The assessment of cybersecurity risks in businesses from the perspective of information systems risk management and independent audit: A study on audit firms
Is this your thesis?
This record came from a bulk archive import. If it’s yours, link it to your profile.
Abstract (EN)
The level of dependency of businesses on information systems has rapidly increased in recent years. This situation has brought not only advantages but also disadvantages such as cybersecurity risks to businesses. Referencing cybersecurity risks faced by businesses in audit reports by independent audit firms has become a significant topic lately. The audit of cybersecurity risks has become an important issue that all audit firms, regardless of their size, need to pay attention to. However, it is not yet known whether the activities of independent auditors working in different-sized firms regarding the audit of cybersecurity risks are equally competent. In this context, the aim of the study is to determine if there is a difference in the effectiveness of activities related to the audit of cybersecurity risks among independent auditors working in firms of different sizes, in terms of identified sub-dimensions. Accordingly, as of May 2023, the employees of 384 active audit firms affiliated with the Public Oversight, Accounting and Auditing Standards Authority have been considered as the research population and grouped according to the sizes of independent audit firms into two categories: "the Big Four" and "others". Therefore, PwC, KPMG, Deloitte, and Ernst & Young firms have been referred to as "the Big Four", while the remaining 380 firms have been labeled as "others". Quantitative research methods were employed in the study, and data was collected using survey techniques. It was found that there should be a minimum of 28 independent auditors in each group for sample calculation. Considering potential losses, the research was initiated with the aim of reaching a minimum of n=30 for each group. When the number of participants reached n=33 for the Big Four and n=72 for the others, data collection was concluded after conducting a power analysis, which determined the statistical power of the research to be 99.9%. According to the findings of the research, significant differences were identified (p<0.001) between independent auditors working in the Big Four and those working in other firms in terms of the corporate approach of independent audit organizations to the audit of cybersecurity risks, information systems audit related to environmental and physical security, and other sub-dimensions addressed in the research. This study, which reveals the differences in approaches to the audit of cybersecurity risks by employees of independent audit organizations based on their sizes, is expected to make a significant contribution to future studies.
Author
Serkan Akın
Institution
How to Cite
Serkan Akın (Doctorate thesis). The assessment of cybersecurity risks in businesses from the perspective of information systems risk management and independent audit: A study on audit firms, 2023, Nevşehir Hacı Bektaş Veli University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Nevşehir Hacı Bektaş Veli University
- Implicature in Turkish(2023)
- The effect of geography lessons which are planned with the STEM method on students' attitudes and 21st century skills(2023)
- Arrangement patterns of verb-deriving construction affixes in Turkish(2025)
- An examination of the relationship between social studies teacher candidates' integrative self-knowledge and perception of good citizenship(2025)
- Commentaries of muammâ in Turkish literature and Muammâyî Ahmed Çelebi's Şerh-i Muammeyât-ı Emrî (Transcribed text-analysis)(2023)
- The stages that have experienced Wahhabism from it's birth to it's present(2023)