Guest lectures EY
15 multiple choice + 5 open questions →separate exam
Guessing correction
Lecture 1: Introduction to IT Controls, Cybersecurity &
Responsible AI
1. IT Control framework & what is risk in business
1.1. What is Risk in Business?
RISK IN BUSINESS
Business risk refers to the possibility that events or conditions – internal or external – may occur that negatively
impact an organization’s ability to achieve its objectives, affecting its operations, finances, reputation, or compliance
obligations.
THE RISE OF TECHNOLOGY RISK
Note: Business goals should be aligned with IT goals to make a company successful.
Why does Technology risk matter?
modern businesses rely heavily on digital systems to
operate efficiently, deliver services, and safeguard
critical data.
As this dependency grows, so does the exposure to
various IT-related risks that can significantly disrupt
operations and damage business performance.
Managing risk isn’t just about avoiding failure - it’s about
enabling resilience, trust and long- term competitiveness.
,How does Risk Management come into play?
Risk management is the structured process of identifying, evaluating, and responding to potential threats that could
negatively impact an organization’s goals, operations, or reputation.
→ It’s a critical discipline across all areas of business, but especially important in today’s digital landscape where IT
systems underpin nearly every function. Effective risk management ensures that potential issues are proactively
addressed.
- System downtime-outages: Some companies want to have everything in their own hands and have
their own data center (but in case of e.g. a fire, data might not be recoverable → a lot of time that
should be spend on solving it) => do they have controls in place for in case something goes wrong.
- Unauthorized system exam: Example: companies might give all permissions to everyone to use SAP,
which means everyone can control it and have the possibility to do everything in the system => not
good
- Outdated legacy systems: a lot of companies have old systems that can pose some critical risks
- Vendor or cloud failures:
Don’t assume everything is fine but be critical
What is Risk Appetite?
Risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its strategic
objectives. It reflects the organization’s values, culture, and capacity to manage risk, serving as a guide for
decision-making at all levels. Risk appetite helps balance opportunity and control, ensuring that risk- taking
aligns with the organization’s goals and stakeholder expectations. Most companies accept some risk to grow
faster.
Examples:
- Government: Very low risk appetite because they need to make sure that their information is 100% correct.
- Banks: should have low risk appetite to make sure they can deliver what they promise and avoid major risks
How does an organization’s risk appetite influence its approach to managing IT risks?
An organization’s risk appetite directly influences how it manages IT risks.
- A low risk appetite leads to more investment in security measures, strict compliance and cautious
technology adoption.
- A higher risk appetite may result in more flexible policies, accepting greater risk for the sake of
innovation or cost- efficiency.
- Ultimately, the organization’s risk tolerance shapes decisions on resource allocation, incident
response, and the extent of security controls implemented.
1.2. What is an audit?
DEFINITION
An audit is a systematic, independent examination of records, processes, or systems to assess accuracy, integrity and
compliance.
We identify 3 core types of audit as seen below:
- Financial audit: The financial audit aims at evaluating the accuracy and fairness of an organization’s financial
statements, balance sheets, cash flow, and accounting records.
- IT audit: The IT audit aims to evaluate the controls and risks related to an organization’s information systems
while focusing on data security, access controls, system development, and IT Governance. (e.g. SAP system
or system made by the company itself)
- Operational audit: The Operational audit aims to assess the efficiency and effectiveness of business
operations while focusing on organizational structure, resource utilization and business processes.
,WHY ARE IT AUDITS IMPORTANT?
6 reasons:
- Data security: IT audits help identify vulnerabilities and ensure the
sensitive data is protected from breaches and unauthorized access
- Governance: IT audits support strong governance by ensuring that
IT aligns with organizational goals and accountability is in place
- System reliability: audits assess the performance and stability of
IT systems to ensure consistent business operations
o system should always be running (can be very critical)
- Risk management: they uncover and help mitigate IT-related risks
that could disrupt services or damage reputations
o to make sure to avoid cyberattacks
- Operating efficiency: by identifying inefficiencies and outdated
processes, IT audits support better use of technology and
resources
- regulatory compliance: they verify whether IT systems meet industry standards and legal requirements,
helping organizations avoid penalties.
1.3. Common IT Risks in a Business Environment
3 pillars:
1. Access management and identity risks
2. Change management risks
3. IT operations and data reliability risks
(1)ACCESS MANAGEMENT AND IDENTITY RISKS
What?
Risk refers to the potential for malicious actors or unauthorized individuals to gain access to systems, networks,
and data by exploiting vulnerabilities.
Causes?
- Weak password policies
- Phising and social engineering attacks
- Poor identity and access management
o Improve Identify regulation by linking login or access to ID via e.g. itsme
- Outdated user access
Impact:
- Sensitive data breach
- Financial loss
- Regulatory non-compliance
- Reputational damage
- Operational disruption
(2)CHANGE MANAGEMENT RISKS
What?
This risk involves the potential for disruption, errors, or security vulnerabilities resulting from poorly planned,
tested, or documented changes to IT systems, applications, or infrastructure
→There should be a process that someone needs to approve it if another person wants to perform a certain action
Causes?
- Lack of formal change management
- Inadequate testing before deployment
- Insufficient documentation
- Unauthorized or unapproved changes
- Lack of change impact assessment
, Impact:
- System downtime
- Operational disruption
- Data loss or corruption
- Security vulnerabilities
- Reduced system performance
- Loss of customer trust
- Regulatory non-compliance
(3)IT OPERATIONS AND DATA RELIABILITY RISKS
What?
This risk involves the failure or mismanagement of routine IT Operations such as scheduled jobs, automated
tasks, and data backups.
➢ companies ask themselves: how much data can we lose or would not matter that much if we accidently lost
it?
➢ e.g. financial institutions need to be able to go back in time to check for example your credibility or whether
you have been paying your debt
Causes:
▪ Lack of Monitoring and Alerts.
▪ Misconfigured or Outdated Scripts.
▪ Insufficient Backup frequency or scope.
▪ Reliance on manual job execution or initiation.
▪ No regular testing of the processes in place
Impact:
▪ Data Loss.
▪ Operational Disruption.
▪ Failed Disaster Recovery Planning.
▪ Loss of productivity.
▪ Security Gaps
▪ Regulatory Non – Compliance.
▪ Reputational Damage.
E.g. you’re in the hospital and suddenly the power goes out, you want to make sure the nurse at least knows what to do with
you
15 multiple choice + 5 open questions →separate exam
Guessing correction
Lecture 1: Introduction to IT Controls, Cybersecurity &
Responsible AI
1. IT Control framework & what is risk in business
1.1. What is Risk in Business?
RISK IN BUSINESS
Business risk refers to the possibility that events or conditions – internal or external – may occur that negatively
impact an organization’s ability to achieve its objectives, affecting its operations, finances, reputation, or compliance
obligations.
THE RISE OF TECHNOLOGY RISK
Note: Business goals should be aligned with IT goals to make a company successful.
Why does Technology risk matter?
modern businesses rely heavily on digital systems to
operate efficiently, deliver services, and safeguard
critical data.
As this dependency grows, so does the exposure to
various IT-related risks that can significantly disrupt
operations and damage business performance.
Managing risk isn’t just about avoiding failure - it’s about
enabling resilience, trust and long- term competitiveness.
,How does Risk Management come into play?
Risk management is the structured process of identifying, evaluating, and responding to potential threats that could
negatively impact an organization’s goals, operations, or reputation.
→ It’s a critical discipline across all areas of business, but especially important in today’s digital landscape where IT
systems underpin nearly every function. Effective risk management ensures that potential issues are proactively
addressed.
- System downtime-outages: Some companies want to have everything in their own hands and have
their own data center (but in case of e.g. a fire, data might not be recoverable → a lot of time that
should be spend on solving it) => do they have controls in place for in case something goes wrong.
- Unauthorized system exam: Example: companies might give all permissions to everyone to use SAP,
which means everyone can control it and have the possibility to do everything in the system => not
good
- Outdated legacy systems: a lot of companies have old systems that can pose some critical risks
- Vendor or cloud failures:
Don’t assume everything is fine but be critical
What is Risk Appetite?
Risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its strategic
objectives. It reflects the organization’s values, culture, and capacity to manage risk, serving as a guide for
decision-making at all levels. Risk appetite helps balance opportunity and control, ensuring that risk- taking
aligns with the organization’s goals and stakeholder expectations. Most companies accept some risk to grow
faster.
Examples:
- Government: Very low risk appetite because they need to make sure that their information is 100% correct.
- Banks: should have low risk appetite to make sure they can deliver what they promise and avoid major risks
How does an organization’s risk appetite influence its approach to managing IT risks?
An organization’s risk appetite directly influences how it manages IT risks.
- A low risk appetite leads to more investment in security measures, strict compliance and cautious
technology adoption.
- A higher risk appetite may result in more flexible policies, accepting greater risk for the sake of
innovation or cost- efficiency.
- Ultimately, the organization’s risk tolerance shapes decisions on resource allocation, incident
response, and the extent of security controls implemented.
1.2. What is an audit?
DEFINITION
An audit is a systematic, independent examination of records, processes, or systems to assess accuracy, integrity and
compliance.
We identify 3 core types of audit as seen below:
- Financial audit: The financial audit aims at evaluating the accuracy and fairness of an organization’s financial
statements, balance sheets, cash flow, and accounting records.
- IT audit: The IT audit aims to evaluate the controls and risks related to an organization’s information systems
while focusing on data security, access controls, system development, and IT Governance. (e.g. SAP system
or system made by the company itself)
- Operational audit: The Operational audit aims to assess the efficiency and effectiveness of business
operations while focusing on organizational structure, resource utilization and business processes.
,WHY ARE IT AUDITS IMPORTANT?
6 reasons:
- Data security: IT audits help identify vulnerabilities and ensure the
sensitive data is protected from breaches and unauthorized access
- Governance: IT audits support strong governance by ensuring that
IT aligns with organizational goals and accountability is in place
- System reliability: audits assess the performance and stability of
IT systems to ensure consistent business operations
o system should always be running (can be very critical)
- Risk management: they uncover and help mitigate IT-related risks
that could disrupt services or damage reputations
o to make sure to avoid cyberattacks
- Operating efficiency: by identifying inefficiencies and outdated
processes, IT audits support better use of technology and
resources
- regulatory compliance: they verify whether IT systems meet industry standards and legal requirements,
helping organizations avoid penalties.
1.3. Common IT Risks in a Business Environment
3 pillars:
1. Access management and identity risks
2. Change management risks
3. IT operations and data reliability risks
(1)ACCESS MANAGEMENT AND IDENTITY RISKS
What?
Risk refers to the potential for malicious actors or unauthorized individuals to gain access to systems, networks,
and data by exploiting vulnerabilities.
Causes?
- Weak password policies
- Phising and social engineering attacks
- Poor identity and access management
o Improve Identify regulation by linking login or access to ID via e.g. itsme
- Outdated user access
Impact:
- Sensitive data breach
- Financial loss
- Regulatory non-compliance
- Reputational damage
- Operational disruption
(2)CHANGE MANAGEMENT RISKS
What?
This risk involves the potential for disruption, errors, or security vulnerabilities resulting from poorly planned,
tested, or documented changes to IT systems, applications, or infrastructure
→There should be a process that someone needs to approve it if another person wants to perform a certain action
Causes?
- Lack of formal change management
- Inadequate testing before deployment
- Insufficient documentation
- Unauthorized or unapproved changes
- Lack of change impact assessment
, Impact:
- System downtime
- Operational disruption
- Data loss or corruption
- Security vulnerabilities
- Reduced system performance
- Loss of customer trust
- Regulatory non-compliance
(3)IT OPERATIONS AND DATA RELIABILITY RISKS
What?
This risk involves the failure or mismanagement of routine IT Operations such as scheduled jobs, automated
tasks, and data backups.
➢ companies ask themselves: how much data can we lose or would not matter that much if we accidently lost
it?
➢ e.g. financial institutions need to be able to go back in time to check for example your credibility or whether
you have been paying your debt
Causes:
▪ Lack of Monitoring and Alerts.
▪ Misconfigured or Outdated Scripts.
▪ Insufficient Backup frequency or scope.
▪ Reliance on manual job execution or initiation.
▪ No regular testing of the processes in place
Impact:
▪ Data Loss.
▪ Operational Disruption.
▪ Failed Disaster Recovery Planning.
▪ Loss of productivity.
▪ Security Gaps
▪ Regulatory Non – Compliance.
▪ Reputational Damage.
E.g. you’re in the hospital and suddenly the power goes out, you want to make sure the nurse at least knows what to do with
you