Moore Stephens
Forensic Accounting

The importance of internal control in the IT age

Internal control plays an important role in every company, enabling it to achieve its objectives by controlling the associated risks.

An increasingly important dimension of internal control is cybersecurity. In fact, technology is constantly evolving, and companies are facing ever greater and more diversified cyber-attack risks.

According to a 2017 Statistics Canada study, 21% of Canadian companies were affected by a cybersecurity incident. For 38% of incidents, the intention was to steal money or demand a ransom, as opposed to 23% of incidents involving the theft of personal and financial information .

Clearly, the more your organization uses information technology, the more it will be a target for criminals. Take, for example, a clothing store that uses an online sales platform, as opposed to a convenience store that sells its products only on-site. The clothing store is much more exposed to information security risks. As a result, it will have to implement a greater number of internal controls relating to cybersecurity. A financial institution will also be highly targeted, given its customers’ personal banking information. What’s more, most companies use computer networks that can be hacked to steal personal and financial data.

 

Are you prepared to minimize the consequences/avoid a cyber attack?

  • Do you have a backup copy of your data? Is it encrypted?
  • Do you have a virtual private network (VPN) for employees who connect to your network remotely?
  • What is your validation process when an employee forgets a password?
  • Have you secured your online services platform?

By choosing to conduct its business activities using information technologies, an organization exposes itself to a number of risks, both for itself and for its customers. It is therefore responsible for securing sensitive information through internal controls. It’s also important to have someone who can take over if there’s a problem with the person responsible for passwords, access or encryption keys.

Examples of internal controls :

  • Firewall;
  • Lock offices and premises;
  • Manage access rights by profile;
  • Data encryption.

Cyber attacks can occur for a variety of reasons and through a variety of methods. It is therefore desirable for a company to be fully prepared to face these threats. To do this, you must :
1. Define the risks relevant to your business
2. Identify the information assets to be protected
3. Establish an internal control process.

In addition, it is vital that the people who create, manage and monitor controls have integrity and ethics, as they will be responsible for the effectiveness of internal control procedures. Failure to do so can expose your organization to major consequences: hacking, loss of reputation, data theft.

Finally, analyzing your environment is a good way to start building an internal control process tailored to your business, and there’s no good time to do it!

We’re here to help! Write to us!

 Enquête canadienne sur la cybersécurité et le cybercrime, 2017
 L’article suivant présente l’impact du décès d’un p.d.g étant le seul à connaitre le mot de passe pour accéder à la cryptomonnaies : https://www.ledevoir.com/economie/547153/des-millions-en-cryptomonnaies-inaccessibles-apres-la-mort-d-un-p-d-g.

Subscribe to receive our advice.

RECENT NEWS

Always well informed

Navigating uncertainty: key challenges for businesses in 2026

For businesses, 2026 looks set to be a year of tight navigation. Uncertainty is no longer just background noise: it now shapes business decisions. Geopolitical, commercial, financial, technological uncertainty… Everything is moving forward, but rarely in a straight line.

READ

The Future of Cryptocurrency Tax Reporting

This article was written by John Liu, CPA, Senior Tax Director at SEGAL LLP, as part of the quarterly newsletter dedicated to Canadian news. This publication is produced by the Canadian member firms of the Moore North America network. This in-depth analysis of cryptocurrency taxation is part of our commitment to remain your trusted partner [...]
READ

Getting Ready For an Audit: A Canadian Company’s Guide

This article comes from DMCL and is part of the quarterly newsletter on Canadian news, a publication produced by the Canadian member firms of the Moore North America network. It discusses strategies that enable companies to effectively prepare for a financial audit, a topic that fits perfectly with our mission to be your preferred partner [...]
READ

Prescribed Rate Drops to 3%: A Tax Planning Opportunity

Nav Pannu, CPA, Partner at DMCL, authored this article as part of the quarterly Canadian news bulletin published by the Canadian member firms within the Moore North America network. This piece provides valuable insights into the recent prescribed interest rate reduction and exemplifies our dedication to serving as your trusted partner by delivering timely updates [...]
READ
  • Montréal
  • Brossard
  • Close to you wherever you go
  • Laval
  • Montréal
  • Brossard
  • Close to you wherever you go
  • Laval
  • Montréal
  • Brossard
  • Close to you wherever you go
  • Laval
  • Montréal
  • Brossard
  • Close to you wherever you go
  • Laval