Effectiveness of cybersecurity audit

51 Pages Posted: 10 Feb 2021 Last revised: 7 Aug 2021

See all articles by Sergeja Slapničar

Sergeja Slapničar

University of Queensland

Tina Vuko

University of Split - Business and Tourism

Marko Čular

University of Split - Business and Tourism

Matej Drašček

Hranilnica LON d.d.

Date Written: December 3, 2020

Abstract

The aim of this paper is to analyze how effective internal audit of cybersecurity is. We developed a Cybersecurity Audit Index composed of three dimensions (planning, performing and reporting) to address this question. We hypothesize that CSA effectiveness is positively related to cyber risk management maturity and negatively to the probability of a successful cyber attack. We tested our hypotheses in a survey with auditors and Chief Audit Executives from various countries and industries. We found that CSA Index scores significantly vary, with a mean of 58 on a scale from 0 to 100. While planning and performing CSA are strongly and positively correlated, they are less strongly related to reporting about CS risk management effectiveness to the Board of Directors. In line with our hypothesis, the CSA Index is positively associated with CS risk maturity, but contrary to our hypothesis, it is not related to the probability of a cyber attack. This is the first paper that comprehensively measures the effectiveness of cybersecurity audit and its effects on CS risk management.

Keywords: cybersecurity, internal audit, assurance, index, maturity

JEL Classification: M42, M15

Suggested Citation

Slapničar, Sergeja and Vuko, Tina and Čular, Marko and Drašček, Matej, Effectiveness of cybersecurity audit (December 3, 2020). Available at SSRN: https://ssrn.com/abstract=3741877 or http://dx.doi.org/10.2139/ssrn.3741877

Sergeja Slapničar

University of Queensland ( email )

St Lucia
Brisbane, Queensland 4072
Australia

Tina Vuko

University of Split - Business and Tourism

Split
Croatia

Marko Čular (Contact Author)

University of Split - Business and Tourism ( email )

Split
Croatia

Matej Drašček

Hranilnica LON d.d. ( email )

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
430
Abstract Views
1,357
Rank
140,653
PlumX Metrics