Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Cybersecurity And Infrastructure Management Rank As Top Technology Challenges, According To Protiviti/ISACA Survey Of IT Audit Leaders
Study & Research

Cybersecurity And Infrastructure Management Rank As Top Technology Challenges, According To Protiviti/ISACA Survey Of IT Audit Leaders

ISBuzz TeamBy ISBuzz TeamFebruary 3, 2017Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

More IT audit functions becoming involved in major technology projects; more IT audit leaders are attending audit committee meetings

MENLO PARK, Calif. Cybersecurity and privacy issues, along with infrastructure management and emerging technologies, rank as the top technology challenges organisations face today, according to a just-released survey report from global consulting firm Protiviti and ISACA, a global business technology professional association for IT audit/assurance, governance, risk and information security professionals. The survey of 1,062 IT audit and internal audit leaders and professionals found that IT audit is also becoming more involved in major technology implementation projects within organisations.

In the survey, respondents were asked to name the top technology or business challenges their organisations face today. The top 10 responses:

  1. IT security and privacy/cybersecurity
  2. Infrastructure management
  3. Emerging technology and infrastructure changes – transformation, innovation, disruption
  4. Resource/staffing/skills challenges
  5. Regulatory compliance
  6. Budgets and controlling costs
  7. Cloud computing/virtualisation
  8. Bridging IT and the business
  9. Project management and change management
  10. Third-party/vendor management

“It is no surprise to find security, technology infrastructure and emerging technologies atop the list of challenges that IT auditors see in their organisations,” said Gordon Braun, a managing director with Protiviti and global leader of the firm’s IT Audit practice. “Yet, we find the other challenges listed to be just as critical to companies, from resource and skills gaps to ongoing transitions to cloud and virtual networks. Additionally, as more and more organisations rely on third parties to support critical applications and infrastructure, the need to excel at managing vendor relationships has increased dramatically. Many organisations have not sufficiently addressed maturing their vendor management practices, and the resulting business risks can be significant.”

According to the ISACA/Protiviti survey, titled A Global Look at IT Audit Best Practices, in large companies (greater than US$5 billion in revenue), 26 percent of IT audit functions have a significant level of involvement in major technology projects, while 45 percent have a moderate level of involvement. IT audit is most frequently involved in the post-implementation stages (65 percent).

“Seeing greater involvement by IT audit in significant technology projects is a positive trend, especially considering the dynamic nature of technology and critical risks related to security and privacy,” said Christos Dimitriadis, Ph.D, CISA, CISM, CRISC, chair of ISACA’s board of directors and group director of information security for INTRALOT. “This is also notable because a substantial percentage of IT projects tend to run over budget and behind schedule and fail to achieve the desired objectives. Having IT audit bring a mindset of risk and control to these projects can be highly advantageous.”

Dimitriadis continued, “However, our results show that IT audit is more involved in the post-implementation stages of these projects versus earlier planning and design stages. We believe there is an opportunity for organisations to derive the most value from their major IT projects by engaging IT audit earlier rather than downstream in the projects. With a solid foundation of assurance on the front end, organisations can have the confidence they need to be innovative and fast-paced in pursuit of their business goals.”

Greater Audit Committee and Executive Engagement

In a majority of organisations (55 percent), the IT audit director regularly attends audit committee meetings. This represents a 6 point jump from the prior survey results (published in late 2015)  and reflects a long-term trend in the survey findings since 2012, when less than one in three IT audit directors attended audit committee meetings regularly.

“There’s no question that cybersecurity and emerging technologies are now a regular topic at the board level,” said Braun. “Audit committee members, in particular, are seeking greater assurance around critical IT risks and controls – internal audit and IT audit leaders must be prepared to demonstrate audit coverage of key areas and articulate where the highest risks remain.”

Another notable trend is the growing number of IT audit leaders who are reporting directly to the CEO. While still not a large number (for example, 13 percent in North America, 26 percent in Europe), these figures, as well as those from other regions, represent notable jumps from the 2015 survey results. “It’s possible that in at least some of these instances, the chief audit executive is serving as the IT audit director, which is positive to see in that it provides the IT audit function with greater executive and board visibility,” said Dimitriadis. “This also is a logical development considering the increasing technology-dependence of organisations and the integral role the IT audit function plays in helping management identify key risks and ensure the proper controls are in place.”

Risk Assessment Frequency

The Protiviti/ISACA study also found that among large companies, 90 percent conduct an IT audit risk assessment. However, a majority (55 percent) only do so on an annual or less-frequent basis. Considering the growing risk landscape resulting from cybersecurity threats and emerging technologies, ISACA and Protiviti suggest that more organisations consider an approach that includes continually reviewing the IT risk landscape and adjusting IT audit plans accordingly.

About the Survey Report and Resources Available:

The sixth annual IT Audit Benchmarking Survey consisted of a series of questions grouped into six categories: Emerging Technology and Business Challenges; IT Implementation Project Involvement; IT Audit in Relation to the Overall Audit Department; Risk Assessment; Audit Plan; and Skills, Capabilities and Hiring. The survey report, along with an infographic and a short video, is available for complimentary download at www.isaca.org/2017itauditstudy and www.protiviti.com/ITauditsurvey.

[su_box title=”About Protiviti” style=”noise” box_color=”#336588″][short_info id=’60713′ desc=”true” all=”false”][/su_box]

[su_box title=”About ISACA®” style=”noise” box_color=”#336588″][short_info id=’61721′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}