Cybersecurity auditors are looking for more than technical problems or opportunities to issue findings. They want to see that a financial institution understands its technology environment, evaluates risk before making decisions, oversees its vendors, and addresses weaknesses before they become regulatory concerns.
That process has become more complicated as banks move critical systems, applications, and sensitive information outside their own networks.
In an episode of the Hero Trust podcast, Ben Mitzelfelt of Integrity Technology Solutions spoke with Ben LeClaire, principal of cybersecurity at Plante Moran, about how cybersecurity auditing has evolved, what banks should consider before purchasing new technology, and how a productive audit relationship can strengthen an institution.
“The environment has changed dramatically. It’s no longer just about what’s inside the bank’s walls. You have to understand where your data is going, who has access to it, and how it’s being protected across multiple vendors.”
— Ben LeClaire
Bank technology environments were once relatively contained.
Core processing systems, servers, email, and other applications were commonly hosted inside the institution’s own environment. Auditors could focus much of their attention on the bank’s internal network, physical infrastructure, access controls, and security practices.
Today, critical systems are increasingly distributed among:
This means an auditor can no longer evaluate only what happens inside the bank.
Auditors must also understand where information travels, which organizations can access it, how vendors protect it, and whether the bank understands the risks associated with those relationships.
“You might be working with a vendor, but that vendor is working with another provider behind the scenes. That’s where things get complicated—banks don’t always have visibility into those fourth-party relationships.”
— Ben LeClaire
One of the most important things a bank can demonstrate is a clear understanding of its own technology environment.
That includes knowing:
Leaders can sometimes struggle to see the full universe of their network, especially as departments purchase new applications and vendors add integrations, APIs, artificial intelligence, and cloud functionality.
A cybersecurity auditor will want to know whether the institution has evaluated these connections and whether its leaders are comfortable with the resulting risk.
The goal is not to prevent the bank from adopting new technology, but to make sure the institution understands what it is adopting before implementation.
New technology is often introduced through a compelling sales presentation. A platform may promise greater efficiency, better customer experiences, automation, stronger reporting, or access to artificial intelligence.
Those benefits may be real. However, evaluating the advantages of a product is only one part of the decision.
Before entering into an agreement, the institution should also understand:
“The biggest risk we see is when organizations fall in love with the solution before they fully understand the risk. Once the contract is signed, your ability to influence controls is significantly reduced.”
— Ben LeClaire
This evaluation should happen before the contract is signed.
Technology decisions should not be made by one executive, department, or technical employee working alone.
LeClaire identified three groups that should participate in the evaluation process.
Executive leaders provide the strategic context for the decision.
“Leadership has to set the tone. If cybersecurity and risk aren’t part of the decision-making process at the top, it won’t be consistently applied throughout the organization.”
— Ben LeClaire
The IT team or technology partner should evaluate how the proposed system will fit into the existing environment.
These users help define the real-world problem the technology is meant to solve.
Bringing these three perspectives together helps the institution evaluate strategic value, technical risk, and operational usefulness before making a commitment.
Banks don’t need to wait until the annual audit to speak with their audit partner.
“We can add a lot of value when we’re brought in early. We’ve seen what works, what doesn’t, and where institutions typically run into trouble.”
— Ben LeClaire
Involving the auditor before a major technology purchase or operational change can provide several benefits, including:
The word “auditor” can create apprehension. Employees may expect an auditor to arrive, find faults, issue findings, and leave the institution to correct everything on its own.
A productive internal audit relationship should work differently.
“We’re not there to be the regulator. A good audit function is more like a doctor’s checkup: it’s about identifying issues early so they don’t become bigger problems later.”
— Ben LeClaire
A strong auditor should take time to understand how the institution actually operates.
That includes:
“The best audits happen when we truly understand the institution—not just the systems, but the business behind them.”
— Ben LeClaire
Choosing an auditor should be treated more like a job interview than a one-time purchase.
Key questions include:
Auditors understand that no institution can eliminate every cybersecurity risk.
What they want to see is a thoughtful and repeatable process for managing that risk.
A bank should be able to demonstrate that it:
The discussion between Ben Mitzelfelt and Ben LeClaire explores how bank cybersecurity auditing has changed, why third- and fourth-party risk deserves greater attention, and how institutions can build more productive relationships with their audit partners.
The full podcast with real-world examples and deeper insights will be available soon on our YouTube page. In the meantime, please subscribe to our YouTube channel to be notified when it goes live.
Editor’s note: Some quotes have been lightly edited for clarity.