00:00:02 The IIA
The Institute of Internal Auditors presents All Things Internal Audit Tech.
00:00:06 The IIA
In this episode, Elizabeth Sullivan sits down with Anthony Pugliese and Matt Pearman to discuss Anthony's first-hand experience joining a global cybersecurity audit at Barclays.
00:00:17 The IIA
They discuss how the team planned and scoped an audit for an AI cloud platform, why senior leadership involvement matters,
00:00:24 The IIA
and how to balance structure with flexibility.
00:00:27 The IIA
Plus, they explore cyber resilience, third-party risk, and how to translate complex technical findings into clear insights for boards and executives.
00:00:37 Liz Sullivan
Matt, can you provide us some high-level context about the cyber risk audit at Barclays and what the team hoped to accomplish through this engagement?
00:00:46 Matt Pearman
Thanks, Liz.
00:00:47 Matt Pearman
Yeah, the cyber risk team at Audit is a large team.
00:00:50 Matt Pearman
It's a global team.
00:00:52 Matt Pearman
and has a number of technical specialists within it.
00:00:56 Matt Pearman
And as we do multiple audits a year on cyber risk.
00:01:00 Matt Pearman
The goal of this particular audit that Anthony was on was to look at the cloud AI platform that's used to build and run AI.
00:01:10 Matt Pearman
That platform is used to access models like Claude and GBT.
00:01:15 Matt Pearman
And the goal of the audit was to look at the controls around that platform and to ensure that the data and the security and the monitoring controls were in place.
00:01:26 Matt Pearman
And that's the assurance that the audit set out to provide, Liz.
00:01:30 Liz Sullivan
Matt, thank you so much for giving us that context and background.
00:01:34 Liz Sullivan
So now, Anthony, how did this opportunity to participate in this audit come about for you and what interested you about following an active audit engagement?
00:01:46 Anthony Pugliese
It was a wonderful opportunity.
00:01:47 Anthony Pugliese
I attended A New York chapter event earlier in the year and was seated between 2 Barclays internal audit leaders.
00:01:54 Anthony Pugliese
And I had mentioned that I wanted to be part of a cyber engagement.
00:01:58 Anthony Pugliese
It was something I hadn't done in quite a while.
00:02:01 Anthony Pugliese
And Barclay was about to begin the planning of its cybersecurity audit.
00:02:05 Anthony Pugliese
And I got an invitation a couple of weeks later.
00:02:09 Anthony Pugliese
I think what interested me the most is we have put so much work into the topic of cyber, including our cybersecurity topical requirement.
00:02:19 Anthony Pugliese
And I wanted to see that in action, but also understand
00:02:23 Anthony Pugliese
how a bank as large as Barclays also handled regulatory requirements and the cyber requirement and just how it managed all the different business aspects of it and who was involved, how long it would take, the kind of thing that would come up.
00:02:37 Anthony Pugliese
So I was interested in just about every angle of seeing one done now and given all the different things that we're dealing with, including AI affecting cyber.
00:02:47 Anthony Pugliese
So I was in the right place at the right time, Matt, I guess.
00:02:51 Anthony Pugliese
And I spoke up about my desire to do it, but really keenly interested, and now probably even more so.
00:02:58 Anthony Pugliese
that was sort of how it all came about.
00:03:00 Liz Sullivan
So looking back at this, let's call it a planning session in New York, what stood out to both of you, to each of you?
00:03:08 Liz Sullivan
What did you hope to gain from this collaboration?
00:03:11 Liz Sullivan
We'll start with you, Anthony.
00:03:13 Anthony Pugliese
I think what stood out to me during that planning exercise, and I was able to join the team live in New York as they were talking through all this, but the team discussion.
00:03:24 Anthony Pugliese
in your mind, that happens, but to actually watch that occur and with so many members of the team, what was really helpful, just the back and forth and understanding and discussion of risks, how the risk would be tackled.
00:03:36 Anthony Pugliese
But the discussion also had a lot of rigor to it, technically, as well as on a business sense.
00:03:43 Anthony Pugliese
What are the top risks?
00:03:45 Anthony Pugliese
What are the issues affecting the business?
00:03:47 Anthony Pugliese
What was the experience in the past?
00:03:49 Anthony Pugliese
So I really found that interesting to say the least.
00:03:52 Anthony Pugliese
And then also the focus on where value could be delivered to Barclays and thinking through all the ways value could be delivered so that there was actually something to report, not just the management to check a list and say it was finished, but to provide real tangible responses as part of the overall engagement and considering that up front in the planning process.
00:04:15 Anthony Pugliese
In your mind, you think that's probably how it works, but I got to actually see that occur.
00:04:19 Anthony Pugliese
hats off to Barclays and to Matt's team, but it was actually very impressive.
00:04:23 Anthony Pugliese
It was very colloquial, very top of mind.
00:04:26 Anthony Pugliese
People were able to kind of put their thoughts out there and that really stood out to me a lot.
00:04:31 Anthony Pugliese
Teamwork and collaboration, if I had to sum that up, I'll get in a couple words.
00:04:36 Liz Sullivan
That is awesome.
00:04:37 Liz Sullivan
Matt, what about you?
00:04:38 Matt Pearman
For me, it's really important that we got the industry-wide perspective and that was something I was particularly excited about with Anthony joining and being able to give us not only the
00:04:49 Matt Pearman
insight from the topical requirements and all the thoughts he had around how to apply that, but also his perspective on the wider industry.
00:04:57 Matt Pearman
And that certainly came through and it was extremely, extremely beneficial.
00:05:01 Liz Sullivan
Great.
00:05:02 Liz Sullivan
And no doubt with cybersecurity being the dominant top risk globally, I'm sure both of you felt very connected to this topic.
00:05:10 Liz Sullivan
So Anthony, let's talk a little bit about your experience.
00:05:13 Liz Sullivan
So from your seat,
00:05:14 Liz Sullivan
sitting in those sessions, how did you see the team approaching the planning and scoping of such a risk that's as broad and as fast moving as cybersecurity?
00:05:24 Anthony Pugliese
I mean, cyber is such a hard engagement.
00:05:25 Anthony Pugliese
So I'll admit, I think I caught about 80% of everything being said because the team was so technical.
00:05:32 Anthony Pugliese
The approaching of the risks overall wasn't just the risk of what happens if we have a cyber attack.
00:05:38 Anthony Pugliese
It was really thinking through the implications of cyber attacks
00:05:42 Anthony Pugliese
and really structuring the engagement, but also providing for flexibility.
00:05:47 Anthony Pugliese
One thing, I'll probably mention it a few times, but as I was speaking to the team on a follow-up call, one of them had attended Black Hat, the Black Hat Conference, and was able to come back midstream and actually add more insight into actually what was being done based on hearing the most current events, including how AI is being used to perpetrate cyber attacks.
00:06:11 Anthony Pugliese
So again, structure, but also flexibility was how I kind of saw the planning being approached and the risks being discussed.
00:06:20 Anthony Pugliese
And Barclays has a long history of being able to understand cyber issues as most banks would, especially a bank that is multinational and has to comply with not just one set of regulations, but multiple, certainly the UK, the US and everywhere else that they operate.
00:06:37 Anthony Pugliese
But structure and flexibility at the same time was actually pretty unique.
00:06:40 Anthony Pugliese
And
00:06:41 Anthony Pugliese
We don't ever want to see cyber audits become a checklist approach because it doesn't take into account the nuances that say a bank or any other regulated industry, but just any industry in general would face.
00:06:53 Anthony Pugliese
So I think that flexibility, it didn't catch me off guard.
00:06:57 Anthony Pugliese
I think it was just really refreshing to see how much made its way into the engagement.
00:07:01 Anthony Pugliese
Like I said, even trainings that the team went to and came back midstream and changed the approach or modified it was impressive.
00:07:09 Anthony Pugliese
It just really stood out.
00:07:11 Anthony Pugliese
while at the same time delivering on the deadlines and expectations of management.
00:07:16 Anthony Pugliese
So structure and flexibility.
00:07:18 Liz Sullivan
Was there anything different from what you expected going in?
00:07:21 Anthony Pugliese
Watching the flexibility, but also the training that the team was going through.
00:07:26 Anthony Pugliese
Matt, as I recall, there was a team right outside where we were working and their job was to better understand AI and they were looking at AI and cyber.
00:07:34 Anthony Pugliese
So there was also training of their newest hires on the topics.
00:07:39 Anthony Pugliese
That really stood out to me as engagement was being done.
00:07:42 Anthony Pugliese
And also, there were very junior people in the room.
00:07:44 Anthony Pugliese
And I think their job was to learn and to listen, as well as the folks that were leading the discussion.
00:07:51 Anthony Pugliese
That's a couple of things that come to mind.
00:07:53 Anthony Pugliese
And Matt and his management team were all there, of course, as well.
00:07:56 Anthony Pugliese
This wasn't done in the background.
00:07:59 Anthony Pugliese
And then all of a sudden, it was all over.
00:08:02 Anthony Pugliese
Somebody like Matt's handed a report.
00:08:04 Anthony Pugliese
He was very much a part of it throughout.
00:08:06 Anthony Pugliese
And I'm not sure I always thought of the
00:08:09 Anthony Pugliese
heads being that involved with the actual planning, it makes perfect sense.
00:08:13 Anthony Pugliese
But in an organization that large, I wasn't aware how close and hands-on certainly that was, but his whole team?
00:08:20 Liz Sullivan
Great.
00:08:20 Liz Sullivan
Well, thank you for sharing that.
00:08:21 Liz Sullivan
So Matt, let's talk to you a bit about this.
00:08:23 Liz Sullivan
So without discussing, of course, the specific findings and things of that nature, what are some of the challenges auditors may encounter when evaluating cyber controls?
00:08:34 Liz Sullivan
Can you share some of your thoughts about that?
00:08:36 Matt Pearman
Having a technical team has helped me
00:08:39 Matt Pearman
just referred to does bring some challenges with it.
00:08:41 Matt Pearman
And one of those is when setting the scope.
00:08:45 Matt Pearman
So when an audit team will go in and look at a particular area and the cybersecurity risks, there are so many controls that could be provided and added to the audit.
00:08:58 Matt Pearman
It's really a challenge to determine which ones are the most important, which ones are key controls.
00:09:05 Matt Pearman
and have the scope bound in a way that it makes sense that it fully addresses the risk and that all the most important and key controls are identified and are provided into the scope of the audit to ensure that there's
00:09:20 Matt Pearman
the right level of coverage and that the report can give the right level of assurance and the proper assurance that it seeks to provide.
00:09:28 Liz Sullivan
So now, Anthony, let's ask you this question.
00:09:31 Liz Sullivan
So did your understanding of Audit evolve as you continued meeting with Matt and his team over time throughout the course of the engagement?
00:09:39 Anthony Pugliese
Yeah, I think I walked in wanting to understand how the whole thing would be scoped.
00:09:44 Anthony Pugliese
I was kind of
00:09:45 Anthony Pugliese
really looking at it from how do you scope it?
00:09:47 Anthony Pugliese
How do you use the topical requirements?
00:09:49 Anthony Pugliese
How do you just look at the whole thing?
00:09:50 Anthony Pugliese
But as it developed, it was interesting to see how evidence was being gathered and challenged and then tied back into the overall conclusion that was being reached on the audit.
00:10:02 Anthony Pugliese
Again, I mentioned this earlier, but kind of that real-time reevaluation of what was being done, the evidence being gathered.
00:10:09 Anthony Pugliese
But I think it evolved in that way.
00:10:13 Anthony Pugliese
I think walking in though, I have to say, given such a large organization like Barclays or probably any of the other mega banks that are around the world, I had a high expectation of how it would be done.
00:10:24 Anthony Pugliese
And I think it probably exceeded it because I also found it to be rather practical.
00:10:30 Anthony Pugliese
I wouldn't say all the time it was just plain English and I understood everything that was going on, but it evolved.
00:10:35 Anthony Pugliese
And so did the way they collected evidence and looked at the evidence and again, tied it into the overall conclusions that were being reached.
00:10:42 Liz Sullivan
Great.
00:10:43 Liz Sullivan
So Matt, Anthony mentioned earlier about how impressed he was to have leadership at that level be engaged and be so connected to this audit.
00:10:51 Liz Sullivan
So what about your side of this?
00:10:54 Liz Sullivan
What impact did you think Anthony's continued involvement had on your audit team as part of this engagement and maybe even other stakeholders?
00:11:03 Matt Pearman
Certainly the thoughtful questions that Anthony came with, the team really enjoyed receiving and
00:11:11 Matt Pearman
It was a really thoughtful and engaged discussion with Anthony and that's something that I very much welcomed and I know the team really enjoyed from having Anthony on the engagement was that curiosity and that level of questioning on why the audit team is thinking about approaching the audit in a certain way.
00:11:35 Matt Pearman
That was a real benefit from having Anthony on the
00:11:39 Matt Pearman
audit and his continued engagement throughout as the weeks progressed and the audit got from planning into field work was truly valuable to have him question each step of the audit life cycle is it mature 3 to reporting.
00:11:56 Liz Sullivan
So here's a question for both of you.
00:11:59 Liz Sullivan
How can visible engagement from senior leadership strengthen internal audit's credibility and influence in an organization since you've both have had a recent experience here?
00:12:09 Anthony Pugliese
Visible support from senior leadership, it really signals that the work internal audit is doing is important, that it matters, and that people are expected to engage with it seriously.
00:12:21 Anthony Pugliese
Not that you don't expect that to happen, but when senior leadership comes in and does that, it's a signal that this is very important.
00:12:29 Anthony Pugliese
It also
00:12:30 Anthony Pugliese
builds credibility for internal audit.
00:12:32 Anthony Pugliese
So I think it's probably the most obvious answer I can think of, but support from senior leadership signals importance and it signals the team is being supported throughout the process.
00:12:43 Anthony Pugliese
And from what I observed at Barclays, and certainly they were being given the resources to get that done because senior leadership understood the complexity and the amount of effort it takes and the constant vigilance
00:12:55 Anthony Pugliese
I think the uniqueness of a bank at times, especially one as large as Barclays, is, I mean, they are particularly sensitive to cyber attacks.
00:13:05 Anthony Pugliese
You just think about the information that we all have sitting in our own banks about us, spending habits, money, just everything.
00:13:13 Anthony Pugliese
So it really was good to see that, as that consumer that we all are with banks, just to watch how that happens.
00:13:21 Anthony Pugliese
I haven't switched my accounts over to Barclays yet, Matt.
00:13:23 Anthony Pugliese
It may be in the future, but that's how I saw senior leadership strengthen the overall process.
00:13:29 Matt Pearman
And from my perspective, just to build on what Anthony's saying, I think the read across from other areas is something that senior leadership has a good line of sight on and can bring into an audit sometimes examples that they've seen elsewhere for the audit team to consider and have a different perspective or at least provide some of the read across
00:13:51 Matt Pearman
that they may have been seeing in other areas.
00:13:54 Liz Sullivan
So how can senior leaders engage meaningfully with internal audit and increase awareness, kind of like what Anthony mentioned earlier on, and also doing all this while preserving the functions and dependents?
00:14:07 Liz Sullivan
What are your thoughts on that?
00:14:08 Liz Sullivan
And either one of you can go on this one.
00:14:10 Anthony Pugliese
I tend to go toward the basic things that kind of stood out to me.
00:14:14 Anthony Pugliese
Asking questions is such an important part of it.
00:14:18 Anthony Pugliese
You don't want to say, okay, you guys go get the cyber audit done and let me know how it goes.
00:14:22 Anthony Pugliese
Again, it's asking questions, giving context for why it's important to senior leadership.
00:14:27 Anthony Pugliese
I mean, sometimes it's not as obvious as we want to protect the bank's infrastructure from a cyber attack.
00:14:32 Anthony Pugliese
There are other reasons as well.
00:14:34 Anthony Pugliese
So that context is important.
00:14:36 Anthony Pugliese
And you know, where it matters, although I didn't see this at Barclays is removing barriers.
00:14:41 Anthony Pugliese
And really, I did see this, really reinforcing the importance of cooperation, obviously not just within internal audit and the cyber team, but across the bank.
00:14:51 Anthony Pugliese
So everybody understands that this is really important.
00:14:55 Anthony Pugliese
And the further down you get an interview.
00:14:57 Anthony Pugliese
in an organization at times, people, yeah, cyber is important, but it's not my thing.
00:15:02 Anthony Pugliese
It's important that significance is stressed by senior leadership.
00:15:06 Anthony Pugliese
So questions, removing barriers, making sure everybody knows how important it is, what the implications of a breach can be to a bank, bringing it to its knees, crippling it, disruption of service for days sometimes.
00:15:19 Anthony Pugliese
But I think leaders can engage meaningfully that way without
00:15:24 Anthony Pugliese
impairing independence, throwing questions in and removing roadblocks and giving context does not impair independence.
00:15:31 Anthony Pugliese
You're listening as an internal auditor to what those things are.
00:15:35 Anthony Pugliese
And it adds to the value of your work.
00:15:37 Anthony Pugliese
And you're doing the work and you're also providing valuable input back to senior leadership about what they're also worried about.
00:15:45 Anthony Pugliese
But Liz, it actually goes back to our Vision 2035 research that we completed a couple of years ago.
00:15:51 Anthony Pugliese
Internal audit
00:15:53 Anthony Pugliese
providing value to senior leadership as much as providing value in getting their work done and assessing risks, but that additional layer of providing true value to where leadership can say, that's worth something valuable to me.
00:16:06 Anthony Pugliese
So some ideas?
00:16:08 Matt Pearman
Totally agree with what you said, Anthony.
00:16:10 Matt Pearman
And from a senior leadership engagement perspective, naturally it's
00:16:15 Matt Pearman
very important to ensure the independence of the function is maintained.
00:16:20 Matt Pearman
One of the things a senior leader can do is bring their perspective on emerging risk from where they sit and what they see and what is on their mind.
00:16:30 Matt Pearman
I think that is something that senior leaders can really bring with them and add value to an internal audit and increase the awareness of the audit team and give even better assurance from that.
00:16:43 Liz Sullivan
All right, so let's talk a little bit about cyber resilience and some key takeaways from your experience.
00:16:49 Liz Sullivan
So very specifically here, beyond identifying gaps and weaknesses, both of you have mentioned value during the course of your conversation so far today.
00:16:59 Liz Sullivan
So what role can internal audit play in supporting an organization's cyber resilience?
00:17:05 Liz Sullivan
That will certainly be value at the table.
00:17:07 Anthony Pugliese
Understanding how to respond, recover, adapt from a cyber incident
00:17:13 Anthony Pugliese
something that could happen is obviously pretty critical.
00:17:16 Anthony Pugliese
And not all organizations have a really strong cyber response plan.
00:17:21 Anthony Pugliese
If you do, it's probably going to be updated pretty quickly because of AI and all the other risks that are becoming more and more important as AI is combined with cyber.
00:17:29 Anthony Pugliese
But also just governance is another big one.
00:17:34 Anthony Pugliese
And Liz, we've looked at that at IIA a few times.
00:17:37 Anthony Pugliese
we know that governance is probably one of the easiest areas for an internal auditor to move in to say whether this organization is adequately looking at how cyber and AI are being used.
00:17:49 Anthony Pugliese
But governance overall, decision making when something happens or before something happens, internal audit identify something and no one does anything about it, that's not good.
00:17:59 Anthony Pugliese
And the last thing, and I could have mentioned this earlier as well during the planning phase,
00:18:04 Anthony Pugliese
But so many third-party dependencies exist, including your suppliers, third-party risk, another one of our newer topical requirements.
00:18:14 Anthony Pugliese
For this reason, most of these attacks are perpetrated not directly at the organization, but through one of its suppliers or vendors.
00:18:22 Anthony Pugliese
That is something I don't think a lot of people think is strongly about.
00:18:26 Anthony Pugliese
Sometimes we get letters from our suppliers or vendors and it says, yes, our controls are good, but not everyone looks at the controls
00:18:34 Anthony Pugliese
at a third party that a business relies on at the same level of scrutiny you would your own organization, yet it's just as viable an entry point, if not the most common entry point, especially into an organization like a bank, where you've probably got a lot of third parties that help support the bank's operation.
00:18:51 Anthony Pugliese
So I think those are some of the things that internal audit can do and can play, a role it can play in supporting just overall resilience.
00:19:00 Matt Pearman
An institute like the IIA provides a lot of structure and framework and standards that organizations can benefit from.
00:19:11 Matt Pearman
And one role that internal audit can play, for example, with the topical requirements on cyber, is sharing what they're seeing come out from some of these important institutions like the IIA.
00:19:24 Liz Sullivan
How can internal auditors translate complex cybersecurity observations into clear, meaningful information for their executives and the board?
00:19:34 Liz Sullivan
Matt, let's start with you.
00:19:35 Matt Pearman
I think one of the key ingredients to having a clear and meaningful message is to identify what is the root cause and be clear on that.
00:19:46 Matt Pearman
And then secondly, if there are any themes that might be emerging from any audit work, that's important as well.
00:19:54 Matt Pearman
And then thirdly, management's progress and their response to anything that might need to be addressed in any remediation activity.
00:20:03 Matt Pearman
I think that is also important to be clear around what is management that is the first line or second line doing in response to any messages that need to be given.
00:20:15 Liz Sullivan
All right, thank you for that, Matt. Anthony, what about you?
00:20:19 Anthony Pugliese
That was a good response. Let me take it from maybe just an additional angle. And I think a lot of times a lot of these complex findings sometimes need to be translated into true business implications. Like you can say, well, here's the problem, here's the remediation. People think, okay, that's great. But it probably would be helpful to say to a
00:20:42 Anthony Pugliese
I'm sure the board at Barclays has probably been inundated with cyber information and cyber understanding and training. But in many organizations, the board is not always able to jump in to these kind of complex things, whether it's cyber or AI or any other complex emerging disruptive technology. But when you tell a board, here's the finding,
00:21:04 Anthony Pugliese
and here's the business implication if that finding is not resolved or mitigated. I think it's very important to translate these kinds of complex things into what could go wrong if it's not taken care of. Maybe you found something that could go wrong that already went wrong at another organization. And it's important that they understand in plain English terms
00:21:27 Anthony Pugliese
what that actually means. And I think that adds value to internal audit. And Liz, it also speaks to, as you remember from being chair of our North American board, us talking about communication skills becoming the number one skill to many chief audit executives for their teams is being able to take these complex things and explain them in an easy to understand format. So, you know, again, business implications, not just the technical side, you know, what could happen?
00:21:56 Anthony Pugliese
if we don't take care of this. So to me, it would be, maybe that's me sitting on that border audit committee is being able to take that and say, this is what could happen to you.
00:22:05 Liz Sullivan
Absolutely. I completely agree. Being able to bring meaning and clarity around cyber risk is important because cyber attacks are not about if it would happen in our environment. It's about when it would happen. So certainly appreciate that. What should audit take away from this engagement about given organizational
00:22:26 Liz Sullivan
greater insight into how audits are planned and performed? Matt, would you like to take this one?
00:22:33 Matt Pearman
The team certainly felt inspired by having Anthony engaged. And secondly, I thought the questions really helped get to the heart of the matter at pace to ensure that the team was really well focused and they were applying their deep technical knowledge in a way that could be understood by
00:22:54 Matt Pearman
a wider audience and having that involvement really allowed the team to move at pace and get to that point. And then lastly, as I was mentioning, I think the external perspective was so valuable to really think just beyond the institution itself, but even broader than that.
00:23:13 Liz Sullivan
Anthony, your thoughts about this one?
00:23:15 Anthony Pugliese
I think it gives greater visibility
00:23:18 Anthony Pugliese
to the discipline that's applied when doing an internal audit engagement, especially on something like cyber. And I'm sure everyone thinks there's a level of discipline, but one thing I was struck by was it was a balance of like, not common sense, but it made perfect sense when explained to me about the planning process and what was being looked at, what was not being looked at. You know, cyber is difficult. You can't look at 100% because you don't even know what the fraudsters are doing next.
00:23:46 Anthony Pugliese
especially with AI, but it gives greater visibility into the discipline and the rigor and the planning and execution and the results that come out of it. So when they understand that, those results and observations become, certainly would be to me, much more valuable to management, audit committees, and boards. So I think it really does
00:24:07 Anthony Pugliese
highlight the kind of work we do in a far more visible way. And again, it lends a lot more credibility to what we find when people understand like, wow, that's quite a scope, you looked at a lot. And again, not to make it a checklist, but to make it tangible. And this gives them the ability to do that.
00:24:24 Liz Sullivan
So it certainly sounds like you both had a really great experience here. So if you were to think about it, if you had one lesson, one from each of you that you'd like to listeners to take away from this engagement about cyber
00:24:36 Liz Sullivan
security auditing, leadership, involvement, the value of internal audit altogether, what would it be? Anthony, would you like to start on this one?
00:24:46 Anthony Pugliese
Yeah, it's a tough one because there's so much. I certainly wish all organizations and all internal audit teams had the ability to look at cyber the way I saw it being looked at at Barclays. Despite being a regulated industry, it still was a tremendous amount of rigor. And
00:25:02 Anthony Pugliese
I think the team's collegiality throughout the process was impressive. Again, you kind of expect that, but to see it happening was good. Combining rigor with relevance and a little bit of common sense, I think goes a long way. So those are the things that I walked away with common sense being someone going to a conference on cybersecurity in the middle of the cyber engagement and bringing all that back and saying, let's do a little few things different here or there. I think that was just great. So rigor,
00:25:32 Anthony Pugliese
with relevance and a little bit of common sense. So a few of the takeaways from what I saw at Barclays.
00:25:38 Liz Sullivan
And Matt, one lesson or takeaway from you to our listeners?
00:25:41 Matt Pearman
I think having someone as senior as Anthony on the audit just really provides such a broad perspective around all of the things that could be considered and the level of
00:25:53 Matt Pearman
questioning and perspective that he brought was extremely valuable for the team and it actually made the audit really enjoyable as well. It sounds like Anthony got a lot from it. I certainly did, but I can also say
00:26:06 Matt Pearman
A lesson for me was the team really enjoyed the audit and having the opportunity to have someone as seen as answer me, ask them about their area and their area of specialism and take a real interest in them. And I think that was something I certainly would seek to do again.
00:26:23 Anthony Pugliese
Yeah, and Liz, one additional thing I have to say, because I haven't mentioned her before in all this,
00:26:28 Anthony Pugliese
But Matt's team was actually kind of fun to work with. Maybe it was because they were trying to be nice to a guest, but I don't think so. I think they were generally a very fun group to be around. But particularly Leanne, I'm going to probably say her name wrong. Everyone says my name wrong, but Leanne Mascarenas, am I saying that right? But Leanne was just really a force. And I mean that in the most positive way. She knew her stuff.
00:26:52 Anthony Pugliese
And I think smiling a lot through the engagement and keeping everyone engaged, it's not easy to set an engagement like this. So also has a really good team around him, no doubt from him hiring them and putting them in the positions they are. But that also helps quite a bit of relevance and the whole way you approach an engagement like that. There's some personality behind it. And that has to be someone that can bring a team together. And that's another one of those Vision 2035 things about soft skills being teamwork.
00:27:21 Anthony Pugliese
and not something every internal or external auditor comes to the table with naturally. That might be one of her core skills from what I saw, but a great team also, very critical.
00:27:32 Liz Sullivan
I love it when auditors put those soft skills to work, don't you? It's awesome. So now finally, Anthony, now that you've participated in a live cyber risk audit from to back,
00:27:44 Liz Sullivan
How is this experience and the knowledge going to impact the future of IRA standards, guidance, or educational resources?
00:27:51 Anthony Pugliese
It was good. I mentioned last time, I think the last time I did cyber engagement, dating myself, 2017, maybe 2016, when I was still running an internal audit team. But I think the experience was just a great direct view at how a current modern engagement's being done. So obviously we're putting out standards, our cyber requirement, topical requirement, and guidance, lots of guidance.
00:28:14 Anthony Pugliese
And it really reinforced to me the need to do that, and maybe even start to bring our guidance down a few levels into the more of the hands-on approach to learning how to do it, because when I saw it being done.
00:28:28 Anthony Pugliese
hands-on, I was able to really walk away with a clear understanding. So I think the standards and guidance and bringing that guidance into a more tangible level and maybe even offering our guidance, beginner, intermediate, advanced, expert kind of levels so that we hit everybody kind of where they are.
00:28:44 Anthony Pugliese
and also provide training and formats that appeal to people. I like to see things. Some people like to just read or listen, but having all of that available as tools and resources is important. So it reinforces what we're doing, but maybe accelerates some of the ideas we had in it.
00:29:01 Liz Sullivan
So Matt and Anthony, thank you for an insightful and candid conversation. Today's discussion reinforces that cybersecurity auditing is not only about evaluating controls, it is in fact about strengthening resilience, communicating risks clearly, and building trust through meaningful leadership engagement. Thank you both for sharing your perspectives, and thank you to our listeners for joining us.
00:29:26 Anthony Pugliese
Thank you.
00:29:28 The IIA
If you like this podcast, please subscribe and rate us. You can subscribe wherever you get your podcasts. You can also catch other episodes on YouTube or at theiia.org. That's T-H-E-I-I-A.org.