HomeCategory

Cybersecurity and Technology Risk

Why Scans Are Not Penetration Tests: Translating Cybersecurity Severity into Business Risk

Executive Summary Somewhere in the Caribbean this week, an executive will approve a payment for a “penetration test,” receive a hundred-page PDF full of colour-coded severity scores, file it with satisfaction — and remain exactly as exposed as before. What was purchased was almost certainly a vulnerability scan: a legitimate, useful, automated exercise that is...

The IIA Cybersecurity Topical Requirement: What Caribbean Internal Audit Functions Must Do Now

  Executive Summary For the first time in the history of the profession, internal auditors worldwide are subject to a mandatory, subject-specific standard for how cybersecurity must be assessed. The Institute of Internal Auditors issued the Cybersecurity Topical Requirement in February 2025 as the first Topical Requirement under the Global Internal Audit Standards, and it...

Internal Audit Meets Cybersecurity: A New Assurance Model for Caribbean Organisations

Executive Summary The previous article in this series ended with a rule every well-governed board eventually adopts: for each material cyber assertion, the board must be able to answer “how do we know that is true?” Much of the answer flows through one function — internal audit. Yet in most Caribbean organisations, internal audit and...

The Cyber-Accountable Board: What Directors Must Know, Ask and Verify

Executive Summary The first two articles in this series established two propositions: cyber risk is an enterprise risk that belongs on the board agenda, and boards can only govern it with independent evidence — cyber assurance — rather than management’s unverified word. This third article addresses the people on whom both propositions land: the directors...

From Cybersecurity to Cyber Assurance: The Missing Link in Caribbean Risk Management

Executive Summary Ask the leadership of almost any Caribbean organisation whether it takes cybersecurity seriously and the answer will be yes — supported by a list of investments: firewalls, endpoint protection, an IT provider, security policies, perhaps a certification. Then ask a different question: how do you know any of it works? The room usually...

Cybersecurity Is No Longer an IT Issue: Why Caribbean Boards Must Treat It as an Enterprise Risk

Executive Summary For most of the past two decades, cybersecurity in the Caribbean has lived in the IT department: a budget line for firewalls and antivirus software, a technical specialist’s responsibility, a subject the board touched once a year, if at all. That arrangement no longer matches reality. Cyber risk has become one of the...

Does Your SME Need an Internal Audit Function? The Case for Co-Sourcing in the Caribbean

Every week, somewhere in the region, a version of the same conversation happens. A business has grown — from a founder and a bookkeeper to a hundred staff, three locations, a bank facility, and perhaps a minority investor — and someone, often the banker or the external auditor, mentions internal audit. The owner’s response is...

Continuous Auditing and Data Analytics: Moving Beyond the Annual Audit Plan

  The annual audit plan rests on a quiet assumption that no one states aloud: that risk moves at the speed of a planning cycle. Book the inventory audit for March, the payroll review for August, the revenue work for November — and trust that the risks will be waiting patiently when the team arrives....

Auditing the Algorithms: GenAI Governance, ISO/IEC 42001, and the New Audit Universe

Somewhere in your organization, an algorithm is making a decision that used to belong to a person. It may be scoring a loan application, flagging a transaction, screening a job candidate, drafting a customer response, or summarizing a contract for an executive who will act on the summary. Caribbean organizations crossed a threshold over the...

Cybersecurity as an Audit Mandate: The Topical Requirement Caribbean Firms Can’t Ignore

For years, cybersecurity occupied a strange place on Caribbean audit plans: acknowledged as important, deferred as specialist, and scoped down to whatever the function felt qualified to look at — usually access forms and password policies. The Global Internal Audit Standards have ended that accommodation. Cybersecurity is the subject of the first Topical Requirement —...

https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.
https://www.dawgen.global/wp-content/uploads/2023/07/Foo-WLogo.png

Dawgen Global is an integrated multidisciplinary professional service firm in the Caribbean Region. We are integrated as one Regional firm and provide several professional services including: audit,accounting ,tax,IT,Risk, HR,Performance, M&A,corporate recovery and other advisory services

Where to find us?
https://www.dawgen.global/wp-content/uploads/2019/04/img-footer-map.png
Dawgen Social links
Taking seamless key performance indicators offline to maximise the long tail.

© 2023 Copyright Dawgen Global. All rights reserved.

© 2024 Copyright Dawgen Global. All rights reserved.