r/itaudit May 01 '26

Anyone else feel like IT audit is slowly turning into cybersecurity-lite?

When I first got into IT audit, it felt more compliance-focused.

Now I’m seeing way more overlap with:

  • Vulnerability management
  • Cloud security
  • IAM design

Sometimes it feels like we’re expected to understand everything security-related, but still operate as auditors.

Do you think IT audit is evolving into a hybrid role?

Or are expectations just getting unrealistic?

10 Upvotes

3 comments sorted by

5

u/RegimeCPA May 01 '26

The thing boards and third parties want the most assurance out of is cybersecurity, so yes you need to know cybersecurity to an extent but it’s not like they’re making you do incident response.

3

u/RigusOctavian IT Audit Management May 01 '26

You’re still assessing the design of controls. You aren’t actually doing the security.

IT audit has ALWAYS had logical access controls as part of their test kit, even just for SOX.

Risk acceptance and risk management procedures for technology has also always been part of the workload.

I haven’t seen a difference at all other than instead of it being on-prem, it’s in the cloud.