Leadership · Insight · Knowledge
Welcome to the Institute of Internal Auditors New Zealand, the professional body for internal auditing
The Institute of Internal Auditors (IIA) and Ernst & Young LLP (EY) release a joint report, "The Risky Six: Key questions to expose gaps in board understanding of organisational cyber resiliency."
Practitioners and researchers from The IIA and EY conducted extensive analysis to determine the root cause of how and why boards get a skewed picture of their organizations' ability to protect themselves from cyber-related risks. The team, which collectively has more than 100 years of experience managing cybersecurity risks within organisations in all industries, identified six key questions that if unanswered likely mean a disconnect exists.
Key data pointing to widespread disconnects from boards - rooted in the team's deep experience in the field, as well as cutting-edge research from The IIA and EY - include the following:
Organisations working toward a collective "yes" for the six questions provide a narrative that is well received by stakeholders inside and outside the organisation. It highlights the due care and diligence underway to battle cyber risk. However, the report also exposes how easily boards can develop false confidence if any of the six questions can't be answered in the affirmative.
Download "The Risky Six" now and learn the six key questions that must be asked to expose gaps in board understanding of organisational cyber resiliency.
The Institute of Internal Auditors (IIA) and Ernst & Young LLP (EY) release a joint report, "The Risky Six: Key questions to expose gaps in board understanding of organisational cyber resiliency."
Practitioners and researchers from The IIA and EY conducted extensive analysis to determine the root cause of how and why boards get a skewed picture of their organizations' ability to protect themselves from cyber-related risks. The team, which collectively has more than 100 years of experience managing cybersecurity risks within organisations in all industries, identified six key questions that if unanswered likely mean a disconnect exists.
Key data pointing to widespread disconnects from boards - rooted in the team's deep experience in the field, as well as cutting-edge research from The IIA and EY - include the following:
Organisations working toward a collective "yes" for the six questions provide a narrative that is well received by stakeholders inside and outside the organisation. It highlights the due care and diligence underway to battle cyber risk. However, the report also exposes how easily boards can develop false confidence if any of the six questions can't be answered in the affirmative.
Download "The Risky Six" now and learn the six key questions that must be asked to expose gaps in board understanding of organisational cyber resiliency.