Key Takeaways:
- From 60% in 2017, currently 78% of internal auditors view cybersecurity concerns as either extremely high or high.
- Nearly 20% of internal audit strategies increasingly center cybersecurity and IT risks, exceeding other categories.
- Internal audits expose flaws; they ensure compliance and enable one to connect cybersecurity projects with corporate goals.
- Working with security advisory companies such as LBMC improves general security plans and provides professional recommendations.
By Garrett Zickgraf
Understanding from the Internal Audit Foundation’s 2024 Report
According to recent research, a good number of internal auditors believe that the primary concern facing businesses is cybersecurity. These poll results emphasize the need of giving protecting of private corporate data far more attention.
Especially on cybersecurity, the 2024 North American Pulse of Internal Audit Benchmarks for Internal Audit Leaders by the Internal Audit Foundation provides vital information on the state of internal audit. The report contains key metrics and survey results conducted by the Foundation and includes data related to audit priorities and post-pandemic recovery.
This report has been a key source of guidance for internal audit and organizational leadership since 2008. It speaks to both current conditions and long-term trends in the internal audit space. By highlighting key areas of focus for internal audit functions, the report helps internal auditors prioritize their activities and allocate resources effectively to ensure that internal audit efforts are aligned with the most significant risks facing an organization.
The latest findings emphasize the prominent role of technology, especially cybersecurity and IT, as the primary areas of concern. Cybersecurity and IT have become the primary risks with more attention on third-party contacts, compliance/regulatory issues, and operational challenges.
Of the Chief Audit Executives and Directors surveyed, shockingly 78% believe the risk from cybersecurity issues is either extremely high or very low. That’s a significant increase from the 60% who felt that way in 2017. Only 21% of respondents say the risk is moderately high, and 1% believe the risk is low. This shows that auditors are more worried about cyber threats than ever before.

Overcoming the allocation for operational, financial reporting, and compliance/regulatory sectors, the survey shows that measures to handle cybersecurity and IT risks form about 20% of internal audit plans. This significant number highlights the increasing concern about cybersecurity and the need of a deliberate strategy to correctly manage these risks.
The Important Role Programs for Internal Audit Play
An internal audit program is crucial in addressing cybersecurity and IT challenges in an increasingly digital environment. Effective internal audit services can help organizations evaluate cybersecurity controls, identify weaknesses, assess whether risks are being appropriately managed, and communicate significant findings to senior management and the board.
For public companies, this broader control environment can also intersect with financial reporting requirements. Effective SOX compliance and internal controls depend on well-designed controls, clear ownership, appropriate testing, and timely remediation of deficiencies, making coordination between internal audit, finance, compliance, and technology teams increasingly important.
To accomplish these objectives, internal auditors should be asking themselves these questions:
- Am I aware of the IT department’s adopted security framework?
- Have we conducted a regular assessment of our cyber maturity?
- What key performance indicators do we use to measure the effectiveness of our cybersecurity controls and IT processes?
If any of the answers to these questions is no, it may be time to reassess the audit plan.
Empowering Internal Auditors in Cybersecurity
Internal auditors have a special role in making their companies safer from cyber threat actors. Today, their job goes beyond just checking the company’s finances. They also look closely at how the company uses technology and protects its information.
By doing thorough checks and risk assessments, internal auditors can find weaknesses and suggest ways to mitigate risks. They also ensure the company’s tech safety measures align with its goals and the rules it needs to follow.
Deep Dive into Risk Assessment
A strong plan for keeping information safe starts with in-depth knowledge of the company’s technology and how it’s protected. First of importance is routinely evaluating cybersecurity control robustness and cyber maturity. These tests enable auditors to expose possible weaknesses and highlight areas for development, so strengthening security posture.
Unveiling Risks
Cybersecurity assessments should identify not only technical vulnerabilities but also the business processes attackers could exploit. Internal auditors can work with stakeholders, review documentation, evaluate technology configurations, and assess controls around sensitive financial activities. Payment processes deserve particular attention because compromised credentials, phishing, and fraudulent payment instructions can quickly turn a cybersecurity incident into a financial loss. Strong wire fraud prevention practices can help reduce this exposure through verification procedures, access controls, employee awareness, and additional approval requirements for high-risk transactions.
Boosting Organizational Safety
Strengthening cybersecurity requires a diversified approach that combines effective security controls, strong governance, extensive risk analysis, and ongoing personnel development. Many of the same principles behind internal controls that prevent fraud—including segregation of duties, oversight, authorization procedures, and clearly defined responsibilities—can also help organizations reduce opportunities for cyber-enabled financial misconduct. Companies that prioritize these elements can build stronger defenses against both operational and cybersecurity threats.
Future of Cybersecurity Inside Internal Audit
Cybersecurity is not a destination; it is a process that is never fixed. Companies have to emphasize the significant part internal auditors help to maintain cybersecurity. Internal auditors are crucial in helping their businesses toward a safe digital environment using appropriate expertise, tools, and teamwork.
The continually shifting nature of cybersecurity concerns internal auditors to be adaptable and forward-looking. Following the latest trends and cybersecurity threats will help internal auditors identify and control risks. This awareness keeps their companies safe in an always changing digital environment.
Looking future, cybersecurity clearly has great importance inside the audit process. Equipped with appropriate tools and knowledge, internal auditors are rather important in enabling their businesses to manage risks. Internal auditors can greatly help to establish a safe and strong digital environment by using creative ideas and working with security experts.
The Value of Security Advisory Services
Working with cybersecurity partners like LBMC and security advisory firms gives businesses professional direction to enhance their security policies. These alliances provide specialized knowledge and innovative ideas, which greatly enhances the security strategy by means of thorough risk assessments, policy development, and evaluation of important records. Developing clear goals and action plans that enhance the general security architecture of a company depends on the cooperation of internal auditors and outside cybersecurity professionals.
The Value of LBMC in Internal Auditing and Cybersecurity
Managing cybersecurity risk effectively requires coordination between technology, risk management, internal controls, and organizational governance. LBMC brings these disciplines together through cybersecurity advisory capabilities and broader audit and assurance services, helping organizations evaluate risk from both technical and business perspectives.
LBMC’s cybersecurity professionals help organizations strengthen existing security programs or develop new ones through services ranging from risk assessments and policy development to Virtual Chief Information Security Officer (vCISO) services.
Organizations that need greater visibility into operational, financial, compliance, and technology-related risks can also leverage LBMC’s internal audit services. Our team can help evaluate whether controls are appropriately designed, identify gaps in the control environment, and provide management and boards with actionable recommendations for strengthening risk management.
Together, these capabilities help organizations address cybersecurity not simply as an IT issue, but as an enterprise risk that requires effective governance, controls, oversight, and ongoing assessment.
Content provided by LBMC Cybersecurity professional – Garrett Zickgraf.







