Accessibility

Day 2 of the Critical Sector Auditing and Risk Analysis Workshop

Following the high-level opening conference, the second day of the critical sector auditing and risk analysis workshop for Malaysia focused on understanding different auditing approaches and their uses.

Sessions led by EU CyberNet experts Christian Schlehuber, Ilmar Toom and Nick Small, introduced participants to different auditing approaches in order to understand how structured maturity assessment can help evaluate organisational resilience. Speakers highlighted that good audits improve resilience not only compliance. 

The main take-aways included: 

  • Risk-based cybersecurity auditing must prioritise threats and vulnerabilities based on their likelihood and potential impact. This approach links security evaluations directly to organisational risk tolerance and strategic objectives, enabling decision-makers to allocate resources efficiently. 
  • Compliance-based cybersecurity auditing ensures cybersecurity aspects have been embedded into workflows. This helps to determine the maturity level of compliance. 
  • Technical-based cybersecurity auditing evaluates whether established controls are adequately designed, implemented and applied which helps to ensure coverage. 
  • Inspection and verification approaches facilitate understanding about how effective the cybersecurity measures are. 
  • The final session discussed the importance of follow-up activities after auditing such as developing plan to drive improvement and control auditing, but also understanding the value of collaborative reviews to identify opportunities for improving the auditing process itself.  

Links 



Keep reading similar articles
EU CyberNet Launches Expert Podcast Series

EU CyberNet launches a podcast series to bridge the expertise from EU CyberNet’s Expert Pool and its partners to wider cybersecurity and cyber capacity building community on people, policies and practices shaping cybersecurity globally.

The 9th Blog Article of the EU CyberNet Expert Blog Series: When AI Makes Cybersecurity Decisions: Five Governance Questions Every Organisation Should Answer

EU CyberNet has published the ninth blog article in its Expert Blog Series. The ninth article, titled “When AI Makes Cybersecurity Decisions: Five Governance Questions Every Organisation Should Answer” is written by EU CyberNet Expert Anahiby Becerril.

The 8th Blog Article of the EU CyberNet Expert Blog Series: The Institutional AI Dependency Test: Can Public Services Continue When AI Cannot Be Trusted? An Evidence-Led Governance Exercise for Cyber Resilience

EU CyberNet has published the eight blog article in its Expert Blog Series. The eight article, titled “The Institutional AI Dependency Test: Can Public Services Continue When AI Cannot Be Trusted? An Evidence-Led Governance Exercise for Cyber Resilience” is written by EU CyberNet Expert Andra T. Alcalá.

Reflecting EU CyberNet Summer School 2026: Participants’ Testimonials

EU CyberNet asked four EU CyberNet Summer School 2026 participants – Gabrielle Botbol, Emmanuel Chagara, Olesya Danylchenko and Lisbeth Laurie – to share their experience in the Summer School.

Reflecting EU CyberNet Summer School 2026: Andrea Calderaro

EU CyberNet discussed with Summer School 2026 participants their experience and thoughts on the future of cyber diplomacy. Read an interview with our co-organiser Andrea Calderaro, Project Director of EU Cyber Direct.

EU CyberNet Participated in Regional Cybersecurity Exchange and the Launch of the Cyber Cluster Global Alliance in Costa Rica

EU CyberNet,together with LAC4, participated in the EU-LAC Digital Alliance technical exchange visit on cybersecurity and secure connectivity in Central America and the Cybersec Summit 2026 in San José, Costa Rica on 11-12 August 2026.