IT Audit & Cybersecurity Controls

IT Audit and Cybersecurity Controls Assessment

Hunter Audit Services performs independent IT audits and cybersecurity control assessments — evaluating how technology governance, security controls and technology risk are actually operating, not how they are described in a policy binder.

Hunter Audit Services does not provide penetration testing, managed security services, financial-statement audits, attest opinions, tax services or CPA services.

Discuss Your Audit Need See What Can Be Reviewed
The Business Problem

Most organizations know which framework they follow. Fewer can show the controls behind it are operating.

Technology environments grow through migrations, acquisitions, new platforms and integrations. Control coverage tends to lag behind that growth, and the lag is rarely visible until something forces the question.

Internal audit functions are often staffed for financial and operational work, with IT and cybersecurity coverage handled by whoever is available rather than whoever has the depth. Security tooling produces a large volume of information, but tooling output is not the same as an independent test of whether a control works.

The result is a gap between the control environment leadership believes exists and the one an auditor, regulator, insurer or customer would find.

Documented is not operating

A written policy, a purchased tool and an approved standard describe intent. Whether the control ran, who reviewed it, and what happened to the exceptions is a separate question.

Coverage follows the org chart

Control review often maps to who owns a system rather than where risk is concentrated, which leaves predictable gaps at the seams between owners.

Self-assessment fatigue

Questionnaires answered by the people responsible for the control are a starting point for an audit, not a substitute for one.

What Hunter Audit Services Does

Independent assessment, tested against evidence.

Scope is agreed in writing before fieldwork begins, so both sides know what is being examined and what is not. Control design is evaluated first, then operating effectiveness is tested against records that already exist — configurations, tickets, approvals, access records, logs and exception handling.

Findings are written as condition, cause, effect and recommendation, and ranked by risk so remediation can be sequenced rather than attempted all at once. Every finding is discussed before the report is finalized.

The work is principal-led. The person who scopes the engagement is the person who performs it.

  • Written scope agreed before fieldwork
  • Control design evaluated, then operating effectiveness tested
  • Evidence drawn from systems of record, not questionnaires
  • Findings ranked by risk, not listed alphabetically
  • Recommendations written to be actionable, not restated framework text
  • Closing discussion before anything is finalized
Areas That Can Be Reviewed

Scope is built from the risk, not from a standard checklist.

A single engagement usually covers a defined subset of the areas below. Reviewing everything at once produces a thinner result than reviewing the right things properly.

Access and Identity

  • User provisioning, modification and removal
  • Privileged and administrative access
  • Authentication and multi-factor controls
  • Periodic access recertification
  • Segregation of duties across systems
  • Service, shared and non-human accounts

Change, Configuration and Development

  • Change authorization, testing and approval
  • Configuration and hardening baselines
  • Patch and vulnerability management
  • System development and implementation controls
  • Environment separation and migration controls
  • Emergency and expedited change handling

Monitoring, Response and Data Protection

  • Logging coverage, retention and review
  • Security monitoring and alert disposition
  • Incident response readiness and documentation
  • Data classification and handling
  • Encryption in transit and at rest
  • Backup, recovery and resilience testing

Governance and Third Parties

  • IT and security policy structure and currency
  • Roles, accountability and oversight reporting
  • Risk acceptance and exception handling
  • Cloud and third-party service provider controls
  • Vendor security review and contract control expectations
  • Control ownership and evidence retention
Engagement Models

Four ways this work is typically engaged.

Defined Engagement

A single IT audit

One IT or cybersecurity audit, scoped to a specific area and delivered start to finish, with no ongoing commitment.

Plan Coverage

An audit-plan area

One or more IT audit areas within an annual plan, executed to internal audit’s methodology, templates and timelines.

Independent View

A review management can rely on

An assessment requested by management, a board or an audit committee that wants a view not produced by the function being reviewed.

After Findings

Remediation validation

Independent verification that corrective action taken on prior findings is actually in place and operating before the finding is closed.

Deliverables

What you receive.

Documentation is written to survive review by someone who was not in the room — an audit committee, an external assessor, or the next person to hold the role.

Written scope and objectives agreed before fieldwork
Documented testing with retained evidence references
Findings stated as condition, cause, effect and recommendation
Risk ranking so remediation can be sequenced
Executive summary written for leadership and boards
Workpapers suitable for internal quality review
Closing discussion before the report is finalized
Practical recommendations, not restated framework language

Written to be used

Reports are structured so a reader can find the significant items in the first page and the support for them in the rest. Findings that require translation before anyone can act on them have failed.

Scope limits stated plainly

The report says what was examined, what was not, and what conclusions the evidence does and does not support. Overstated assurance is worse than no assurance.

Who Does the Work

Experience that goes beyond framework knowledge.

Principal-Led

34 years inside the federal audit environment.

Engagements are led by Bret D. Hunter, CIA, a former Senior IT Auditor with the Treasury Inspector General for Tax Administration. His background includes 34 years in the Federal Inspector General audit environment and service as a Lead or Senior Auditor on numerous TIGTA cybersecurity audit reports involving complex technology environments and significant federal programs.

Certified Internal Auditor

More about Bret D. Hunter →

Best Fit

Where this work earns its cost.

Particularly useful when

  • Technology reliance has grown faster than control review
  • An audit plan includes IT or cybersecurity areas the team cannot staff
  • Leadership wants an independent view of the control environment
  • A customer, regulator, insurer or board is asking harder control questions
  • Prior findings need independent verification before they are closed
  • A framework is in place but has never been tested against evidence

Probably not the right fit if

  • You need penetration testing or technical security operations
  • You want an assessment written toward a predetermined conclusion
  • You need the same party to implement and then audit the same controls
  • You need a CPA attestation such as SOC 2 or a financial-statement opinion

What this service is not

Hunter Audit Services performs audit and assessment work. It does not sell, implement or operate security tooling, and it does not audit controls it designed or implemented. It does not issue attestation reports, authorizations to operate or certifications. Hunter Audit Services does not provide financial-statement audits, attest opinions, tax services or CPA services.

Related Services

Related capabilities.

IT audit work frequently connects to capacity, federal-control and technology-risk needs.

Get Started

Bring the audit need, not a finished scope.

Tell us briefly what you need, the type of organization involved and the timing. We will determine quickly whether Hunter Audit Services is a good fit.