Internal and Forensic Audit · Emerging Issues and Challenges
Cyber Security and IT Risk Challenges in Internal Audit
Updated 11 October 2026 · Fact-checked
Cyber security and IT risk challenges are threats to an entity's systems, data and operations that internal auditors must assess, test and report on. You solve questions by identifying the risk, linking it to a control, stating the audit test, and giving a clear recommendation to management and the audit committee.
Understand Cyber Security and IT Risk Challenges
Every business now runs on IT systems. Accounts, payroll, sales, customer records and bank payments all sit in software. If these systems fail, are hacked or are misused, the business loses money, data and trust. This is IT risk. Cyber risk is the part of IT risk that comes from attacks or misuse by people, such as phishing, ransomware, unauthorised access, data theft and insider abuse.
The internal auditor does not run the security system. Management and the IT team do that. The auditor gives independent assurance that risks are identified, controls are designed well and they actually work. The auditor also reports gaps to management and the audit committee, and follows up on fixes.
Two layers of control matter. IT general controls (ITGCs) cover the whole environment: access management, change management, backup and recovery, IT operations and security of the network and data centre. Application controls sit inside a specific system, such as input validation, approval limits, and reconciliations of output. Weak ITGCs make application controls unreliable, because someone could change the program or data without trace.
Data privacy is a growing area. Entities hold personal data of customers and employees. In India, the Digital Personal Data Protection Act, 2023 governs how personal data is processed. The auditor checks whether the entity knows what personal data it holds, has a lawful basis and consent where needed, limits access, retains data only as required, and has a plan for breach response. Sector regulators may add their own rules, such as for banks and insurers.
IT governance is about who is accountable. Good governance means the board and senior management set the IT strategy, approve policies, assign roles such as a chief information security officer, and monitor cyber risk. Common challenges for auditors include fast-changing threats, shortage of technical skills, reliance on cloud and outsourced vendors, remote working, and lack of clear data ownership.
Key rules to remember
- Risk rating
- Risk = Likelihood × Impact
- Used to rank cyber risks so audit effort goes to high-risk areas first. It is a scoring approach, not a statutory formula.
- CIA triad
- Confidentiality + Integrity + Availability
- The three goals of information security. Map every threat to the goal it breaks.
- Control chain
- Risk → Control → Test → Finding → Recommendation
- Use this sequence to structure any answer.
- Types of ITGC
- Access + Change management + Operations/Backup + Security
- Core ITGC areas to list in a checklist answer.
- Three lines
- Management (1st) → Risk and compliance (2nd) → Internal audit (3rd)
- Internal audit is independent assurance, not the owner of the control.
How to solve Cyber Security and IT Risk Challenges questions
Use this method for any case or theory question on cyber and IT risk. It keeps your answer in the provision, analysis, conclusion format.
- 1Read the facts and underline the incident or weakness, such as shared passwords, no backup test, or a vendor with data access.
- 2Name the risk and the CIA goal it affects: confidentiality, integrity or availability.
- 3State the relevant control or framework point: ITGC area, application control, privacy requirement or governance duty.
- 4Say what the internal auditor would test: inspect access lists, review change logs, test restore of backups, check vendor contracts, and similar.
- 5Conclude on the gap and its significance using likelihood and impact.
- 6Recommend a fix, an owner and a timeline, and say it will be reported to the audit committee and followed up.
- 7Keep the auditor's role clear: assure and advise, not operate the control.
Quickest way: Risk-Control-Test-Report in four lines
When to use it: Use when time is short or the question asks for a checklist, list of risks or role of the auditor.
- Write the area: access, change, backup, network, privacy or governance.
- List two or three risks under it in one line each.
- Add one audit test per risk.
- Close with the reporting line: findings go to management and the audit committee, with follow-up.
Common mistakes in Cyber Security and IT Risk Challenges
Saying the internal auditor is responsible for implementing cyber security controls.
Students mix up the roles of management and audit.
Fix: State that management owns controls. The auditor gives independent assurance and recommendations.
Giving only generic points like 'use strong passwords' with no audit test.
The question is read as an IT question, not an audit question.
Fix: For each control, add what the auditor will inspect or test and what evidence will be kept.
Confusing general controls with application controls.
Both involve IT, and the terms sound alike.
Fix: Remember: general controls protect the whole environment; application controls work inside one process or system.
Ignoring third-party and cloud vendors.
Students focus on in-house systems only.
Fix: Add vendor due diligence, contract clauses on security and data, right to audit, and review of vendor assurance reports.
Quoting data privacy law from memory with wrong details.
Students try to show depth without being sure of the text.
Fix: State principles in plain words: consent or lawful use, purpose limits, security safeguards, breach response. Name the Digital Personal Data Protection Act, 2023 only for the framework.
Ending without a conclusion or report to the audit committee.
The answer stops after listing risks.
Fix: Always close with significance, recommendation, owner and follow-up.
Worked examples
Example 1
During an internal audit of Sundaram Textiles Ltd, you find that former employees' user IDs are still active in the accounting software and two of them logged in last month. Explain the risk and your audit response.
Show the solution
- Facts: leavers' accounts were not disabled, and some were used after exit.
- Risk: unauthorised access breaks confidentiality and integrity. Someone could view or alter financial data or approve payments. Likelihood is high because use has already occurred; impact could be fraud or misstatement.
- Control area: this is an ITGC failure in user access management, covering joiner, mover and leaver processes.
- Tests: obtain the HR list of leavers and match it with active user IDs; review login logs of the two accounts; check what transactions they performed; review whether access reviews are done periodically.
- Conclusion: a significant control gap, with possible loss and a need to examine transactions.
- Recommendation: disable the IDs at once, review transactions made, link HR exit to IT deactivation, and run quarterly access reviews.
- Report: communicate to management and the audit committee, and follow up until the fix is verified.
Answer: The failure is in ITGC access management and is high risk because the IDs were actually used. Test leaver lists against active IDs and review the logs and transactions. Recommend immediate deactivation, an HR-IT exit process and periodic access reviews, and report to the audit committee with follow-up.
Example 2
Bharat Retail Ltd stores customer personal data and uses an outside cloud vendor. List the data privacy and IT governance points an internal auditor should assess.
Show the solution
- Data inventory: check whether the company knows what personal data it holds, where it sits and who can access it.
- Lawful use: check that data is collected for stated purposes with consent or another valid basis, in line with the Digital Personal Data Protection Act, 2023.
- Security safeguards: test access restrictions, encryption where used, and monitoring of unusual access.
- Retention: check that data is not kept longer than needed and is erased as per policy.
- Vendor: review the contract for security and data protection terms, breach notice, and audit rights; obtain independent assurance on the vendor's controls.
- Incident response: check that a breach response plan exists, has an owner and has been tested.
- Governance: check board or committee oversight, a named security head, approved policies, and regular cyber risk reporting.
- Report gaps with priority to management and the audit committee.
Answer: The auditor should assess data inventory, lawful use and consent, security safeguards, retention, vendor contract and assurance, breach response, and board-level IT governance, then report prioritised findings with follow-up.
Exam tips
- Structure every answer as risk, control, test, recommendation. Examiners reward this order.
- Use the CIA triad words to classify risks. It makes answers crisp.
- In case questions, tie your points to the facts given, such as the vendor, the leaver IDs or the missing backup test.
- Keep legal references modest and accurate. Plain-language principles score better than shaky section numbers.
- Always show the reporting step to the audit committee and follow-up.
Practice questions from Emerging Issues and Challenges
- Which control most effectively limits the damage to Ganga Foods Ltd if ransomware encrypts its production file server?
- Ganga Logistics Ltd wants its internal audit to cover ESG disclosures, as stakeholders increasingly expect assurance on non-financial inform…
- Under a continuous auditing set-up at Bharat Logistics Ltd, the internal audit team has configured automated rules that flag exceptions in t…
- Sundaram Textiles Ltd's internal audit head notices that the audit committee has stopped receiving her reports directly; they now pass throu…
- Kaveri Retail Ltd's internal auditor wants to test whether the company's staff can recognise phishing attempts. Which audit approach best pr…
Cyber Security and IT Risk Challenges in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Security and IT Risk Challenges: frequently asked questions
What is the role of the internal auditor in cyber security?
The internal auditor gives independent assurance on whether cyber risks are identified and controls work. The auditor tests controls, reports gaps and follows up. Management remains responsible for running the controls.
What should an IT general controls audit checklist include?
Cover user access management, change management, backup and recovery, IT operations and job scheduling, and physical and network security. Add vendor management and incident response. For each item, note the test and the evidence.
What are the main data privacy audit challenges in India?
Common challenges are not knowing where personal data sits, weak consent and purpose records, vendor handling of data, and lack of breach response plans. Auditors must also keep up with the Digital Personal Data Protection Act, 2023 and any sector rules.
How are general controls different from application controls?
General controls protect the whole IT environment, such as access and change controls. Application controls work inside one system, such as input checks and approval limits. Weak general controls reduce reliance on application controls.