reporting.
Specifically, auditors are required to understand how the organization uses IT systems and identify cybersecurity risks arising from the use of technology. These risks represent potential vulnerabilities or threats that could lead to errors, fraud, or disruption in financial reporting.
They must also be able to evaluate the design and effectiveness of controls related to those risks and assess whether cybersecurity risks could lead to material misstatements in the financial statements or a deficiency in ICFR.
When a cybersecurity incident, such as a data breach, ransomware attack, or unauthorized system access, does occur, the auditor’s responsibility shifts from risk identification to impact evaluation. The auditor must determine how the incident affects financial reporting, audit evidence, and disclosures.
Non-Audit Engagements Related to Cyber Security
In some cases, auditors may be engaged to provide broader assurance on cybersecurity risk management programs through frameworks such as SOC for Cybersecurity, developed by the AICPA.
These engagements are distinct from a financial statement audit. They focus on evaluating how an organization identifies, manages, and responds to cybersecurity risks, rather than assessing the financial reporting impact of specific incidents.
While separate from a financial statement audit, these services reflect the growing role of auditors in providing assurance over cybersecurity-related risks.
Why Cybersecurity Audits Matter More Than Ever
Cybersecurity doesn’t just belong to IT. It is both a risk issue (what could go wrong) and an incident issue (what has gone wrong). From an audit perspective, both dimensions matter because each can affect financial reporting, disclosure, and internal control over financial reporting.
As a result, auditors must take a proactive, risk-based approach. This includes:
- Integrating cyber-related risks into audit planning
- Aligning IT risk assessment with financial reporting objectives
- Evaluating how well organizations prevent, detect, and respond to incidents within their control environment
What Auditors Are Not Responsible For
To avoid misconceptions, it’s equally important to understand what auditors do not do. Auditors are not responsible for:
- Designing or implementing cybersecurity programs
- Preventing cyberattacks
- Monitoring systems in real time
- Guaranteeing that no breaches occur
Cybersecurity ownership ultimately resides with management. The auditor’s role is to provide independent assurance, not operational oversight.
Assessing Cybersecurity Risks as Part of Audit Risk
Cybersecurity-related risks are incorporated into the broader audit risk assessment process. Auditors must consider how threats, such as unauthorized access, system vulnerabilities, or phishing attacks could compromise financial records, allow unauthorized changes to financial data, or disrupt systems that support financial reporting.
Auditing standards require auditors to identify and assess risks of material misstatement, including those arising from IT vulnerabilities or cybersecurity threats.
Evaluating IT Systems and Controls
A key part of the auditor’s responsibility is gaining an understanding of the entity’s IT environment and the role it plays in financial reporting. Auditors must:
- Understand how transactions flow through systems
- Identify which applications and systems are important to financial reporting
- Evaluate general IT controls (such as access controls, system changes, and data integrity processes)
For example, if a company’s financial data is stored in an ERP system, auditors will assess whether access to that system is appropriately restricted, changes to system configurations are properly controlled, and data is protected from unauthorized modification. Weaknesses in these areas can increase the likelihood that a cybersecurity risk could materialize into an incident.
Testing Internal Controls Relevant to Financial Reporting
Auditors also evaluate internal controls that are designed to mitigate cybersecurity-related risks when those controls are relevant to financial reporting.
These controls may include:
- Access controls over financial systems and data
- Change management controls over system configurations and programs
- Logging and monitoring controls relevant to the integrity of financial information
- Incident response procedures that help preserve data and support continuity of financial reporting
By testing these controls, auditors provide assurance that systems supporting financial reporting are functioning as intended. Strong IT controls are critical because they help ensure the accuracy, integrity, and reliability of information used in financial reporting and audit procedures
Responding to Identified Cyber Risks
When auditors identify cybersecurity risks, they focus on prevention and likelihood. Their response typically includes:
- Assessing whether controls are properly designed and implemented
- Testing the effectiveness of those controls
- Adjusting the audit approach if risk levels are higher than expected
For example, if weak access controls are identified, the auditor may increase substantive testing due to higher risk of unauthorized changes.
Responding to Identified Cyber Incidents
When a cybersecurity incident has occurred, the auditor’s focus shifts to impact and evidence. This includes evaluating whether:
- Financial data was altered, destroyed, or made unavailable
- Internal controls were bypassed or failed
- Financial statement balances or disclosures are affected
- Additional audit procedures are necessary
For example, following a ransomware attack, an auditor would assess whether financial records were compromised, whether backup data is reliable, and whether disclosures about the incident are required.
The focus is always on how the incident affects financial reporting and audit conclusions—not on remediating the issue itself.
Learn More with CPE Courses from Becker
Build your audit skills and learn more about cybersecurity and emerging technology with these CPE courses: