What Bank Cybersecurity Auditors Are Really Looking For

What Bank Cybersecurity Auditors Are Really Looking For
7:54


Cybersecurity auditors are looking for more than technical problems or opportunities to issue findings. They want to see that a financial institution understands its technology environment, evaluates risk before making decisions, oversees its vendors, and addresses weaknesses before they become regulatory concerns.

That process has become more complicated as banks move critical systems, applications, and sensitive information outside their own networks.

In an episode of the Hero Trust podcast, Ben Mitzelfelt of Integrity Technology Solutions spoke with Ben LeClaire, principal of cybersecurity at Plante Moran, about how cybersecurity auditing has evolved, what banks should consider before purchasing new technology, and how a productive audit relationship can strengthen an institution.

“The environment has changed dramatically. It’s no longer just about what’s inside the bank’s walls. You have to understand where your data is going, who has access to it, and how it’s being protected across multiple vendors.”
— Ben LeClaire

 

Why Have Bank Cybersecurity Audits Become More Complex?

Bank technology environments were once relatively contained.

Core processing systems, servers, email, and other applications were commonly hosted inside the institution’s own environment. Auditors could focus much of their attention on the bank’s internal network, physical infrastructure, access controls, and security practices.

Today, critical systems are increasingly distributed among:

  • Cloud platforms
  • Managed service providers
  • Software-as-a-service applications
  • Core and loan-processing providers
  • Data hosting companies
  • Vendors that rely on their own subcontractors

This means an auditor can no longer evaluate only what happens inside the bank.

Auditors must also understand where information travels, which organizations can access it, how vendors protect it, and whether the bank understands the risks associated with those relationships.

“You might be working with a vendor, but that vendor is working with another provider behind the scenes. That’s where things get complicated—banks don’t always have visibility into those fourth-party relationships.”
— Ben LeClaire

 

What Do Auditors Expect Banks To Know About Their Technology?

One of the most important things a bank can demonstrate is a clear understanding of its own technology environment.

That includes knowing:

Leaders can sometimes struggle to see the full universe of their network, especially as departments purchase new applications and vendors add integrations, APIs, artificial intelligence, and cloud functionality.

A cybersecurity auditor will want to know whether the institution has evaluated these connections and whether its leaders are comfortable with the resulting risk.

The goal is not to prevent the bank from adopting new technology, but to make sure the institution understands what it is adopting before implementation.

 

Why Should Risk Be Evaluated Before Signing A Technology Contract?

New technology is often introduced through a compelling sales presentation. A platform may promise greater efficiency, better customer experiences, automation, stronger reporting, or access to artificial intelligence.

Those benefits may be real. However, evaluating the advantages of a product is only one part of the decision.

Before entering into an agreement, the institution should also understand:

“The biggest risk we see is when organizations fall in love with the solution before they fully understand the risk. Once the contract is signed, your ability to influence controls is significantly reduced.”
— Ben LeClaire

This evaluation should happen before the contract is signed.

 

Who Should Participate in a Bank’s Technology Evaluation?

Technology decisions should not be made by one executive, department, or technical employee working alone.

LeClaire identified three groups that should participate in the evaluation process.

1. Executive Management

Executive leaders provide the strategic context for the decision.

“Leadership has to set the tone. If cybersecurity and risk aren’t part of the decision-making process at the top, it won’t be consistently applied throughout the organization.”
— Ben LeClaire

 

2. Information Technology

The IT team or technology partner should evaluate how the proposed system will fit into the existing environment.

3. Department Leaders and End Users

These users help define the real-world problem the technology is meant to solve.

Bringing these three perspectives together helps the institution evaluate strategic value, technical risk, and operational usefulness before making a commitment.

 

When Should A Bank Involve Its Cybersecurity Auditor?

Banks don’t need to wait until the annual audit to speak with their audit partner.

“We can add a lot of value when we’re brought in early. We’ve seen what works, what doesn’t, and where institutions typically run into trouble.”
— Ben LeClaire

Involving the auditor before a major technology purchase or operational change can provide several benefits, including:

  • Identifying common implementation risks
  • Highlighting vendor management gaps
  • Anticipating regulatory focus areas
  • Strengthening future audit planning

 

Is A Cybersecurity Auditor Working Against the Bank?

The word “auditor” can create apprehension. Employees may expect an auditor to arrive, find faults, issue findings, and leave the institution to correct everything on its own.

A productive internal audit relationship should work differently.

“We’re not there to be the regulator. A good audit function is more like a doctor’s checkup: it’s about identifying issues early so they don’t become bigger problems later.”
— Ben LeClaire

 

What Does A Productive Audit Relationship Look Like?

A strong auditor should take time to understand how the institution actually operates.

That includes:

  • Products and services
  • Customers and markets
  • Technology infrastructure
  • Remote and hybrid workforce
  • Internal and outsourced systems
  • Strategic priorities
  • Current risks and planned initiatives
 

“The best audits happen when we truly understand the institution—not just the systems, but the business behind them.”
— Ben LeClaire

 

What Should Banks Ask A Potential Cybersecurity Audit Partner?

Choosing an auditor should be treated more like a job interview than a one-time purchase.

Key questions include:

  • How do you stay informed about new threats?
  • How do you develop the audit scope?
  • What happens between reviews?
  • How do you support remediation?
  • Who will perform the work?

 

What Are Auditors Ultimately Looking For?

Auditors understand that no institution can eliminate every cybersecurity risk.

What they want to see is a thoughtful and repeatable process for managing that risk.

A bank should be able to demonstrate that it:

  • Understands its technology environment
  • Knows where sensitive information is stored
  • Evaluates vendors and their subcontractors
  • Assesses risk before implementation
  • Involves the right internal stakeholders
  • Maintains appropriate security controls
  • Communicates with its audit and technology partners
  • Addresses identified weaknesses
  • Adapts as threats and technology change

 

Watch The Full Hero Trust Conversation

The discussion between Ben Mitzelfelt and Ben LeClaire explores how bank cybersecurity auditing has changed, why third- and fourth-party risk deserves greater attention, and how institutions can build more productive relationships with their audit partners.

The full podcast with real-world examples and deeper insights will be available soon on our YouTube page. In the meantime, please subscribe to our YouTube channel to be notified when it goes live.

 

Editor’s note: Some quotes have been lightly edited for clarity.

Leave a Reply