From It Audit Findings to Cybersecurity Governance: A Risk-Based Remediation Framework for Critical Digital Infrastructure

Main Article Content

Josephat Deogratius Katundabwile
David Mbui Kamau

Abstract

An IT audit finding does not reduce risk. Risk falls only when an organisation understands the finding, connects it to a critical system or business service, determines its risk level, assigns an accountable owner, implements a treatment, verifies that the treatment worked, formally addresses whatever risk remains, and reports progress to those charged with oversight. Evidence from the auditing and information systems literatures indicates that this chain breaks routinely, and that findings accumulate as open items rather than closing as reduced exposure. This article asks how organisations can convert audit findings into prioritised, accountable, measurable, and verified remediation, with particular attention to critical digital infrastructure, where an unremediated weakness affects service continuity for dependent sectors rather than the audited organisation alone. Using a structured narrative literature review of thirty peer-reviewed sources and seven authoritative frameworks, the review identifies four recurring failure modes: findings disconnected from business impact, ownership that is nominal rather than accountable, verification treated as administrative closure, and residual risk accepted informally. Drawing on enterprise risk management integration guidance, governance accountability models, and exploit-based prioritization research, the article proposes an eleven-stage risk-based remediation framework running from finding validation through continuous monitoring, together with eight measures spanning timeliness, ownership, verification quality, and business linkage. The framework is proposed rather than empirically validated, and no claim is made that it has produced measured improvement in any organisation.

Article Details

Section

Articles

How to Cite

From It Audit Findings to Cybersecurity Governance: A Risk-Based Remediation Framework for Critical Digital Infrastructure. (2026). International Journal of Research Publications in Engineering, Technology and Management (IJRPETM), 9(4), 1614-1624. https://doi.org/10.15662/IJRPETM.2026.0904008

References

1. Alqahtani, N., & Almukaynizi, M. (2026). VulnScore: A deployed system for patch prioritization combining human input and temporal threat intelligence. International Journal of Information Security, 25, Article 2. https://doi.org/10.1007/s10207-025-01164-3

2. Amani, F., Magnan, M., & Moldovan, R. (2025). Cybersecurity risks and incidents disclosure: A literature review. Accounting Perspectives. https://doi.org/10.1111/1911-3838.12411

3. Büyüközkan, G., & Güler, M. (2025). Cybersecurity maturity model: Systematic literature review and a proposed model. Technological Forecasting and Social Change, 213, 123996. https://doi.org/10.1016/j.techfore.2025.123996

4. Calvin, C., Cybersecurity and Infrastructure Security Agency. (n.d.). Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA): Frequently asked questions. Retrieved August 19, 2026, from https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia/faqs

5. Chen, C., Hartmann, C. C., & Gottfried, A. (2022). The impact of audit committee IT expertise on data breaches. Journal of Information Systems. https://doi.org/10.2308/isys-2020-076

6. Culot, G., Nassimbeni, G., Podrecca, M., & Sartor, M. (2021). The ISO/IEC 27001 information security management standard: Literature review and theory-based research agenda. The TQM Journal, 33(7), 76–105. https://doi.org/10.1108/tqm-09-2020-0202

7. Eulerich, M., & Holt, M. (2025). Characteristics of cybersecurity and IT involvement by the IA activity. International Journal of Accounting Information Systems, 56, 100726. https://doi.org/10.1016/j.accinf.2025.100726

8. Eulerich, M., Huang, Q., Pawlowski, J., & Vasarhelyi, M. A. (2025). Using process mining as an assurance tool in the three-lines-model. International Journal of Accounting Information Systems, 56, 100731. https://doi.org/10.1016/j.accinf.2025.100731

9. Gale, M., Bongiovanni, I., & Slapničar, S. (2022). Governing cybersecurity from the boardroom: Challenges, drivers, and ways ahead. Computers & Security, 121, 102840. https://doi.org/10.1016/j.cose.2022.102840

10. Haapamäki, E., & Sihvonen, J. (2026). Mandatory cybersecurity disclosure: Early evidence from 10-K reports. International Journal of Accounting Information Systems, 57, 100775. https://doi.org/10.1016/j.accinf.2026.100775

11. Héroux, S., & Fortin, A. (2024). How the three lines of defense can contribute to public firms’ cybersecurity effectiveness. International Journal of Disclosure and Governance, 22(2), 377–396. https://doi.org/10.1057/s41310-024-00226-7

12. Imdieke, A. J. (2022). The role of timing and management’s remediation actions in preventing failed remediation of material weaknesses in internal controls. Contemporary Accounting Research, 39(1), 157–198. https://doi.org/10.1111/1911-3846.12725

13. Institute of Internal Auditors. (2020). The IIA’s three lines model: An update of the three lines of defense. The Institute of Internal Auditors.

14. Institute of Internal Auditors. (2026). Statement of position: The three lines model. The Institute of Internal Auditors.

15. ISACA. (2018). COBIT 2019 framework: Introduction and methodology. ISACA.

16. Jacobs, J., Romanosky, S., Adjerid, I., & Baker, W. (2020). Improving vulnerability remediation through better exploit prediction. Journal of Cybersecurity, 6(1). https://doi.org/10.1093/cybsec/tyaa015

17. Jacobs, J., Romanosky, S., Edwards, B., Adjerid, I., & Roytman, M. (2021). Exploit prediction scoring system (EPSS). Digital Threats: Research and Practice, 2(3), 1–17. https://doi.org/10.1145/3436242

18. Lois, P., Drogalas, G., Karagiorgos, A., Thrassou, A., & Vrontis, D. (2021). Internal auditing and cyber security: Audit role and procedural contribution. International Journal of Managerial and Financial Accounting, 13(1), 25. https://doi.org/10.1504/ijmfa.2021.116207

19. Lowry, M. R., Vance, A., & Vance, M. D. (2025). Inexpert supervision: Field evidence on boards’ oversight of cybersecurity. Management Science. https://doi.org/10.1287/mnsc.2023.04147

20. Mentzelou, K., Chountalas, P. T., Kitsios, F. C., Magoutas, A. I., & Dasaklis, T. K. (2025). Identifying and modeling barriers to compliance with the NIS2 directive: A DEMATEL approach. Journal of Cybersecurity and Privacy, 5(4), 97. https://doi.org/10.3390/jcp5040097

21. Miller, T., Staves, A., Maesschalck, S., Sturdee, M., & Green, B. (2021). Looking back to look forward: Lessons learnt from cyber-attacks on industrial control systems. International Journal of Critical Infrastructure Protection, 35, 100464. https://doi.org/10.1016/j.ijcip.2021.100464

22. Mojtahedi, A., & Zhou, L. (2024). Information technology internal control material weaknesses in financial reporting: Categories, trends, associations, and industry effects. International Journal of Accounting Information Systems, 53, 100679. https://doi.org/10.1016/j.accinf.2024.100679

23. National Institute of Standards and Technology. (2025d). Prioritizing cybersecurity risk for enterprise risk management (NIST Interagency Report 8286B, Update 1). https://doi.org/10.6028/NIST.IR.8286B-upd1

24. National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST Cybersecurity White Paper 29). https://doi.org/10.6028/NIST.CSWP.29

25. National Institute of Standards and Technology. (2025a). Identifying and estimating cybersecurity risk for enterprise risk management (NIST Interagency Report 8286A, Rev. 1). https://doi.org/10.6028/NIST.IR.8286Ar1

26. National Institute of Standards and Technology. (2025b). Integrating cybersecurity and enterprise risk management (ERM) (NIST Interagency Report 8286, Rev. 1). https://doi.org/10.6028/NIST.IR.8286r1

27. National Institute of Standards and Technology. (2025c). Staging cybersecurity risks for enterprise risk management and governance oversight (NIST Interagency Report 8286C, Rev. 1). https://doi.org/10.6028/NIST.IR.8286Cr1

28. Patterson, C. M., Nurse, J. R. C., & Franqueira, V. N. L. (2023). Learning from cyber security incidents: A systematic review and future research agenda. Computers & Security, 132, 103309. https://doi.org/10.1016/j.cose.2023.103309

29. Pollmeier, S., Bongiovanni, I., & Slapničar, S. (2023). Designing a financial quantification model for cyber risk: A case study in a bank. Safety Science, 159, 106022. https://doi.org/10.1016/j.ssci.2022.106022

30. Pursiainen, C., & Kytömaa, E. (2023). From European critical infrastructure protection to the resilience of European critical entities: What does it mean? Sustainable and Resilient Infrastructure, 8(sup1), 85–101. https://doi.org/10.1080/23789689.2022.2128562

31. Sarbanes-Oxley Act of 2002, Pub. L. No. 107-204, 116 Stat. 745 (2002).

32. Sathurshan, M., Saja, A., Thamboo, J., Haraguchi, M., & Navaratnam, S. (2022). Resilience of critical infrastructure systems: A systematic literature review of measurement frameworks. Infrastructures, 7(5), 67. https://doi.org/10.3390/infrastructures7050067

33. Savaş, S., & Karataş, S. (2022). Cyber governance studies in ensuring cybersecurity: An overview of cybersecurity governance. International Cybersecurity Law Review, 3(1), 7–34. https://doi.org/10.1365/s43439-021-00045-4

34. Slapničar, S., Axelsen, M., Bongiovanni, I., & Stockdale, D. (2023). A pathway model to five lines of accountability in cybersecurity governance. International Journal of Accounting Information Systems, 51, 100642. https://doi.org/10.1016/j.accinf.2023.100642

35. Slapničar, S., Vuko, T., Čular, M., & Drašček, M. (2022). Effectiveness of cybersecurity audit. International Journal of Accounting Information Systems, 44, 100548. https://doi.org/10.1016/j.accinf.2021.100548

36. Steinbart, P. J., Raschke, R. L., Gal, G., & Dilla, W. N. (2012). The relationship between internal audit and information security: An exploratory investigation. International Journal of Accounting Information Systems, 13(3), 228–243. https://doi.org/10.1016/j.accinf.2012.06.007

37. Steinbart, P. J., Raschke, R. L., Gal, G., & Dilla, W. N. (2018). The influence of a good relationship between the internal audit and information security functions on information security outcomes. Accounting, Organizations and Society, 71, 15–29. https://doi.org/10.1016/j.aos.2018.04.005

38. U.S. Securities and Exchange Commission. (2023). Cybersecurity risk management, strategy, governance, and incident disclosure (Release Nos. 33-11216; 34-97989; File No. S7-09-22). https://www.sec.gov/rules/final/2023/33-11216.pdf

39. Valkenburg, B., & Bongiovanni, I. (2024). Unravelling the three lines model in cybersecurity: A systematic literature review. Computers & Security, 139, 103708. https://doi.org/10.1016/j.cose.2024.103708

40. Vuko, T., Slapničar, S., Čular, M., & Drašček, M. (2024). Key drivers of cybersecurity audit effectiveness: A neo-institutional perspective. International Journal of Auditing. https://doi.org/10.1111/ijau.12365

41. Wallis, T., & Dorey, P. (2023). Implementing partnerships in energy supply chain cybersecurity resilience. Energies, 16(4), 1868. https://doi.org/10.3390/en16041868