A chief audit executive at Brentwood Utilities concludes that senior management has accepted a level of cyber risk that may exceed what the organisation can bear. The chief audit executive wants to follow the correct sequence for communicating this concern. What is the appropriate course?
- ADiscuss the matter with senior management first, and if the chief audit executive concludes it remains unresolved, communicate it to the board. Correct
- BReport the accepted risk directly to the external regulator before raising it internally, since the exposure could harm parties beyond the organisation.
- CRecord the disagreement in the working papers and take no further step unless the risk later materialises into an actual loss.
- DEscalate the matter to the board straight away without first discussing it with senior management, to protect the function's independence.
Why A is correct: Correct: the sequence is to raise the accepted risk with senior management, and where the chief audit executive judges it unresolved, escalate to the board for their attention.
Why B is wrong: Tempting because cyber failures can affect outsiders, but the defined process routes the concern through senior management and the board internally, not to a regulator ahead of any internal escalation.
Why C is wrong: Tempting because documentation is expected, but recording alone does not satisfy the duty to discuss the matter with senior management and escalate it if it stays unresolved.
Why D is wrong: Tempting because independence matters, but bypassing senior management skips the first step of the process, which gives management the chance to resolve the concern before board escalation.