How board members can perform oversight of cybersecurity risks

Please note: This item is from our archives and was published in 2018. It is provided for historical reference. The content may be out of date and links may no longer function.

With organisations’ technology and systems under constant attack from hackers, cybersecurity oversight has become an increasingly important responsibility for board members.

New laws and regulations for managing and reporting on data security and cybersecurity risks create additional challenges for companies as they work to stay on top of the latest security trends and keep their systems and data safe.

A new tool from the Center for Audit Quality, which is affiliated with the American Institute of CPAs, provides board members with questions they can use in discussions with management and CPA firms about cybersecurity risks and disclosures.

The questions are related to:

  • Understanding how the financial statement auditor considers cybersecurity risk. Questions board members can ask include: How are cybersecurity risks that auditors identify addressed in the audit process? What impact would a cybersecurity breach have on the auditor’s assessment of internal control over financial reporting?
  • Understanding the role of management and the responsibilities of the financial statement auditor related to cybersecurity disclosures. Board members’ questions may include the following: How has management considered cybersecurity risks in its ability to report on information required in US Securities and Exchange Commission filings? What does the auditor consider related to cybersecurity disclosures?
  • Understanding management’s approach to cybersecurity risk management. Among the questions board members can ask: What framework does management use in designing its cybersecurity risk management programme? What processes are in place to periodically evaluate the cybersecurity risk programme and controls?
  • Understanding how CPA firms can assist boards of directors in their oversight of cybersecurity risk management. Board members’ questions may include the following: What additional offerings can CPA firms provide related to cybersecurity, since the financial statement auditor’s focus is on IT risks that affect financial reporting?

Ken Tysiac (Kenneth.Tysiac@aicpa-cima.com) is an FM magazine editorial director.

Up Next

AI readiness, skills gaps top concerns of finance leaders

By Steph Brown
December 17, 2025
Eighty-eight per cent of finance professionals believe AI will be the most transformative tech trend over the next 12 to 24 months. Yet only 8% feel their organisations are “very well prepared” to manage it, a new AICPA and CIMA survey shows.
Advertisement

LATEST STORIES

Finance and cyber resilience

5 elements of an effective AI prompt

AI readiness, skills gaps top concerns of finance leaders

Expert advice for navigating challenges, changes, self-doubt

Legislation set to lower EU sustainability reporting threshold

Advertisement
Read the latest FM digital edition, exclusively for CIMA members and AICPA members who hold the CGMA designation.
Advertisement

Related Articles

Finance and cyber resilience
5 elements of an effective AI prompt