Skip to Content

INDEPENDENT IT AND CYBERSECURITY AUDIT

Are your critical technology controls working in practice?

LiajLiajocom Consulting provides independent, risk-based audits of IT governance, cybersecurity, applications, infrastructure, cloud services, databases, operations and resilience.

The objective is to determine whether technology risks are understood, controls are appropriately designed and management can rely on evidence that those controls operate effectively.

Discuss an IT Audit

 Reliable technology depends on more than documented procedures

Critical business activities rely on interconnected applications, identities, databases, infrastructure, cloud services, external providers and operational processes. A weakness in one layer can undermine controls elsewhere.

Liajocom Consulting evaluates the control environment as an operating system of responsibilities, processes and technologies, rather than as a collection of isolated policy documents.

When an independent IT audit adds value

1

Assurance over critical services 

Establish whether the technology and controls supporting important business processes are reliable, secure and appropriately governed.

2

Change or transformation 

Assess risks introduced by cloud migration, system implementation, outsourcing, organisational change, security transformation or new operating models.

3

Independent challenge 

Provide management, boards, Internal Audit, Risk or regulated control functions with an objective assessment of a defined technology domain.

Questions the audit can answer


Determine whether decision rights, control ownership, risk acceptance, escalation and management oversight are defined and operate in practice.

Assess identity lifecycle controls, authentication, privileged access, segregation, periodic review, technical accounts and evidence of accountable use.

Evaluate whether changes are authorised, tested, segregated, traceable, deployed safely and supported by effective emergency procedures.

Examine monitoring, incident management, vulnerability handling, configuration, capacity, job execution, backup, recovery and operational responsibilities.

Assess continuity requirements, dependencies, recovery arrangements, testing, restoration evidence and management understanding of residual risk.

Evaluate supplier due diligence, contracts, performance, security, concentration, subcontracting, continuity, information rights and exit arrangements.

IT and cybersecurity audit scope

Engagements may cover one control domain, one system, one business process or a broader technology environment. Scope and test depth are determined by risk and agreed assurance objectives.

IT Governance

Technology strategy, decision structures, policies, accountabilities, risk ownership, management oversight, resource prioritisation, performance information and alignment with business objectives.

IT General Controls

Access management, change management, computer operations, control monitoring and other foundational controls supporting reliable systems and information.

Cybersecurity

Security governance, risk management, protective controls, vulnerability management, monitoring, incident response, configuration, awareness and evidence of operational effectiveness.

Identity and Access

Joiner, mover and leaver controls, authentication, authorisation, privileged access, technical accounts, segregation of duties, recertification and activity traceability.

Infrastructure and Cloud

Architecture, network security, hosts, platforms, cloud governance, configuration, administrative access, monitoring, tenancy, resilience and shared-responsibility arrangements.

Databases and Applications

Application access, configuration, interfaces, processing integrity, database administration, sensitive data, logging, batch controls, errors and technology-dependent business controls.

Change Management

Request, risk assessment, approval, development, testing, segregation, release, emergency change, rollback, documentation and post-implementation review.

Operations and Resilience

Monitoring, incidents, problems, jobs, capacity, availability, backup, restoration, continuity, disaster recovery, crisis arrangements and resilience testing.

ICT Third-Party Risk and DORA

Provider governance, due diligence, contracts, subcontractors, performance, security, incidents, concentration, continuity, testing, information rights, exit and alignment with relevant DORA control requirements.

A scope proportionate to the assurance need


Targeted IT Control Review

A focused assessment of one area, such as privileged access, vulnerability management, change control, cloud governance, backup or supplier oversight.


Suitable when:

  •  A specific concern has been identified
  •  An incident exposed a possible weakness
  •  A recent change requires assurance
  •  One control area needs deeper review


Typical output:

Focused conclusions, findings and recommended actions.

System or Process Audit

An end-to-end audit of the technology and controls supporting a particular application, infrastructure service or business process.


Suitable when:

  •  The system supports a critical activity
  •  Several controls must work together
  •  A major change altered the environment
  •  Internal Audit needs an independent conclusion


Typical output:

Scope-specific audit report and remediation register.

IT Control Environment Review

A broader assessment of governance, IT general controls, cybersecurity, operations, resilience and external dependencies.


Suitable when:

  •  No consolidated assurance view exists
  •  Several control areas need assessment
  •  Transformation has changed the risk profile
  •  Management needs clear priorities


Typical output:

Executive assurance report and risk-based roadmap.

Risk-based and evidence-driven

1

Understand

Establish the system’s purpose, stakeholders, architecture, lifecycle stage, decisions, dependencies, operating context and material risks.

2

Determine criteria

Identify applicable internal requirements, contractual obligations, governance expectations, control objectives and agreed assessment criteria.

3

Examine evidence

Review documentation, configurations, records, data flows, validation results, contracts, monitoring information, logs and other relevant evidence.

4

Test and challenge

Evaluate control design and operation, investigate exceptions, challenge assumptions and determine whether evidence supports management’s assertions.

5

Conclude and report

Connect observations to risks, control objectives, causes, consequences and practical remediation priorities.

Evidence, not promises

Evidence is selected according to the system, risk and audit objective. Liajocom Consulting seeks to corroborate statements through records, configurations and samples where access and scope permit.

Governance and lifecycle evidence

  •  Strategies, policies and standards
  •  Committee and management records
  •  Risk and control assessments
  •  Roles and responsibility matrices
  •  Procedures and operating records
  •  Service and performance reports
  •  Incident and problem records
  •  Change and release records
  •  Continuity plans and test results
  •  Supplier governance records

Technical and operational evidence

  •  Identity and access extracts
  •  Privileged-access records
  •  System and security configurations
  •  Network and architecture diagrams
  •  Vulnerability and patch information
  •  Logs and monitoring results
  •  Backup and restoration records
  •  Application and database settings
  •  Cloud control information
  •  Technical supplier evidence

Clear conclusions for management and control functions


Deliverable 1: Executive audit summary

Overall conclusion, significant risks, decisions required and management priorities.

Deliverable 2: Detailed control assessment

Design and operating-effectiveness conclusions for the controls included in scope.

Deliverable 3: Evidence-based findings

Clear description of condition, criteria, cause, consequence and recommended response, where supported by the engagement evidence.

Deliverable 4: Risk-prioritised remediation register

Practical actions organised by significance, dependency and agreed responsibility.

Deliverable 5: Scope and evidence trail

Record of systems, locations, periods, criteria, evidence and tests supporting the audit conclusion.

Deliverable 6: Closing presentation

Structured communication for management and relevant governance or control functions.

 Every material conclusion should be explainable. Every finding should be supported. Every recommendation should be actionable.

IT audit informed by hands-on technology experience


Independent

The purpose of the engagement is assurance, not the sale of security products, managed services or technology implementation. 

Technically grounded

Liajocom Consulting’s audit capability is built on prior experience across software, databases, Windows, Unix and enterprise information systems.

Audit-grade

More than ten years of IT audit experience in Luxembourg supports disciplined scoping, evidence assessment, professional challenge and reporting.

Founder-led

The professional responsible for scoping remains directly involved in testing, conclusions and reporting.

Important clarification


Liajocom Consulting can assess IT governance, controls, documentation, evidence and readiness against agreed criteria, including applicable local and EU regulations like DORA or GDPR.
Unless expressly agreed otherwise, the engagement is not a statutory conformity assessment, does not constitute legal advice and does not result in an official regulatory certificate. Legal interpretation remains the responsibility of the client and its qualified legal advisers.

Frequently asked questions

Yes. The engagement may focus on a single area, such as privileged access, cloud governance, database security, resilience or ICT third-party controls.

No. Control auditing and technical penetration testing are different activities. Liajocom Computing does not provide such specialised testing.

Yes. The engagement can be performed as an independent assignment within an approved Internal Audit plan or as a separate assurance review, subject to clearly defined responsibilities.

Yes. Recommendations are designed to address the identified risk and underlying control weakness. Final implementation decisions remain with management.

Yes. A process-oriented audit can examine both technology controls and the technology-dependent business controls required for reliable processing.

Do you need an independent view of a critical technology risk?

Discuss the system, control domain or business service that requires assurance.

Liajocom Consulting will help define a focused, risk-based scope.


Request a Confidential IT Audit Discussion