Auditor Insights: Day-to-Day Operations of Internal Audit

by Joseph Kirkpatrick / June 13, 2023

Internal audit provides a level of monitoring which is generally not available when working with a third-party auditor. If you’re going on a long road trip, how likely are you to hop in the car and start driving? You’re not – most people will take the car to the shop for an oil change and overall inspection. If the road trip is the audit engagement, the practice of taking the…

5 Best Practices for Cloud Security

by Sarah Harvey / December 19, 2022

How has the cloud impacted your organization’s security? Has it left you wondering – what consequences could we face if a malicious outsider gained access to our cloud environment? Would our clients stay loyal to us if our database was compromised? What can we do to implement cloud security? Our five best practices for cloud security, especially in Azure and AWS environments, include: Identity and Access Management (IAM) Multi-factor authentication…

Auditor Insights: Vulnerability Assessments vs. Penetration Testing

by Sean Rosado / April 5, 2023

Confusion About Vulnerability Assessments and Penetration Testing In my work as a penetration tester, I work with clients who are attempting to meet security and compliance objectives through penetration tests, vulnerability assessments, and other information security-related exercises. What I’ve seen time and time again is organizations who are confused about the difference between vulnerability assessments and penetration testing. I’m passionate about educating our clients on security exercises and determining what…

Who’s Responsible for Cloud Security?

by Sarah Harvey / December 19, 2022

As more and more organizations migrate to the cloud, it drives cloud service customers to consider how the cloud will impact their privacy, security, and compliance. First, cloud service customers must understand how their cloud service provider delivers a secure solution. Second, cloud service customers must consider their new role in cloud security. Some cloud service customers mistakenly believe that when they migrate to the cloud, their cloud security responsibilities…

Auditor Insights: Compliance from the Start

by Shannon Lane / October 11, 2023

Why Don’t Organizations Start with Compliance? At its core, business is a function of time, vision, service, and money. What do we provide? How do we intend to provide it? What takes precedence - the opportunity now or the infrastructure to support things tomorrow? How do we do what we do in a way that makes sense with the resources we have? I’ve found that compliance tends to be one…