Mind the Gap: Cyber security risk in the new normal
February 2021
2
Mind the Gap: Cyber security risk in the new normal
3
Mind the Gap: Cyber security risk in the new normal
Foreword Cyber security is without a doubt the perennial risk of the 21st century, and it has been particularly exacerbated by the coronavirus pandemic. Businesses have had to juggle competing priorities and operational disruption whilst ensuring that working devices and networks are secure. At the same time, criminals have sought to capitalise on the crisis by exploiting remote working protocols through increasing the pace and sophistication of cyber-attacks. With many organisations looking to shift to remote working practices more permanently after the pandemic, establishing a strong and effective cyber security culture within organisations has never been more crucial to cyber resilience. The human factor in preventing attacks is key, and internal audit has a vital role to play in promoting an effective cyber security culture in their organisations to mitigate the risk of human error. This report aims to educate, inform and guide internal audit’s thinking in this area. The core of this research is based on a survey of senior internal auditors in the UK and Ireland. It reveals a gap between the work of internal audit in providing assurance on cyber security risk and assessing and promoting cyber security culture in the organisations they serve. A positive aspect of the results indicated that most senior internal auditors are including cyber security in audit plans (81%), identifying threats and auditing the mitigation plan (58%), and conducting risk assessment in collaboration with their IT and Risk colleagues (62%). However, in areas that directly contribute to effective cyber security culture, only a third report contributing to cyber security strategy/policy in the organisation (32%), creating a culture to learn from mistakes (31%) and assessing whether their organisation is investing in security training for employees (33%). Clearly there is room here for more internal audit functions to step up to the plate and be more pro-active and hands on within their organisations in relation to cyber security culture. The survey also highlighted the impact of the coronavirus pandemic on cyber security practices and resilience. Over a half (51%) of respondents reported that they have suffered a cyber-attack in the last 12 months that has had an impact on products and services, and 42% of respondents have said that employees working remotely has created a barrier to implementing better cyber security practices. However, more positively, 65%
of senior internal auditors have said that discussions on cyber security risk have taken place more frequently since the beginning of the pandemic. Internal audit has a vital role to play in providing assurance that a robust cyber security awareness culture has been established and is operating effectively. Internal audit can make an assessment on the factors that influence cyber security culture, build key relationships across the organisation, and challenge executive management on their awareness and understanding of the associated risks. This will help to formulate a clear understanding of the risk appetite and help to report any gaps and weaknesses to the board and audit committee. The case studies in the report showcase good practice examples across different sectors. They demonstrate how internal audit functions have approached cyber security culture in their audit assessments, and any key lessons they have learnt. We hope that they will inspire your work in this sphere. Throughout this year and beyond, we would like to encourage internal audit functions to play their role in promoting a good cyber security culture in their organisation. In particular, highlight that culture, and more specifically human error is an important factor in cyber security risk, and it should be considered together with the policies and strategies in the organisation. Businesses are only as strong as their weakest point in cyber security. We hope that this report will be a useful tool in helping you provide assurance on cyber security culture within your organisation.
John Wood, Chief Executive Chartered Institute of Internal Auditors
4
Mind the Gap: Cyber security risk in the new normal
About the research We conducted a survey of 177 senior internal auditors (including 104 Chief Audit Executives) across all sectors in the UK and Ireland. Over half of the respondents were from public interest entities including FTSE 100, FTSE 101-350 and other publicly listed firms and large private companies. The aim of the survey was twofold. Firstly, to find out what internal audit teams are doing in helping the organisations they serve to manage and mitigate the risk of cyber-attacks. Secondly, in promoting a cyber security culture across their organisations.
A survey of 177 senior internal auditors including:
59%
34%
Senior Internal Audit Managers
7% 4%
11%
18% 10%
Other publicly listed organisation
Other – including pharmaceutical, professional services and consulting
12% 20%
6%
Large private organisation
5%
Other
Manufacturing & engineering
Other
12% FTSE 101-350
Central & local government
Internal Audit Leads
Their organisations were classed as the following:
FTSE 100
Financial services sector
19%
Internal Audit Managers
We also conducted an interview with a cyber security expert, Magdalena Skorupa, Cyber Risk, Data Privacy & Compliance Director at Reckitt Benckiser to help us shed light on the survey results and suggest enhancement of internal audit functions in this sphere.
These 177 senior internal auditors came from the following sectors:
Chief Audit Executives/Heads of Internal Audit
12%
In addition to the survey, we conducted interviews with Chief Audit Executives and cyber security professionals across different sectors including a large UK financial services organisation, Barts Health and West Midlands Ambulance NHS Trusts, Northern Ireland Water and Vodafone to share best practice internal audit in cyber security culture, and presented these as case studies.
45%
Education
3%
Information & communication
The size of their internal audit functions were as follows:
65% Small (1-10 staff)
*All figures have been rounded to the nearest percentage point
23%
Medium (11-50 staff)
12%
Large (51-100+ staff)
5
Mind the Gap: Cyber security risk in the new normal
Key results The top three methods that organisations use to manage and mitigate cyber security risk are:
The key responsibilities within internal audit teams with regard to assessing cyber security risk and assessing the steps management has put in place to mitigate that risk are:
33%
report assessing whether their organisation has invested in security training for employees adapted to the new remote working environment
46%
29%
securing infrastructure
installing antivirus protection software
81%
62%
conducting risk assessment in collaboration with IT and Risk colleagues
including cyber security in audit plans
32%
report contributing to cyber security strategy/ policy in the organisation
27%
employee training
58%
identifying threats and audit mitigation plan
31%
report creating a culture to learn from mistakes
6
Mind the Gap: Cyber security risk in the new normal
Key results A majority of respondents have said that their organisations have practices in place to promote effective cyber security culture such as:
Senior internal auditors report having discussed cyber security risk with the following colleagues:
85%
with the audit committee
cyber security strategy and policies
79%
only
41%
report having discussed it with the board
senior management buy-in and support on cyber security strategy and policies
76%
77%
employees at all levels are aware of and recognise their role in cyber security
with executive management
65%
65%
reported that these discussions have taken place more frequently since the beginning of the pandemic.
The three biggest barriers to implementing better cyber security practices during the COVID-19 pandemic are:
91%
said that implementing a stronger cyber security culture within their organisation would prevent potential cyber-attacks.
competing priorities
48%
employees working remotely
42%
86%
with the IT director and senior IT colleagues
81%
with members of the internal audit team
51%
of respondents reported that they have suffered a cyber-attack in the last 12 months that has had an impact on products and services.
insufficient budget
28%
7
Mind the Gap: Cyber security risk in the new normal
Introduction Cyber security has been at the forefront of organisations’ thinking for many years. As evidenced by our annual Risk in Focus research, it has been voted as the number one risk for the third year running, where 79% of 579 Chief Audit Executives (CAEs) identified it as a top risk to their organisation. With cyber security risk being exacerbated during the coronavirus pandemic, it has forced businesses to find solutions on a mass scale without trade-offs between productivity and cyber security resilience. This is not least because the consequences of cyber security breaches such as data loss, reputation and customer retention are critical for organisations’ long-term sustainability. Cyber security breaches are indiscriminate of the size and sector, with many major organisations such as the NHS, Travelex and British Airways significantly affected in the past. Cyber security Ventures predict that the costs of global cybercrime will reach $10.5 trillion in 2025, compared to $3 trillion in 2015.1 The World Economic Forum’s Global Risks Report 2021 ranked cyber security failure among the highest likelihood of risks of the next ten years due to increasingly sophisticated and frequent cybercrimes.2 Similarly, it was reported that 90% of cyber data breaches have been caused by human error in 2019, according to the analysis of data from the Information Commissioner’s Office (ICO).3 This suggests that the vast majority of cyber-attacks can be prevented by simple cyber security hygiene measures and the human factor in preventing attacks is key. That is why embedding an effective cyber security awareness culture is nearly always the best form of defence. The European Union Agency for Network and Information Security (ENISA) defines cyber security culture as “the knowledge, beliefs, perceptions, attitudes, assumptions, norms and values of people regarding cyber security and how they manifest themselves in people’s behaviour with information technologies.”4 With the primary concern of establishing an effective culture as “making information security considerations an integral part of an employee’s job, habits and conduct, embedding them in their day-to-day actions.” Internal audit has a vital role to play in promoting cyber security awareness across the organisation and providing assurance that a
1 2 3 4
robust cyber security awareness culture has been established and is operating effectively. The aim of this report is to highlight the gap in assessment of cyber security practices in organisations and encourage internal audit teams in supporting their organisations to be cyber resilient and future-proof. 177 senior internal auditors participated in the survey which formed the basis of this research, and we also conducted 4 in-depth interviews with CAEs and cyber security professionals who have done some interesting work in this sphere. These have formed 4 case studies which illustrate good practice internal audit in promoting a good cyber security culture and we hope that they will serve as inspiration for other internal audit teams to do the same.
“The human behavioural element is critical to cyber and data security risk. Lacking personal interaction, staff can be more susceptible to social engineering ploys as they cannot immediately sense-check emails with nearby co-workers. There is also greater potential for controls and safety measures to soften or be circumvented when workers are not being watched, as they are overlooked and ignored to save time.” Risk in Focus 2021
Cybercrime Magazine | Cybercrime to cost the world $10.5 trillion annually by 2025 World Economic Forum | Global Risks Report 2021 CybSafe | Human error to blame for 9 in 10 UK cyber data breaches in 2019 ENISA | Cyber Security Culture in organisations
8
“Despite the technical cyber security controls that we have in place it is still broadly recognised within the organisation that the biggest threat comes from within – for example, an internal user falling for a phishing email and introducing malware.” Nicola Brennan, Head of Internal Audit, Northern Ireland Water
Mind the Gap: Cyber security risk in the new normal
9
Mind the Gap: Cyber security risk in the new normal
Findings Cyber security practices in the organisation As we expected, the survey results showed that almost half (46%) of senior internal auditors said that securing infrastructure is the top method used by their organisation to manage and mitigate cyber security risk. This is followed by installing anti-virus software (29%) and employee training (27%).
Many reports, including an assessment by INTERPOL of the COVID-19 pandemic on cybercrime showed that around two-thirds of countries have reported significant use of COVID-19 themes for phishing and fraud since the outbreak.5 We were pleased to see employee training feature in the top three methods for organisations to manage and mitigate cyber security risk.
What are the top three methods that your organisation uses to manage and mitigate cyber security risk? 45.8%
Secure your infrastructure
28.8%
Install Anti-Virus Software
27.1%
Employee training
26%
Vulnerabilities assessments
25.4%
Penetration testing
23.2%
Implement multi-factor authentication
20.3%
Malware protection
20.3%
Patch management
19.2%
Back-up critical data Invest in security training for employees
17%
Identify threats, make a plan, and learn from mistakes
17% 16.4%
Keep software up-to-date
11.3%
ISO 27001 compliance
2.3%
Other 0%
5%
Similarly, with regard to cyber security culture specifically, a large majority of respondents said that their organisations have the following in place to promote effective cyber security culture practices within their organisation: cyber security strategy and policies (79%), senior management buy-in and support on cyber security strategy and
5
10%
15%
20%
25%
30%
35%
40%
policies (76%), employees at all levels are aware of and recognise their role in cyber security (65%), employees participate in regular cyber security training programmes (63%), policies are updated to reflect enhanced risk due to remote working (62%) and that cyber security is seen as a collective concern in the organisation (59%).
INTERPOL | INTERPOL report shows alarming rate of cyber-attacks during COVID-19
45%
50%
10
Mind the Gap: Cyber security risk in the new normal
Which of the following does your organisation have in place to promote effective cyber security culture practices within your organisation? (tick all that apply) 78.5%
Cyber security strategy and policies Employees participate in regular cyber security training programmes Senior management buy-in and support on cyber security strategy and policies Employees at all levels are aware of and recognise their role in cyber security Cyber security is seen as a collective concern in the organisation Policies updated to reflect the enhanced risk due to remote working
62.7% 76.3% 65% 58.8% 61.6% 4%
None that I am aware of
5.6%
Other 0%
10%
Internal audit and cyber security culture Looking at internal audit functions specifically, in terms of assessing cyber security risk and assessing the steps that management have put in place to mitigate that risk, as expected, a majority of respondents (81%) said that that they include cyber security in audit plans. Given the significance of the subject we would normally expect to see omission
20%
30%
40%
50%
60%
70%
80%
90%
100%
from the audit plan to have received support from the audit committee. 62% said that they conduct risk assessment in collaboration with their IT and Risk colleagues, and 58% said that they identify threats and audit the mitigation plan. Overall, this suggests that the majority of internal audit functions feature cyber security in their assurance work and are mature in the traditional approach to assessing cyber security risk.
What are the key responsibilities within your internal audit team with regard to assessing cyber security risk and assessing the steps management has put in place to mitigate that risk? (tick all that apply) 36.2%
Vulnerabilities assessment
29.9%
Penetration testing
81.4%
Including cyber security in audit plans Risk assessment in collaboration with the IT and Risk colleagues
61.6% 14.7%
Addressing staff shortages in IT/cyber security
52%
Identify opportunities to manage and mitigate cyber security risk Contributing to cyber security strategy/policy in organisation
32.2% 8.5%
Other 0%
10%
20%
30%
40%
50%
60%
70%
80%
90%
100%
11
Mind the Gap: Cyber security risk in the new normal
What are the key responsibilities within your internal audit team with regard to assessing cyber security risk and assessing the steps management has put in place to mitigate that risk? (tick all that apply) ISO 27001 compliance - inspections to ensure compliance
15.3% 32.8%
Keep software up-to-date Install Anti-Virus Protection Software, ensure that it is monitored so attempted breaches are identified Back up critical data - frequency and where is the back up stored e.g. the cloud Invest in security training for employees - adapted for the new remote working environment Secure your infrastructure - are the steps taken adequate? Implement multi-factor authentication - in place and effective
36.7% 42.9% 32.8% 48% 28.2% 58.2%
Identify threats and audit the mitigation plan
31.1%
Create a culture to learn from mistakes 0%
5%
10%
However, it was surprising to see that, in comparison, only a third of senior internal auditors reported including assessment of cyber security practices that help promote effective cyber security culture within the organisation. Only 33% reported investing in security training for employees adapted for the new working environment, 32% reported contributing to cyber security strategy and policies, and only 31% reported creating a culture to learn from mistakes. In turn highlighting a significant gap between the traditional forms of cyber security risk assessments and the cultural aspects in their assurance work. With a unique view of the organisation and ability to make an impact, internal audit should have a more proactive role in their assessment of cyber security culture and its promotion across the organisation. We would like to see internal audit teams address that gap through identifying any weaknesses in practices that impact cyber security culture and highlighting these to all three groups: the executive management, the board and the audit committee. This can be achieved by building relationships with key stakeholders across the organisation and participating in key meetings and challenging executive management on the knowledge and awareness of key risks associated with cyber security. In the new normal, technology controls will remain a significant part of the mitigation of cyber security risk. It is recognising that the most
15%
20%
25%
30%
35%
40%
45%
50%
55%
60%
effective form of cyber security is a combination of technology and awareness within the organisation to mitigate human error. Many employees have been working from home during the coronavirus pandemic and many are likely to continue in a more hybrid way in the future, meaning strong and effective cyber security culture is crucial to protecting organisations against cyber-attacks. Furthermore, of the senior internal auditors we surveyed, it was positive to see that 85% report discussing cyber security risk with the audit committee, 77% with executive management, 86% with their IT Director and senior IT colleagues, 81% with other members of the internal audit team and 51% with the risk committee.
“The main ways in which we influence the broader organisation is through the way that we interact with the big committees, in what we say, what our reports say and how we challenge stakeholders.” Head of Audit for Cyber Security, Large UK Financial Services Organisation
12
Mind the Gap: Cyber security risk in the new normal
Has the internal audit function discussed cyber security risk with any of the following? (tick all that apply) 40.7%
The board
85.3%
The audit committee
51.4%
The risk committee
76.8%
The executive management
86.4%
IT Director and senior IT colleagues
80.8%
Members of your internal audit team
1.1%
None of the above 0%
10%
20%
30%
However, it was disappointing to see that that only 41% report discussing cyber security risk with the board. This is critical in ensuring that the assurance agreed reflects wider organisational cyber security risk strategies. Similarly, it is crucial that your audit recommendations are understood and taken on board and that you get enough support to make a real difference in the business. Internal audit has a vital role to play in providing assurance over cyber security risk and that a robust cyber security culture is established and operating effectively. We would expect that internal audit would ensure that key stakeholders in the organisation would have insight into the status and progress of cyber security programmes and any gaps and inefficiencies identified in relation to cyber security culture as part of their wider assessments. Furthermore, of those that reported having discussions on cyber security risk with either the board, audit committee, risk committee, executive management, IT Director and senior IT colleagues and members of their internal audit team, 65% reported that these discussions have taken place more frequently since the beginning of the pandemic. Similarly, a large majority have also reported that they have also discussed the role of effective cyber security culture in managing and mitigating cyber security risk with the stakeholders mentioned above.
40%
60%
70%
80%
90%
100%
key relationships and working together with the rest of the business on solutions, and perhaps the most vital, building credibility through really knowing the area that you audit. It was positive to find that a large majority (91%) of respondents to the survey said that implementing a stronger cyber security culture within their organisation would help prevent potential cyber-attacks. Similarly, a report from ISACA and CMMI Institute found that 95% of organisations believe that a gap exists between their current and desired cyber security culture.6 This suggests that whilst organisations and internal audit understand the value of cyber security culture, they could be finding it challenging to address this. We hope that that this report will encourage internal audit to play a more active role in assessing and promoting cyber security culture in their organisation.
Do you think that implementing a stronger cyber security culture within your organisation would help prevent potential cyber-attacks?
In terms of culture, for internal audit to add value they need to ensure that they are seen as a partner to the business through building those
6
50%
ISACA and CMMI Institute | Narrowing the culture gap for better business results
9% No
91% Yes
13
Mind the Gap: Cyber security risk in the new normal
Has the COVID-19 pandemic exacerbated cyber security risk for your organisation?
Impact of the COVID-19 pandemic As expected, the majority of respondents (59%) said that the COVID-19 pandemic has exacerbated cyber security risk for their organisation, and 27% said it had not. However, it was concerning to see that 14% of senior internal auditors were not sure of the impact of the pandemic on cyber security risk given that it is on the top of the risk agenda for many organisations.
13.6% Not sure
27.1% No
Similarly, when asked whether their organisation faced any key barriers in implementing better cyber security practices during the COVID-19 pandemic, almost half (48%) said that competing priorities were the key barrier in implementing better cyber security practices, followed by 42% of respondents who said employees working from home/remotely.
59.3% Yes
Has your organisation faced any key barriers in implementing better cyber security practices during the COVID-19 pandemic? 47.5%
Competing priorities
6.2%
Lack of executive management buy-in
lack of understanding amongst employees/colleagues
16.4% 27.7%
Insufficient budget Employees working from home/ remotely
42.4% 26%
None
4.0%
Other 0%
5%
10%
15%
This suggests that there could be added value in having effective cyber security culture practices in place for organisations’ long-term sustainability. With over a half (51%) of survey respondents reporting that their organisation has suffered a cyber-attack in the last 12 months that has had an impact on products and services, by encouraging employees to be more vigilant and aware of potential cyber-attacks, the impact of long-term remote working on cyber resilience would be mitigated. Employees could be more proactive in cyber security if they perceive themselves to have a key role to play in cyber security. Internal audit is best placed within the organisation to assess and ensure that cyber security risk is widely understood by all employees and that the employees play their part in cyber security by acting as ‘human firewalls’.
20%
25%
30%
35%
40%
45%
50%
This would mitigate the likelihood of policies and procedures being circumvented during times of increased stress and competing priorities such as the current coronavirus pandemic.
“I have seen organisations put in brand new firewalls and all these technical updates for it all to be undone by one user who has not followed rules or engaged. User awareness is key.” Gary Colman, Head of IT Audit and Assurance Services, West Midlands Ambulance NHS Trust
14
Mind the Gap: Cyber security risk in the new normal
Questions for internal audit • Have you included human factor risk in your assessment of cyber security risk? • Are senior management and the board aware of key risks associated with cyber security? Are they aware of the cyber security culture in the organisation? • Have you worked with senior management and the board to develop a cyber security strategy/policy?
• Do you regularly follow up with relevant stakeholders that own cyber security risks, such as the Chief Information Security Officer (CISO) and IT department to get a better understanding of cyber security culture in your organisation? • Have you conducted research to be credible in conversations with relevant stakeholders on cyber security risk?
• Are employees and contractors receiving up-to-date training adapted to the remote working environment? • How have you ensured that a good cyber security culture is operating effectively in the organisation? • Is there a cyber incident response plan in place? Is it operating effectively? • Have you assessed whether resources (e.g. technology and staff) are needed to address cyber security risk more effectively?
Conclusion Cyber security has been one of the top risks for organisations over recent years. It has been particularly exacerbated during the COVID-19 pandemic, as cybercriminals have sought to exploit human weaknesses and remote working protocols. It is clear that more could be done by organisations and their internal audit teams to manage and mitigate this dynamic risk. With mass remote working, cyber security can no longer be seen as only an IT risk. Cyber security requires an understanding from all employees of their role in protecting the organisation against the bad actors. Internal audit must have a thorough understanding of what influences cyber security culture and be able to share this with the management and the board in order to influence the organisation’s cyber resilience. For internal audit to do this, they need to build relationships with key stakeholders, follow up on any gaps and inefficiencies in cyber security culture and challenge the organisation on their knowledge and awareness of this dynamic risk area. With remote working here to stay (at the very least, in a hybrid way) for the foreseeable future, it is crucial that internal audit addresses gaps in cyber security risk and is a key advocate in cyber security awareness and culture within their organisations.
Mind the Gap: Cyber security risk in the new normal
“With security controls being layered we cannot accept weaknesses in one layer with mitigating controls in another layer. The key defence model needs to be robustly controlled at every level so don’t let executives get complacent because of the number of controls that they have.” Head of Audit for Payments, Large UK Financial Services Organisation
15
16
Mind the Gap: Cyber security risk in the new normal
Case study: Michael Townsend, Head of Internal Audit at London Audit (Part of Barts Health NHS Trust) and Gary Colman, Head of IT Audit and Assurance Services at West Midlands Ambulance NHS Trust Cyber security risk and cyber-crime have been big issues for the NHS since the ‘WannaCry’ attack in 2017. NHS counter fraud activity has an impact on cyber security culture. All NHS audit providers like London Audit have separate counter fraud teams that consider the risk of cyber security fraud within their proactive plans. These Local Counter Fraud Specialists ensure there are regular alerts going out to staff to encourage awareness on phishing risks and avoiding malicious websites. They have regular virtual clinics set up to brief staff around the associated risk areas. Gary’s IT audit team conducts phishing tests to test staff susceptibility and monitor click rates, even running it as a mini competition between departments to encourage participation. In the past they have also done USB key drops on sites, that would report back if someone plugged them in. They also conduct anonymous surveys of staff to examine their attitudes and risk appetite towards cyber security, with the next survey due to launch as part of a much wider cyber security audit in the next few months. In response to the COVID-19 pandemic, the London Audit team have also adjusted the scope of this year’s planned cyber security audit to reflect staff working from home and to address some of the emerging risks. All NHS organisations send out a number of pieces of guidance to staff to maintain awareness, make sure they are accessing systems through VPNs, ensure that confidential documents are disposed of appropriately and are aware when conversations could be overheard. Additionally, TIAN (the national network of NHS based internal audit providers) recently conducted an anonymous survey of NHS IT Directors looking at the impact of the pandemic on cyber security within their organisations. Following on from this, they produced an executive summary with guidance to help organisations across the NHS to gain assurance on cyber security.
Across the NHS (within every NHS body and also non-NHS bodies that handle NHS data) organisations are required to complete a nationally mandated “data and security protection toolkit”. This is a self-assessment conducted every year by the Trust’s information governance team and includes the expected requirements for different aspects of information security and data security. Within the toolkit there is an element that requires mandatory annual completion on information governance training by all staff. As part of the process, there is a requirement for every NHS internal audit team to provide assurance over the robustness of the organisation’s self-assessment of the toolkit.
“Internal audit needs to look at the big picture, and the wider user awareness and governance aspects. If you have technical controls, they can easily be undone by a user with a click of a button, so user awareness is key.”
17
Mind the Gap: Cyber security risk in the new normal
Impact of the WannaCry ransomware attack Many NHS Trusts were affected by the WannaCry attack over 3 years ago, which has increased focus and investment on cyber security risk, including raising staff awareness about their role in cyber security. There was a significant increase in IT audit work and the amount of assurance sought over the associated risks, including conducting follow-up reviews of post-WannaCry action plans. In the last few years, NHS bodies have also been running incident simulations, similar to that of WannaCry. As part of the simulations, they will test the incident response of the department and capture key lessons learnt.
Senior management, boards and audit committees across the NHS have expected to be kept regularly up-to-date with developments by their audit and cyber security teams, and have made it a priority to address any actions. Every NHS organisation has incident reporting systems and incident response plans in place. At West Midlands Ambulance Service NHS Trust (WMAS) for example, they use the main Trust’s incident response procedures and policies for all incidents including cyber security. Other Trusts have dedicated cyber security incident response routes as well. These incident response procedures are widely advertised and communicated through the intranet so all employees across the organisation are aware. If there is an incident, there would be a review of procedures, lessons learnt, and practices amended to reflect it. Cyber security is part of the NHS learning culture.
Key lessons learned and advice for other audit teams While a lot around cyber security is technical, there is a bigger part for cyber security risk that is around people issues, and training and awareness raising. The key is to keep focusing on it and making sure that staff are informed of any new developments from potential attackers. The main advice is to make sure that you are fully using all possible avenues to communicate the message, including updating the intranet, messages on payslips, emails and surveys. Internal audit needs to look at the big picture, and the wider user awareness and governance aspects. If you have technical controls, they can easily be undone by a user with a click of a button, so user awareness is key.
18
Mind the Gap: Cyber security risk in the new normal
Case study: Preeti Sadarangani, Global Head of Internal Audit and Paul Holland, Global Head of Technology Audit at Vodafone Group Plc Cyber security risk is one of the top risks for Vodafone and managing that across a large and diverse technology-driven organisation comes with its challenges. The internal audit team in Vodafone (VIA) plays a significant role – as a business advisor, constructive challenger, and an independent assurance provider – and influences the way cyber risks are understood, managed and mitigated within the organisation. VIA uses their thorough understanding of the business and its risk to include audits in their audit plan that are most relevant. This includes specific ‘cyber audits’ but also brings out cyber risk within wider audits. As a consequence, and fuelled by both audit results (i.e. reports) and ways of working, VIA helps drive the company’s cyber security culture. VIA achieves this through: •
Upskilling – to safeguard quality and credibility
• Transparency – substantiating the facts as well as the ‘why?’ • Risk appetite – it’s about understanding and managing risk, not eliminating it
Upskilling – Getting it done together Embedding specialist knowledge: about 5% of the VIA team consists of deep cyber security specialists, often ‘pentesters’. This enables the audit approach to include testing approaches that replicate what the external threat actors would do in the real world - penetration testing, phishing emails, etc. As such, this team delivers end-to-end technical audits, as well as enables broader integrated audit with specialised technical activities, similar to how our data analytics specialists support and enable audits. Risk understanding by Audit leadership: The VIA cyber auditors are part of the company’s cyber risk council through which they remain aware of issues and initiatives in real-time, as well as are able to influence the company’s decision making from the outset. The VIA cyber lead briefs the audit leadership each month on developments in cyber, including any issues from across the group (and their root causes), to help drive a common understanding of the implications of any
potential cyber related control gaps. Lifting the full team to a base level of knowledge: To bring about greater awareness and understanding of cyber risks within the full internal audit community, and under a wider ‘super skilled’ initiative, competency mapping was performed across the global team. Dedicated and customised cyber security trainings were conducted with live scenarios, break-away studies, and quizzes to test the proficiency and application of the cyber risks within business processes. ‘Guest Auditors’ from the cyber security teams are used to transfer their knowledge to auditors and at the same time appreciate and understand audit techniques to help them in their cyber security operations. Secondments or transfers from audit into the cyber security team within the business helped strengthen the understanding of risks arising from cyber security issues.
Transparency - Glass half full as well as half empty Data driven risk management: Every audit finding by VIA relating to cyber security is backed with data, internal benchmarks across countries and quantification of the risk (how many servers, which systems, which patches and with what aging, which markets, what business line etc.), that bring to life the size, scale and therefore the business impact of possible gaps. Moving away from sampling to do more robust data analytics on a wider coverage of
19
Mind the Gap: Cyber security risk in the new normal
technology assets, coupled with ethical hacking techniques, makes the risk come to life and not remain as a hypothetical scenario. Where relevant, data models and analytics routines are shared with the first or second line teams to support the ongoing monitoring of controls. Alignment with 1st and 2nd Lines: Cyber risk related audit findings are mapped to the key performance indicators (cyber security baseline scores). Where the audit findings might contradict scores reported by the business, these are called out and used to formally provide an opinion on the second line. This approach leads to increasing levels of alignment and perception of risk by management and the Board. Glass half full as well as half empty: VIA’s data driven approach enables audit to offer both a glass half empty versus half full view. I.e. key performance indicators often provide the ‘half full’ view on what has been achieved, which is complemented with a more ‘half empty’ perspective on what is still left to do. For example, a 99% patching outcome can be presented as a ‘green’ indicator, however in the cyber threat world, a 1% gap can still expose the business to risk if the risks related to that specific gap are not well understood. Reporting on both control effectiveness as well as ineffectiveness helps keep the foot on the pedal of ensuring continuous focus and monitoring of cyber risks. The why: Supporting the data-based audit findings (the ‘what’), is the use of a robust methodology on root-causes (the ‘why’) and existence of improvement plans. The VIA team determines the fundamental causes of control gaps (is there enough appreciation of the risk, are there resources and budgets commensurate to size of the risk, etc.) as well as the adequacy of existing improvement plans to drive an understanding and focus on those mitigation actions that will fundamentally fix the
gaps versus a shorter term tactical ‘sticking plaster’ action.
Risk appetite – Driving consistency in risk tolerance Policies and standards play a key role in setting the company’s risk appetite. As in the example above, what is the right tolerance in patching compliance and what are the requirements around understanding the gap? As trusted advisors to the business, the VIA team is regularly approached, and proactively reaches out, to provide input on the cyber security related policies, procedures and initiatives. In specific cases where there are practical challenges to implement some of the requirements e.g. due to legacy architecture, those are to be tracked as deviations, rather than diluting the policy requirements. Audit also plays a key role in driving consistency in risk tolerance across the organisation. Practically this means that through their audits – VIA drives a culture of compliance with policies and to make sure risk management is focused on the areas that could cause most harm. After all, the objective is to manage risk, not to attempt to eliminate it completely. Similarly, VIA also offers a continuous challenge to the risk acceptance process followed by management by calling any instances out in the audit reports where we do not concur with rationale that has led to the risk acceptance. In summary; through the rigour and quality of audits, specific ways of working, and continuous engagement with the stakeholders, VIA supports the organisational objectives of driving a culture of trust and transparency in the area of cyber risk, throughout the company.
Key lessons learned and advice for other audit teams • Ensure credible expertise, through specialists and by upskilling the full audit team. • Be passionate about data to quantify control gaps and let the facts do the talking. • Be rigorous in calling out any instances of non-compliance with policy or good practice standards, and to what extent they matter.
• Be inquisitive by probing and challenging to understand implications and the root causes, and explain things in ‘plain English’. • Maintain close relationships while building a respected independence - i.e. know when to stand firm - and ensure alignment across all the three Lines.
• Make those connections! There are very few functions within a company that get a company-wide end-to-end view like internal audit, so do not underestimate the value that you can provide if you really connect the collective knowledge audit has. This drives real consciousness within the organisation, as not being sufficiently aware about a potential risk is never a good position to be in.
20
Mind the Gap: Cyber security risk in the new normal
Case study: Head of Audit for Cyber Security and Head of Audit for Payments at a Large UK Financial Services Organisation The audits that their team conduct comment on both cyber security and cyber security culture aspects and in addition to that they also conduct business monitoring through continuous engagement with stakeholders, to keep track on any changes in the business and any resulting cyber risks. This allows the audit team to assess cyber security culture on a continuous basis, supported through reviewing committee packs, and group defined metrics such as training rates and phishing tests. If business monitoring (e.g. metrics review) show a decline, this could result in an audit being added to the plan. When their audit teams assess culture, they assess the findings to identify whether there was the right level of oversight or management importance assigned to that control, which can help support an opinion of whether they are risk focused and have the right culture. Consequently, they are able to flag root causes in the findings such as training, education or supervision and suggest appropriate actions. Their cyber security strategy has a large focus on education and awareness as part of it, such as phishing, other test emails and newsletters, as well as education pieces around the activities of employees. This is not only to encourage better cyber security practices at work but also at home, helping their employees to be better protected. It was expected that if the employees can learn to be cyber savvy at home, for example, by teaching about their children’s privacy and finances, they will also carry that into their working practices. A further goal of the strategy is taking the human out of dangerous interactions through automating some of the controls across the organisation, as well as an ongoing focus on the increased cyber risks associated with insiders. They are focused, as are many firms across financial services, on reducing the risk of an internal/insider compromise, particularly with the move to home or remote working. Their Chief Audit Executive attends the meetings for the board, legal entity board, audit committee and risk committee which allows them to challenge and get the appropriate level of oversight. Similarly,
in preparation for board meetings they are invited to comment on and challenge the papers that get distributed. Their audit function also attends the sub-board meeting dedicated to cyber security and resilience topics, where they present and discuss any related cyber security controls.
COVID-19 response COVID-19 has brought many challenges across the financial services industry with mass remote working, with most employees (including customer call centres) and suppliers moving to working from home. This led to many changes in processes that in turn led to an assessment of these changes on their risks and controls (many of which had to be invoked almost overnight). For example, the audit team looked at configurations of new laptops (in near real time) that colleagues would use at home for customer payments and validated that these had been built to the required standards). The responsibilities and priorities of their audit plan also changed with the pandemic and increased risks. Their audit team coordinated a department-wide approach to COVID-19, thinking about the impact of the pandemic on risks (particularly cyber security) and audit plans, considering how they should be adjusted. This led to the issue of around 30 COVID-19 related audits in this time (many added specifically to cover new or increased COVID-19 risks, others with scope significantly altered to focus on these risks). Further, their audit department supported a number of secondments to key business areas impacted by COVID-19.
21
Mind the Gap: Cyber security risk in the new normal
The organisation also evoked a policy exception forum for cyber security, through which any changes in working practices and controls were managed. However, given that it is likely that remote working will be the norm for an extended period of time, they will have some policy changes to reflect that in the next few months, and will be thinking about how to apply that to the new hybrid control environment, a key area of focus for regulators.
Lessons learnt from cyber security incidents For incident management, as per industry guidelines they have defined playbooks for multiple cyber security scenarios such as data loss events, ransomware attacks and broader business focused scenarios such as Brexit and pandemics. These are reviewed on a regular basis and refreshed with the key learnings of any incidents as well. Each business unit has their incident management representative and regular incident management testing exercises are conducted to simulate the various scenarios such as cyber-attacks, customer data theft and fraud, where they will invite representatives across all business areas to attend the forum meetings and simulate what they would do in the event of an incident. There are also many forums that cyber security experts attend across the broader industry, where they share intelligence with senior level stakeholders across other large financial services organisations/institutions in the UK. There is a culture of collaboration between the large financial institutions, for example if another organisation experiences a cyber-attack (such as a denial-of-service attack) then they will also make others aware.
One of the opportunities for them to learn lessons and demonstrate the effectiveness of their cyber security controls is the Bank of England’s CBEST6 penetration test which gets conducted approximately every two to three years on a randomised basis to see how secure the banks are, based on their controls and systems. The test will try to compromise high value systems (e.g. payment systems) or extract user data depending on the threat that they choose to act upon. CBEST is an end-to-end intelligence-based test which is similar to tests conducted by their own ‘advanced intrusion testing’ team, following industry standard attack testing methods such as the MITRE ATT&CK framework. Collaboration across the financial services industry has improved and there is an increased culture of collaboration and sharing of insights, much of which is publicly available to aid improvements in cyber security. These include recent significant breaches such as Capital One (cloud breach), Bank of Bangladesh (payments fraud) and Travelex (ransomware). These incidents are regularly used to update the incident playbooks to ensure the industry remains at the leading edge of cyber security. In audit they also use the publicly available case studies to validate our test methodologies and assess robustness of lessons learnt exercises. They also have processes in place to share information with suppliers to help strengthen cyber security culture and controls over end-toend processes. To support suppliers, they have a dedicated security team that shares advice, training and intelligence that may help suppliers with their own cyber security practices, particularly useful if they are smaller organisations with fewer resources or subject matter expertise.
Key lessons learned and advice for other audit teams • The audit team actively monitor the business and external events/ incidents to ensure audit learn from these and help target specific risk areas for further review during their audits. • You get a great view of cyber security culture through strong business monitoring. Through attending and contributing to committee meetings you get a real sense of the culture through observing decision making and risk appetite. So, whilst you can’t easily or regularly audit culture as a topic, it’s something you need to think about and conclude on in every audit that you do.
6
• Cyber security is everyone’s responsibility in the organisation so no business unit can simply outsource the risk for a central team to do it.
ability to contain an attack, protecting critical systems (such as payments) from more vulnerable technologies on other areas of the network.
• Good cyber security hygiene • They encourage employees to measures can dramatically reduce the escalate where the business are not risks – the weakest link in the chain is doing the right thing or applying the usually the simplest one and can be right controls (such as not patching undone with the click of a button. cyber security vulnerabilities timely or if they are using outdated • It’s a real challenge to secure legacy technology), because if a team is technology, it can cause a lot of not doing the right thing then the security vulnerabilities where there organisation as a whole is exposed. are old systems in place. If you can Self-identification of risks is a key part fully segregate legacy technology of their governance framework. ahead of decommissioning or upgrading, it really helps with the
CBEST is a framework that delivers intelligence-led penetration tests against the critical systems of financial institutions, developed in partnership with the Bank of England (BoE).
22
Mind the Gap: Cyber security risk in the new normal
Case study: Nicola Brennan, Head of Internal Audit at Northern Ireland Water Northern Ireland Water is a Government Owned Company (GoCo) and is the sole provider of water and sewerage services in Northern Ireland. Network and Information Systems (NIS) regulations came into effect in 2018 that required ‘operators of essential services’ to demonstrate robust cyber security controls over critical national infrastructure, in their case, the water production processes. The operating technology (OT) controlling these production processes had not been traditionally considered in the same way as IT from a cyber security perspective. The challenges were also different, for example, you can’t just stop water production to patch systems, and OT assets are not managed with the IT lifecycle in mind. In preparation for this, the board asked the Head of Internal Audit to facilitate an independent cyber security review. Cyber security specialists were engaged through their cosourcing contract to assess the cyber maturity of that operating technology (OT). This was instrumental in building a business case for significant investment in OT cyber security, with backing from the board. Following this, a cyber security resilience programme was set up, with the Head of Internal Audit, sitting on the programme board in an advisory capacity as well. Overall, around 25% of NI Water’s audit plan is directed to cyber security related assurance audits either at network level, within key business IT applications or within the OT environment. Key areas of focus include the assessment of processes over firewall integrity and monitoring, threat and vulnerability scanning including penetration testing, intrusion detection and whether the security patching regime is operating effectively to prevent successful exploitation of a vulnerability– ensuring an appropriate defence in depth approach. They also look at how access management and data security protection is being controlled, both within and with third parties. Furthermore, from a resilience perspective, they also provide assurance as to whether there is effective incident response capability through disaster
recovery planning processes. More recently with the expansion of IoT and AI/ robotics they are also considering how to ensure providing appropriate assurance over related governance controls. It is recognised that any such initiatives should go through some central IT scrutiny and approval first. This is critical to assess whether the technology has appropriate security and data protection controls considered and designed up front.
Providing assurance on cyber security culture Internal audit assesses how effective supporting policies are and how well they are embedded and understood through training and awareness to ensure that everyone throughout the organisation understands what their responsibilities are in relation to cyber security. On the back of their audit assessments, a key development has been the implementation of regular mandatory e-learning within the business across a range of areas, including cyber security and data protection. Whilst the cyber security team have responsibility for arranging regular phishing campaigns for staff, internal audit then provides assurance over such campaigns. Overall, cyber security is recognised as a key corporate risk, so internal audit regularly reviews associated risk reporting and provides assurance that it reflects and aligns with internal audit findings and agreed improvement actions. They also have a strong follow-up process in place, to ensure that any actions are remediated timely and effectively. Together with the cyber security team, internal audit report to the executive committee and audit and risk committees on a quarterly basis, highlighting progress and any challenges with the cyber resilience
23
Mind the Gap: Cyber security risk in the new normal
programme and key associated audit actions. This support from the very top assists in driving a strong cyber security culture.
Building key relationships and awareness raising When the internal audit team commissioned a piece of work on cyber maturity on the OT environment and brought in cyber specialists via their co-sourcing contract, it provided the executive management team and the board with an independent expert view on the company’s level of cyber security. It also brought the risk of cyber threats to life by providing the executive management and the board with an understanding of how they could materialise through practical examples. In turn, this helped to build the case for significant financial investment in cyber defences. Internal audit, working with IT security, have promoted the need for appropriate cyber and data security clauses within all of their contracts as appropriate. Increasingly, third parties or the extended enterprise are technology dependent in delivering critical services and hence it is just as important there’s assurance over their cyber security.
The Head of Internal Audit has worked closely with business stakeholders and their key third parties to ensure that the ‘right of audit’ is included within contracts as appropriate and they indeed exercise that right, providing assurance over key third parties’ IT security and controls as part of their assurance provision. An example is their customer billing and contact services outsourced contract, which is subject to periodic audit by the internal audit team. Internal audit has been raising awareness and promoting the need for consistent IT governance across the organisation which would also contribute to improving cyber security controls and awareness. In this respect, the internal audit team offer and provide advisory input to new policies and processes as they are being developed. This strengthens relationships and demonstrates the value-add by internal audit, rather than auditing known issues. Finally, as the cyber security second line matures further, internal audit plans to continue to work closely in liaison with the team and identify opportunities to respectively leverage from each-others work.
Key lessons learned and advice for other audit teams One of the main challenges in auditing cyber security is gaining credibility with IT security colleagues. They had overcome this by engaging cyber specialists through a co-sourcing arrangement which ensured that not only were they able to provide a view on the more technical cyber security aspects, but also while they worked alongside the internal audit team they transferred a lot of knowledge to the team. This helped with building credibility and internal audit’s relationship with IT security colleagues. A key lesson learned is that best practice solutions may not always be possible within the organisation due to the existing infrastructure in place that are unable to accommodate the controls required. Therefore, internal audit needs to be able to understand the technical limitations and adapt accordingly. Ultimately, the key is to be able to strike a balance between what is possible to achieve within the organisation and best practice, as the outcome may not be a best practice solution but instead a good risk based compromise.
About the Chartered Institute of Internal Auditors The Chartered Institute of Internal Auditors is the only professional body dedicated exclusively to training, supporting and representing internal auditors in the UK and Ireland. We have 10,000 members in all sectors of the economy. First established in 1948, we obtained our Royal Charter in 2010. About 2,500 members are Chartered Internal Auditors and have earned the designation CMIIA. Over 1,000 of our members hold the position of head of internal audit and the majority of FTSE 100 companies are represented amongst our membership. Members are part of a global network of 200,000 members in 170 countries, all working to the same International Standards and Code of Ethics.
Stay connected
Chartered Institute of Internal Auditors 13 Abbeville Mews 88 Clapham Park Road London SW4 7BX tel 020 7498 0101 email info@iia.org.uk www.iia.org.uk