Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Vice President of Internal Audit at Student Transportation of America
Michael Levy
Internal Audits in Cyber Security for Enhanced Organizational Value


Please shed some light on today's major challenges in the internal audit space.
Protecting an organization from potential reputational or financial threats and building a line of defense is a collective effort involving IT and internal audit departments. While IT teams focus on developing and managing systems to increase defenses, the internal audit team evaluates what has been designed by IT and provides recommendations on ways to enhance it. The internal audit team acts as a lens for identifying risks and providing configuration reviews.
In today's fast-paced technological environment, the possibility of a cyber incident is greater than ever. It is important for organizations to work with their Internal Audit teams to evaluate strategies and plans that enhance cybersecurity and proactively assist in monitoring cyber governance frameworks such as CIS and NIST. It is impossible to guarantee 100% security to organizations. Therefore, having robust strategies and plans in place to respond and recover from threats as quickly as possible is crucial.
The scope and engagement of internal audit is not universal and can differ from organization to organization. Therefore, internal auditors need to take a tailored approach to assess the specific risks involved in each organization and provide recommendations based on their insights. When proposing a framework, internal auditors usually incorporate guidance and standards set by industry experts to create them, thus ensuring they are in line with best practices. Internal Audit departments should leverage the guidance and standards developed by the Institute of Internal Auditors to assist and ensure uniformity of their approach.
Are there any recent projects you have been working on, and what are some of the process elements leveraged to make them successful?
As a VP of internal audit, I have been involved in several projects to improve various organizations' cybersecurity postures. During these projects, I assess the organization's maturity level regarding cybersecurity and its processes and often leverage a framework such as the CIS Framework (Center for Information Security). Frameworks assist in developing a prioritization funnel to identify gaps in risk and efforts and evaluate the required changes in processes and costs to enhance security. After this process, it is up to the IT teams to implement the changes or execute the new projects.
Protecting an organization from potential reputational or financial threats and assessing the strategy for layered defenses is a collective effort involving IT and internal audit departments.
In light of your experience, what will be your advice to fellow peers in the industry?
Collaboration and communication between internal audit and IT departments can significantly enhance an organization's overall security. By working together, internal audit teams can provide valuable insights into potential risks and recommend ways to improve security measures that the IT team has put in place. Both teams need to understand the scope and objectives of each other's roles to ensure they are working towards a common goal. This collaborative approach can help organizations stay ahead of potential threats and respond quickly and effectively to any security incidents.

