Skip to Content

The Public Sector’s Cyber Risk Coverage

Articles Logan Wamsley Oct 07, 2026

Integrating cybersecurity into other engagements may explain the gap between its high risk rating and low priority in audit plans.

Public sector audit plans may appear to underemphasize cybersecurity, but cyber risks are often addressed throughout other audit engagements.

The IIA’s 2025 North American Pulse of Internal Audit report uncovered a concerning trend within the public sector. More than 70% of audit leaders in the sector ranked cybersecurity as a high or very high risk, making it by far the highest-rated risk in the survey. Yet only 7% of respondents said they included cybersecurity in their audit plan.

On the surface, this Pulse finding suggests a gap between cybersecurity risk and audit coverage in the public sector, but there may be more to the story. The report raises important questions about how local government audit functions assess cyber risk and incorporate it into their audit plans. 

Context Is Key

While cybersecurity remains one of the most significant risks, increasingly today’s organizations see it as a risk that affects every part of the business. That perspective can help public sector functions shape audit planning, with cyber risks becoming part of every audit.

Stefan Lundborg
KTH Royal Institutes of Technology

“Cybersecurity is a cross-cutting risk area, meaning that it is a relevant factor to consider in most audits, regardless of the specific audit theme,” says Stefan Lundborg, postdoctoral fellow at Sweden’s KTH Royal Institute of Technology and former CAE of Örebro University. “The risk assessment could mirror the general organizational dependence on IT systems, making cybersecurity risks ever-present in the organization while simultaneously not necessarily comprising an independently auditable risk area.”

Governance structures also can influence how public sector audit functions address cyber risk, and some of those structures do not require a standalone assessment by internal audit. “From my perspective, cyber risk is already covered by the chief information security officer (CISO),” says Mahmoud Elbagoury, CAE of Ladun Investment Company, a publicly listed firm in Saudi Arabia. “If there is a CISO in place, it should cover the cybersecurity risk from his point of view, especially in the public sector.” In this case, he says, internal audit’s role is to ensure second-line responsibilities are carried out and to provide the governing body assurance over cybersecurity practices and activities.

Mahmoud Elbagoury
CAE
Ladun Investment Company

For some organizations, this approach is ideal because cybersecurity is highly technical and complex, often requiring skills beyond internal audit’s strengths, Elbagoury says. “In Saudi Arabia, cybersecurity is considered a very unique specialization, and most CAEs in our region come from an accounting or external background,” he notes.

Maximizing Internal Audit’s Value

Still, the Pulse findings raise concerns. When cybersecurity is embedded across multiple audits, rather than a dedicated engagement, coverage can lose focus.

Derek Jamieson
Director of Membership and Service Development
Chartered Institute of Internal Auditors

“Cyber can also be embedded into a number of audits, but what I’d be interested in is how much cyber work is actually done in these audits,” says Derek Jamieson, director of Membership and Service Development at the Chartered Institute of Internal Auditors in the UK and Ireland. For example, he notes that during a 25-day engagement, auditors may only spend two days on cyber risk and may primarily focus on reviewing policy documents, procedures, and evidence, rather than on substantive testing. “Therefore, risk coverage in this space might actually be thin.”

Referring to The IIA’s Cybersecurity Topical Requirement and User Guide can help public-sector audit functions avoid this pitfall. These resources can help auditors assess cyber risk alongside other risks while ensuring cybersecurity is adequately covered across the three lines. As Elbagoury notes, collaboration between internal audit and the CISO is especially important.

In a LinkedIn blog post, “Cybersecurity Topical Requirement or Cybersecurity Internal Audit Standard,” Elbagoury writes, “The Cybersecurity Topical Requirement does not aim to turn the internal auditor into a technical expert, but rather to enable them to provide consistent and reliable professional assurance on how this risk is managed within the organization, based on clear and specific requirements.”

Elbagoury says he has found tremendous value in sharing the Topical Requirement and User Guide with his company’s CISO to prepare to coordinate future assessments. “He said they significantly enriched his point of view regarding cybersecurity, specifically regarding proper governance, risk management, and controls,” he says. “We now have a common language that we can share between ourselves and the client.”

A New Way of Thinking

The Pulse finding about public sector audit functions may point to a new, interconnected way of thinking about cyber risk, rather than a failure to prioritize it. As organizations increasingly view cybersecurity as an enterprisewide risk, internal audit must ensure it still receives sufficient attention. Integrating cyber risk is only effective if there is meaningful coverage.

Logan Wamsley

Logan Wamsley is associate manager, content development at The IIA.