Cyber Security: Why Accountants Need to be Vigilant
The term \"security\" simply means to protect individuals, assets, and organizations from various threats. It is the state of being free from vulnerabilities, threats, and dangers in a general sense. Safeguarding the assets from potential threats is one of the primary duties of the management, and as an auditor (or an accounting professional), it is our responsibility to ensure and provide assurance to the stakeholders that an organization\'s assets of all kinds are well-protected from all possible threats. Further, an accountant provides a signature on the audit report and various other assurance documents which provide reasonable assurance to the stakeholders that an independent party has ensured the organization\'s interests are well protected. Now, we can only imagine the level of responsibility that the stakeholders have put on the shoulders of an accountant. It is, hence, the professional duty of an accountant to honour this responsibility and provide a reasonable assurance.
A few decades ago, it was relatively easier to identify threats and put adequate control measures against them. Threats were mostly physical and visible to accountants as well, and it was relatively easier to measure the controls put in place while executing professional duty. However, with the advent of the personal computer and the internet, the definition of vulnerability and threat has transformed significantly. At present, existing physical threats and vulnerabilities persist, and the volume of vulnerabilities that are present in cyberspace is increasing manifold, and it is going to be an increasing trend further.
Cyberthreats and Cybersecurity
The Canadian Center for Cyber Security, 2022, defines \'cyberthreats\' as \"any activities that are intended to compromise the security of an information system by altering the confidentiality, integrity, and availability (CIA) of a system or information contained therein or disrupting digital life in general.\" Any activity intended to gain illegal access to an information system with malicious intent can be understood as a cyberthreat. When the threats materialize, it is known as a cyberattack. Actors (hackers, systems, malicious codes, etc.) who try to gain illicit access to an information system or a part of it for malicious activities with the intention to cause harm to the system are known as cyberthreats. Whereas \'cybersecurity\' is the practice of combating multifaceted problems (cyberthreats) in an information system with the intention to prevent cyberthreats from materializing their illicit activities and protecting the CIA of an information system (Syed, Khaver, & Yasin, 2019). Similarly, the International Standardization Organization (ISO) defines the term \'cybersecurity\' as \"the preservation of the CIA of the information or data in cyberspace (connection of people, software, services, and devices on the internet using any network).\" We can understand cybersecurity as the protection of data in the network space, be it internet or intranet or any other type of network, used to connect multiple devices and systems for communicating with each other.
Present Status of Cyberthreats and Cybersecurity Around the World
The total monetary value of damages incurred by cybercrime around the world is going to be around $10.5 trillion by 2025. The loss and the cost of detecting and escalating a cyber incident are around $1.3 million and $1.58 million respectively. Thousands of cyber incidents related to identity theft, phishing, ransomware, DDoS, etc., occur around the world on a regular basis, and there are various incidents of breach of personal information and data every year (John & Swanston, 2024). Some of these attacks are on the company and some on an individual level, and these attacks are mostly intended for the purpose of soliciting an amount of money from the victim or through any other medium by using the information gathered during the incident.
The number of workforces in the cybersecurity domain are in an increasing trend; however, there is still a shortage of highly skilled professionals in this domain. Furthermore, organizations have also started to set aside a budget for cybersecurity, and it is expected that this trend will follow in the coming years (National University, 2024). One might wonder why accountants even need to bother in this domain which doesn\'t seem to be in connection with the accounting profession. The fact is that there is a huge technological skills gap among accountants and this poses a risk to the accounting profession altogether (INAA Group, 2022). When accountants with gaps in skill sets perform their duty and if a significant or material aspect of the business is overlooked, it poses a serious threat to the business as well as the accountant.
Importance of Security for an Accountant
There are five fundamental principles of ethics for professional accountants viz. integrity, objectivity, professional competence and due care, confidentiality, and professional behavior (The ICAI, 2019). Each of these principles is expected to be followed by every professional accountant while discharging their duties and responsibilities. If an accountant doesn\'t understand the security perspective of an organization, there is a high risk that the accountant might perform the duty without being professional. Concepts like going concern, materiality, professional biases, auditor\'s opinion, and reasonable assurance must all be tested during an engagement. Security here means the safeguarding of the assets of a company and protecting the human lives that the business of a company affects. Lapses in security can pose serious threats to fundamental accounting principles, increasing the high risk of accountants becoming biased, issuing an inappropriate opinion, or providing false assurance to the clients.
Since the last decade of the 20th century, humankind started using internet and personal computers, which quickly gained widespread use and popularity. Thanks to companies like Microsoft, Apple, IBM, and many other pioneering innovators that made this possible. The world today would be much more different if the growth of information technology had been much slower than we experienced in the last few decades. While this may seem like a change that doesn\'t significantly impact the accounting profession; however, the concept of security has evolved. Earlier security would mean physical security of physical assets; however, in the present time, physical assets need to be protected along with logical assets, and cybersecurity. This is the reason why an accountant needs to understand the concept of cybersecurity and its impact on professional engagements.
Tools for Accountants to Gauge the Cyberthreats and Assess Cybersecurity
So far, we\'ve established that an accountant needs to understand the aspects of cyberthreats and cybersecurity during an engagement. Now, let\'s discuss in brief some of the tools and reference materials that will help in this process. An accountant is never expected to become a cybersecurity expert or a technology wizard, but they are expected to understand the basics and have adequate knowledge so they can seek assistance, if needed, from an expert and understand the expert\'s results or solutions. Some of the tools or techniques for an accountant are:
- A decade earlier, DISA or ISA was considered an added advantage and mandatory for conducting bank audits. However, the time has changed, and every accountant can leverage professional engagement and add value to the clients or service by taking this course. This is the first stepping stone towards understanding the various facets of an information system, cyberthreats, cybersecurity, etc.
- Having a basic understanding of various cybersecurity frameworks and best practices to test whether such practices are being applied at the client\'s business. However, the level of knowledge depends upon the nature of the business of the client. However, if we set aside clients engaged in the technology sector, a basic understanding would suffice for obtaining reasonable assurance. Frameworks like NIST Cyber Security Framework, ISO 27001, COBIT, CIS, etc. help an accountant to understand cybersecurity and its various aspects (Rayers, 2024).
- Understanding the concept of a Business Continuity Plan and Disaster Recovery Plan and educating the clients about this as well as helping the clients to formulate the plan for them is another tool for accountants to ensure that cyberthreats are reasonably taken care of by the client (Anders, 2019).
- Regular updates of ERPs and accounting software, transition into cloud computing, implementation of strict data encryption protocols and testing such protocols, reviewing security policy of the client, etc. are other techniques or tools that help accountants to estimate reasonably cyberthreats and cybersecurity measures (Juern, 2024).
- Being updated with the best practices and latest updates from the cyberworld is another way of being up to date with the latest information and insights.
- Teaming up with cybersecurity professionals to increase reasonable assurance during engagements.
- Small firms might not be able to invest heavily in cybersecurity-related matters. Hence, these firms may team up and come up with a better solution combined to protect themselves.
- Learning to use AI/ML tools that are useful in engagements; however, AI is a double-edged sword for accountants. While it provides new frontiers to deal with large volumes of data, analyzing patterns, etc., it may also attract newer threats at the same time. A solid understanding of AI is required for an accountant to be effective.
The goal is to assess the assertions that might have a significant impact on the auditor\'s professional work and opinion, such as going concern or materiality. An accountant must stay aware of the latest information and tools to help during the engagement.
Way Forward for the Accountants
New threats emerge every day which directly or indirectly affect the accounting world and accountants. Accountants at the present time are bombarded with lots of unprecedented threats, putting a lot of pressure on them to learn to deal with such challenges. Leading the practice is not an option; however, accountants need to be smart and find a way around this situation. In cyber security proactiveness matters, it is the duty of the client as well as an accountant to take proactive actions to ensure cybersecurity and disclose them in the annual reports (Haapamäki & Sihvonen, 2019). Accounting world has networks and connections with every other world, and it has become imperative that a combined effort through regular communication and discussion between the clients, cybersecurity professionals, and accountants is necessary to protect valuable assets and information against any cyberthreats (Lehenchuk, Vygivska, & Hryhorevska, 2022).
IFAC suggests that accountants upskill themselves, understand the relevant processes and technologies, develop awareness of the cyberworld, understand the business nature of their client, and establish multidisciplinary team to perform the engagement to be effective during the present and future times where the cyberthreats will be in the increasing trend, and need for highly motivated and capable accountants will arise (Tsen, 2019). Except for audit and assurance engagements, accountants can leverage their interest in technology and knowledge to uniquely help entities in finding effective and efficient cybersecurity solutions. The accountants can help in risk identification, design of system and adequate controls, testing the operating effectiveness of the cybersecurity controls, cybersecurity reporting to external stakeholders, and providing assurance on cybersecurity-related matters (Eaton, Grenier, & Layman, 2019). There are new opportunities arising for the accounting profession due to the unique training and skillset of accountants to the accounting profession, and accountants leveraging this information and equipped with the necessary skillset and mindset can expand the horizon of the practice as well.
There is no alternative but to remain vigilant, stay updated, learn new skills, collaborate with multidisciplinary teams, and work alongside other professionals to develop new avenues for practice while providing reasonable assurance in current engagements. The time has come for accountants to come out and seek challenges and thrive in the new world. The bottom line for the future is to be open-minded, and constantly seek to learn new information and skills.
Conclusion
Cyber threats are inevitable - the only way to maintain professionalism and perform with reasonable assurance during an engagement is by being proactive and vigilant against such threats. It is essential to ensure that reasonable controls are in place so that these threats do not materialize, or even if they do, their impact is minimized - ensuring that going concern and materiality are not affected. The average cost of cyber incidents has increased by 10% in 2024 and reached USD 4.88 Million, and the average cost savings is USD 2.22 Million for organizations using advanced cyber protection technologies in the prevention of cyber-attacks (IBM, 2024). One of the major root causes for data breaches is human error in the organizations, accounting for around 22% and IT failure accounts for 23%, and it is the responsibility of an accountant to assess the effectiveness of any training or awareness programs implemented by the organization and the effectiveness of IT operations.
There is no way out, either accountants need to adapt or run out of practice areas, since everything is going to be under the radar of information technology and cyber threats will follow pursuit. Accountants need to learn to adapt quickly, as the threats are emerging at a speed hitherto unimaginable and if accountants the watchdog of the society, as the motto of The ICAI suggests - are not well-equipped to perform their duty then there will be a serious risk to the society at large.
In conclusion, this article highlights the cybersecurity perspective and the role of accountants. Further, rigorous studies are necessary to scope the roles of different stakeholders in preventing cyber incidents and protecting the organizations. Similarly, studies on reducing human error and IT failures must be carried out extensively, as nearly 50% of cyber incidents occur due to an organization\'s internal incompetencies. The accounting profession must also assess the impact of such incidents on the reliability and effectiveness of the accounting assignments, and raise stakeholders\' trust alongside.
References:
- Anders, S. B. (2019). Cybersecurity Tools for CPAs. The CPA Journal. Retrieved from https://www.cpajournal.com/2019/09/13/cybersecurity-tools-for-cpas-2/
- Canadian Center for Cyber Security. (2022). An introduction to the cyber threat environment. Ottawa: Communications Security Establishment. Retrieved from Canadian Center for Cyber Security: https://www.cyber.gc.ca/sites/default/files/ncta-2022-intro-e.pdf
- Deloitte, Charife, T., & Mossad, M. (2023). AI in cybersecurity: A double-edged sword. Retrieved from Deloitte: https://www2.deloitte.com/xe/en/pages/about-deloitte/articles/securing-the-future/ai-in-cybersecurity.html
- Eaton, T. V., Grenier, J. H., & Layman, D. (2019). Accounting and Cybersecurity Risk Management. Current Issues in Auditing, 13(2), C1-C9. doi:https://doi.org/10.2308/ciia-52419
- Haapamäki, E., & Sihvonen, J. (2019). Cybersecurity in accounting. Managerial Auditing Journal, 34(7), 808-834. doi:http://dx.doi.org/10.1108/MAJ-09-2018-2004
- IBM. (2024). Cost of a Data Breach Report 2024. IBM. Retrieved from https://www.ibm.com/downloads/cas/1KZ3XE9D
- INAA Group. (2022, May 30). Addressing the So-Called \'Digital Skills Gap\' in Accountancy. Retrieved from Addressing the So-Called \'Digital Skills Gap\' in Accountancy: https://www.inaa.org/addressing-the-so-called-digital-skills-gap-in-accountancy/
- John, M., & Swanston, B. (2024, February 28). Cybersecurity Stats: Facts And Figures You Should Know. Retrieved from Forbes: https://www.forbes.com/advisor/education/it-and-tech/cybersecurity-statistics/#Sources
- Juern, N. (2024, May 25). Cybersecurity Risk Management for Accountants: Essential Strategies, Compliance, and Future Trends. Retrieved from 7tech: https://www.7tech.com/2024/05/25/cybersecurity-risk-management-for-accountants-essential-strategies-compliance-and-future-trends/
- Lehenchuk, S., Vygivska, I., & Hryhorevska, O. (2022). Protection of accounting information in the conditions of cyber security. Problems of Theory and Methodology of Accounting, Control and Analysis, 2(52), 40-46.
- National University. (2024, August 6). 101 Cybersecurity Statistics and Trends for 2024. Retrieved from National University: https://www.nu.edu/blog/cybersecurity-statistics/
- Rayers, J. (2024, May 30). Top 11 cybersecurity frameworks in 2024. Retrieved from Connectwise: https://www.connectwise.com/blog/cybersecurity/11-best-cybersecurity-frameworks
- Syed, R., Khaver, A. A., & Yasin, M. (2019). What is Cybersecurity? Sustainable Development Policy Institute. Retrieved from https://www.jstor.org/stable/resrep29108.5
- The ICAI. (2019). The Fundamental Principles. In T. ICAI, Code of Ethics (p. 4). New Delhi: The ICAI.
- Tsen, S. (2019, May 16). Cybercrime Threatens Trust in Business How Accountants Can Help. Retrieved from IFAC: https://www.ifac.org/knowledge-gateway/discussion/cybercrime-threatens-trust-business-how-accountants-can-help