Cyber and financial audit
Please use Iphone to browse to:
www.jesperdeboer.nl/quiz.aspx
Agenda
- Own-experience
- Maersk
- Relation with FA
- Frameworks
- Materials you can use
Own-experience
Back in 1996...
Have you ever been hacked?
Annual accounts 2017:
- Cost increased by +- 300 mln
- Effected the result by +- 20%
- Unqualified Opinion
- No key audit matter
Quiz 1: What will you do?
- a. Do nothing
- b. Perform a pentest
- c. Perform a cyber audit based on framework
- d. Reperform client control activities
Relation with Financial audit
- Direct financial damage
- Indirect consequences due to reputational damage
- Loss of intellectual property
- Fines for violating regulations
- Dutch Accounting Standard 400 --> description of the main risks and uncertainties
Our audit approach
DAAM 12200 Internal Control § 146. For audits of listed entities, if we become aware of conditions or events indicating a cyber-security breach, the team shall consult with the NPPD.
Deloitte Framework 2018
- Improved and usable "Health check MKB"
- Focus on area’s: identification, prevention, detection, response and recover. We added more focus on governance, responsibilities and vendor management.
- It does not focus on: internal audit and cyber security framework and on technical measures.
- Understand the entity (discussion) or D&I