While the top three hot spots audit executives must focus on for 2021 all made appearances in last year’s list, they have all been altered by the nature of working in the pandemic:
- IT governance: Abrupt work-from-home mandates have accelerated digital roadmaps, causing many organizations to vault years forward in the space of a few weeks. This move has spurred the rapid adoption of new technologies both on the employee and customer side, presenting new challenges to productivity, consumer preferences and guarding against security vulnerabilities. CAEs need to assess how new technology adoption may be hobbling their IT departments’ plans, with IT support incident requests doubling in early 2020 to support a huge increase in work-from-home employees. Additionally, managing access rights for many more remote workers presents new risks such as “privileged user abuse,” which is expected to climb over the next 12 to 24 months according to a Gartner IT executive survey.
- Data governance: The pandemic means that organizations are expected to collect more sensitive personal information from employees and customers than ever before. Yet, data governance practices are regressing, with fewer dedicated resources to data privacy than in previous years. Organizations face increasingly complex data environments where their data is housed. Growth in software-as-a-service (SaaS) and delays to upgrading legacy systems have created work environments where data is distributed across disparate platforms, software and servers. Such complexities continue to test audit executives, with only 45% expressing high confidence in their ability to manage data governance risk.
- Cyber vulnerabilities: Cyber vulnerabilities are especially acute this year, due to the rapid organizational changes needed to protect employees and serve customers in the midst of a pandemic. Despite increased cybersecurity spending, only 24% of organizations routinely follow cybersecurity best practices, this will result in cyberattacks that are expected to cost organizations $6 trillion annually by 2021. Drivers of this risk include lapses in security controls and increased employee vulnerability to social engineering. More than half of employees are currently using personal devices to do work remotely, while 61% have indicated their employer has not provided tools to secure these devices. Additional security lapses include a lack of attention to employee’s home network security and status of antivirus software.
“The pandemic is forcing many audit and risk executives to address their organization’s deficiencies in the most critical areas,” said Ms. McKnight. “Inadequate data governance and IT security practices will have even steeper consequences in the current environment than pre-pandemic, particularly when considering the types of data many organizations feel compelled to collect as a result of new health and safety measures.”
Gartner creates its annual Audit Plan Hot Spots report by combining input from interviews and surveys from across its global network of client organizations and experts. Gartner clients can read more in Audit Plan Hot Spots report.
Clients interested in Gartner’s research on dynamic risk governance can read Dynamic Risk Governance Is the New Risk Mandate.
Nonclients can find more information and download a summary of the report at 2021 Audit Plan Hot Spots Executive Summary.
About the Gartner Audit Practice
The Gartner Audit practice helps audit directors and their teams build plans that drive results, strengthen department capabilities, and minimize exposure to fraud and risk. Learn more at https://www.gartner.com/en/audit-risk.