Aller au contenu

O papel da Auditoria Interna na Gestão de Riscos Cibernéticos em Instituições Financeiras Brasileiras - Estudo sob a perspectiva das três linhas

Enregistré dans:
Détails bibliographiques
Auteur principal: Ferreira, Lucas Vinicius
Date de publication: 2024
Format: Master thesis
Langue: por
Source: Repositório Comum do Brasil - Deposita
Download full: https://deposita.ibict.br/handle/deposita/736
Résumé: The increasing digitalization of the global financial sector, driven by the demand for fast and personalized services, faces significant challenges with the increase in cyberattacks, requiring a joint effort from all sectors of the company to manage cyber risks. This work aimed to identify ways in which internal audit can generate value and contribute to ensuring the effectiveness and improvement of processes related to cyber risk management within Brazilian financial institutions. To achieve the proposed objective, semi-structured interviews were conducted with 16 professionals from the areas of internal audit, risk management and information security, representing 10 financial institutions. Bardin’s content analysis methodology (2016) was used to analyze the collected data, allowing the categorization and interpretation of current practices and challenges faced in cyber risk management. The results demonstrated that internal audit plays an important role in ensuring the effectiveness of cybersecurity controls, including, depending on the context, conducting penetration tests to validate implemented controls. The use of analytical data to conduct continuous auditing was also highlighted as an effective strategy to identify emerging risks. However, there are still significant challenges to be faced, such as the need to integrate cyber risk management into the corporate strategy of institutions. To overcome this, it was suggested that assessments focusing on these risks be carried out when designing new business models and products. In addition, to improve cyber risk management, the findings suggest the need for constant updating of processes and controls in response to new threats, as well as the adoption of new technologies, such as artificial intelligence and machine learning, which can improve the detection and mitigation of cyber threats. The work identified 53 context units or key success factors, in addition to 50 benefits and 52 challenges to be faced in the active participation of internal audit in cyber risk management within financial institutions.