top of page
Search

Why SOX Compliance Must Include Cybersecurity Risk Assessments

Cybersecurity is no longer only an information technology concern. A cyberattack, unauthorized system change, compromised privileged account or failed backup can directly affect financial reporting, regulatory disclosures and the reliability of internal controls.

For organizations subject to the Sarbanes-Oxley Act, cybersecurity risks must therefore be considered as part of the organization’s system of Internal Control over Financial Reporting.

Corporate Compliance Seminars’ SOX Compliance for Cybersecurity Assessments webinar helps auditors, compliance professionals and information security personnel connect cybersecurity risks with SOX requirements, COSO, IT general controls and financial reporting.


Cybersecurity Can Undermine Financial Reporting

Organizations depend on technology to initiate, authorize, process, record and report financial transactions. When those systems are compromised, financial data may become incomplete, inaccurate or unavailable.


Cybersecurity events can affect:

  • General-ledger and financial-reporting systems;

  • Revenue, purchasing, payroll and inventory applications;

  • Interfaces between financial applications;

  • Access to sensitive accounting information;

  • Management estimates and reporting data;

  • The integrity of automated controls;

  • Regulatory filings and public disclosures; and

  • Management’s ability to certify internal controls.


A cybersecurity assessment performed for SOX purposes must go beyond asking whether the organization has firewalls, antivirus software and written security policies. Auditors must determine whether cybersecurity controls are appropriately designed, implemented and operating effectively.


Connecting SOX, COSO and Cybersecurity

The Sarbanes-Oxley Act does not provide a separate catalog of required cybersecurity controls. However, SOX Sections 302 and 404 require management to address controls supporting reliable financial reporting and disclosure.


The COSO Internal Control—Integrated Framework provides the foundation for evaluating these controls. Cybersecurity risks may affect all five COSO components:

  1. Control Environment: Management’s cybersecurity governance, accountability and ethical expectations.

  2. Risk Assessment: Identification and evaluation of cyber threats that could affect financial reporting.

  3. Control Activities: Logical access, change management, backup, interface, physical-security and application controls.

  4. Information and Communication: Escalation of cybersecurity incidents and communication with management, auditors and the audit committee.

  5. Monitoring Activities: Continuous monitoring, vulnerability management, control testing and remediation.


The central question is not whether a cybersecurity program exists. The question is whether the program protects the systems, applications and data supporting financial reporting.


IT General Controls Remain Essential

Weak IT general controls can undermine otherwise well-designed financial controls. A reconciliation or management review may appear effective, but its value is questionable when the underlying data can be changed by unauthorized users.


SOX cybersecurity assessments should examine areas such as:

  • User-access provisioning and termination;

  • Adds, changes and deletions to system access;

  • Role-based access;

  • User-entitlement reviews;

  • Privileged and administrative accounts;

  • Service accounts;

  • Segregation-of-duties conflicts;

  • Network segmentation;

  • Firewall configuration;

  • Patch management;

  • Vulnerability management;

  • Malware protection;

  • Encryption;

  • Data-loss prevention;

  • Systems development and change management;

  • Financial-application changes;

  • Interface controls;

  • Backup schedules;

  • Backup monitoring; and

  • Restoration testing.


Auditors must also evaluate the evidence supporting these controls. A policy, system screenshot or management representation does not automatically prove that a control operated effectively throughout the audit period.


Cybersecurity Risk Assessments Must Be Relevant to SOX

A broad enterprise cybersecurity assessment may identify hundreds of technical risks. The SOX assessment must determine which risks could materially affect financial reporting, internal-control certifications or required disclosures.


An effective assessment should:

  • Identify financially significant systems and applications;

  • Map business processes to supporting technology;

  • Identify cybersecurity threats affecting financial data;

  • Evaluate inherent risk;

  • identify relevant controls;

  • assess control design;

  • test operating effectiveness;

  • document deficiencies;

  • evaluate compensating controls; and

  • determine whether deficiencies could become significant deficiencies or material weaknesses.


Risk heat maps can help communicate priorities, but assigning colors to risks is not enough. Each rating should be supported by defined criteria, evidence and a clear explanation of potential financial-reporting consequences.


Cybersecurity Incidents May Create Disclosure Obligations

Cybersecurity incidents can also create responsibilities beyond control testing.


Organizations must determine whether an incident is material and whether it requires regulatory or investor disclosure.


The assessment process should consider:

  • Who receives notice of a suspected incident;

  • How materiality is evaluated;

  • Whether financial-reporting systems or data were affected;

  • Whether the incident changed previously issued disclosures;

  • How information is communicated to legal counsel, management and the audit committee;

  • Whether material nonpublic information is adequately protected; and

  • Whether insider-trading restrictions have been communicated and enforced.


Internal auditors and compliance professionals should understand how cybersecurity incident management connects with disclosure controls and procedures.


Who Should Attend?

This four-CPE-credit webinar is designed for professionals responsible for SOX compliance, cybersecurity, internal controls and regulatory reporting, including:

  • Internal auditors;

  • IT auditors;

  • SOX program managers;

  • Compliance officers;

  • Information security professionals;

  • Controllers and accounting managers;

  • External auditors;

  • Risk-management professionals; and

  • Audit committee support personnel.


Participants should have a basic understanding of auditing and information security. No advance preparation is required.


Upcoming Webinar Dates

Corporate Compliance Seminars will present SOX Compliance for Cybersecurity Assessments on:

  • Monday, October 5, 2026

  • Monday, December 7, 2026


The live webinar is scheduled from 10:00 a.m. to 2:30 p.m. Central Time and provides four CPE credits in Auditing and Information Technology.


The registration fee is $280 per participant. Private events can also be scheduled for organizations registering two or more participants.


Build a Defensible SOX Cybersecurity Assessment

SOX cybersecurity compliance cannot be achieved through a checklist assembled once a year. Organizations need a structured process connecting cybersecurity threats, financial-reporting risks, IT controls, testing procedures, audit evidence and remediation.


The most important question is straightforward:

Could a cybersecurity failure prevent, alter, delay or conceal information used in financial reporting?


If the answer is yes, the risk belongs within the SOX assessment.


 
 
 

Recent Posts

See All
What the CIA Taught Me About Audit Tradecraft

I learned the real meaning of tradecraft while designing a training-tracking system for new intelligence officers at the Central Intelligence Agency. The system had to track more than completed course

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page