INTHEBLACK September 2026 - Flipbook - Page 57
partner in accounting and business advisory
at Findex.
“Lack of preparedness for an attack is
still a very common issue in our profession.
Not just being prepared to defend against
attacks, but being prepared to respond when
those defences are breached.
“We are constantly advised to have a ‘breach
mindset’, but we rarely see this in practice until
a breach actually occurs and lessons are learned
the hard way,” he notes.
CYBER RESILIENCE
A common cybersecurity model is the
“three pillars” of People, Process/Policy and
Technology, which work in unison to underpin
cyber resilience. This resilience ensures not only
the capability to defend against attacks, but
also to reduce the impact of successful attacks
and weather the storm.
This three-pillar approach means that
finance professionals are required to be across
business-critical processes and policies, from
cyber governance and operational resilience
to Cyber Security Incident Response Plans
and disclosure obligations.
An incident response plan includes internal
and external communication processes in
the event of an incident, as well as the roles,
responsibilities, accountabilities and authorities
of personnel and teams.
In the aftermath of an attack, Wise says
that a lack of preparedness, inadequate
processes and insufficient governance can pose
longer-lasting reputational risk to a business
than the actual attack itself. Finance leaders
do not need a computer-science degree in
order to help stakeholders support cyber
resilience, he believes. Yet they do require
the insight to ask the right questions about
issues like data residency, backup procedures
and incident response plans.
“For example, this means not only ensuring
that backup procedures are in place with
multiple copies, but also that backups are
tested to ensure they can actually be relied
on in the event of a cyber incident,” Wise says.
“Ultimately, finance professionals do not need
to have all the technical answers, but they do
need to be able to show that cybersecurity
defence is a priority and is being factored into
decisions and processes.”
LISTEN
to a podcast
episode on AI
and cybersecurity
READ
an article on how
to protect yourself
from deepfakes
EXPLORE
CPA Australia’s range
of cybersecurity
courses
intheblack.cpaaustralia.com.au 57