Every industry has its own nuances. We take that into consideration and approach business solutions with the specific lens required of your field. Our teams are comprised of talent with relevant experience and we’re prepared to meet every challenge.
How a healthcare organization scaled IT leadership through Office of the CIO services
Learn how a healthcare organization strengthened IT governance, cybersecurity, and strategic planning through Office of the CIO services without hiring a full-time CIO.
AI Strategy Starts with People (Part 1)
Lorem ipsum dolor set
Elliott Davis Accelerates Growth with Leadership Promotions and Strategic Talent Expansion
Lorem ipsum dolor set
SEC semiannual reporting proposal: What financial institution leaders need to know
Lorem ipsum dolor set
Most companies don't need a better budget. They need a planning system
Lorem ipsum dolor set
Courage Changes Everything
Lorem ipsum dolor set
Understanding the Cash vs. Tax Carry Mismatch in Private Equity Funds
AI is moving faster than most organizations can keep up, and that uncertainty can create excitement, fear, and resistance.
Elliott Davis Accelerates Growth with Leadership Promotions and Strategic Talent Expansion
Elliott Davis, a top 50 U.S. accounting and advisory firm, is continuing its momentum with a series of leadership promotions and strategic talent investments that reflect the firm’s ongoing evolution and its commitment to meeting customer needs.
SEC semiannual reporting proposal: What financial institution leaders need to know
Learn how the SEC's proposed semiannual reporting framework could affect bank reporting calendars, investor expectations, governance, controls, and compliance.
Most companies don't need a better budget. They need a planning system
Many companies outgrow traditional budgeting before they realize it. Learn how modern FP&A connects forecasting, scenario planning, operational drivers, and strategy.
Courage Changes Everything
Courage doesn't just change how you show up, it changes how the people around you show up, too.
Every industry has its own nuances. We take that into consideration and approach business solutions with the specific lens required of your field. Our teams are comprised of talent with relevant experience and we’re prepared to meet every challenge.
How a healthcare organization scaled IT leadership through Office of the CIO services
Learn how a healthcare organization strengthened IT governance, cybersecurity, and strategic planning through Office of the CIO services without hiring a full-time CIO.
AI Strategy Starts with People (Part 1)
Lorem ipsum dolor set
Elliott Davis Accelerates Growth with Leadership Promotions and Strategic Talent Expansion
Lorem ipsum dolor set
SEC semiannual reporting proposal: What financial institution leaders need to know
Lorem ipsum dolor set
Most companies don't need a better budget. They need a planning system
Lorem ipsum dolor set
Courage Changes Everything
Lorem ipsum dolor set
Understanding the Cash vs. Tax Carry Mismatch in Private Equity Funds
AI is moving faster than most organizations can keep up, and that uncertainty can create excitement, fear, and resistance.
Elliott Davis Accelerates Growth with Leadership Promotions and Strategic Talent Expansion
Elliott Davis, a top 50 U.S. accounting and advisory firm, is continuing its momentum with a series of leadership promotions and strategic talent investments that reflect the firm’s ongoing evolution and its commitment to meeting customer needs.
SEC semiannual reporting proposal: What financial institution leaders need to know
Learn how the SEC's proposed semiannual reporting framework could affect bank reporting calendars, investor expectations, governance, controls, and compliance.
Most companies don't need a better budget. They need a planning system
Many companies outgrow traditional budgeting before they realize it. Learn how modern FP&A connects forecasting, scenario planning, operational drivers, and strategy.
CISA’s Microsoft 365 alert is a wake-up call: Are cloud misconfigurations exposing your organization to risk?
Lorem ipsum dolor set
The One Big Beautiful Bill’s impact on meals and entertainment: What business owners need to know
Lorem ipsum dolor set
Understanding the importance of SOC for blockchain: A comprehensive guide
Lorem ipsum dolor set
The impact of AI on business: A sector-by-sector guide – Article 4
Lorem ipsum dolor set
Helping a private school benchmark compensation for its staff
Lorem ipsum dolor set
Management asked: "What are the biggest threats to the district and are we adequately addressing these threats?"
Context
The school district required an enterprise risk assessment to determine high-risk areas/processes
Based on the risk assessment results, we prioritized the highest risk areas within our audit plan, which included IT general controls and cybersecurity
Conducted an internal audit of IT general controls and cybersecurity processes and identified areas for cybersecurity posture improvements
Our Approach
Risk Assessment
Determined the residual risk ratings for key processes by considering the school district's inherent risks (i.e., types of risks and likelihood of occurrence) and the potential impact to the school districts if these risks materialized, after considering the mitigating internal controls (i.e., control effectiveness)
Based on the residual risk ratings, the internal audit plan was developed for the subsequent three-year period, prioritizing the highest risk areas including cybersecurity
Internal Audit Process
Conducted detailed corroborative interviews of key IT and cybersecurity stakeholders to gain an understanding of the current state of implemented controls and identify potential control gaps
Performed substantive testing and data analysis of key IT general and cybersecurity controls to determine the sufficiency of design and operating effectiveness of implemented controls
Reported on the potential risks and impacts of identified IT and cybersecurity deficiencies, utilizing specific and measurable attributes to best estimate the impacts in an actionable format
Provided recommended corrective action plans to jumpstart the remediation process for the identified vulnerabilities
Customer Impact
Received detailed summary of internal audit results, including recommendations to improve the overall security of the school district
Technology staff able to coordinate immediately with Elliott Davis and respond to critical findings
Utilizing the internal audit results, the school district improved the security controls surrounding its critical computer systems and information resources to mitigate the impacts of internal and external cybersecurity threats
We Can Help
For more information on this and other topics, contact a member of our team.
The information provided in this communication is of a general nature and should not be considered professional advice. You should not act upon the information provided without obtaining specific professional advice. The information above is subject to change.
contact our team
contact our team
contact our team.
relatedinsights
Web application penetration testing: The top three discoveries of 2022
Discover the top three web application vulnerabilities identified in penetration tests: broken access control, security misconfiguration, and insecure design. Learn how these flaws align with OWASP Top Ten risks and why regular web application testing is essential for cybersecurity.
Article
February 7, 2023
Why organizations should implement a GRC management tool
Discover how Governance, Risk, and Compliance (GRC) tools enhance efficiency, security, and visibility in managing IT and business risks. Learn how automated workflows and real-time reporting can streamline compliance and improve organizational resilience.
Article
February 6, 2023
Pass-through entity tax elections
Learn how pass-through entity (PTE) tax elections can help business owners bypass the federal SALT deduction cap. Explore state-specific rules, potential tax savings, and key considerations to determine if this election is right for your business.
Article
February 6, 2023
What is a penetration test and how is automated different than manual?
Understand the differences between automated and manual penetration testing to strengthen your cybersecurity. Learn how expert-led testing mimics real-world cyber threats, uncovers critical vulnerabilities, and enhances your security posture.
Article
January 10, 2023
The Impact of a Single Vulnerability
Learn how vulnerability chaining can turn minor security gaps into full-scale network compromises. Discover real-world penetration testing insights, attack pathways, and how to mitigate risks before cybercriminals strike. Strengthen your security with expert guidance.