insight-ingle-left-2
insight-ingle-left-3

September 30, 2026

Why Cybersecurity Belongs in Internal Audit’s Annual Plan

When a regulator or external auditor examines an insurance company’s cybersecurity program, written policies are only the beginning of what they are likely to dive into. They may also expect evidence that key controls are working as intended. That is where Internal Audit has a role distinct from IT. While IT may manage many cyber controls day to day, Internal Audit can independently assess whether those controls are designed appropriately, operating effectively, and supported by evidence.

Putting cybersecurity on the annual Internal Audit plan gives insurers the opportunity to identify gaps before an outside review does. It also gives management and the audit committee a better view of where cyber risk may require attention, including areas that could affect financial exposure or business operations.

The case for including cyber in annual planning is getting stronger. Requirements such as New York’s 23 NYCRR Part 500, state privacy laws, and the Institute of Internal Auditors’ Cybersecurity Topical Requirement are giving Internal Audit leaders more reason to include cyber in annual planning. The IIA requirement is mandatory when Internal Audit provides assurance services on cybersecurity and establishes a baseline for assessing governance, risk management, and control processes.

For insurers, the question is no longer simply whether a policy exists, or a process owner says a control is being performed. Internal Audit needs to determine whether the control is working and give cybersecurity the same rigor as other significant areas of organizational risk.

Regulatory expectations raise questions Internal Audit should answer first

New York’s 23 NYCRR Part 500 is a good example. Each year, covered entities must either certify that they materially complied with applicable cybersecurity requirements during the prior calendar year or acknowledge areas of material noncompliance and report on remediation. That determination must be supported by sufficient data and documentation, such as risk assessments, testing results, and records of remediation efforts. Larger organizations that qualify as “Class A companies” under NYDFS size and revenue thresholds face additional requirements, including independent audits of their cybersecurity programs.

California has also added cybersecurity audit requirements under the California Consumer Privacy Act (CCPA). Beginning in 2026, certain businesses must now prepare for annual cybersecurity audits, with reporting deadlines phased in starting in 2028. The rules also address when insurance companies are subject to the CCPA.

For Internal Audit leaders, these requirements raise a question during annual planning: If the organization must demonstrate that a cybersecurity requirement has been implemented, what evidence has Internal Audit examined to support that conclusion?

A readiness assessment can help answer it before a regulatory or external review begins. It gives the organization time to examine controls in depth, identify gaps, and address findings before an outside reviewer does.

The benefit extends beyond compliance. Findings can inform remediation priorities, resource decisions, and the organization’s understanding of operational and financial exposure.

Inquiry starts the audit, and operating-effectiveness testing takes it further

Interviews, walkthroughs, and policy reviews all belong in a cybersecurity audit. They establish how a process is designed, who owns it, and what the organization says should occur.

The next question is whether the control operated as intended.

Consider a policy stating that critical vulnerabilities are patched within 30 days. Reviewing the policy confirms that a requirement exists. Speaking with the process owner can explain how the organization intends to meet it. Technical testing can then determine whether critical vulnerabilities remain active beyond that stated timeframe.

The same blind spot can arise when Internal Audit relies heavily on an IT self-assessment without independently examining the evidence behind it. A self-assessment may provide useful information about the program, but Internal Audit still needs an appropriate level of testing before drawing an assurance conclusion.

A well-scoped cybersecurity engagement should be able to determine:

  • Whether the control addresses the identified risk and applicable requirement. 
  • Whether the organization can produce evidence that the control was performed. 
  • Whether testing supports the conclusion that the control operated effectively during the period under review. 

That depth matters because regulators and external auditors may examine the evidence behind the process. If an Internal Audit engagement stops after inquiry and documentation review, a later technical examination may reach a different conclusion.

The goal is to test at a depth appropriate to the risk and the outside scrutiny the organization may face. Doing so gives management time to respond while findings are still internal.

Specialized cybersecurity expertise can strengthen Internal Audit testing

Many Internal Audit professionals come from accounting, finance, operations, or other business disciplines. Cybersecurity engagements may require specialized knowledge of vulnerability management, access controls, system configuration, logging, and other technical processes. That gap between Internal Audit’s traditional skill set and the technical demands of cybersecurity testing can influence whether a cyber engagement makes it onto the annual plan at all, as well as how far the testing goes once the work begins.

If the Internal Audit team does not have the cybersecurity expertise, staff capacity, or time required for that work, it can bring in outside specialists to perform the technical portions of the engagement while the Internal Audit function retains oversight. This is often referred to as co-sourcing. For example, Johnson Lambert can work alongside an insurer’s Internal Audit team to conduct walkthroughs, coordinate with control owners, define the audit scope, perform technical testing, and document the results.

Identifying those resource needs during annual planning gives Chief Audit Executives a stronger basis for discussing support with the audit committee. The conversation can start with the cyber risks and requirements the audit plan needs to cover, then consider whether the Internal Audit team has the skills and capacity to examine them effectively.

Cybersecurity audits can support both regulatory readiness and broader priorities

What prompts an insurer to include cybersecurity in its annual audit plan can vary. Johnson Lambert has worked with insurers preparing for a specific regulatory requirement as well as organizations seeking a broader view of how their cyber program was performing.

In one case, an insurer facing upcoming NYDFS requirements needed to validate whether its cybersecurity controls were operating effectively before executive leadership submitted its annual compliance certification. Working under the company’s Internal Audit function, Johnson Lambert conducted a co-sourced engagement that included defining the audit scope, leading walkthroughs with control owners, and testing operating effectiveness against applicable NYDFS requirements. The audit gave management a stronger basis for its compliance statements and time to address identified gaps before an external examination.

For another insurer, the goal was to evaluate its cybersecurity posture against the CIS Critical Security Controls and identify gaps across the organization. Johnson Lambert performed the assessment and delivered findings, recommendations, and a roadmap that gave Internal Audit, the CIO, IT leadership, and business stakeholders a shared view of program performance. The assessment highlighted areas where controls were working well and identified technical weaknesses that required attention, giving the organization a structured plan for prioritizing remediation efforts.

In both cases, Internal Audit had an opportunity to examine cyber risk before an external review or another business need dictated the timing. That early attention allows Internal Audit to examine the areas most relevant to the organization, whether the immediate need is regulatory readiness or a stronger understanding of the cyber program.

Put cybersecurity on the plan before an outside reviewer sets the agenda

For Internal Audit leaders, the annual planning process is the time to decide whether cybersecurity is receiving enough attention and whether the planned scope goes deep enough to test operating effectiveness. Waiting until an external review begins leaves less time to identify and address gaps.

Johnson Lambert works with insurance Internal Audit teams on co-sourced cybersecurity engagements, including regulatory readiness work and assessments against recognized control frameworks. We can help shape the cyber portion of the annual audit roadmap around applicable requirements and model standards, provide the technical skills needed for testing, and prepare your organization for the level of examination regulators and external auditors may bring.

As you develop or revisit your annual Internal Audit plan, consider one question: If a regulator or external auditor tested our cybersecurity controls in depth today, what would Internal Audit already know?

If you are evaluating where cybersecurity belongs in your internal audit plan or whether your current testing goes far enough, contact Johnson Lambert to discuss your organization’s needs and upcoming priorities.

Frequently Asked Questions About Cybersecurity in Internal Audit

  • Why should cybersecurity be included in an insurer’s annual Internal Audit plan? Including cybersecurity in the annual Internal Audit plan gives the organization an independent view of whether key cyber controls are designed appropriately and operating as intended. It can also help identify gaps before a regulator or external auditor reviews the program. 
  • What is Internal Audit’s role in cybersecurity? IT may manage cybersecurity controls day to day, while Internal Audit independently evaluates whether those controls address the relevant risks, operate effectively, and are supported by evidence. This gives management and the audit committee another view of the organization’s cyber risk.
  • What evidence should Internal Audit review when evaluating cybersecurity controls? Evidence may include risk assessments, testing results, remediation records, control documentation, and other materials that demonstrate whether a control was performed and operated as intended. 
  • Why is inquiry alone not enough when reviewing cybersecurity controls? Interviews, walkthroughs, and policy reviews explain how a control is supposed to work. Testing is needed to determine whether it operated as described. For example, a policy may require critical vulnerabilities to be patched within 30 days, while technical testing may find vulnerabilities that remain active beyond that timeframe. 
  • What does operating effectiveness mean in a cybersecurity review? Operating effectiveness refers to whether a control worked as intended during the period being examined. Internal Audit should be able to determine whether the control addressed the identified risk, was performed as required, and is supported by evidence. 
  • How can Internal Audit prepare for NYDFS cybersecurity requirements? Internal Audit can include cybersecurity work in the annual plan before a regulatory review occurs. For insurers subject to 23 NYCRR Part 500, that may include examining the evidence supporting compliance statements and testing relevant controls before required filings or independent reviews. 
  • What is co-sourcing in Internal Audit? Co-sourcing allows an Internal Audit function to bring in outside specialists while retaining oversight of the engagement. For cybersecurity work, those specialists may support walkthroughs, scope development, technical testing, coordination with control owners, and documentation. 
  • When should an Internal Audit team consider outside cybersecurity specialists? Outside support may make sense when the team does not have the cybersecurity expertise, staff capacity, or time needed for the planned work. Identifying those needs during annual planning can help the Chief Audit Executive determine what resources are required to examine cyber risks effectively.
Kim Mobley

Kim Mobley

Partner

Duncan Phillips

Duncan Phillips

Manager

Are you evaluating where cybersecurity belongs in your internal audit plan?

Contact Johnson Lambert to discuss your organization’s needs and upcoming priorities.

Contact Us

Why Cybersecurity Belongs in Internal Audit’s Annual Plan

When a regulator or external auditor examines an insurance company’s cybersecurity program, written policies are only the beginning of what they are likely to dive into. They may also expect evidence that key controls are working as intended. That is where Internal Audit has a role distinct from IT. While IT may manage many cyber controls day to day, Internal Audit can independently assess whether those controls are designed appropriately, operating effectively, and supported by evidence.

Putting cybersecurity on the annual Internal Audit plan gives insurers the opportunity to identify gaps before an outside review does. It also gives management and the audit committee a better view of where cyber risk may require attention, including areas that could affect financial exposure or business operations.

The case for including cyber in annual planning is getting stronger. Requirements such as New York’s 23 NYCRR Part 500, state privacy laws, and the Institute of Internal Auditors’ Cybersecurity Topical Requirement are giving Internal Audit leaders more reason to include cyber in annual planning. The IIA requirement is mandatory when Internal Audit provides assurance services on cybersecurity and establishes a baseline for assessing governance, risk management, and control processes.

For insurers, the question is no longer simply whether a policy exists, or a process owner says a control is being performed. Internal Audit needs to determine whether the control is working and give cybersecurity the same rigor as other significant areas of organizational risk.

Regulatory expectations raise questions Internal Audit should answer first

New York’s 23 NYCRR Part 500 is a good example. Each year, covered entities must either certify that they materially complied with applicable cybersecurity requirements during the prior calendar year or acknowledge areas of material noncompliance and report on remediation. That determination must be supported by sufficient data and documentation, such as risk assessments, testing results, and records of remediation efforts. Larger organizations that qualify as “Class A companies” under NYDFS size and revenue thresholds face additional requirements, including independent audits of their cybersecurity programs.

California has also added cybersecurity audit requirements under the California Consumer Privacy Act (CCPA). Beginning in 2026, certain businesses must now prepare for annual cybersecurity audits, with reporting deadlines phased in starting in 2028. The rules also address when insurance companies are subject to the CCPA.

For Internal Audit leaders, these requirements raise a question during annual planning: If the organization must demonstrate that a cybersecurity requirement has been implemented, what evidence has Internal Audit examined to support that conclusion?

A readiness assessment can help answer it before a regulatory or external review begins. It gives the organization time to examine controls in depth, identify gaps, and address findings before an outside reviewer does.

The benefit extends beyond compliance. Findings can inform remediation priorities, resource decisions, and the organization’s understanding of operational and financial exposure.

Inquiry starts the audit, and operating-effectiveness testing takes it further

Interviews, walkthroughs, and policy reviews all belong in a cybersecurity audit. They establish how a process is designed, who owns it, and what the organization says should occur.

The next question is whether the control operated as intended.

Consider a policy stating that critical vulnerabilities are patched within 30 days. Reviewing the policy confirms that a requirement exists. Speaking with the process owner can explain how the organization intends to meet it. Technical testing can then determine whether critical vulnerabilities remain active beyond that stated timeframe.

The same blind spot can arise when Internal Audit relies heavily on an IT self-assessment without independently examining the evidence behind it. A self-assessment may provide useful information about the program, but Internal Audit still needs an appropriate level of testing before drawing an assurance conclusion.

A well-scoped cybersecurity engagement should be able to determine:

  • Whether the control addresses the identified risk and applicable requirement. 
  • Whether the organization can produce evidence that the control was performed. 
  • Whether testing supports the conclusion that the control operated effectively during the period under review. 

That depth matters because regulators and external auditors may examine the evidence behind the process. If an Internal Audit engagement stops after inquiry and documentation review, a later technical examination may reach a different conclusion.

The goal is to test at a depth appropriate to the risk and the outside scrutiny the organization may face. Doing so gives management time to respond while findings are still internal.

Specialized cybersecurity expertise can strengthen Internal Audit testing

Many Internal Audit professionals come from accounting, finance, operations, or other business disciplines. Cybersecurity engagements may require specialized knowledge of vulnerability management, access controls, system configuration, logging, and other technical processes. That gap between Internal Audit’s traditional skill set and the technical demands of cybersecurity testing can influence whether a cyber engagement makes it onto the annual plan at all, as well as how far the testing goes once the work begins.

If the Internal Audit team does not have the cybersecurity expertise, staff capacity, or time required for that work, it can bring in outside specialists to perform the technical portions of the engagement while the Internal Audit function retains oversight. This is often referred to as co-sourcing. For example, Johnson Lambert can work alongside an insurer’s Internal Audit team to conduct walkthroughs, coordinate with control owners, define the audit scope, perform technical testing, and document the results.

Identifying those resource needs during annual planning gives Chief Audit Executives a stronger basis for discussing support with the audit committee. The conversation can start with the cyber risks and requirements the audit plan needs to cover, then consider whether the Internal Audit team has the skills and capacity to examine them effectively.

Cybersecurity audits can support both regulatory readiness and broader priorities

What prompts an insurer to include cybersecurity in its annual audit plan can vary. Johnson Lambert has worked with insurers preparing for a specific regulatory requirement as well as organizations seeking a broader view of how their cyber program was performing.

In one case, an insurer facing upcoming NYDFS requirements needed to validate whether its cybersecurity controls were operating effectively before executive leadership submitted its annual compliance certification. Working under the company’s Internal Audit function, Johnson Lambert conducted a co-sourced engagement that included defining the audit scope, leading walkthroughs with control owners, and testing operating effectiveness against applicable NYDFS requirements. The audit gave management a stronger basis for its compliance statements and time to address identified gaps before an external examination.

For another insurer, the goal was to evaluate its cybersecurity posture against the CIS Critical Security Controls and identify gaps across the organization. Johnson Lambert performed the assessment and delivered findings, recommendations, and a roadmap that gave Internal Audit, the CIO, IT leadership, and business stakeholders a shared view of program performance. The assessment highlighted areas where controls were working well and identified technical weaknesses that required attention, giving the organization a structured plan for prioritizing remediation efforts.

In both cases, Internal Audit had an opportunity to examine cyber risk before an external review or another business need dictated the timing. That early attention allows Internal Audit to examine the areas most relevant to the organization, whether the immediate need is regulatory readiness or a stronger understanding of the cyber program.

Put cybersecurity on the plan before an outside reviewer sets the agenda

For Internal Audit leaders, the annual planning process is the time to decide whether cybersecurity is receiving enough attention and whether the planned scope goes deep enough to test operating effectiveness. Waiting until an external review begins leaves less time to identify and address gaps.

Johnson Lambert works with insurance Internal Audit teams on co-sourced cybersecurity engagements, including regulatory readiness work and assessments against recognized control frameworks. We can help shape the cyber portion of the annual audit roadmap around applicable requirements and model standards, provide the technical skills needed for testing, and prepare your organization for the level of examination regulators and external auditors may bring.

As you develop or revisit your annual Internal Audit plan, consider one question: If a regulator or external auditor tested our cybersecurity controls in depth today, what would Internal Audit already know?

If you are evaluating where cybersecurity belongs in your internal audit plan or whether your current testing goes far enough, contact Johnson Lambert to discuss your organization’s needs and upcoming priorities.

Frequently Asked Questions About Cybersecurity in Internal Audit

  • Why should cybersecurity be included in an insurer’s annual Internal Audit plan? Including cybersecurity in the annual Internal Audit plan gives the organization an independent view of whether key cyber controls are designed appropriately and operating as intended. It can also help identify gaps before a regulator or external auditor reviews the program. 
  • What is Internal Audit’s role in cybersecurity? IT may manage cybersecurity controls day to day, while Internal Audit independently evaluates whether those controls address the relevant risks, operate effectively, and are supported by evidence. This gives management and the audit committee another view of the organization’s cyber risk.
  • What evidence should Internal Audit review when evaluating cybersecurity controls? Evidence may include risk assessments, testing results, remediation records, control documentation, and other materials that demonstrate whether a control was performed and operated as intended. 
  • Why is inquiry alone not enough when reviewing cybersecurity controls? Interviews, walkthroughs, and policy reviews explain how a control is supposed to work. Testing is needed to determine whether it operated as described. For example, a policy may require critical vulnerabilities to be patched within 30 days, while technical testing may find vulnerabilities that remain active beyond that timeframe. 
  • What does operating effectiveness mean in a cybersecurity review? Operating effectiveness refers to whether a control worked as intended during the period being examined. Internal Audit should be able to determine whether the control addressed the identified risk, was performed as required, and is supported by evidence. 
  • How can Internal Audit prepare for NYDFS cybersecurity requirements? Internal Audit can include cybersecurity work in the annual plan before a regulatory review occurs. For insurers subject to 23 NYCRR Part 500, that may include examining the evidence supporting compliance statements and testing relevant controls before required filings or independent reviews. 
  • What is co-sourcing in Internal Audit? Co-sourcing allows an Internal Audit function to bring in outside specialists while retaining oversight of the engagement. For cybersecurity work, those specialists may support walkthroughs, scope development, technical testing, coordination with control owners, and documentation. 
  • When should an Internal Audit team consider outside cybersecurity specialists? Outside support may make sense when the team does not have the cybersecurity expertise, staff capacity, or time needed for the planned work. Identifying those needs during annual planning can help the Chief Audit Executive determine what resources are required to examine cyber risks effectively.
Kim Mobley

Kim Mobley

Partner

Duncan Phillips

Duncan Phillips

Manager